RESEARCH & WRITING
Vulnerability analysis, bug-hunting methodology, and DeFi security — for auditors and the teams they report to.
- 01
Utilizing the Feedback Loop Properly to Find More Bugs
7 minThe security community's version of the feedback loop is missing the reward that makes habits actually stick. A framework for deliberately training bug-pattern recognition using cue, craving, response, and reward.
methodology - 02
The Whitehat System Is Broken. Here Is What Needs to Change.
6 minWhen a Renegade Finance attacker returned funds after negotiating a 'bounty,' part of the security community sympathized. Why that wasn't a whitehat story — and what bug bounty infrastructure actually needs to fix.
disclosure - 03
Find More Bugs by Learning to Break a Protocol's Assumptions
6 minInvariants sit on top of assumptions, and that's where most exploits live. A framework for finding the beliefs a protocol depends on and testing whether they actually hold.
methodology