Web3 security research

Adversarial security research for web3 protocols.

We break what's supposed to be unbreakable.

Disclosed on Cantina · Code4rena · Immunefi

Signature finding

A 128-bit shortcut that put $422M at risk

Polymarket V2 identified every combinatorial basket by a keccak hash truncated to 128 bits — leaving 64-bit collision resistance on an identifier that custodied the entire pUSD backing.

$100K
bounty awarded
$422M
backing at risk
2^64
collision resistance
Fixed
confirmed & patched

By colliding two economically distinct baskets to the same truncated id, an attacker could redeem a cheap, worthless position as an expensive one — minting unbacked pUSD against the full ~$422M vault. Every step was permissionless. The report shipped three executable Foundry PoCs and a measured cost curve for the collision grind.

It was rejected twice as "asserted, not demonstrated." The dispute grounded the grind in real cryptographic precedent — SHAttered and SHA-mbles — plus candidate-space math, and separated the conceded bug from the one step no PoC can show by construction.

Read the full report on Cantina →
Verdict trail
  1. 2026 · Jun 9
    Rejected — "collision asserted, not demonstrated"
  2. 2026 · Jul 15
    Rejected again on re-review
  3. 2026 · Aug 6
    Pulled from rejected, fixed, paid $100K
Track record

Findings on the record

A security researcher specializing in zero-knowledge proof systems, pairing-based cryptography and blockchain runtime security — with escalated and paid findings across Cantina, Code4rena, Immunefi and HackerOne. Full-time blockchain-security research at Argentina's National Atomic Energy Commission (CNEA) since 2023, on top of years building and auditing smart contracts.

TargetSeverityOutcomePlatform
Polymarket V2 — unbacked pUSD mint via 128-bit id collision High Cantina
Phantom Medium Cantina
zkVerify / EZKL Verifier — VK-controlled loop, 2,400% block delay High Immunefi
Rujira / THORChain — liquidation repay / SharePool undercharge Medium Code4rena
Glow Finance — collateral theft, gradual insolvency Low Code4rena
SKALE SGXWallet — key-export oracle, DKG leak, SEK-on-disk Critical Prepared HackerOne
Chainlink Price Auctions v2 — CowSwap partial-fill DoS, stale-feed freeze (~$91K) High + Medium Code4rena
GMX Solana — unbounded competition, VirtualInventory desync Low Code4rena
Injective Peggy — fee index rebuild, cross-chain composability Low Code4rena
Jupiter Lend — missing oracle confidence/deviation check Medium Code4rena
Renegade Dark Pool — non-constant-time HMAC, timing side-channel Medium Code4rena
Monero-oxide — 16,667× fee inflation via quantization mask Medium Immunefi

cantina.xyz/u/gasfedev code4rena/@Mariscal Immunefi #1734 HackerOne HackenProof

Services

What we do

Focused engagements on the parts of a protocol where value actually moves.

Smart-contract audits

Line-by-line review of Solidity, Vyper, Rust and Move — scoped to your protocol's real threat model, not a checklist.

Protocol & cryptographic review

Identifier schemes, hashing, signatures, accounting invariants — the structural failures that survive a normal audit.

Adversarial PoC testing

Every finding ships with a running Foundry test that executes the exploit — crypto-real, not a happy-path assertion.

Approach

How we find what others miss

01

Adversarial-first

We start from how the protocol pays out, then work backward to what breaks the invariant — attacker's seat, not reviewer's.

02

We go where audits passed

The Polymarket bug lived under a reviewed bit-layout. Hardened, already-audited code is exactly where the deep bugs hide.

03

Every claim runs

No finding leaves without an executable PoC and a cost model. If it can't be demonstrated, it isn't submitted.

Also from Builders Alfa Tech

We build AI infrastructure, too

A separate line of products, running on our own self-hosted compute.

ChatPyme

AI that answers your WhatsApp, 24/7.

Visit →
Marioneta

An assistant that triages your team's internal chat.

Visit →
Inferencia

OpenAI-compatible LLM API, one endpoint, no lock-in.

Visit →