We break what's supposed to be unbreakable.
conditionId = keccak256(legs)
BASE_HASH_BITS = 128 / 256
Polymarket V2 identified every combinatorial basket by a keccak hash truncated to 128 bits — leaving 64-bit collision resistance on an identifier that custodied the entire pUSD backing.
By colliding two economically distinct baskets to the same truncated id, an attacker could redeem a cheap, worthless position as an expensive one — minting unbacked pUSD against the full ~$422M vault. Every step was permissionless. The report shipped three executable Foundry PoCs and a measured cost curve for the collision grind.
It was rejected twice as "asserted, not demonstrated." The dispute grounded the grind in real cryptographic precedent — SHAttered and SHA-mbles — plus candidate-space math, and separated the conceded bug from the one step no PoC can show by construction.
Read the full report on Cantina →A security researcher specializing in zero-knowledge proof systems, pairing-based cryptography and blockchain runtime security — with escalated and paid findings across Cantina, Code4rena, Immunefi and HackerOne. Full-time blockchain-security research at Argentina's National Atomic Energy Commission (CNEA) since 2023, on top of years building and auditing smart contracts.
| Target | Severity | Outcome | Platform |
|---|---|---|---|
| Polymarket V2 — unbacked pUSD mint via 128-bit id collision | High | $100K · fixed | Cantina |
| Phantom | Medium | Paid | Cantina |
| zkVerify / EZKL Verifier — VK-controlled loop, 2,400% block delay | High | Paid | Immunefi |
| Rujira / THORChain — liquidation repay / SharePool undercharge | Medium | Paid | Code4rena |
| Glow Finance — collateral theft, gradual insolvency | Low | Paid | Code4rena |
| SKALE SGXWallet — key-export oracle, DKG leak, SEK-on-disk | Critical | Prepared | HackerOne |
| Chainlink Price Auctions v2 — CowSwap partial-fill DoS, stale-feed freeze (~$91K) | High + Medium | Paid | Code4rena |
| GMX Solana — unbounded competition, VirtualInventory desync | Low | Paid | Code4rena |
| Injective Peggy — fee index rebuild, cross-chain composability | Low | Paid | Code4rena |
| Jupiter Lend — missing oracle confidence/deviation check | Medium | Paid | Code4rena |
| Renegade Dark Pool — non-constant-time HMAC, timing side-channel | Medium | Paid | Code4rena |
| Monero-oxide — 16,667× fee inflation via quantization mask | Medium | Paid | Immunefi |
cantina.xyz/u/gasfedev code4rena/@Mariscal Immunefi #1734 HackerOne HackenProof
Focused engagements on the parts of a protocol where value actually moves.
Line-by-line review of Solidity, Vyper, Rust and Move — scoped to your protocol's real threat model, not a checklist.
Identifier schemes, hashing, signatures, accounting invariants — the structural failures that survive a normal audit.
Every finding ships with a running Foundry test that executes the exploit — crypto-real, not a happy-path assertion.
We start from how the protocol pays out, then work backward to what breaks the invariant — attacker's seat, not reviewer's.
The Polymarket bug lived under a reviewed bit-layout. Hardened, already-audited code is exactly where the deep bugs hide.
No finding leaves without an executable PoC and a cost model. If it can't be demonstrated, it isn't submitted.
A separate line of products, running on our own self-hosted compute.