<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>Asymmetric Research</title>
    <link>https://asymmetric.com/blog/</link>
    <description>Security research from Asymmetric Research</description>
    <item>
      <title>Under the Hood: Engineering Commonware Fuzzing</title>
      <link>https://asymmetric.com/blog/under-the-hood/</link>
      <guid>https://asymmetric.com/blog/under-the-hood/</guid>
      <pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate>
      <description>Fuzzing Commonware isn't a pile of one-off harnesses. It's engineered: deterministic runtime, controlled randomness, reviewable fuzz targets, reproducible crashes, promoted regressions.</description>
    </item>
    <item>
      <title>All Roads Lead to Panic: A Starknet Oracle Story</title>
      <link>https://asymmetric.com/blog/all-roads-lead-to-panic-a-starknet-oracle-story/</link>
      <guid>https://asymmetric.com/blog/all-roads-lead-to-panic-a-starknet-oracle-story/</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <description>Pragma is one of Starknet's main oracles, pricing collateral and liquidations for lending protocols holding tens of millions on-chain. This post explains how a missing access-control check could have let anyone disable its core price feeds for a few cents.</description>
    </item>
    <item>
      <title>Across Solana Event Spoofing</title>
      <link>https://asymmetric.com/blog/across-solana-event-spoofing/</link>
      <guid>https://asymmetric.com/blog/across-solana-event-spoofing/</guid>
      <pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate>
      <description>On Solana, events are often reconstructed from transaction traces, and failed transactions still emit data. This bug in Across could have allowed attackers to spoof deposit events and trick relayers into filling orders with no real deposit behind them.</description>
    </item>
    <item>
      <title>Solana p-token: Catching a Bug Before Mainnet</title>
      <link>https://asymmetric.com/blog/solana-p-token-catching-a-bug-before-mainnet/</link>
      <guid>https://asymmetric.com/blog/solana-p-token-catching-a-bug-before-mainnet/</guid>
      <pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate>
      <description>CU optimizations come with risks. This post details a critical bug we found in p-token before mainnet, subtle enough to survive in a heavily scrutinized codebase.</description>
    </item>
    <item>
      <title>Understanding Agents: Code Coverage for Coding Agents</title>
      <link>https://asymmetric.com/blog/understanding-agents-code-coverage-for-coding-agents/</link>
      <guid>https://asymmetric.com/blog/understanding-agents-code-coverage-for-coding-agents/</guid>
      <pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate>
      <description>When an agent audits your codebase, a common question is: what did it actually read and with what intent? Current tools don't answer that. We built a prototype and open-sourced it.</description>
    </item>
    <item>
      <title>Solana Vulnerabilities That Aren’t: Unpacking Common Misreports</title>
      <link>https://asymmetric.com/blog/solana-vulnerabilities-that-arent-unpacking-common-misreports/</link>
      <guid>https://asymmetric.com/blog/solana-vulnerabilities-that-arent-unpacking-common-misreports/</guid>
      <pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate>
      <description>The most persistent security misinformation doesn't come from obscure corners of the internet, but from official docs, learning resources, and popular LLMs. Learn about the Solana vulnerabilities that aren't, and why they keep spreading.</description>
    </item>
    <item>
      <title>Wrong Offset: Bypassing Signature Verification in Relay</title>
      <link>https://asymmetric.com/blog/wrong-offset-bypassing-signature-verification-in-relay/</link>
      <guid>https://asymmetric.com/blog/wrong-offset-bypassing-signature-verification-in-relay/</guid>
      <pubDate>Mon, 22 Sep 2025 00:00:00 GMT</pubDate>
      <description>Relay Protocol's contracts trusted Ed25519 verification without validating offsets, opening the door to forged allocator signatures and potential double-spends. Learn about the bug, the risks it posed to cross-chain liquidity, and how the issue was addressed.</description>
    </item>
    <item>
      <title>Threat Contained: marginfi Flash Loan Vulnerability</title>
      <link>https://asymmetric.com/blog/threat-contained-marginfi-flash-loan-vulnerability/</link>
      <guid>https://asymmetric.com/blog/threat-contained-marginfi-flash-loan-vulnerability/</guid>
      <pubDate>Wed, 17 Sep 2025 00:00:00 GMT</pubDate>
      <description>A new instruction broke the flash loan logic, creating a way to borrow without repaying and putting $160M at risk. We explain the vulnerability, potential impact, and how it was fixed.</description>
    </item>
    <item>
      <title>Behind the Scenes of a Blocked Phishing Attempt</title>
      <link>https://asymmetric.com/blog/threat-contained-behind-the-scenes-of-a-blocked-phishing-attempt/</link>
      <guid>https://asymmetric.com/blog/threat-contained-behind-the-scenes-of-a-blocked-phishing-attempt/</guid>
      <pubDate>Tue, 01 Jul 2025 00:00:00 GMT</pubDate>
      <description>An attacker posing as a well-known web3 founder messaged one of our engineers via Telegram. Rather than ignoring the attempt, we isolated and analyzed the payload in a controlled environment, turning a live phishing attempt into a learning opportunity. </description>
    </item>
    <item>
      <title>Boredom Over Beauty: Why Code Quality is Code Security</title>
      <link>https://asymmetric.com/blog/boredom-over-beauty-why-code-quality-is-code-security/</link>
      <guid>https://asymmetric.com/blog/boredom-over-beauty-why-code-quality-is-code-security/</guid>
      <pubDate>Tue, 03 Jun 2025 00:00:00 GMT</pubDate>
      <description>Some of the most devastating vulnerabilities stem from complexity, inconsistency, and chaos. This post explains why predictable, well-formed code is the foundation of security.</description>
    </item>
    <item>
      <title>Finding Fractures: An Intro to Differential Fuzzing in Rust</title>
      <link>https://asymmetric.com/blog/finding-fractures-an-intro-to-differential-fuzzing-in-rust/</link>
      <guid>https://asymmetric.com/blog/finding-fractures-an-intro-to-differential-fuzzing-in-rust/</guid>
      <pubDate>Thu, 15 May 2025 00:00:00 GMT</pubDate>
      <description>In the year 2050, a malformed JSON input lead to the complete shutdown of the Replicant P2P network. Today, we'll reproduce this bug class in ~100 lines of code.</description>
    </item>
    <item>
      <title>Invocation Security: Navigating Vulnerabilities in Solana CPIs</title>
      <link>https://asymmetric.com/blog/invocation-security-navigating-vulnerabilities-in-solana-cpis/</link>
      <guid>https://asymmetric.com/blog/invocation-security-navigating-vulnerabilities-in-solana-cpis/</guid>
      <pubDate>Wed, 23 Apr 2025 00:00:00 GMT</pubDate>
      <description>Cross-program invocation (CPI) is the mechanism on Solana through which one program calls another. It's used for system instruction calls, SPL token transfers, custom program execution, and even event emissions, making it a core part of writing functional programs in Solana.</description>
    </item>
    <item>
      <title>Corrupt Commitments: Proposer Equivocation Bug in Helix MEV Relay</title>
      <link>https://asymmetric.com/blog/corrupt-commitments-proposer-equivocation-bug-in-helix-mev-relay/</link>
      <guid>https://asymmetric.com/blog/corrupt-commitments-proposer-equivocation-bug-in-helix-mev-relay/</guid>
      <pubDate>Fri, 06 Dec 2024 00:00:00 GMT</pubDate>
      <description>This blogpost details a vulnerability identified in Titan's Helix MEV Relay which could be abused by trusted proposers to perform equivocation attacks, during which private transaction information is prematurely revealed, leading to potential transaction reordering.</description>
    </item>
    <item>
      <title>Ghost in the Block: Ethereum Consensus Vulnerability</title>
      <link>https://asymmetric.com/blog/ghost-in-the-block-ethereum-consensus-vulnerability/</link>
      <guid>https://asymmetric.com/blog/ghost-in-the-block-ethereum-consensus-vulnerability/</guid>
      <pubDate>Thu, 19 Sep 2024 00:00:00 GMT</pubDate>
      <description>In this blog post, we will show how a small difference in SSZ deserialization between the Prysm and Lighthouse clients could have allowed an attacker to severely degrade Ethereum consensus.</description>
    </item>
    <item>
      <title>Circle's CCTP Noble Mint Bug</title>
      <link>https://asymmetric.com/blog/circles-cctp-noble-mint-bug/</link>
      <guid>https://asymmetric.com/blog/circles-cctp-noble-mint-bug/</guid>
      <pubDate>Tue, 27 Aug 2024 00:00:00 GMT</pubDate>
      <description>We privately disclosed a vulnerability to Circle via their bug bounty program. The vulnerability could have been exploited by circumventing the CCTP message sender verification process to mint fake USDC tokens on Noble.</description>
    </item>
    <item>
      <title>Evmos Precompile State Commit Infinite Mint</title>
      <link>https://asymmetric.com/blog/evmos-precompile-state-commit-infinite-mint/</link>
      <guid>https://asymmetric.com/blog/evmos-precompile-state-commit-infinite-mint/</guid>
      <pubDate>Thu, 01 Aug 2024 00:00:00 GMT</pubDate>
      <description>This post details a vulnerability we identified in Evmos, an EVM-compatible Cosmos chain, that could have been exploited to mint infinite amounts of $EVMOS tokens. Due to EVM state commits during precompile execution, it could cause a mismatch between the state held within EVM and the Bank module.</description>
    </item>
    <item>
      <title>Cosmos IBC Reentrancy Infinite Mint</title>
      <link>https://asymmetric.com/blog/cosmos-ibc-reentrancy-infinite-mint/</link>
      <guid>https://asymmetric.com/blog/cosmos-ibc-reentrancy-infinite-mint/</guid>
      <pubDate>Tue, 16 Apr 2024 00:00:00 GMT</pubDate>
      <description>This post discusses a vulnerability in ibc-go, a reference implementation of the Cosmos Inter-Blockchain Communication (IBC) protocol. A reentrancy vulnerability during the handling of timeout messages could have allowed an attacker to mint an infinite amount of IBC tokens on affected Cosmos chains.</description>
    </item>
    <item>
      <title>Ethereum Log Confusion in Polygon's Heimdall</title>
      <link>https://asymmetric.com/blog/polygon-log-confusion/</link>
      <guid>https://asymmetric.com/blog/polygon-log-confusion/</guid>
      <pubDate>Thu, 08 Feb 2024 00:00:00 GMT</pubDate>
      <description>In this post, we describe a vulnerability in Heimdall, the validator software of the Polygon Proof-of-Stake (PoS) blockchain. This flaw, if exploited, could have allowed a rogue/compromised validator to take over the Heimdall consensus layer and inject fraudulent events into the StakeSync mechanism.</description>
    </item>
  </channel>
</rss>