Security intelligence for an onchain world.
Timely analysis, field notes, and company perspectives for the teams responsible for securing Web3.
- Publications
- 22
- Editorial tracks
- 3
- Access
- Open archive
01 / Latest
Stories worth your attention
The newest analysis and updates from the ExVul security team.

Source Says 50. Bytecode Says 0: The Sui Move Compiler Bug That Could Silently Drop Payments
Smart contracts execute bytecode, not the source developers review. We investigate a fixed Sui Move match-lowering bug that could erase a value-flow branch, turning a modeled 50-unit credit into 0 while still producing valid, verifiable bytecode.
Sui Mainnet Halt of May 28, 2026: An Address Balance Gas Underflow Post-Mortem
A deep post-mortem of the May 28, 2026 Sui mainnet stall: a single missing case at the seam of Address Balance and coin reservations let a failed transaction emit a poisoned accumulator Split, underflowing the per-checkpoint settlement system transaction and halting every validator.
HB Token Exploit Analysis: ~$193K Lost to AMM Reserve Manipulation via Reward Path
On April 7, 2026, HB Token on BSC was exploited for ~$193,936 USDT. The attacker leveraged a structural flaw in the protocol's reward distribution mechanism — tightly coupled with live AMM reserve mutations — to distort internal spot pricing and drain the pool.
02 / Archive
Browse every publication
Research, incident analysis, and updates from across ExVul.
Showing 19 publications

One Line, All Funds: How a Static IV Turned Nightly Wallet's Encryption Into a Two-Time Pad
A single const declaration at module scope reused the same AES-CTR initialization vector for every encryption call, enabling full mnemonic and private key recovery from any Nightly Wallet vault — without ever knowing the user's password.

How a One-Byte Discriminator Can Silently Break Anchor's Event System
A deep dive into a dispatch hardening gap in the Anchor framework where custom discriminators can shadow the Event CPI sentinel, silently disabling the event system with no compiler warnings.

In-Depth Security Risk Analysis of the Fingerprint Browser Industry
A comprehensive security analysis revealing systemic vulnerabilities in fingerprint browsers that have led to millions in losses. This report examines real-world incidents, technical vulnerabilities, and the dangerous trust model these products create for users managing high-value digital assets and cryptocurrency wallets.
SwapNet Attack Analysis: $13.43M Lost to Arbitrary Call Vulnerability
A detailed vulnerability analysis of the SwapNet protocol exploit on January 25, 2026, where an attacker exploited arbitrary call vulnerabilities in the smart contracts to steal approximately $13.43 million across multiple blockchains.

Truebit Protocol Attack Analysis: 8,535 ETH Lost to Integer Overflow
A detailed vulnerability analysis of the Truebit Protocol exploit on January 8, 2026, where an attacker exploited an integer overflow vulnerability in the token purchase price calculation logic, resulting in a loss of 8,535.36 ETH.

Deep Dive: The yETH Weighted StableSwap Exploit - Part 1
An in-depth analysis of the yETH Weighted StableSwap exploit, exploring how the transition from Curve's invariant to a weighted model introduced critical vulnerabilities through product-term collapse.

HackQuest Collaboration
We're excited to announce that ExVul has officially partnered with HackQuest to advance Web3 security education and training across the ecosystem.

ExVul Partners with Bitget Exchange
ExVul is proud to announce our strategic partnership with Bitget, one of the world's leading cryptocurrency exchanges.

Securing the SEI Blockchain Ecosystem
ExVul has completed a comprehensive security audit of the SEI blockchain's core infrastructure and smart contract platform.

OKX Exchange Security Collaboration
ExVul announces security collaboration with OKX, providing smart contract auditing services for their DeFi products.

TON Smart Contract Security Deep Dive
A comprehensive analysis of security considerations for smart contract development on The Open Network (TON).

Auditor's Handbook: Dissecting the Security Layers of Clarity
A comprehensive comparison of Clarity and Solidity smart contract languages from a security auditor's perspective.

DeFi Security Best Practices for 2024
Essential security practices for DeFi protocol developers based on our audit experience across hundreds of protocols.

NFT Smart Contract Security Guide
Common vulnerabilities in NFT contracts and how to prevent them, based on our analysis of major NFT exploits.

Cross-Chain Bridge Security Analysis
Deep dive into cross-chain bridge vulnerabilities that have led to billions in losses.

Flash Loan Attack Patterns and Prevention
Comprehensive analysis of flash loan attack patterns observed across DeFi protocols.

Chrome Extension Wallet Ciphertext Replacement Attack
Many chrome extension wallets use indexedDB to store encryption key data, but there exists a cipher text replacement attack that can steal user's private keys or mnemonic phrases.

Solana Program Security Guide
Security considerations unique to Solana program development and common vulnerability patterns.

Move Language Security on Aptos
Security analysis of the Move programming language and Aptos-specific considerations.
The signal, without the noise.
A concise briefing of new threats, incident analysis, and ExVul field notes.
- Material security developments
- New technical analysis
- No promotional clutter