Map the deployed system.
We map the protocol as an economic machine: the target with the tokens, oracles and routers it trusts. We reason about the graph as it runs today, not a fresh repo before launch.
Authorized fork-based exploitability testing
A private blockchain security firm running a 23-chain intelligent hive. It fork-proves drains before attackers do, and ships proof only when value actually moves. Proof, not opinion.
§01 The premise
So we don't read it like a document. We map it like a machine: the target with every token, oracle and router it trusts. Then we take it apart from the outside, the way the people who take these things apart actually do.
At the current block, with the tokens, oracles and routers your contracts already trust. Not a fresh repo. Not an idealised diagram of one.
Every path we take is one a stranger could take today for the price of gas. An owner using powers they already hold is not an exploit; it is a governance decision.
A candidate path becomes a finding when value has moved to an account the outsider controls, and not before. Everything else is refuted and thrown away.
§02 Track record
Two kinds of number, kept honestly apart. Under a single client mandate we measured $11M of at-risk exposure across 32 permissionless zero-days, value quantified in the audit, never extracted. Separately, the autonomous engine has independently fork-proven a 14,050 USDT drain on BSC: value that actually moved to an outsider's account, reproducible on demand. A candidate counts only after the honesty layer rejects washes and phantom mints. No inflated counts, no hallucinated issues. If it doesn't reproduce, it doesn't ship.
LIVE The hunt
How we operate, run live: map the graph, propose the path, then write a working exploit and run it against a forked mainnet. When it reverts, the swarm reads the failure and rewrites it, escalating each pass until value moves or the path dies. Every proven drain sharpens the next hunt. Independently fork-proven: a 14,050 USDT drain on BSC, reproducible on demand.
The animation behind this text is decorative. It shows a target contract resolving, its satellite contracts and value-flow edges being mapped, six agents probing candidate attack paths, most paths being refuted, two surviving paths fusing into one chain, and value flowing to an attacker-controlled address where the profit is measured as an atomic balance delta.
§03 How we operate
We map the protocol as an economic machine: the target with the tokens, oracles and routers it trusts. We reason about the graph as it runs today, not a fresh repo before launch.
From an unprivileged outsider with no special access, we enumerate the permissionless paths that could move value. Each is a falsifiable claim, not a guess.
For each candidate the engine writes a complete, self-contained exploit, compiles it, and runs it against a mainnet fork with flash-sized capital. When it reverts, the failure is fed back and the exploit is rewritten, escalating the stake each pass, until value moves or the attempts run out. We execute the path, not describe it.
The same meter as the hunt: an atomic balance delta on the outsider's own accounts. This mandate measured $11M of at-risk exposure. Value was quantified, not extracted. If value didn't move, it isn't a finding.
An adversarial pass tries to refute every result before it is reported. A claim the measurement can't reproduce is demoted, not shipped.
You get a working exploit, a measured extraction, and the steps to reproduce it, under coordinated disclosure. Where funds are at risk, a rescue lane returns them to a pre-registered safe harbor, never to us.
§04 Selected findings
Four representative findings, redrawn from disclosed engagements. Client identities and addresses are withheld; the mechanism is not.
Share price reads spot reserves from an AMM whose depth a single flash-funded trade can move. In one transaction the caller can mint, push the price, then redeem against inflated backing, and value leaves the vault's own reserves.
A view getter reads pool balances during an ERC-777 transfer callback, mid-update. Integrators that price against it see a momentarily inconsistent state and can be induced to misvalue collateral.
Division is applied before multiplication and truncation consistently favors the caller. Repeated over a loop the dust compounds past de-minimis, and an empty-vault first depositor can set an extreme share price.
A delegated module uses unstructured storage whose layout collides with the proxy's owner slot. A crafted call through the module can overwrite the admin without any privileged role.
§05 Ground truth
Before anything reasons about anything, six reading heads go down and take measurements off the chain and the code. The council argues from those, not from guesses.
Proxy and implementation slots, owner and admin, paused flags, role assignments, read at the current block. Turns "possibly uninitialized" into a fact.
The source is scanned for dangerous shapes: unguarded external calls, reentrancy ordering, missing initializer guards, tx.origin auth. Leads, never proof.
Every simulated call reports the internal token and ETH transfers it actually caused, and decodes the reason for anything that reverted.
The target is matched against known vault, lending and AMM lineages, and that family's documented incident history is pulled into scope.
Real supply, reserves and share price, so attack sizing uses real numbers. First-depositor and donation-inflation surfaces are flagged on sight.
Hardcoded secrets, forgeable signatures, privileged plain-wallet admins, keys leaked in calldata, predictable randomness. Read-only. No key is ever used to sign.
§06 Published research
The method, then the defense written against it.
Mephis: A Recursive Reinforcement Hive for Coordinating Agent Swarms in Weaponized Exploitation of Smart Contracts
A six-agent swarm that writes its own exploits, and a deterministic runtime that believes only what it can drain. Every conjecture is authored as code, run against a forked mainnet, and confirmed or refuted by the measured delta before it is reported. Every outcome trains the next hunt; the engine rewrites its own attack code when a stronger one can be proven. Authorization-gated; rescue-only on chain.
Mephis Threat: Defense Against Autonomous Compositional Exploitation
A six-phase kill chain of the hive, and Sentinel, four layers that meet it where it has to touch the world: hardening, simulation-time deception, behavioral detection, on-chain containment.
§07 Mandate
Everything above happens inside a box you draw and sign. There is no public access and no self-serve attack on somebody else's protocol.
The attacker is always an unprivileged outsider. In scope: any permissionless path that moves funds, including an auth bypass that then extracts value.
Engagements are private and require a written mandate. A target is admitted only after review, on a signed allowlist. The tooling is bound to an authorized operator identity and will not broadcast for anyone else.
Simulation runs against a forked state. Nothing touches mainnet without a countersigned live lane.
The only live capability offered as a service default. Where mandated, at-risk funds are relocated to a recovery address fixed in writing at engagement time.
Never to an address chosen mid-attack. Never as profit.
§08 Engagement