Case Studies

Focused writeups from selected security reviews across ZK, Solana, Move, EVM, Stellar, and DePIN infrastructure.

Filter:

Beamable Network

Beamable Network

SolanaDePIN
November 2025

DePIN Infrastructure Security Assessment

Summary

In November 2025, we conducted a comprehensive security assessment of Beamable Network's Solana-based DePIN infrastructure in collaboration with Hashlock. Beamable is building decentralized physical infrastructure enabling permissionless participation in network operations. The Rust-based smart contract architecture handles critical functions including node registration, reward distribution, and stake management across their decentralized network. Given the financial stakes involved in DePIN protocols and the complexity of coordinating physical infrastructure with on-chain incentives, rigorous security validation was essential before mainnet deployment.

Findings

Our collaborative security assessment uncovered 8 vulnerabilities across severity levels: 2 high, 2 medium, and 4 low-severity issues. The high-severity findings affected core staking and reward distribution mechanisms that could have enabled economic attacks against honest node operators. We identified critical access control gaps in administrative functions that could have allowed unauthorized modifications to network parameters. The medium-severity issues involved potential denial-of-service vectors in node registration flows and edge cases in reward calculation logic. Low-severity findings focused on gas optimization opportunities and code quality improvements. All findings were addressed by the Beamable team prior to mainnet launch, establishing a secure foundation for their decentralized infrastructure network.

Somnia

Somnia

EVMInfrastructure
September 2025

EVM Layer 1 Security Audit

Summary

In 2025, Somnia, an EVM-compatible L1 blockchain capable of processing over 1 million transactions per second, engaged security researchers through a competitive audit contest on HackenProof to validate their infrastructure ahead of mainnet launch. With a $270M ecosystem fund, backing from the Virtual Society Foundation and Improbable, and approximately 60 validators preparing for launch, Somnia required rigorous security validation of its novel MultiStream consensus architecture and core protocol infrastructure. The platform's ambitious performance goals of sub-second finality and support for millions of simultaneous users in gaming, social, and metaverse applications demanded thorough analysis of potential consensus safety and liveness risks.

Findings

Our security audit covered Somnia's blockchain implementation and critical protocol infrastructure. The assessment focused on their novel MultiStream consensus mechanism, validator coordination protocols, state transition logic, and EVM execution layer modifications. As a high-performance L1 targeting over 1 million TPS with sub-second finality, the audit prioritized analyzing potential edge cases in consensus safety and liveness guarantees. The engagement demonstrated Somnia's commitment to security-first development as they prepare to deliver CEX-level performance for next-generation gaming, social, and metaverse applications on a decentralized infrastructure.

Bluefin

Bluefin

SuiDeFi
July 2025

DeFi Perpetuals Security Audit

Summary

In July 2025, Bluefin engaged security researchers through a competitive audit contest on HackenProof to secure their perpetual futures exchange infrastructure. As a Sui-based DEX processing over $5 billion in monthly trading volume and backed by leading firms including Polychain, SIG, and Brevan Howard, Bluefin required rigorous security validation before scaling their institutional-grade trading platform. The audit contest attracted top-tier security talent, with researchers conducting comprehensive analysis of the platform's Move smart contract architecture and core mathematical libraries.

Findings

The audit contest uncovered critical vulnerabilities in foundational systems that handle billions in trading activity. One high-severity finding affected core mathematical operations used throughout the platform. While the immediate exploitation risk was limited, the discovery was crucial due to its foundational nature in a system processing high-frequency trades and managing substantial user funds. The vulnerability demonstrated how seemingly isolated bugs in base libraries can pose systemic risks as platforms evolve. With a $45,000 reward pool distributed among researchers, the engagement highlighted Bluefin's commitment to security-first development as they compete to bring CEX-level performance to decentralized derivatives trading.

Aquarius

Aquarius

StellarDeFi
June 2025

DeFi Protocol Security Audit

Summary

Aquarius is Stellar's first liquidity management layer, designed to supercharge trading by bringing more liquidity to the network and enabling community control over reward distribution across market pairs. Created by Ultra Stellar, builders of StellarX, StellarTerm, and LOBSTR wallet, Aquarius incentivizes both SDEX market makers and AMM liquidity providers through its AQUA token reward system. With a novel AMM protocol offering stable and volatile pools, multi-hop swaps, and on-chain governance for reward allocation, Aquarius required comprehensive security validation of its smart contract infrastructure before managing significant liquidity across the Stellar ecosystem.

Findings

Our security assessment, conducted through Cantina, examined Aquarius's liquidity pool architecture, reward distribution mechanisms, and governance systems built on Stellar's Soroban smart contract platform. The audit focused on constant product invariant enforcement in volatile pools, reward distribution logic for SDEX market makers, AMM swap mechanisms, and voting systems that control liquidity allocation. As Stellar's pioneering DeFi liquidity layer built with Rust-based smart contracts, the engagement prioritized analyzing the novel integration of SDEX incentives with AMM liquidity provision. The assessment validated Aquarius's position as Stellar's DeFi hub, enabling secure liquidity provision across the network's decentralized exchange infrastructure.

ZkSync Era

ZkSync Era

EVMInfrastructure
June 2025

Zero Knowledge L2 Infrastructure Security Audit

Summary

In June 2025, we conducted a security assessment of ZkSync Era's zero-knowledge EVM Layer 2 infrastructure in collaboration with Taran.Space. ZkSync Era is one of the leading ZK-rollup solutions, enabling Ethereum scalability through validity proofs while maintaining EVM compatibility. The Rust-based codebase handles critical operations including proof generation, state management, and bridge functionality securing billions in user assets. Given ZkSync's position as critical Ethereum scaling infrastructure, the audit required deep expertise in both zero-knowledge cryptography and Rust systems programming to thoroughly evaluate the security posture.

Findings

Our comprehensive security assessment identified 10 issues across the codebase: 1 high-severity, 1 medium-severity, 4 low-severity, and 4 informational findings. The high-severity vulnerability affected a critical component in the proof verification pipeline that could have compromised the integrity guarantees of the ZK-rollup under specific conditions. The medium-severity finding involved edge cases in state transition validation that could have led to inconsistent state roots. Low-severity issues addressed potential denial-of-service vectors and gas optimization opportunities in the sequencer logic. Informational findings provided recommendations for code maintainability and documentation improvements. All critical and medium findings were remediated before our final report, strengthening ZkSync Era's position as secure, production-grade Ethereum scaling infrastructure.

Crestal Network

Crestal Network

EVMDePIN
March 2025

DePIN Infrastructure Security Assessment

Summary

Crestal Network is building The Nation, a platform enabling anyone to create productive AI agents that autonomously generate revenue, manage wallets, launch tokens, and access powerful skills for on-chain and off-chain value creation. The core infrastructure consists of agent creation and management smart contracts built as upgradeable contracts supporting gasless transactions through ERC-4337, along with ERC20-based payment functions. With AI agents handling critical financial operations and autonomous decision-making, Crestal required rigorous security validation of its agent management infrastructure before enabling widespread adoption across their ecosystem.

Findings

Our security assessment, conducted through Sherlock, covered Crestal's agent creation and update management contracts, focusing on the upgradeable contract architecture, ERC-4337 gasless transaction implementation, and ERC20 payment processing logic. The engagement identified critical vulnerabilities that could have compromised agent ownership and financial security. We discovered a high-severity access control vulnerability in core contract functions that could have enabled unauthorized fund transfers, posing significant risk to users' agent wallets and platform integrity. Additionally, we uncovered medium-severity issues affecting worker assignment timeout mechanisms and signature verification systems that could have led to service disruptions and potential replay attacks. Following our comprehensive review and remediation guidance, Crestal fortified The Nation's smart contract foundation, enabling secure autonomous AI agent deployment and operation across the ecosystem.