Summary
Security Reviews groups public, reproducible research by vulnerability class. Each review links a vulnerable target, an exploit proof of concept, a remediated branch, a report, and automated checks.
Role and scope
I reproduce the vulnerable behavior, document impact and assumptions, implement or explain remediation, and keep the evidence runnable in CI.
Problem and constraints
A written finding is difficult to evaluate when the vulnerable state, exploit path, fixed behavior, and assumptions cannot be reproduced independently.
Architecture
The catalogue uses one public repository per vulnerability class. Reports, source, exploit tests, fixed branches, and CI remain close enough to compare without hiding the technical path behind a summary page.
Security context
The research covers Web and application security, Solidity and Vyper contracts, ZK circuits, formal verification, and indirect prompt injection. Public platform associations include the Treasury Board of Canada Secretariat, Reserve Protocol, Revert Finance, Chainlink Payment Abstraction V2, and K2.
Testing and verification
Public repositories include executable exploit and remediation checks using the tool appropriate to each target, including Foundry, Halmos, Circom, and GitHub Actions.
Public results
Published examples cover share inflation, signature replay, reward accounting drift, oracle freshness, reentrancy, fee rounding, access control, under-constrained circuits, and arithmetic verification.
Resources and links
Scope and current status
Confidential submissions are not included in this catalogue.
