Fitting a general DELEGATECALL forwarder into a 36-byte jump-free bytecode whitelist, then abusing a validated arbitrary storage write in a reversed vault
Stacking a Move market-key confusion, a caller-controlled price, and a primitive-type witness to drain an incentive vault on Sui
Draining a meta-transaction vault through a relayer credit-transfer with no signature check, plus the intended ECDSA malleability and cross-function reentrancy chain
Draining a lending pool through a proxy storage collision that aliases pendingAdmin onto the oracle price, reachable via an unpermissioned multicall self-call
Writeup for Bank Heist from BITSCTF 2026. A hard blockchain challenge exploiting missing program_id checks in CPI verification.
A detailed writeup for the House of Illusions challenge from 0xL4ugh CTF V5. A Hard Blockchain/Smart Contract Security challenge involving proxy patterns, ABI encoding exploits, and compiler differences.
Blockchain challenge involving address collision attack against a Rust-based rollup node using Ed25519 signatures and Blake3 hashing.