When Hyperliquid has to clear bad debt, who covers it?
We reverse-engineered the closed-source risk engine, verified some core properties & compared it to other perps. It's not neutral: the more leveraged and profitable your position, the sooner it's closed.
Full breakdown ↓
Dialed in! Nikolaos Mourousias (@deltaclock), Caue Obici (@caueobici) & Bruno Halltari (@BrunoModificato) of OtterSec used a Code Injection bug to exploit LM Studio in the second round, earning $20,000 and 4 Master of Pwn points. Full win! #Pwn2Own#P2OBerlin
The pre-release version of Anchor v2 is out.
v2 is over 90% smaller and 3-6x faster than v1, and represents months of work focused on speed, extensibility, and security. This is a major architectural change from a dense macro-based framework to a more easily extensible trait system, with security built in from day one.
Excited for teams to give it a try. Still a few rough edges, but please DM/comment with any feedback!
We recently achieved renderer RCE and universal XSS on Samsung's default browser.
Here's how we abused an out-of-date V8 to construct the exploit chain.
We achieved a guest-to-host escape by exploiting a QEMU 0-day where the bytes written out of bounds were uncontrolled.
Full breakdown of the technique, glibc allocator behavior, and our heap spray/RIP-control primitive ↓
We recently achieved guest-to-host escape by exploiting a QEMU 0day.
We’ll share details on a new technique leveraging the latest glibc allocator behavior and what we believe is a novel QEMU-specific heap spray/RIP-control primitive.
Writeup coming next week.
We found the same Fiat-Shamir bug in six independent zkVMs.
The result: an attacker can bypass the cryptography entirely and prove mathematically impossible statements (like minting $1M out of thin air).
Full breakdown ↓
Pwndbg 2026.02.18 is out!
We visualize branches in nearpc, sync ur decompiler (IDA/Binja/Ghidra) via decomp2dbg, annotate stack vars from dbgsyms/decomp, added new cmds for tracing kernel allocs/frees, dump task info: https://t.co/Gz2rdZlzxp
Sponsor us: https://t.co/YdAmbhJHyF
Spend the summer in NYC (we cover rent). Work alongside our team on audits and tooling, learn how we actually do security research, and get support for your own projects. Apply below ↓
We’re excited to announce a shared leadership structure with @asymmetric_re! Teams today face risks that span audits, research, engineering, and incident response, and clear coordination is important.
NEW: ERC-4337 paymasters unlock powerful UX by abstracting gas costs, but they also add complexity and subtle bugs.
We break down common pitfalls in real-world implementations and how to design production-ready paymasters.
https://t.co/YLoWOdXq4T
Shop is closed! We hope you had a lot of fun playing this year’s Hack.lu CTF!
Congratulations to everybody who solved challenges and especially the winners:
🥳 Congrats to the winners! 🎉 💪
🥇 @kalmarunionenDM
🥈 @justCatTheFish
🥉 @0rganizers
https://t.co/e8nHgLE8B8