ABOUT / STERNSTUNDE LAB
Understand the program.
Find its failures.
Sternstunde Lab investigates complex software for security weaknesses. We establish how a system works before testing the guarantees it is meant to provide.
Research starts with code review.
Good vulnerability research begins with rigorous source analysis. We trace components, state changes, and the assumptions between them until we can explain the program's behavior. That understanding shapes the security tests.
Our system maps connect source paths, component interactions, and state changes to the questions we test. We publish selected maps with their supporting code and observations on our research blog.
Web3 security research
We investigate complex Web3 systems by tracing their implementation and interactions. That work has produced high-impact findings across the projects we've studied.
See selected findingsBrowser security research
Ten High-severity findings across browser sandbox and memory-safety code, including nine published CVEs.
Explore the browser studyOur research is led by an Immunefi-ranked security researcher. View the researcher profile ↗
SERVICES