RESEARCH BLOG
What the code
actually does.
We map how a system moves data and makes decisions before investigating where its guarantees can fail. Each article connects that model to pinned source, available tests or traces, and a specific security question.
Where OpenZeppelin Checks a Privileged Call
We map the manager and target call routes before asking which check protects each path to a privileged effect.
A Block Timestamp, from Construction to Finalization
Polkadot's producer, validator, and finalization hook form one lifecycle; only then can we test whether a reachable block satisfies it.
One Block Height, Multiple Histories
We map go-ethereum's canonical index and stored fork headers before asking which branch a consumer reads.
What Go's Router Does Before a Handler Runs
A local ServeMux trace establishes when a path redirects, so an application's authorization can be assessed against the path it actually handles.
An Invariant Panic Is Only the Last Step
We map when Cosmos SDK checks invariants, then identify the state and writers a reachable panic would require.
Two Views of State Inside a Cache
Cosmos SDK merges pending writes with stored keys; mapping those views comes before judging what a range operation can change.
Following a Historical Query to the Final Read
We trace the requested height from CometBFT through Cosmos SDK before checking which stored version supplies the answer.
We share lessons from our work investigating complex systems.