Mmehveteroinmehvetero.com·1d ago · 8 min readHow a Missing `assert!` Drained $3.44M From Typus Finance — and Why the Code Looked CorrectOn October 15, 2025, at 13:05 UTC, an attacker began draining Typus Finance's TLP liquidity pool on the Sui network. Thirty-four minutes later, the contracts were paused — but the pool was already emp00
Rrobertovg24inrobertovg.hashnode.dev·4d ago · 8 min readVerifiable BookmarkletsI just added a small new tool to the site: Verifiable Bookmarklets. Every bookmarklet it generates carries a SHA-256 fingerprint, so anyone can check that the javascript: link they received was really00
Mmehveteroinmehvetero.com·6d ago · 7 min readThree Sui Exploits, One Disease — Why "The Math Looked Fine" Keeps Costing Hundreds of MillionsCetus lost $223M to a shift overflow. Aftermath lost $1.14M to a negative fee. Bucket Protocol ships a decimal scaling bug today. All three passed audits. All three have the same root cause. I've spe00
BB0dj0xinb0dj0x.hashnode.dev·6d ago · 6 min readHow to Start Bug Bounty Hunting in 2026: The Complete Beginner's GuideEverything you need to know to find your first vulnerability, get paid, and build a real reputation in cybersecurity — without breaking any laws. If you've typed "how to start bug bounty hunting" int10
CGCristiano Gabrieliincrisdigital.hashnode.dev·Jul 26 · 11 min read The New AI Attack Surface: How Modern Models Become Targets Introduction I’ve been working with AI systems long enough to notice a strange shift. Not the kind you see in marketing slides or conference talks, but the quiet kind — the one that shows up when a mo00
Xxvzf_optinxvzfopt.hashnode.dev·Jul 22 · 8 min readModernizing a Legacy OSINT Framework in Python: Part 2Introduction Welcome back to part 2 of my Recon-NGX blog series. In part 1 I introduced the project, outlined its goals and then talked about what led me to take it on. If you haven’t seen it yet, I’d00
CSChris Sheridaninhalosecurityhasnodedev.hashnode.dev·Jul 21 · 2 min readHALO v2.7: One Registry, 29 Tools, and a More Reliable MCP ArchitectureI just finished a major refactor of HALO, my open source AI-powered security agent. The biggest change wasn’t adding another feature. It was simplifying the architecture. Instead of scattering tool de00
VGVivek Goswamiinvivekgoswami.hashnode.dev·Jul 19 · 2 min readTryHackMe’s Room - Tomghost Walkthrough Reconnaissance I usually begin with a classic Network Mapper(nmap) scan with the service version detection and aggressive scanning. As we can see here 22,53,8009,8080 are in open state 8080 HTTP wit10
CSChris Sheridaninhalosecurityhasnodedev.hashnode.dev·Jul 12 · 4 min readOnline vs. Offline Password Attacks: A Field Guide Password attacks are one of the first things people learn in offensive security, and one of the most commonly muddled. The confusion usually comes down to a single distinction that determines which to00
JAJavier Alonsoinejpt.hashnode.dev·Jul 11 · 5 min readHow I passed the eJPTv2 at 14Hey everyone! My name is Javier Alonso, I'm from Spain, and I am exactly 14 years, 1 month, and 2 days old. Today, June 29, 2026, I achieved something I was super excited about and have been working r01F