samczsun
ResearchContact
  • Higher Bug Bounties Won’t Stop Hacks

    Bug bounties are passive, but security is an active process

    Dec 2025
  • Hiding in Plain Sight

    Most people trust, but how many people verify?

    Nov 2021
  • Two Rights Might Make A Wrong

    Too much raw fish doesn’t make a better roll of sushi

    Aug 2021
  • The Dangers of Surprising Code

    The only thing worse than a bug in your code that breaks everything is a bug in your code that subtly breaks one thing

    Aug 2021
  • Booby Trapping the Ethereum Blockchain

    This is how an attacker could have hid a ticking time bomb on the Ethereum blockchain that, when triggered, would hard fork the entire network

    May 2021
  • Uncovering a Four Year Old Bug

    What does it take to find a bug? What about one in a contract that's survived the test of time?

    Apr 2021
  • Paradigm CTF 2021 - swap

    A guided walkthrough for swap, the hardest challenge in Paradigm CTF 2021

    Apr 2021
  • The Block Mined In January, 584942419325

    In a consensus protocol, the simplest mistake could have devastating effects.

    Mar 2021
  • So you want to use a price oracle

    Everything you need to know about price oracles and how to use them safely

    Nov 2020
  • Changing Lanes

    A reflection on my transition from Trail of Bits to Paradigm

    Oct 2020
  • Escaping the Dark Forest

    On September 15, 2020, a small group of people worked through the night to rescue over 9.6MM USD from a vulnerable smart contract. This is our story.

    Sep 2020
  • Authereum, meet Parity

    2017 was fun. Let's never do it again.

    Feb 2020
  • Taking undercollateralized loans for fun and for profit

    Price manipulation, now with 100% more blockchain

    Sep 2019
  • The Livepeer slashing vulnerability

    What happens when good intentions go bad?

    Jul 2019
  • The 0x vulnerability, explained

    An in-depth look at how 0x's Exchange contract was vulnerable

    Jul 2019
© samczsun