Research · Tag · Dos
Posts tagged dos.
2 entries · sorted: recency← All research
SECURITY-RESEARCH
2026-07-07
Eighteen advisories, ten node implementations, one attack class
Since NR-2026-001, eighteen advisories across ten independent node implementations. Not unrelated bugs: one recurring attack class, unauthenticated ingress surfaces where a cheap request forces disproportionate cost. Egress and memory amplification, pre-auth CPU exhaustion, connection exhaustion, and crashes.
Simon Morley
Read →1 min read
VALIDATOR-SECURITY
2026-05-21
Expensive work before authentication: the RPC pattern we keep finding
The DoS class that scales against validators isn't volumetric. It's small requests that cost the node real work before it authenticates the caller. The pattern we keep finding across clients, and the fix.
Simon Morley
Read →2 min read
