NullRabbit
cohort.v1
Research · Tag · Methodology

Posts tagged methodology.

9 entries · sorted: recency← All research
SECURITY-RESEARCH
2026-06-26

The same method, pointed at the packet path

We took the parser-family lens that finds HTTP smuggling bugs and pointed it at the Linux kernel's network receive path, through Google's sanctioned bug-bounty programs. Then we measured our own opportunity honestly, and the honest answer was 'thin, for now.'

Simon Morley
Read →5 min read
SECURITY-RESEARCH
2026-06-25

How we hunt request smuggling without breaking anything

A timing hunch is not a finding. The discipline that separates real desync research from noise is the part nobody photographs: a lab of real proxies, a back-end you own that logs the literal forwarded bytes, and a hard line about who you're allowed to point any of it at.

Simon Morley
Read →6 min read
SECURITY-RESEARCH
2026-06-23

What we build when we're not looking at validators

The method we built for blockchain validator security turns out to be a general-purpose bug-finding method. We've started pointing it at two pieces of infrastructure everyone shares: the open-source HTTP proxy ecosystem, and the Linux kernel's packet path.

Simon Morley
Read →3 min read
SECURITY-RESEARCH
2026-06-22

The h3 FIN/EOM desync, and why your smuggling tool can't send it

HTTP/3 request smuggling is almost unploughed ground. Not because the surface is small, but because nearly every tool speaks h1/h2 only, and the few that speak h3 do it through a conformant QUIC library that won't let you send the bug.

NullRabbit Labs
Read →4 min read
SECURITY-RESEARCH
2026-06-09

The 99% was wrong. So was the 0.32.

Our detector's 99% accuracy was memorisation, and the 0.32 we nearly published in its place was wrong too. The clean experiment found the real split: cross-chain detection generalises, attribution doesn't.

Simon Morley
Read →5 min read
SECURITY-RESEARCH
2026-06-02

Anyone can knock a validator over once. The skill is designing an attack you can learn from

Making a node fall over is easy and proves nothing. The craft is building a reproducer that isolates the mechanism, measures it against an honest baseline, bounds the cost, and runs on one command, so the number actually means something.

Simon Morley
Read →3 min read
SECURITY-RESEARCH
2026-05-27

How we decide a finding is real before we tell you about it

We had a clean denial-of-service against consensus. Re-verification said the baseline was that low by config. No attack. So we pulled it. The discipline that catches our own mistakes is the reason our advisories are worth reading.

Simon Morley
Read →3 min read
RESEARCH
2026-05-12

How we're building cross-chain ML detection for blockchain validator infrastructure

How we built a wire-shape detector that transfers across chains. V8 trained only on Sui hit 51 out of 51 zero-shot on Solana attacks it had never seen, because mechanism-class features carry across chains while host-telemetry features don't.

Simon
Read →4 min read
SUBSTRATE
2026-05-06

Why ML Detection on Validator Infrastructure Keeps Reporting ROC = 1.000

V1 of our trainer scored ROC = 1.000 across all 17 folds. Two minutes of audit found why. Eight leak surfaces later, here's the apparatus that stops you fooling yourself with one.

Simon
Read →5 min read