Security research & engineering for decentralized networks

The Decentralized Immune System for Decentralized infrastructure.

NullRabbit is an AI-powered, eBPF-enforced security layer for decentralized networks.

We map, predict, and drop hostile P2P inputs and resource-exhaustion attacks at the kernel before they cause node failure or availability loss.

Watch the Live eBPF Demo →Explore the NRDAX Taxonomy →
[01] · The problem

Decentralized networks are vulnerable at the transport layer.

Traditional security tools don't understand libp2p gossip, QUIC handshake floods, or peer-to-peer memory exhaustion. A single malicious packet can take a network node offline. NullRabbit investigates and reproduces these exact mechanisms to build active defenses.

blind
Contract & transaction security
Audits program logic and on-chain state. Never sees the packet that takes the node down.
late
Traditional monitoring & EDR
Doesn't speak libp2p, QUIC or devp2p. Reports CPU, memory and disk after the damage has landed.
covered
NullRabbit
Maps the technique, predicts the anomaly, and drops the packet at the kernel before user space ever pays for it.
[02] · The stack

Full-stack infrastructure security research. Intelligence feeds cognition; cognition arms enforcement.

1Map
2Predict
3Drop
4Propagate
[03] · Live telemetry & R&D

Active research. Live telemetry.

Everything we claim, you can query. The taxonomy, the models and the risk telemetry are live and publicly inspectable. The enforcement mesh is active research, demonstrated end-to-end. We label which is which.

01liveSlashr Risk IndexLive tracking of validator incidents and operational risk across 7 networks.slashr.dev →02liveMachine-readable by defaultSTIX 2.1, JSON API, and MCP server integrations, so SOC pipelines and AI agents consume the intel directly.nrdax.com →03liveOpen standardsPublic corpus, DOIs, and CVE/GHSA crosswalks to support the broader security community.huggingface.co/NullRabbit →04r&dEnforcement meshThe eBPF/XDP agent is demonstrated end-to-end, on camera, dropping hostile traffic at the kernel. Mesh threat propagation is in active development.decentralized-firewall →
[04] · Latest threat research
Research index →
Research2026-08-10
Casper P2P TLS-1.3 P-521 pre-auth ECDSA verify burn
casper · p2p · tls
Research2026-08-10
Burning go-ethereum RPC CPU with one eth_call to the BLAKE2F precompile
ethereum · go-ethereum · rpc
Research2026-08-10
Amplifying go-ethereum RPC responses with an eth_simulateV1 block-number gap
ethereum · go-ethereum · rpc
Research2026-08-10
rusty-kaspa gRPC pre-auth HTTP/2 stream flood causing inbound-peering exhaustion and eviction
kaspa · rusty-kaspa · grpc
Research2026-08-10
Walrus storage-node HTTP/2 Rapid Reset: memory exhaustion via u32::MAX default
walrus · http2 · rapid-reset
Research2026-08-10
Zebra getaddresstxids RPC response amplification
zcash · zebra · json-rpc
[05] · Incident response

Under attack, or seeing behaviour your dashboards can't explain?

Send NullRabbit the artefacts. We reproduce the mechanism, classify it in NRDAX, and build the countermeasure into the mesh.

Packet captures
Crash traces
Validator incident timelines
Client versions & correlated downtime
Suspicious RPC or P2P traffic
Resource-consumption evidence
Never send private keys, seed phrases or any other secret material. NullRabbit does not need them and will not store them.
[06] · Partnerships

Advancing the standard of care for decentralized networks.

Partner with us on research or infrastructure deployment.

Research partnership →Infrastructure deployment →