Security research & engineering for decentralized networks

The Decentralized Immune System for Decentralized infrastructure.

NullRabbit is an AI-powered, eBPF-enforced security layer for decentralized networks.

We map, predict, and drop hostile P2P inputs and resource-exhaustion attacks at the kernel before they cause node failure or availability loss.

Watch the Live eBPF Demo →Explore the NRDAX Taxonomy →
[01] · The problem

Decentralized networks are vulnerable at the transport layer.

Traditional security tools don't understand libp2p gossip, QUIC handshake floods, or peer-to-peer memory exhaustion. A single malicious packet can take a network node offline. NullRabbit investigates and reproduces these exact mechanisms to build active defenses.

blind
Contract & transaction security
Audits program logic and on-chain state. Never sees the packet that takes the node down.
late
Traditional monitoring & EDR
Doesn't speak libp2p, QUIC or devp2p. Reports CPU, memory and disk after the damage has landed.
covered
NullRabbit
Maps the technique, predicts the anomaly, and drops the packet at the kernel before user space ever pays for it.
[02] · The stack

Full-stack infrastructure security research. Intelligence feeds cognition; cognition arms enforcement.

1Map
2Predict
3Drop
4Propagate
[03] · Live telemetry & R&D

Active research. Live telemetry.

Everything we claim, you can query. The taxonomy, the models and the risk telemetry are live and publicly inspectable. The enforcement mesh is active research, demonstrated end-to-end. We label which is which.

01liveSlashr Risk IndexLive tracking of validator incidents and operational risk across 7 networks.slashr.dev →02liveMachine-readable by defaultSTIX 2.1, JSON API, and MCP server integrations, so SOC pipelines and AI agents consume the intel directly.nrdax.com →03liveOpen standardsPublic corpus, DOIs, and CVE/GHSA crosswalks to support the broader security community.huggingface.co/NullRabbit →04r&dEnforcement meshThe eBPF/XDP agent is demonstrated end-to-end, on camera, dropping hostile traffic at the kernel. Mesh threat propagation is in active development.decentralized-firewall →
[04] · Latest threat research
Research index →
Research2026-07-22
Crashing an Agave validator during snapshot bootstrap with one oversized account length
solana · agave · snapshot-bootstrap
Research2026-07-22
How an exposed debug_traceCall lets one unauthenticated request burn seconds of go-ethereum CPU
research · ethereum · go-ethereum
Research2026-07-22
How a wide-range eth_getLogs query turns a few hundred bytes into an unbounded response on exposed go-ethereum RPC nodes
research · ethereum · go-ethereum
Research2026-07-22
How a zero-value GetBlockHeaders request underflows to serve go-ethereum's entire header chain (CVE-2024-32972)
ethereum · go-ethereum · devp2p
Research2026-07-22
One prior-knowledge h2c connection multiplexes N eth_getLogs past an L4 per-connection cap on go-ethereum's JSON-RPC port
research · ethereum · go-ethereum
Research2026-07-22
Bypassing go-ethereum's --http.vhosts host allowlist with an empty Host, forged by an HAProxy HTTP/2→1.1 downgrade
research · ethereum · go-ethereum
[05] · Incident response

Under attack, or seeing behaviour your dashboards can't explain?

Send NullRabbit the artefacts. We reproduce the mechanism, classify it in NRDAX, and build the countermeasure into the mesh.

Packet captures
Crash traces
Validator incident timelines
Client versions & correlated downtime
Suspicious RPC or P2P traffic
Resource-consumption evidence
Never send private keys, seed phrases or any other secret material. NullRabbit does not need them and will not store them.
[06] · Partnerships

Advancing the standard of care for decentralized networks.

Partner with us on research or infrastructure deployment.

Research partnership →Infrastructure deployment →