P2P and gossip
Message floods on consensus channels, peer-pool pollution, discovery reflection, gossip control messages that panic the process.
Your contracts get audited. Your cloud gets a compliance scan. The node in between, its P2P port, its RPC, its handshake, its signer, is where an attacker knocks you off consensus, and almost nobody tests it. We do. We attack it with the techniques from our own published advisories, on a node you control, and hand you the fix.
Figures as of 8 October 2026. Reproduced means a lab-fidelity, bundle-backed instance, not a citation.
A validator rarely falls over because of a contract bug. It falls over because one cheap, unauthenticated request makes the node do expensive work: decode, verify, scan, allocate. No exploit, no log line, no alert. Just a node that stops voting. Your existing testing was never built to look there.
| Generic infra pentest | Smart contract audit | NullRabbit | |
|---|---|---|---|
| Attacks the P2P and gossip ports | ○ | ○ | ● |
| Measures CPU spent before a peer authenticates | ○ | ○ | ● |
| Prices RPC amplification per request | ○ | ○ | ● |
| Tests your signer, admin and slashing-protection surface | ○ | ○ | ● |
| Maps the routing and hosting you share with other validators | ○ | ○ | ● |
| Reproduces against your exact client versions | ○ | ○ | ● |
| Port scan and TLS configuration | ● | ○ | ● |
| Contract logic and bytecode | ○ | ● | ○ |
Measured in our lab, published with the reproducer. These are the techniques we bring to your engagement.
Each area below has at least one published advisory behind it. We test what we have already broken elsewhere.
Message floods on consensus channels, peer-pool pollution, discovery reflection, gossip control messages that panic the process.
TLS, Noise, SecretConnection, BIP324 and RLPx handshakes that spend asymmetric crypto on strangers. QUIC and TLS half-open pinning.
JSON-RPC, gRPC, GraphQL and WebSocket subscriptions. Response amplification, executor saturation, HTTP/2 stream abuse, allowlist bypass.
Admin interfaces, remote signers, slashing protection, bridge signing ports, unauthenticated write paths into fork choice.
Snapshot parsing, state sync services and chunk handling: the code that runs on untrusted input while you are trying to recover.
Hosting provider and ASN concentration, shared RPC dependencies, and which of your nodes go dark together when one upstream fails.
The outside view. What an attacker can reach, and what it costs you.
Your client, your build, your config. Attacked properly.
The failure that takes out thirty validators at once.
No. Reproduction runs on a staging node or a replica built from your versions. Testing against production happens only with written authorisation, rate-limited, in a window you choose.
Because most of this class is out of scope. Resource exhaustion on unauthenticated surfaces is routinely vendor-declared out-of-scope for bounty and embargo, which is why our advisories are public. Nobody is paid to find it, so it stays on your node.
Your fleet, your configuration and your report stay confidential. If a finding is a bug in the client software itself, we take it to the vendor and agree timing with you so you are patched first.
Every stack in the NRDAX registry, 39 with lab reproductions today, from Ethereum execution and beacon nodes to Solana, Cosmos, Sui, IOTA, Cardano, Bitcoin and the Internet Computer. New stacks by arrangement.
Every finding ships with the evidence to re-run it. Our public record includes the misses: three advisories have been withdrawn in the open when they did not hold up. How we verify a finding.
Tell us which networks you run, which clients, and how many nodes. We come back with a scope and a date.
security@nullrabbit.ai