NullRabbit
cohort.v1
NullRabbit Labs · Whitepaper-led · Open Source

Autonomous defence
for decentralized
networks.

Adversarial AI is attacking validator infrastructure. We defend it with adversarial AI - trained on the network itself, acting at machine speed, only when authority has been earned. Zero latency impact.

Join Cohort v1.0 Read the research
OPEN-SOURCE NODES·PROPRIETARY INTELLIGENCE·NO BLACK BOXES
fig.1 · authority pipelineshadow · evidence · enforce
Footnote

Every event above is counterfactual - what IBSR would have done under earned authority. Live enforcement begins only on your consent, scoped to a class of abuse, revocable at any time.

[01]·The threat is here

The wave is here,
not coming.

AI agents now discover and chain zero-day exploits autonomously, at $50 a vulnerability. Validator infrastructure - trillions in staked capital, hundreds of independent operators, no central SOC - is uniquely exposed.

April 2026 · Production exploitincident.221

Litecoin MWEB · 13-block reorg

A DoS-plus-consensus exploit on Litecoin's MWEB caused a 13-block reorganisation with roughly $600K in cross-chain exposure. The patch had been available for 37 days. Not a zero-day - a known-day that defenders couldn't close in time.

13 BLOCKS·$600K·37 DAYS UNPATCHED
CoinDesk →
December 2025 · DDoS waveincident.197

Solana absorbed 6 Tbps. Sui degraded.

Two major decentralized networks were hit with sustained DDoS in the same week. Same wave, different outcomes. The difference was the defensive substrate underneath - most chains don't have one.

6 TBPS·2 NETWORKS·1 WEEK
CoinDesk →
[02]·The platform

Every validator becomes a sensor.
Every sensor strengthens every defender.

One brain. Two open-source nodes. The network defends itself - at kernel speed, with authority earned, not asserted.

fig.2 · cohort propagationprobe @ node - · reached 0 nodes · 0ms
one validator probed → every validator protected
the decentralized brain
cohort intelligence

Mesh

Collective intelligence, trained on the network it defends.

  • Every validator becomes a sensor; the brain learns from all of them.
  • When one validator is probed, every validator gains the protection.
  • Intelligence improves with every node on the network.
Read more →
judgment - open source
behavioural baselines

IBSR

Observes, learns, reports home - on your traffic, not synthetic data.

  • Behavioural baselines on real packets, not synthetic data.
  • Counterfactual evidence - see what would have been blocked, first.
  • Authority earned on your traffic, not asserted by a vendor.
Read more →
enforcement - open source
xdp / ebpf

Guard

Kernel-speed action when authority has been granted.

  • XDP / eBPF blocking. Microsecond decision-to-action.
  • Acts only on judgments Mesh has authorised on your network.
  • Drop-in compatible - replaces or sits alongside your firewall.
Read more →
[03]·The substrate

Normalising the abnormal.

There is no MITRE ATT&CK for validator infrastructure. No CVE pipeline. No shared format for what an attack on a decentralized network actually looks like. The industry has no substrate.

We built one. An open multi-modal bundle format, an open ten-family taxonomy, and a proprietary corpus of 1,092 contract-validated attack bundles across 19 primitives.

Read the research →
tbl.1 · taxonomy fragment10 families · 19 primitives
01recon.fingerprintbundle×142
02recon.discoverybundle×88
03dos.volumetricbundle×211
04dos.amplifybundle×134
05p2p.eclipsebundle×56
06p2p.sybilbundle×73
07consensus.equivocatebundle×92
08consensus.reorgbundle×47
09rpc.injectionbundle×161
10rpc.replaybundle×88
1,092 contract-validated attack bundles total
[04]·Earned autonomy

Trust by evidence,
not assertion.

Most autonomous defence asks for blind trust. We don't. IBSR runs in shadow mode on your traffic, producing counterfactual evidence of what it would have done. You decide when the evidence is sufficient.

Authority is granted in stages, scoped to specific abuse classes, and revocable at any time. The framework is published, peer-reviewable, and open.

Read the framework →
STAGE 0

Shadow

auto-on

IBSR observes packets in passive mode. No enforcement. Counterfactual evidence accumulates.

STAGE 1

Scoped

operator-granted

Operator grants authority for one abuse class. Guard begins enforcing for that class only.

STAGE 2

Broad

evidence-required

Authority expands by evidence, never by request. Each class is opt-in and revocable.

STAGE 3

Network

cohort-vote

Cohort-wide policy. One validator's judgment becomes another's protection.

[05]·Cohort v1.0 · open call

Cohort v1.0 is forming.

8 founding seats. We are assembling the first cohort now - operators who have felt the wave and want a hand on the rudder while the substrate is still being written.

Right now we need your time and your telemetry - not your trust. Later: full platform access, roadmap influence, and founding-cohort pricing locked in.

01

Validator operators

staked operators · any size

You run validators on production networks and feel the wave first. You want telemetry on what is actually probing your nodes.

02

Full node / RPC providers

public & private RPC

You serve the network's reads and absorb its noise. DDoS, scraping and RPC abuse are your daily reality.

03

Foundations & core teams

L1 / L2 foundations

You set protocol policy and own the defensive substrate. You can authorise a cohort and shape the taxonomy.

04

Infrastructure & staking providers

staking-as-a-service · DePIN

You run nodes at scale for others. One judgment on your fleet protects every delegator behind it.

Apply to Cohort v1.0 →Talk to us
networks we’re prioritisingseeking operators
EthereumL1
open
PrysmL1
open
SolanaL1
open
SuiL1
open
BitcoinL1
open
AptosL1
open
IOTAL1
open
TONL1
open
Your networktell us →
nominate
Run something not listed? We want the hardest networks to defend. Nominate it.