NullRabbit
cohort.v1
Research · Tag · Scanning

Posts tagged scanning.

7 entries · sorted: recency← All research
SLASHR
2026-04-14

We Scanned 5,700 [Solana, Eth, Sui, Atom] Validators. Here's What We Found.

NullRabbit scanned 5,715 validator hosts across Solana and Sui, running 10,139 scans and identifying 1,340 CVE findings across 155 hosts. Here's what the validator attack surface actually looks like.

Simon
Read →5 min read
SLASHR
2026-04-06

Slashr: Real-Time Validator Incident Tracking Across Four Networks

Slashr tracks validator delinquency, jailing, slashing, and missed votes across Solana, Ethereum, Sui, and Cosmos in real time. Wallet checks, rankings, automated scanning, and reliability reports -- all from on-chain data.

Simon
Read →6 min read
SUI
2026-03-25

DeFi Under the Microscope: 1,075 Hosts, 3,001 Ports, One Timing Scan

A first look at what DeFi validator infrastructure looks like at the kernel level. We crack open the consolidated dataset -- embedding galaxies, jitter fingerprints, RTT ridgelines, and 10,000 anomaly events across 642 silent hosts.

Simon
Read →6 min read
SUI
2026-03-20

What Does a DeFi Network Actually Look Like?

Every blockchain network has a physical fingerprint. We pointed our eBPF/XDP scanner at 1,075 hosts across multiple DeFi validator networks and mapped 3,001 timing fingerprints to reveal the structure underneath the consensus layer.

Simon
Read →5 min read
EBPF
2026-03-18

The Kernel Doesn't Care About Your Restart Script

Building a production BPF/XDP scanner is an exercise in humility. Orphaned XDP programs, async Rust deadlocks, stale binaries, silent TC failures -- here is everything that broke and what we did about it.

Simon
Read →7 min read
SUI
2026-03-13

What We Found Scanning the Sui Validator Network

We scanned 138 Sui validators across 20 countries using kernel-level temporal fingerprinting. 41% have SSH exposed, 57 run unexpected internet-facing services, and 9 confirmed CVEs sit on 4 hosts -- including 2 critical at CVSS 9.8. Here is what we found and why it matters for DeFi.

Simon
Read →6 min read
OPEN-SOURCE
2026-02-26

Open-Sourcing Our Autonomous Defence Arsenal: Here's What's Inside

We're open-sourcing the tooling behind NullRabbit's autonomous kernel-level network defence: the scanning, intelligence, observation, and adversarial validation layers that feed our enforcement pipeline. Six tools, MIT licensed, with more coming.

Simon
Read →5 min read