SecLat Blog
Insights on security and trust in Web3
Explore articles about audits, mitigation strategies, and lessons from our smart contract security team.
Recent posts
Ethernaut Level 3 Walkthrough: Exploiting Weak On-Chain Randomness in Solidity
In this article, we will analyze and solve Ethernaut Level 3: Coin Flip.
An Oracle Does Not Need to Be Broken to Liquidate You: How Thin Liquidity, a Short TWAP, and Leverage Triggered Morpho Liquidations
How a thin DeFi market feeding a short TWAP can turn PT, YT, looped leverage, and health factors into a liquidation risk, and how teams can reduce it.
How Six Failures Turned a MAYAChain Outbound Bug Into a Pool Drain
A technical breakdown of how transaction-voter state, outbound matching, subsidy accounting, and pool math compounded into a MAYAChain exploit.
When a blockchain rolls back: the Harmony ONE exploit and the cost of recovery
What Harmony's planned rollback after unauthorized ONE issuance teaches protocol teams about finality, operational disruption, and incident readiness.
Ethernaut Level 2 Walkthrough: Exploiting a Misnamed Constructor in Solidity
In this article, we will analyze and solve Ethernaut Level 2: Fallout.
BTCPay Server remote Lightning access: treat node credentials as emergency secrets
What BTCPay Server operators should do after the August 2026 active attack affecting remote LND access, including patching, credential rotation, and review steps.
Ethernaut Level 1 Walkthrough: Exploiting Access Control in Solidity
In this article, we will analyze and solve Ethernaut Level 1: Fallback.
Coldcard and the risk that starts before signing
The reported Coldcard incident shows why key security depends on entropy, build configuration, and a prepared response.
Your Smart Contract Can Be Bug-Free and Still Get Hacked: Five Attack Surfaces Audits Cannot Ignore
Five security surfaces protocol teams should include in a review, beyond smart contract logic.