AUTONOMOUS SECURITY RESEARCH

Security intelligence for the onchain world.

INVARYN is an agentic security researcher designed to investigate the full blockchain stack, form attacker driven hypotheses, and validate critical vulnerabilities through reproducible exploit paths.

See how it works ↘
RESEARCH SURFACE04 DOMAINS
  1. 01Smart contracts
  2. 02Blockchain infrastructure
  3. 03Zero knowledge systems
  4. 04Cryptographic protocols
01Attacker driven
02Full stack reasoning
03Proof before alerts

THE SECURITY GAP

The hardest vulnerabilities do not respect boundaries.

Protocol security is not confined to a single contract or language. Failures emerge between components, assumptions, and trust boundaries. INVARYN is being built to investigate those interactions as one connected attack surface.

THE RESEARCH LOOP

From architecture to reproducible proof.

A structured investigation process designed to remove weak hypotheses before they become noisy findings.

01

Map

Understand the architecture, state transitions, privileges, and trust boundaries.

02

Hypothesize

Form attacker driven paths across functions, contracts, and system components.

03

Reproduce

Turn promising paths into executable tests and controlled exploit conditions.

04

Validate

Confirm reachability and impact, then preserve the evidence needed to reproduce it.

RESEARCH SURFACE

One system. The full onchain stack.

Domain depth matters. Cross domain reasoning matters more when the failure lives between them.

01 / EXECUTION

Smart contracts

State transitions, economic logic, permissions, integrations, and adversarial composition.

02 / SYSTEMS

Blockchain infrastructure

Consensus, networking, clients, bridges, cross chain state, and operational trust.

03 / PROOF

Zero knowledge systems

Constraint integrity, circuit assumptions, prover and verifier boundaries, and implementation risk.

04 / PRIMITIVES

Cryptographic protocols

Protocol design, key handling, authentication, signatures, and adversarial edge cases.

DESIGNED OUTPUT

Evidence, not a list of model guesses.

The goal is not to generate more alerts. It is to deliver a finding that a security team can understand, reproduce, and act on.

  • Root cause and affected state
  • Attacker path and required conditions
  • Impact with explicit boundaries
  • Reproducible proof of concept
INV / FINDING MODELVALIDATION PATH
C
CRITICAL / CROSS COMPONENT

Verified exploit path

ROOT CAUSE
Trust boundary violation
REACHABILITY
Attacker controlled
PROOF
Reproducible test

Conceptual output model. Product interface is in development.

RESPONSIBLE DISCLOSURE

Research will be published when it is safe to publish.

Technical reports and vulnerability research are currently moving through private research and coordinated disclosure processes. Public material will appear here as remediation and publication windows close.

Visit research ↗

LAUNCHING SOON

Build with an attacker in the loop.