<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Smart contract audits from Veridise</title>
	<atom:link href="https://veridise.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://veridise.com/</link>
	<description></description>
	<lastBuildDate>Wed, 19 Aug 2026 16:46:08 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://veridise.com/wp-content/uploads/2024/01/Symbol-on-light-bg-copy-150x150.png</url>
	<title>Smart contract audits from Veridise</title>
	<link>https://veridise.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Constant Product Manipulation: When a Token Breaks the Pool It Was Built For</title>
		<link>https://veridise.com/blog/audit-insights/constant-product-manipulation-future-protocol-exploit/</link>
		
		<dc:creator><![CDATA[Jon Stephens]]></dc:creator>
		<pubDate>Wed, 19 Aug 2026 16:35:56 +0000</pubDate>
				<category><![CDATA[Audit insights]]></category>
		<category><![CDATA[Featured]]></category>
		<guid isPermaLink="false">https://veridise.com/?p=20500</guid>

					<description><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/08/FPC-AH-Blog-Banner1--e1787158016359.jpg" alt="Constant Product Manipulation: When a Token Breaks the Pool It Was Built For" style="width:100%; height:auto;"></div>
<h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Constant Product Manipulation: When a Token Breaks the Pool It Was Built For</h2>
<p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This article is about a class of bug where a token&#039;s own transfer logic breaks an invariant of the protocol it was written to work with. New take every week. Find Jon at @FormallyJon.</p>
<p>Custom token implementations that add fees or constraints to events like transfers, mints and...</p>
<p><a href="https://veridise.com/blog/audit-insights/constant-product-manipulation-future-protocol-exploit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>

]]></description>
										<content:encoded><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/08/FPC-AH-Blog-Banner1--e1787158016359.jpg" alt="Constant Product Manipulation: When a Token Breaks the Pool It Was Built For" style="width:100%; height:auto;"></div><h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Constant Product Manipulation: When a Token Breaks the Pool It Was Built For</h2><p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This article is about a class of bug where a token&#039;s own transfer logic breaks an invariant of the protocol it was written to work with. New take every week. Find Jon at @FormallyJon.

Custom token implementations that add fees or constraints to events like transfers, mints and...</p><p><a href="https://veridise.com/blog/audit-insights/constant-product-manipulation-future-protocol-exploit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Mina Multisig Audit: Veridise Reviews FROST Signing</title>
		<link>https://veridise.com/blog/audits-archive/mina_multisig_audit_frost_signature/</link>
		
		<dc:creator><![CDATA[Jon Stephens]]></dc:creator>
		<pubDate>Tue, 11 Aug 2026 16:18:24 +0000</pubDate>
				<category><![CDATA[Audits archive]]></category>
		<category><![CDATA[Featured]]></category>
		<guid isPermaLink="false">https://veridise.com/?p=20478</guid>

					<description><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/08/Mina-multisig-audit.jpg" alt="Mina Multisig Audit: Veridise Reviews FROST Signing" style="width:100%; height:auto;"></div>
<h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Mina Multisig Audit: Veridise Reviews FROST Signing</h2>
<p style="font-size: 16px; line-height: 1.5;">Mina Multisig lets Mina and ecosystem projects operate through a threshold signature instead of a single key, adapting the FROST protocol to Mina&#039;s Pallas curve and Poseidon hashing. Veridise completed a manual audit of that implementation in June 2026, reviewing the two Rust crates that turn FROST&#039;s signing flow into Mina-compatible signatures. The audit found six issues, all fixed, before...</p>
<p><a href="https://veridise.com/blog/audits-archive/mina_multisig_audit_frost_signature/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>

]]></description>
										<content:encoded><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/08/Mina-multisig-audit.jpg" alt="Mina Multisig Audit: Veridise Reviews FROST Signing" style="width:100%; height:auto;"></div><h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Mina Multisig Audit: Veridise Reviews FROST Signing</h2><p style="font-size: 16px; line-height: 1.5;">Mina Multisig lets Mina and ecosystem projects operate through a threshold signature instead of a single key, adapting the FROST protocol to Mina&#039;s Pallas curve and Poseidon hashing. Veridise completed a manual audit of that implementation in June 2026, reviewing the two Rust crates that turn FROST&#039;s signing flow into Mina-compatible signatures. The audit found six issues, all fixed, before...</p><p><a href="https://veridise.com/blog/audits-archive/mina_multisig_audit_frost_signature/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Low-Level Call Hijacking: How a Trusted Router Call Cost $3.5M</title>
		<link>https://veridise.com/blog/audit-insights/low_level_call_hijacking_arcadia_exploit/</link>
		
		<dc:creator><![CDATA[Jon Stephens]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 13:56:52 +0000</pubDate>
				<category><![CDATA[Audit insights]]></category>
		<category><![CDATA[Featured]]></category>
		<guid isPermaLink="false">https://veridise.com/?p=20471</guid>

					<description><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/08/low_level_call_hijacking_arcadia_exploit_Jon_Stephens-e1785938189392.jpg" alt="Low-Level Call Hijacking: How a Trusted Router Call Cost $3.5M" style="width:100%; height:auto;"></div>
<h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Low-Level Call Hijacking: How a Trusted Router Call Cost $3.5M</h2>
<p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This one is about privileged contracts that forward caller-supplied data straight into a low-level call, and how a senior auditor catches the bug before it ships. New take every week, and you can follow Jon at @FormallyJon.</p>
<p>A protocol can define exactly which contracts may act on its...</p>
<p><a href="https://veridise.com/blog/audit-insights/low_level_call_hijacking_arcadia_exploit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>

]]></description>
										<content:encoded><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/08/low_level_call_hijacking_arcadia_exploit_Jon_Stephens-e1785938189392.jpg" alt="Low-Level Call Hijacking: How a Trusted Router Call Cost $3.5M" style="width:100%; height:auto;"></div><h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Low-Level Call Hijacking: How a Trusted Router Call Cost $3.5M</h2><p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This one is about privileged contracts that forward caller-supplied data straight into a low-level call, and how a senior auditor catches the bug before it ships. New take every week, and you can follow Jon at @FormallyJon.

A protocol can define exactly which contracts may act on its...</p><p><a href="https://veridise.com/blog/audit-insights/low_level_call_hijacking_arcadia_exploit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Insolvency Vulnerability: The Euler Finance $197M Exploit</title>
		<link>https://veridise.com/blog/audit-insights/insolvency-vulnerability-euler-finance-exploit/</link>
		
		<dc:creator><![CDATA[Jon Stephens]]></dc:creator>
		<pubDate>Tue, 28 Jul 2026 14:08:39 +0000</pubDate>
				<category><![CDATA[Audit insights]]></category>
		<category><![CDATA[Featured]]></category>
		<guid isPermaLink="false">https://veridise.com/?p=20391</guid>

					<description><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/07/insolvency-vulnerability-euler-finance-exploit_Jon_Stephens-e1785248010564.jpg" alt="Insolvency Vulnerability: The Euler Finance $197M Exploit" style="width:100%; height:auto;"></div>
<h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Insolvency Vulnerability: The Euler Finance $197M Exploit</h2>
<p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This article is about a solvency invariant that was correctly enforced until a later upgrade, an upgrade that was itself audited. New take every week. Find Jon at @FormallyJon.</p>
<p>A protocol can run the same safety check in every function that moves user funds, then add one new...</p>
<p><a href="https://veridise.com/blog/audit-insights/insolvency-vulnerability-euler-finance-exploit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>

]]></description>
										<content:encoded><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/07/insolvency-vulnerability-euler-finance-exploit_Jon_Stephens-e1785248010564.jpg" alt="Insolvency Vulnerability: The Euler Finance $197M Exploit" style="width:100%; height:auto;"></div><h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Insolvency Vulnerability: The Euler Finance $197M Exploit</h2><p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This article is about a solvency invariant that was correctly enforced until a later upgrade, an upgrade that was itself audited. New take every week. Find Jon at @FormallyJon.

A protocol can run the same safety check in every function that moves user funds, then add one new...</p><p><a href="https://veridise.com/blog/audit-insights/insolvency-vulnerability-euler-finance-exploit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Flash Loan Governance Attacks: How Borrowed Voting Power Drains a Protocol</title>
		<link>https://veridise.com/blog/audit-insights/flash_loan_governance_vulnerability_beanstalk_182m/</link>
		
		<dc:creator><![CDATA[Jon Stephens]]></dc:creator>
		<pubDate>Tue, 21 Jul 2026 13:48:20 +0000</pubDate>
				<category><![CDATA[Audit insights]]></category>
		<category><![CDATA[Featured]]></category>
		<guid isPermaLink="false">https://veridise.com/?p=20343</guid>

					<description><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/07/flash_loan_governance_vulnerability_beanstalk_182m_Jon_Stephens-2-scaled.jpg" alt="Flash Loan Governance Attacks: How Borrowed Voting Power Drains a Protocol" style="width:100%; height:auto;"></div>
<h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Flash Loan Governance Attacks: How Borrowed Voting Power Drains a Protocol</h2>
<p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This week&#039;s edition looks at how governance systems that measure voting power instantaneously, rather than from a fixed checkpoint, become exploitable the moment flash loan liquidity is large enough to buy a temporary supermajority, even for a single block. Jon publishes one of these every week; follow...</p>
<p><a href="https://veridise.com/blog/audit-insights/flash_loan_governance_vulnerability_beanstalk_182m/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>

]]></description>
										<content:encoded><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/07/flash_loan_governance_vulnerability_beanstalk_182m_Jon_Stephens-2-scaled.jpg" alt="Flash Loan Governance Attacks: How Borrowed Voting Power Drains a Protocol" style="width:100%; height:auto;"></div><h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Flash Loan Governance Attacks: How Borrowed Voting Power Drains a Protocol</h2><p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This week&#039;s edition looks at how governance systems that measure voting power instantaneously, rather than from a fixed checkpoint, become exploitable the moment flash loan liquidity is large enough to buy a temporary supermajority, even for a single block. Jon publishes one of these every week; follow...</p><p><a href="https://veridise.com/blog/audit-insights/flash_loan_governance_vulnerability_beanstalk_182m/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Bridge Misconfiguration Vulnerabilities: How One Zero Value Cost $190M</title>
		<link>https://veridise.com/blog/audit-insights/bridge_misconfiguration_nomad_190m_exploit/</link>
		
		<dc:creator><![CDATA[Jon Stephens]]></dc:creator>
		<pubDate>Wed, 15 Jul 2026 13:06:07 +0000</pubDate>
				<category><![CDATA[Audit insights]]></category>
		<category><![CDATA[Featured]]></category>
		<guid isPermaLink="false">https://veridise.com/?p=20285</guid>

					<description><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/07/bridge_misconfiguration_nomad_190m_exploit_Jon_Stephens-scaled-e1784120715710.png" alt="Bridge Misconfiguration Vulnerabilities: How One Zero Value Cost $190M" style="width:100%; height:auto;"></div>
<h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Bridge Misconfiguration Vulnerabilities: How One Zero Value Cost $190M</h2>
<p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This one is about configuration bugs that live in a value set at deployment rather than in the code itself, and how a senior auditor catches them. New take every week. Find Jon at @FormallyJon.</p>
<p>A protocol can audit its code, ship sound validation logic, and still introduce...</p>
<p><a href="https://veridise.com/blog/audit-insights/bridge_misconfiguration_nomad_190m_exploit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>

]]></description>
										<content:encoded><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/07/bridge_misconfiguration_nomad_190m_exploit_Jon_Stephens-scaled-e1784120715710.png" alt="Bridge Misconfiguration Vulnerabilities: How One Zero Value Cost $190M" style="width:100%; height:auto;"></div><h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Bridge Misconfiguration Vulnerabilities: How One Zero Value Cost $190M</h2><p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This one is about configuration bugs that live in a value set at deployment rather than in the code itself, and how a senior auditor catches them. New take every week. Find Jon at @FormallyJon.

A protocol can audit its code, ship sound validation logic, and still introduce...</p><p><a href="https://veridise.com/blog/audit-insights/bridge_misconfiguration_nomad_190m_exploit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Proving the Absence of Soundness Bugs in ZKsync Airbender</title>
		<link>https://veridise.com/blog/security-tools/zksync_airbender_security_formal_verification/</link>
		
		<dc:creator><![CDATA[Shankara Pailoor]]></dc:creator>
		<pubDate>Tue, 30 Jun 2026 14:54:46 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Security tools]]></category>
		<guid isPermaLink="false">https://veridise.com/?p=20256</guid>

					<description><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/06/zksync_airbender_security_formal_verification.png" alt="Proving the Absence of Soundness Bugs in ZKsync Airbender" style="width:100%; height:auto;"></div>
<h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Proving the Absence of Soundness Bugs in ZKsync Airbender</h2>
<p style="font-size: 16px; line-height: 1.5;">Matter Labs engaged Veridise for a tooling-focused security assessment of ZKsync Airbender, the STARK-based RISC-V zkVM that proves execution for the ZKsync ecosystem, ahead of its V2 prover upgrade. Using formal verification to target the soundness bugs that ordinary testing cannot catch, and fuzzing for the ones it can, the engagement verified most of the prover&#039;s circuits and found three...</p>
<p><a href="https://veridise.com/blog/security-tools/zksync_airbender_security_formal_verification/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>

]]></description>
										<content:encoded><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/06/zksync_airbender_security_formal_verification.png" alt="Proving the Absence of Soundness Bugs in ZKsync Airbender" style="width:100%; height:auto;"></div><h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Proving the Absence of Soundness Bugs in ZKsync Airbender</h2><p style="font-size: 16px; line-height: 1.5;">Matter Labs engaged Veridise for a tooling-focused security assessment of ZKsync Airbender, the STARK-based RISC-V zkVM that proves execution for the ZKsync ecosystem, ahead of its V2 prover upgrade. Using formal verification to target the soundness bugs that ordinary testing cannot catch, and fuzzing for the ones it can, the engagement verified most of the prover&#039;s circuits and found three...</p><p><a href="https://veridise.com/blog/security-tools/zksync_airbender_security_formal_verification/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Access Control Bugs in Smart Contracts: How a Negated Check Cost $730K</title>
		<link>https://veridise.com/blog/audit-insights/smart-contract-access-control-superrare-exploit/</link>
		
		<dc:creator><![CDATA[Jon Stephens]]></dc:creator>
		<pubDate>Mon, 29 Jun 2026 15:00:05 +0000</pubDate>
				<category><![CDATA[Audit insights]]></category>
		<category><![CDATA[Featured]]></category>
		<guid isPermaLink="false">https://veridise.com/?p=20251</guid>

					<description><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/06/smart-contract-access-control-vulnerability.jpg" alt="Access Control Bugs in Smart Contracts: How a Negated Check Cost $730K" style="width:100%; height:auto;"></div>
<h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Access Control Bugs in Smart Contracts: How a Negated Check Cost $730K</h2>
<p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This article is about an access control bug that can be easily overlooked since a check is present but effectively does not restrict access. New take every week. Find Jon at @FormallyJon.</p>
<p>A require statement can correctly identify the authorized parties but be implemented in such a way...</p>
<p><a href="https://veridise.com/blog/audit-insights/smart-contract-access-control-superrare-exploit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>

]]></description>
										<content:encoded><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/06/smart-contract-access-control-vulnerability.jpg" alt="Access Control Bugs in Smart Contracts: How a Negated Check Cost $730K" style="width:100%; height:auto;"></div><h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Access Control Bugs in Smart Contracts: How a Negated Check Cost $730K</h2><p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This article is about an access control bug that can be easily overlooked since a check is present but effectively does not restrict access. New take every week. Find Jon at @FormallyJon.

A require statement can correctly identify the authorized parties but be implemented in such a way...</p><p><a href="https://veridise.com/blog/audit-insights/smart-contract-access-control-superrare-exploit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Audit Habit That Would Have Caught Resupplyfi’s $9.6m Bug: The Auditor’s Take</title>
		<link>https://veridise.com/blog/audit-insights/resupplyfi-hack-audit-habit/</link>
		
		<dc:creator><![CDATA[Jon Stephens]]></dc:creator>
		<pubDate>Wed, 13 May 2026 14:42:08 +0000</pubDate>
				<category><![CDATA[Audit insights]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[boundary conditions]]></category>
		<category><![CDATA[DeFi exploit]]></category>
		<category><![CDATA[ERC-4626]]></category>
		<category><![CDATA[ERC-4626 inflation attack]]></category>
		<category><![CDATA[lending protocol exploit]]></category>
		<category><![CDATA[oracle manipulation]]></category>
		<category><![CDATA[ResupplyFi]]></category>
		<category><![CDATA[ResupplyFi hack]]></category>
		<category><![CDATA[share price inflation]]></category>
		<category><![CDATA[smart contract audit]]></category>
		<guid isPermaLink="false">https://veridise.com/?p=20055</guid>

					<description><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/05/Jon-Stephens-RessuplyFi-Hack.png" alt="The Audit Habit That Would Have Caught Resupplyfi’s $9.6m Bug: The Auditor’s Take" style="width:100%; height:auto;"></div>
<h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">The Audit Habit That Would Have Caught Resupplyfi’s $9.6m Bug: The Auditor’s Take</h2>
<p style="font-size: 16px; line-height: 1.5;">In June 2025, ResupplyFi&#039;s wstUSR lending market lost $9.6 million in a single transaction. One division operation rounded down to zero at a boundary the solvency check did not anticipate.</p>
<p>The check read the zero as &quot;this borrower is well within their loan-to-value ceiling,&quot; and the attacker borrowed the full pool against 1 wei of collateral. The bug class is an...</p>
<p><a href="https://veridise.com/blog/audit-insights/resupplyfi-hack-audit-habit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>

]]></description>
										<content:encoded><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/05/Jon-Stephens-RessuplyFi-Hack.png" alt="The Audit Habit That Would Have Caught Resupplyfi’s $9.6m Bug: The Auditor’s Take" style="width:100%; height:auto;"></div><h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">The Audit Habit That Would Have Caught Resupplyfi’s $9.6m Bug: The Auditor’s Take</h2><p style="font-size: 16px; line-height: 1.5;">In June 2025, ResupplyFi&#039;s wstUSR lending market lost $9.6 million in a single transaction. One division operation rounded down to zero at a boundary the solvency check did not anticipate.

The check read the zero as &quot;this borrower is well within their loan-to-value ceiling,&quot; and the attacker borrowed the full pool against 1 wei of collateral. The bug class is an...</p><p><a href="https://veridise.com/blog/audit-insights/resupplyfi-hack-audit-habit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>LLZK Joins Ethereum Security Quadratic Funding Round on Giveth</title>
		<link>https://veridise.com/blog/veridise-announcements/llzk-joins-ethereum-security-quadratic-funding-round-on-giveth/</link>
		
		<dc:creator><![CDATA[Thomas Guerber]]></dc:creator>
		<pubDate>Tue, 28 Apr 2026 13:43:58 +0000</pubDate>
				<category><![CDATA[Veridise announcements]]></category>
		<guid isPermaLink="false">https://veridise.com/?p=19866</guid>

					<description><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/04/ChatGPT-Image-28-avr.-2026-14_56_45.png" alt="LLZK Joins Ethereum Security Quadratic Funding Round on Giveth" style="width:100%; height:auto;"></div>
<h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">LLZK Joins Ethereum Security Quadratic Funding Round on Giveth</h2>
<p style="font-size: 16px; line-height: 1.5;">LLZK, the open source compiler framework for zero knowledge circuit verification, has been accepted into TheDAO Security Fund&#039;s first decentralized funding initiative on Giveth. The round uses quadratic funding to allocate 500 ETH ($1M) across projects strengthening Ethereum&#039;s security ecosystem, and LLZK is one of them.</p>
<p>TLDR</p>
<p> 	LLZK accepted into TheDAO Security Fund&#039;s QF round on Giveth.<br />
 	500 ETH ($1M) matching...</p>
<p><a href="https://veridise.com/blog/veridise-announcements/llzk-joins-ethereum-security-quadratic-funding-round-on-giveth/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>

]]></description>
										<content:encoded><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/04/ChatGPT-Image-28-avr.-2026-14_56_45.png" alt="LLZK Joins Ethereum Security Quadratic Funding Round on Giveth" style="width:100%; height:auto;"></div><h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">LLZK Joins Ethereum Security Quadratic Funding Round on Giveth</h2><p style="font-size: 16px; line-height: 1.5;">LLZK, the open source compiler framework for zero knowledge circuit verification, has been accepted into TheDAO Security Fund&#039;s first decentralized funding initiative on Giveth. The round uses quadratic funding to allocate 500 ETH ($1M) across projects strengthening Ethereum&#039;s security ecosystem, and LLZK is one of them.

TLDR

 	LLZK accepted into TheDAO Security Fund&#039;s QF round on Giveth.
 	500 ETH ($1M) matching...</p><p><a href="https://veridise.com/blog/veridise-announcements/llzk-joins-ethereum-security-quadratic-funding-round-on-giveth/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
