<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Smart contract audits from Veridise</title>
	<atom:link href="https://veridise.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://veridise.com/</link>
	<description></description>
	<lastBuildDate>Fri, 25 Sep 2026 02:23:13 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://veridise.com/wp-content/uploads/2024/01/Symbol-on-light-bg-copy-150x150.png</url>
	<title>Smart contract audits from Veridise</title>
	<link>https://veridise.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>When a Contract Trusts the Caller&#8217;s Encoding</title>
		<link>https://veridise.com/blog/audit-insights/arbitrary_external_call_injection_socket_exploit/</link>
		
		<dc:creator><![CDATA[Jon Stephens]]></dc:creator>
		<pubDate>Wed, 16 Sep 2026 14:12:25 +0000</pubDate>
				<category><![CDATA[Audit insights]]></category>
		<category><![CDATA[Featured]]></category>
		<guid isPermaLink="false">https://veridise.com/?p=20544</guid>

					<description><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/09/arbitrary_external_call_injection_socket_exploit_Jon_Stephens-scaled.png" alt="When a Contract Trusts the Caller&#8217;s Encoding" style="width:100%; height:auto;"></div>
<h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">When a Contract Trusts the Caller&#8217;s Encoding</h2>
<p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This one covers arbitrary external call injection, where a contract performs an action on a caller&#039;s behalf without checking what that action is. Each week&#039;s take goes out at @FormallyJon.</p>
<p>Arbitrary external call injection is what happens when a contract builds an external call out of arguments its...</p>
<p><a href="https://veridise.com/blog/audit-insights/arbitrary_external_call_injection_socket_exploit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>

]]></description>
										<content:encoded><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/09/arbitrary_external_call_injection_socket_exploit_Jon_Stephens-scaled.png" alt="When a Contract Trusts the Caller&#8217;s Encoding" style="width:100%; height:auto;"></div><h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">When a Contract Trusts the Caller&#8217;s Encoding</h2><p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This one covers arbitrary external call injection, where a contract performs an action on a caller&#039;s behalf without checking what that action is. Each week&#039;s take goes out at @FormallyJon.

Arbitrary external call injection is what happens when a contract builds an external call out of arguments its...</p><p><a href="https://veridise.com/blog/audit-insights/arbitrary_external_call_injection_socket_exploit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Reentrancy in Reward Accounting: How $27M Was Paid Out on a Deposit</title>
		<link>https://veridise.com/blog/audit-insights/reentrancy_reward_accounting_penpie_27m_exploit/</link>
		
		<dc:creator><![CDATA[Jon Stephens]]></dc:creator>
		<pubDate>Tue, 01 Sep 2026 14:54:57 +0000</pubDate>
				<category><![CDATA[Audit insights]]></category>
		<category><![CDATA[Featured]]></category>
		<guid isPermaLink="false">https://veridise.com/?p=20528</guid>

					<description><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/09/reentrancy_reward_accounting_penpie_27m_exploit_jon_stephens-scaled.png" alt="Reentrancy in Reward Accounting: How $27M Was Paid Out on a Deposit" style="width:100%; height:auto;"></div>
<h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Reentrancy in Reward Accounting: How $27M Was Paid Out on a Deposit</h2>
<p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This one is about a reentrancy bug, and about what a reward calculation measures when it subtracts two balances. There is a new one each week, and Jon posts them at @FormallyJon.</p>
<p>Penpie accepted Pendle market LP tokens and paid depositors the rewards those tokens earned, boosted above...</p>
<p><a href="https://veridise.com/blog/audit-insights/reentrancy_reward_accounting_penpie_27m_exploit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>

]]></description>
										<content:encoded><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/09/reentrancy_reward_accounting_penpie_27m_exploit_jon_stephens-scaled.png" alt="Reentrancy in Reward Accounting: How $27M Was Paid Out on a Deposit" style="width:100%; height:auto;"></div><h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Reentrancy in Reward Accounting: How $27M Was Paid Out on a Deposit</h2><p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This one is about a reentrancy bug, and about what a reward calculation measures when it subtracts two balances. There is a new one each week, and Jon posts them at @FormallyJon.

Penpie accepted Pendle market LP tokens and paid depositors the rewards those tokens earned, boosted above...</p><p><a href="https://veridise.com/blog/audit-insights/reentrancy_reward_accounting_penpie_27m_exploit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Veridise Audits the Strategy Contracts Behind Lombard&#8217;s Bitcoin Vaults</title>
		<link>https://veridise.com/blog/audits-archive/lombard_smart_contract_audit_strategy_vault/</link>
		
		<dc:creator><![CDATA[Veridise]]></dc:creator>
		<pubDate>Fri, 28 Aug 2026 13:25:33 +0000</pubDate>
				<category><![CDATA[Audits archive]]></category>
		<category><![CDATA[Featured]]></category>
		<guid isPermaLink="false">https://veridise.com/?p=20522</guid>

					<description><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/08/lombard_smart_contract_audit_strategy_vault-1-scaled.jpg" alt="Veridise Audits the Strategy Contracts Behind Lombard&#8217;s Bitcoin Vaults" style="width:100%; height:auto;"></div>
<h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Veridise Audits the Strategy Contracts Behind Lombard&#8217;s Bitcoin Vaults</h2>
<p style="font-size: 16px; line-height: 1.5;">Lombard has launched an on-chain vault system where risk curators and asset managers offer Bitcoin yield products to users through a single vault deposit. Veridise audited the smart contracts behind that vault infrastructure, the strategy logic, blocklist, converters, shards, and validator, pairing manual review with property-based fuzz testing. The review found one high-severity bug, since fixed, and fixed 14 findings...</p>
<p><a href="https://veridise.com/blog/audits-archive/lombard_smart_contract_audit_strategy_vault/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>

]]></description>
										<content:encoded><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/08/lombard_smart_contract_audit_strategy_vault-1-scaled.jpg" alt="Veridise Audits the Strategy Contracts Behind Lombard&#8217;s Bitcoin Vaults" style="width:100%; height:auto;"></div><h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Veridise Audits the Strategy Contracts Behind Lombard&#8217;s Bitcoin Vaults</h2><p style="font-size: 16px; line-height: 1.5;">Lombard has launched an on-chain vault system where risk curators and asset managers offer Bitcoin yield products to users through a single vault deposit. Veridise audited the smart contracts behind that vault infrastructure, the strategy logic, blocklist, converters, shards, and validator, pairing manual review with property-based fuzz testing. The review found one high-severity bug, since fixed, and fixed 14 findings...</p><p><a href="https://veridise.com/blog/audits-archive/lombard_smart_contract_audit_strategy_vault/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>ZK Circuit Equivalence Checking: Introducing LLEQ</title>
		<link>https://veridise.com/blog/research/zk-circuit-equivalence-checking-introducing-lleq/</link>
		
		<dc:creator><![CDATA[Raghav Malik]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 13:54:51 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Research]]></category>
		<guid isPermaLink="false">https://veridise.com/?p=20508</guid>

					<description><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/08/zk_circuit_equivalence_checking_lleq_Raghav_Malik_-scaled.jpg" alt="ZK Circuit Equivalence Checking: Introducing LLEQ" style="width:100%; height:auto;"></div>
<h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">ZK Circuit Equivalence Checking: Introducing LLEQ</h2>
<p style="font-size: 16px; line-height: 1.5;">Every ZK circuit is written twice. The witness generator evaluates the computation and assigns concrete values to the circuit&#039;s signals, and the constraints are polynomial equations that decide whether a given assignment gets accepted. A developer writes both, often on adjacent lines of the same file. The prover runs the witness generator to produce a set of signal values, and...</p>
<p><a href="https://veridise.com/blog/research/zk-circuit-equivalence-checking-introducing-lleq/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>

]]></description>
										<content:encoded><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/08/zk_circuit_equivalence_checking_lleq_Raghav_Malik_-scaled.jpg" alt="ZK Circuit Equivalence Checking: Introducing LLEQ" style="width:100%; height:auto;"></div><h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">ZK Circuit Equivalence Checking: Introducing LLEQ</h2><p style="font-size: 16px; line-height: 1.5;">Every ZK circuit is written twice. The witness generator evaluates the computation and assigns concrete values to the circuit&#039;s signals, and the constraints are polynomial equations that decide whether a given assignment gets accepted. A developer writes both, often on adjacent lines of the same file. The prover runs the witness generator to produce a set of signal values, and...</p><p><a href="https://veridise.com/blog/research/zk-circuit-equivalence-checking-introducing-lleq/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Constant Product Manipulation: When a Token Breaks the Pool It Was Built For</title>
		<link>https://veridise.com/blog/audit-insights/constant-product-manipulation-future-protocol-exploit/</link>
		
		<dc:creator><![CDATA[Jon Stephens]]></dc:creator>
		<pubDate>Wed, 19 Aug 2026 16:35:56 +0000</pubDate>
				<category><![CDATA[Audit insights]]></category>
		<category><![CDATA[Featured]]></category>
		<guid isPermaLink="false">https://veridise.com/?p=20500</guid>

					<description><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/08/FPC-AH-Blog-Banner1--e1787158016359.jpg" alt="Constant Product Manipulation: When a Token Breaks the Pool It Was Built For" style="width:100%; height:auto;"></div>
<h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Constant Product Manipulation: When a Token Breaks the Pool It Was Built For</h2>
<p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This article is about a class of bug where a token&#039;s own transfer logic breaks an invariant of the protocol it was written to work with. New take every week. Find Jon at @FormallyJon.</p>
<p>Custom token implementations that add fees or constraints to events like transfers, mints and...</p>
<p><a href="https://veridise.com/blog/audit-insights/constant-product-manipulation-future-protocol-exploit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>

]]></description>
										<content:encoded><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/08/FPC-AH-Blog-Banner1--e1787158016359.jpg" alt="Constant Product Manipulation: When a Token Breaks the Pool It Was Built For" style="width:100%; height:auto;"></div><h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Constant Product Manipulation: When a Token Breaks the Pool It Was Built For</h2><p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This article is about a class of bug where a token&#039;s own transfer logic breaks an invariant of the protocol it was written to work with. New take every week. Find Jon at @FormallyJon.

Custom token implementations that add fees or constraints to events like transfers, mints and...</p><p><a href="https://veridise.com/blog/audit-insights/constant-product-manipulation-future-protocol-exploit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Mina Multisig Audit: Veridise Reviews FROST Signing</title>
		<link>https://veridise.com/blog/audits-archive/mina_multisig_audit_frost_signature/</link>
		
		<dc:creator><![CDATA[Jon Stephens]]></dc:creator>
		<pubDate>Tue, 11 Aug 2026 16:18:24 +0000</pubDate>
				<category><![CDATA[Audits archive]]></category>
		<category><![CDATA[Featured]]></category>
		<guid isPermaLink="false">https://veridise.com/?p=20478</guid>

					<description><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/08/Mina-multisig-audit.jpg" alt="Mina Multisig Audit: Veridise Reviews FROST Signing" style="width:100%; height:auto;"></div>
<h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Mina Multisig Audit: Veridise Reviews FROST Signing</h2>
<p style="font-size: 16px; line-height: 1.5;">Mina Multisig lets Mina and ecosystem projects operate through a threshold signature instead of a single key, adapting the FROST protocol to Mina&#039;s Pallas curve and Poseidon hashing. Veridise completed a manual audit of that implementation in June 2026, reviewing the two Rust crates that turn FROST&#039;s signing flow into Mina-compatible signatures. The audit found six issues, all fixed, before...</p>
<p><a href="https://veridise.com/blog/audits-archive/mina_multisig_audit_frost_signature/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>

]]></description>
										<content:encoded><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/08/Mina-multisig-audit.jpg" alt="Mina Multisig Audit: Veridise Reviews FROST Signing" style="width:100%; height:auto;"></div><h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Mina Multisig Audit: Veridise Reviews FROST Signing</h2><p style="font-size: 16px; line-height: 1.5;">Mina Multisig lets Mina and ecosystem projects operate through a threshold signature instead of a single key, adapting the FROST protocol to Mina&#039;s Pallas curve and Poseidon hashing. Veridise completed a manual audit of that implementation in June 2026, reviewing the two Rust crates that turn FROST&#039;s signing flow into Mina-compatible signatures. The audit found six issues, all fixed, before...</p><p><a href="https://veridise.com/blog/audits-archive/mina_multisig_audit_frost_signature/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Low-Level Call Hijacking: How a Trusted Router Call Cost $3.5M</title>
		<link>https://veridise.com/blog/audit-insights/low_level_call_hijacking_arcadia_exploit/</link>
		
		<dc:creator><![CDATA[Jon Stephens]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 13:56:52 +0000</pubDate>
				<category><![CDATA[Audit insights]]></category>
		<category><![CDATA[Featured]]></category>
		<guid isPermaLink="false">https://veridise.com/?p=20471</guid>

					<description><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/08/low_level_call_hijacking_arcadia_exploit_Jon_Stephens-e1785938189392.jpg" alt="Low-Level Call Hijacking: How a Trusted Router Call Cost $3.5M" style="width:100%; height:auto;"></div>
<h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Low-Level Call Hijacking: How a Trusted Router Call Cost $3.5M</h2>
<p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This one is about privileged contracts that forward caller-supplied data straight into a low-level call, and how a senior auditor catches the bug before it ships. New take every week, and you can follow Jon at @FormallyJon.</p>
<p>A protocol can define exactly which contracts may act on its...</p>
<p><a href="https://veridise.com/blog/audit-insights/low_level_call_hijacking_arcadia_exploit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>

]]></description>
										<content:encoded><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/08/low_level_call_hijacking_arcadia_exploit_Jon_Stephens-e1785938189392.jpg" alt="Low-Level Call Hijacking: How a Trusted Router Call Cost $3.5M" style="width:100%; height:auto;"></div><h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Low-Level Call Hijacking: How a Trusted Router Call Cost $3.5M</h2><p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This one is about privileged contracts that forward caller-supplied data straight into a low-level call, and how a senior auditor catches the bug before it ships. New take every week, and you can follow Jon at @FormallyJon.

A protocol can define exactly which contracts may act on its...</p><p><a href="https://veridise.com/blog/audit-insights/low_level_call_hijacking_arcadia_exploit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Insolvency Vulnerability: The Euler Finance $197M Exploit</title>
		<link>https://veridise.com/blog/audit-insights/insolvency-vulnerability-euler-finance-exploit/</link>
		
		<dc:creator><![CDATA[Jon Stephens]]></dc:creator>
		<pubDate>Tue, 28 Jul 2026 14:08:39 +0000</pubDate>
				<category><![CDATA[Audit insights]]></category>
		<category><![CDATA[Featured]]></category>
		<guid isPermaLink="false">https://veridise.com/?p=20391</guid>

					<description><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/07/insolvency-vulnerability-euler-finance-exploit_Jon_Stephens-e1785248010564.jpg" alt="Insolvency Vulnerability: The Euler Finance $197M Exploit" style="width:100%; height:auto;"></div>
<h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Insolvency Vulnerability: The Euler Finance $197M Exploit</h2>
<p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This article is about a solvency invariant that was correctly enforced until a later upgrade, an upgrade that was itself audited. New take every week. Find Jon at @FormallyJon.</p>
<p>A protocol can run the same safety check in every function that moves user funds, then add one new...</p>
<p><a href="https://veridise.com/blog/audit-insights/insolvency-vulnerability-euler-finance-exploit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>

]]></description>
										<content:encoded><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/07/insolvency-vulnerability-euler-finance-exploit_Jon_Stephens-e1785248010564.jpg" alt="Insolvency Vulnerability: The Euler Finance $197M Exploit" style="width:100%; height:auto;"></div><h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Insolvency Vulnerability: The Euler Finance $197M Exploit</h2><p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This article is about a solvency invariant that was correctly enforced until a later upgrade, an upgrade that was itself audited. New take every week. Find Jon at @FormallyJon.

A protocol can run the same safety check in every function that moves user funds, then add one new...</p><p><a href="https://veridise.com/blog/audit-insights/insolvency-vulnerability-euler-finance-exploit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Flash Loan Governance Attacks: How Borrowed Voting Power Drains a Protocol</title>
		<link>https://veridise.com/blog/audit-insights/flash_loan_governance_vulnerability_beanstalk_182m/</link>
		
		<dc:creator><![CDATA[Jon Stephens]]></dc:creator>
		<pubDate>Tue, 21 Jul 2026 13:48:20 +0000</pubDate>
				<category><![CDATA[Audit insights]]></category>
		<category><![CDATA[Featured]]></category>
		<guid isPermaLink="false">https://veridise.com/?p=20343</guid>

					<description><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/07/flash_loan_governance_vulnerability_beanstalk_182m_Jon_Stephens-2-scaled.jpg" alt="Flash Loan Governance Attacks: How Borrowed Voting Power Drains a Protocol" style="width:100%; height:auto;"></div>
<h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Flash Loan Governance Attacks: How Borrowed Voting Power Drains a Protocol</h2>
<p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This week&#039;s edition looks at how governance systems that measure voting power instantaneously, rather than from a fixed checkpoint, become exploitable the moment flash loan liquidity is large enough to buy a temporary supermajority, even for a single block. Jon publishes one of these every week; follow...</p>
<p><a href="https://veridise.com/blog/audit-insights/flash_loan_governance_vulnerability_beanstalk_182m/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>

]]></description>
										<content:encoded><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/07/flash_loan_governance_vulnerability_beanstalk_182m_Jon_Stephens-2-scaled.jpg" alt="Flash Loan Governance Attacks: How Borrowed Voting Power Drains a Protocol" style="width:100%; height:auto;"></div><h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Flash Loan Governance Attacks: How Borrowed Voting Power Drains a Protocol</h2><p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This week&#039;s edition looks at how governance systems that measure voting power instantaneously, rather than from a fixed checkpoint, become exploitable the moment flash loan liquidity is large enough to buy a temporary supermajority, even for a single block. Jon publishes one of these every week; follow...</p><p><a href="https://veridise.com/blog/audit-insights/flash_loan_governance_vulnerability_beanstalk_182m/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Bridge Misconfiguration Vulnerabilities: How One Zero Value Cost $190M</title>
		<link>https://veridise.com/blog/audit-insights/bridge_misconfiguration_nomad_190m_exploit/</link>
		
		<dc:creator><![CDATA[Jon Stephens]]></dc:creator>
		<pubDate>Wed, 15 Jul 2026 13:06:07 +0000</pubDate>
				<category><![CDATA[Audit insights]]></category>
		<category><![CDATA[Featured]]></category>
		<guid isPermaLink="false">https://veridise.com/?p=20285</guid>

					<description><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/07/bridge_misconfiguration_nomad_190m_exploit_Jon_Stephens-scaled-e1784120715710.png" alt="Bridge Misconfiguration Vulnerabilities: How One Zero Value Cost $190M" style="width:100%; height:auto;"></div>
<h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Bridge Misconfiguration Vulnerabilities: How One Zero Value Cost $190M</h2>
<p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This one is about configuration bugs that live in a value set at deployment rather than in the code itself, and how a senior auditor catches them. New take every week. Find Jon at @FormallyJon.</p>
<p>A protocol can audit its code, ship sound validation logic, and still introduce...</p>
<p><a href="https://veridise.com/blog/audit-insights/bridge_misconfiguration_nomad_190m_exploit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>

]]></description>
										<content:encoded><![CDATA[<div style="text-align:center;"><img src="https://veridise.com/wp-content/uploads/2026/07/bridge_misconfiguration_nomad_190m_exploit_Jon_Stephens-scaled-e1784120715710.png" alt="Bridge Misconfiguration Vulnerabilities: How One Zero Value Cost $190M" style="width:100%; height:auto;"></div><h2 style="font-size: 24px; font-weight: bold; margin-top: 15px; line-height: 1.45;">Bridge Misconfiguration Vulnerabilities: How One Zero Value Cost $190M</h2><p style="font-size: 16px; line-height: 1.5;">The Auditor&#039;s Take is a weekly series by Jon Stephens, CEO of Veridise. This one is about configuration bugs that live in a value set at deployment rather than in the code itself, and how a senior auditor catches them. New take every week. Find Jon at @FormallyJon.

A protocol can audit its code, ship sound validation logic, and still introduce...</p><p><a href="https://veridise.com/blog/audit-insights/bridge_misconfiguration_nomad_190m_exploit/" style="color: #0073e6; font-size: 16px; font-weight: bold;">Read More →</a></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
