COLOSSEUM · CRYPTO WORLD'S FAIR '26

PROOF,NOT OPINION.

You built it — now test it like an attacker. Point the pack at your contract, wallet or protocol — it finds the bug class, writes the exploit, runs it on a local validator — never mainnet —and anchors the verdict on-chain. Security you can check yourself — proof, not opinions.

cachorro — the pack terminal
The cachorro — a wireframe guard dog in neon phosphor green, chained to a Solana program
$ unleash <target>
PACK MINDreplay of a real hunt
▊
$6.3M on the board|174 programs indexed|14 hunts logged|12 proven · 3 refuted by gate · 0 false positives shipped|8 receipts anchored on devnet|0 mainnet txs — local validator only|journal: hash-chained

THE BOARD IS THE THREAT MAP

$6.3M standing incentiveall 174 ↗

Every program below already pays for a verified exploit. Someone will collect — the only question is who hunts first. If your program is on this board, it should be the pack.

Chainlink$3.0MHUNT ▸
0x$1.0MHUNT ▸
Raydium$505KHUNT ▸
Orca$500KHUNT ▸
Aevo$300KSCOPE ↗
Pyth Network$250KHUNT ▸
~/

THE HUNT, END TO END

~40min — 2.5h
1
$ cachorro hunt <your-program>
POINT AT YOUR PROGRAM

Your contract, wallet or protocol — GitHub repo or on-chain program ID. Fetch and static lint run in seconds — no wallet, no signup, no sales call.

fetch 5s · static 7s
2
$ pack --stages research..review
WATCH THE PACK THINK

RESEARCH → ANALYZE → DEVIL → POC → REVIEW. Every hypothesis, dead-end and verdict streams live — you watch the reasoning, not a spinner.

reasoning, not a spinner
3
$ attest verify <sha256>
VERIFY THE RECEIPT

Findings ship with an executable PoC (treatment drains, control blocks) and an on-chain attestation anchored to the exact bytes tested.

anchored on-chain · revocable
$285M

drained from Drift in 128 seconds — after the audit. Reports ship prose; Immunefi won't pay without a runnable exploit. Detection is commodity. Proof is the product.

nothing promotes without proof — the gate is enforced by the machine, not the prompt
OBSERVATION
static lint + on-chain dump become typed graph nodes
● ENFORCED
HYPOTHESIS
each candidate carries a falsifier — what would disprove it
● ENFORCED
EXPERIMENT
treatment vs negative control on a local validator
● ENFORCED
VERIFIED
the gate refuses promotion without oracle SUPPORTS + reproduction
● ENFORCED
oracle verdict on the last hunt: SUPPORTS — treatment drained 5,000,000,000 lamports, control rejected with Custom(1)

THE PROOF STACK

probabilistic → calibrated → deterministic

Probabilistic models hallucinate bugs — false positives. Statistical scanners sleep through them — false negatives. The pack uses each where it wins:

PROPOSE
the model hunts
Research + analysis fan out for recall — semgrep sets the coverage floor, the model reads what patterns miss. It may be wrong; that's allowed here.
WEIGH
the judge calibrates
Every promoted claim gets a typed exploit-plausibility score from a System One judge — a probability, not prose. Dissent shows on the certificate.
PROVE
the machine disposes
Nothing ships without oracle verdict + reproduction on a local validator — treatment drains, control blocks. The gate is code, not a prompt.
then the pack audits itself: self-audit tripwires catch bias — promotion without proof, suspiciously-easy verification, confirmation collapse — and atlas coverage reports which vuln classes were actually exercised. flags become part of the receipt's journal.

WHAT A $150K AUDIT SHIPS

vs what the pack ships

For protocol teams about to wire five figures for a PDF — contracts, wallets, protocols. And for every team that already knows Immunefi pays for exploits, not prose.

THE FIRM
  • ✗ 8–16 week queue while your TVL sits exposed
  • ✗ a PDF where most “findings” are informational noise
  • ✗ you pay for triage — they never prove a thing executes
  • ✗ expires silently the day you ship an upgrade
THE PACK
  • ✓ hours, not months — you watch the hunt live
  • ✓ executable PoCs — treatment drains, control blocks
  • ✓ machine-enforced gate: no proof, no finding
  • ✓ a receipt on-chain that expires when your program does

THE RECEIPT LIVES ON-CHAIN

Every finished hunt anchors a SHA-256 digest of the report — bound to the audited commit, the build digest and the hash-chained evidence journal — as a Solana memo. Tamper with either side and the digests diverge.

And the receipt knows when it's stale: the program upgrades, the digest stops matching, the attestation expires on its own.

▸ verify a receipt yourself — no trust in us required ↗
A holographic attestation scroll chained on-chain
ATTESTATIONdevnet
memocachorro:v1:3987b6c4…
tx5QnooNTuvmjZ… ↗
recomputeddigest ✓ matches
verifyrecomputed → MATCH
trivial for your users to verify — hard for anyone to fake

WHAT THE PACK HUNTS

ACCOUNTS & AUTHORITY
Missing signer/owner checks, account substitution, type confusion, remaining_accounts abuse, duplicate mutable accounts — the classes that empty a vault in one instruction.
PDA · CPI · MATH
Seed collisions and init_if_needed reinit, unpinned program IDs on arbitrary CPI, introspection atomicity, share inflation, cast/rounding bugs, close & rent theft.
ORACLE · TOKEN-2022 · ZK
Stale/manipulable price feeds, mint↔vault binding, transfer hooks — plus on-chain verifier soundness, nullifier double-spend and root validation for zk programs.

LEARN BY HUNTING

Your team reads the attacker's playbook — every Sealevel vulnerability class, vulnerable vs secure side by side, the real exploit it caused, and a button that sets the pack loose on it.

ENTER THE LABS ▸

FIELD LOG

every row is a real run
RECENT HUNTS—
loading…
RULES OF ENGAGEMENT
  • ▸ Audit only what you are authorized to audit — an active bounty or the owner's own program — authorized surface only.
  • ▸ PoCs run on a local validator or a local fork. No attack transaction ever touches mainnet.
  • ▸ Nothing is submitted automatically. A human reproduces the bug and files it through the official channel.
  • ▸ Untrusted targets are cloned, never built — a third-party build.rs is arbitrary code execution.
WHAT ATTESTED MEANS

cachorro-attested = this exact artifact was adversarially tested and here is the reproducible evidence, on-chain and revocable.

It is not a proof the program is safe. Verified builds have been hacked twice. We narrow the gap — reproduced PoCs, negative controls, bytes-bound digests — and say so out loud.

THE SKEPTIC SECTION

"isn't this just an LLM reading code?"
Probabilistic models hallucinate bugs (false positives); statistical scanners sleep through them (false negatives). The pack couples both: the model proposes for recall, the machine disposes for precision — nothing becomes a finding without oracle verdict + reproduction.
"does it replace a human audit?"
No — and anyone who says otherwise is selling you noise. It's the verified floor under one: cheap, continuous, executable. Deep economic exploits still want a human brain.
"does it touch mainnet?"
Never. Every PoC runs on a local validator or fork. The only on-chain write is the memo receipt.
"who submits the bug?"
A human, through the official bounty channel, after reproducing it. Nothing auto-submits.
"why trust the receipt?"
Don't. Recompute the digest yourself — that's the whole point. /verify
your contract. your wallet. your protocol. your move.
TEST IT. PROVE IT. SHIP THE RECEIPT.

Recon on your program is free — see what the pack finds before you pay anyone anything. The engagement prices against the audit you didn't buy: paid in SOL, verified on-chain, and it expires loudly when you upgrade.