PROOF,NOT OPINION.
You built it — now test it like an attacker. Point the pack at your contract, wallet or protocol — it finds the bug class, writes the exploit, runs it on a local validator — never mainnet —and anchors the verdict on-chain. Security you can check yourself — proof, not opinions.

Every program below already pays for a verified exploit. Someone will collect — the only question is who hunts first. If your program is on this board, it should be the pack.
THE HUNT, END TO END
~40min — 2.5hYour contract, wallet or protocol — GitHub repo or on-chain program ID. Fetch and static lint run in seconds — no wallet, no signup, no sales call.
RESEARCH → ANALYZE → DEVIL → POC → REVIEW. Every hypothesis, dead-end and verdict streams live — you watch the reasoning, not a spinner.
Findings ship with an executable PoC (treatment drains, control blocks) and an on-chain attestation anchored to the exact bytes tested.
drained from Drift in 128 seconds — after the audit. Reports ship prose; Immunefi won't pay without a runnable exploit. Detection is commodity. Proof is the product.
THE PROOF STACK
probabilistic → calibrated → deterministicProbabilistic models hallucinate bugs — false positives. Statistical scanners sleep through them — false negatives. The pack uses each where it wins:
WHAT A $150K AUDIT SHIPS
vs what the pack shipsFor protocol teams about to wire five figures for a PDF — contracts, wallets, protocols. And for every team that already knows Immunefi pays for exploits, not prose.
- ✗ 8–16 week queue while your TVL sits exposed
- ✗ a PDF where most “findings” are informational noise
- ✗ you pay for triage — they never prove a thing executes
- ✗ expires silently the day you ship an upgrade
- ✓ hours, not months — you watch the hunt live
- ✓ executable PoCs — treatment drains, control blocks
- ✓ machine-enforced gate: no proof, no finding
- ✓ a receipt on-chain that expires when your program does
THE RECEIPT LIVES ON-CHAIN
Every finished hunt anchors a SHA-256 digest of the report — bound to the audited commit, the build digest and the hash-chained evidence journal — as a Solana memo. Tamper with either side and the digests diverge.
And the receipt knows when it's stale: the program upgrades, the digest stops matching, the attestation expires on its own.
▸ verify a receipt yourself — no trust in us required ↗
WHAT THE PACK HUNTS
LEARN BY HUNTING
Your team reads the attacker's playbook — every Sealevel vulnerability class, vulnerable vs secure side by side, the real exploit it caused, and a button that sets the pack loose on it.
FIELD LOG
every row is a real run- ▸ Audit only what you are authorized to audit — an active bounty or the owner's own program — authorized surface only.
- ▸ PoCs run on a local validator or a local fork. No attack transaction ever touches mainnet.
- ▸ Nothing is submitted automatically. A human reproduces the bug and files it through the official channel.
- ▸ Untrusted targets are cloned, never built — a third-party build.rs is arbitrary code execution.
cachorro-attested = this exact artifact was adversarially tested and here is the reproducible evidence, on-chain and revocable.
It is not a proof the program is safe. Verified builds have been hacked twice. We narrow the gap — reproduced PoCs, negative controls, bytes-bound digests — and say so out loud.
THE SKEPTIC SECTION
Recon on your program is free — see what the pack finds before you pay anyone anything. The engagement prices against the audit you didn't buy: paid in SOL, verified on-chain, and it expires loudly when you upgrade.