spearbit/armory

A one-stop shop for blockchain security researchers looking for educational material and alpha to level-up and get an edge on competition. This is not your standard roadmap, top 10 vulnerabilities, or find-the-bug content. This is for the real researchooors.

405

39 commits

updated Mar 1, 2026

See the code

README

Spearbit Armory GitHub Banner


Requesting a Security Review

In order to request a security review, please fill out our short request form.

For a brief overview of what Spearbit is and what we have to offer click here or reach out to us via Twitter.

If you have any urgent needs or would prefer a direct contact, please reach out to our COO - miike@spearbit.com

Who are we?

Spearbit is a distributed network of industry-leading security researchers tackling the most complex and mission-critical protocols across web3. Our network has extensive experience on every part of the blockchain technology stack.

Table of Contents

Content

This section contains all externally available educational material from Spearbit. The goal of publicizing and creating content like this is to foster and support a community of dedicated researchers consistently motivated to take the next step in their web3 security knowledge and for that material to be just as beneficial to those with more experience in the field as it is to juniors.

Tldr; We believe in elevating the standard for security research, thus our content will reflect the same.

ZKP Education

This section contains ZKP resources produced by Spearbit researchers or invited seminar guests in order to provide a stronger base for researchers to develop their understanding of security posture within ZKPs

TitleTypeMedia Link
Introduction to ZKPsSeminarVideo
Demsytifying ZKPsWrite-upArticle
Intoduction to ZKP SecuritySeminarVideo
Nova: ZK Bug of the Year BreakdownSeminarVideo
Analyzing Polygon zkEVM: PIL State MachinesSeminarVideo
Polygon zkEVM Flawed Division Vulnerability BreakdownThread + ManimThread
Improper Rewards Calculation on Epoch BoundaryThread + ManimThread

Report and Finding Breakdowns

These breakdowns are concise and guided write-ups of findings from some of Spearbit’s top researchers. Study them intently in order to extract the process and perspective of some of the best researchers in the game.

TitleRiskProtocol(s)Written BreakdownReport Link
Morpho ↔ Aave v3 integration edge caseCritical (Morpho Labs)Morpho Labs (primary) and Aave v3 (dependency)BreakdownReport
Balancer DependencyCriticalAera Finance and BalancerBreakdownReport
“Clones-with-immutable-args” and improper Bytes ValidationCriticalSudoswapBreakdownReport
Polygon zkEVM Flawed Division Remainder CheckCriticalPolygon zkEVMBreakdownReport

Spearbit Tips

Spearbit Tips is a weekly initiative to introduce general recommendations for security researchers and developers in order to support knowledge sharing across the web3 security ecosystem and continue raising the bar in our industry.

#TitleAuthorWritten Breakdown
1Reviewing Optimized YulNoah MarconiWrite-up
2Proper Code SpecificationNoah MarconiWrite-up
3Clearly Defined NatspecHickupWrite-up
4Verification PatternsNoah MarconiWrite-up
5In-line CommentsHickupWrite-up
6Human Error and Test CoverageNoah MarconiWrite-up
7Protocol DiagrammingJonatasWrite-up

Researcher Spotlights

These spotlights serve to highlight the gems of the web3 security company working over at Spearbit. We have titans of the blockchains security community on our team that have a treasure trove of information to gain from studying their respective journeys.

NameSpotlight
@cmichelioSpotlight
@NoahMarconiSpotlight
@0xLeastwoodSpotlight
@0xRajeevSpotlight
@HickupHSpotlight
@brockjelmoreSpotlight

Seminars and Breakdowns

These seminars and breakdowns provide deep technical content for security researchers that wish to elevate their current skillset and gain insights from a wide variety of experts in web3 security.

TitleAuthorWritten BreakdownAdditional Resources
Agent Buttercup - running agent-based models (ABMs) in an EVM environmentRaghav Bansal
Uniswap - Hyperfragmented Liquidity and Adversarial MempoolsXin Wan
Cairo Security (Peteris Erins)Peteris Erins
Nova: The ZK Bug of the Year (by Wilson Nguyen)mercysjest
Web3 Private Infrastructure with HOPRscbuergel
ZKP Security Overviewrkm0959
Cross-Chain Security: LayerZero LabsRyan Zarick
Analyzing Polygon's zkEVM PIL State MachinesLeonardo Alt
Community Workshop: SudoswapRajeev, Cryptonicle1, and Deivitto
Arbiter - EVM logic simulator for security and performance testingJepsen & ColinWrite-up
WhatsABI? with ShazowShazow
Circuit Safety and an Introduction to Noir (Aztec Network)Maddiaa & Maxim
Community Workshop: CloberHickup
Numerical Analysis for DeFi AuditsKurt BarryWrite-upLink
Economic SecurityfmrmfLink
Security Education and Assessment LabRajeevLink
Deep Dive Into Seaport0ageLink
Optimal Front Running Attacks & How to Stop ThemMax ResnickLink
From Exploit to Recovery: Unraveling DeFi IncidentsSpreekLink
Community WorkshopZach ObrontLink
How to Foundry 2.0Brock ElmoreLink
EVM Through HUFFDevtooliganLink1
ZK Series: IntroPorter AdamsWrite-upSlides
Community WorkshopRiley HolterhusSlides
EVM Seminar: 7 things about the EVMAlex BeregszasziSlides
OpenSeacurity with SpearbitOpenSea + Spearbit TeamsShow notes
The Bridge Risk Framework SeminarVaibhav ChellaniL2 Bridge Risk Framework
Fuzzing Tools Series: Certora ProverMichael George--
Fuzzing Tools Series: EchidnaGustavo GriecoEchidna Spearbit Demo
Forta Introduction SeminarChristian Seifert and Andy Beal--
Simple Security Toolkit WalkthroughBrock ElmoreSimple Security Toolkit
Spearbit at TrustX: LanguagesPanel--
Spearbit at TrustX: Simplify Solidity Code with Sorted Contracts and Security RiskSpencer, Gerard, and Rey--
Understanding Bridge SecurityArjun Bhuptani--
How to FoundryBrock ElmoreFoundry Book

Protocol Diagrams

This section will serve to provide public visuals and diagrams of the complex systems that our researchers come across during their security reviews in order to promote knowledge sharing and pattern matching for other security researchers in the industry.

TitleResearcherProtocol(s)Diagram Link
Sudoswap V2 DiagramGerard PersoonSudoswapDiagram
Compound Finance Governance and Lending/BorrowingJonatasCompoundDiagram
Metastreet State DiagramJonatasMetastreetDiagram

Contributors

obheda12

38 commits

luksgrin

1 commits

spearbit/armory

A one-stop shop for blockchain security researchers looking for educational material and alpha to level-up and get an edge on competition. This is not your standard roadmap, top 10 vulnerabilities, or find-the-bug content. This is for the real researchooors.

405

39 commits

updated Mar 1, 2026

See the code

README

Spearbit Armory GitHub Banner


Requesting a Security Review

In order to request a security review, please fill out our short request form.

For a brief overview of what Spearbit is and what we have to offer click here or reach out to us via Twitter.

If you have any urgent needs or would prefer a direct contact, please reach out to our COO - miike@spearbit.com

Who are we?

Spearbit is a distributed network of industry-leading security researchers tackling the most complex and mission-critical protocols across web3. Our network has extensive experience on every part of the blockchain technology stack.

Table of Contents

Content

This section contains all externally available educational material from Spearbit. The goal of publicizing and creating content like this is to foster and support a community of dedicated researchers consistently motivated to take the next step in their web3 security knowledge and for that material to be just as beneficial to those with more experience in the field as it is to juniors.

Tldr; We believe in elevating the standard for security research, thus our content will reflect the same.

ZKP Education

This section contains ZKP resources produced by Spearbit researchers or invited seminar guests in order to provide a stronger base for researchers to develop their understanding of security posture within ZKPs

TitleTypeMedia Link
Introduction to ZKPsSeminarVideo
Demsytifying ZKPsWrite-upArticle
Intoduction to ZKP SecuritySeminarVideo
Nova: ZK Bug of the Year BreakdownSeminarVideo
Analyzing Polygon zkEVM: PIL State MachinesSeminarVideo
Polygon zkEVM Flawed Division Vulnerability BreakdownThread + ManimThread
Improper Rewards Calculation on Epoch BoundaryThread + ManimThread

Report and Finding Breakdowns

These breakdowns are concise and guided write-ups of findings from some of Spearbit’s top researchers. Study them intently in order to extract the process and perspective of some of the best researchers in the game.

TitleRiskProtocol(s)Written BreakdownReport Link
Morpho ↔ Aave v3 integration edge caseCritical (Morpho Labs)Morpho Labs (primary) and Aave v3 (dependency)BreakdownReport
Balancer DependencyCriticalAera Finance and BalancerBreakdownReport
“Clones-with-immutable-args” and improper Bytes ValidationCriticalSudoswapBreakdownReport
Polygon zkEVM Flawed Division Remainder CheckCriticalPolygon zkEVMBreakdownReport

Spearbit Tips

Spearbit Tips is a weekly initiative to introduce general recommendations for security researchers and developers in order to support knowledge sharing across the web3 security ecosystem and continue raising the bar in our industry.

#TitleAuthorWritten Breakdown
1Reviewing Optimized YulNoah MarconiWrite-up
2Proper Code SpecificationNoah MarconiWrite-up
3Clearly Defined NatspecHickupWrite-up
4Verification PatternsNoah MarconiWrite-up
5In-line CommentsHickupWrite-up
6Human Error and Test CoverageNoah MarconiWrite-up
7Protocol DiagrammingJonatasWrite-up

Researcher Spotlights

These spotlights serve to highlight the gems of the web3 security company working over at Spearbit. We have titans of the blockchains security community on our team that have a treasure trove of information to gain from studying their respective journeys.

NameSpotlight
@cmichelioSpotlight
@NoahMarconiSpotlight
@0xLeastwoodSpotlight
@0xRajeevSpotlight
@HickupHSpotlight
@brockjelmoreSpotlight

Seminars and Breakdowns

These seminars and breakdowns provide deep technical content for security researchers that wish to elevate their current skillset and gain insights from a wide variety of experts in web3 security.

TitleAuthorWritten BreakdownAdditional Resources
Agent Buttercup - running agent-based models (ABMs) in an EVM environmentRaghav Bansal
Uniswap - Hyperfragmented Liquidity and Adversarial MempoolsXin Wan
Cairo Security (Peteris Erins)Peteris Erins
Nova: The ZK Bug of the Year (by Wilson Nguyen)mercysjest
Web3 Private Infrastructure with HOPRscbuergel
ZKP Security Overviewrkm0959
Cross-Chain Security: LayerZero LabsRyan Zarick
Analyzing Polygon's zkEVM PIL State MachinesLeonardo Alt
Community Workshop: SudoswapRajeev, Cryptonicle1, and Deivitto
Arbiter - EVM logic simulator for security and performance testingJepsen & ColinWrite-up
WhatsABI? with ShazowShazow
Circuit Safety and an Introduction to Noir (Aztec Network)Maddiaa & Maxim
Community Workshop: CloberHickup
Numerical Analysis for DeFi AuditsKurt BarryWrite-upLink
Economic SecurityfmrmfLink
Security Education and Assessment LabRajeevLink
Deep Dive Into Seaport0ageLink
Optimal Front Running Attacks & How to Stop ThemMax ResnickLink
From Exploit to Recovery: Unraveling DeFi IncidentsSpreekLink
Community WorkshopZach ObrontLink
How to Foundry 2.0Brock ElmoreLink
EVM Through HUFFDevtooliganLink1
ZK Series: IntroPorter AdamsWrite-upSlides
Community WorkshopRiley HolterhusSlides
EVM Seminar: 7 things about the EVMAlex BeregszasziSlides
OpenSeacurity with SpearbitOpenSea + Spearbit TeamsShow notes
The Bridge Risk Framework SeminarVaibhav ChellaniL2 Bridge Risk Framework
Fuzzing Tools Series: Certora ProverMichael George--
Fuzzing Tools Series: EchidnaGustavo GriecoEchidna Spearbit Demo
Forta Introduction SeminarChristian Seifert and Andy Beal--
Simple Security Toolkit WalkthroughBrock ElmoreSimple Security Toolkit
Spearbit at TrustX: LanguagesPanel--
Spearbit at TrustX: Simplify Solidity Code with Sorted Contracts and Security RiskSpencer, Gerard, and Rey--
Understanding Bridge SecurityArjun Bhuptani--
How to FoundryBrock ElmoreFoundry Book

Protocol Diagrams

This section will serve to provide public visuals and diagrams of the complex systems that our researchers come across during their security reviews in order to promote knowledge sharing and pattern matching for other security researchers in the industry.

TitleResearcherProtocol(s)Diagram Link
Sudoswap V2 DiagramGerard PersoonSudoswapDiagram
Compound Finance Governance and Lending/BorrowingJonatasCompoundDiagram
Metastreet State DiagramJonatasMetastreetDiagram

Contributors

obheda12

38 commits

luksgrin

1 commits