Research
Findings, replays, and field notes from the Trilocore team. We publish what we can reproduce: on-chain incidents rebuilt from deployed bytecode, and the tooling that makes them repeatable.
Re-auditing the Euler attack: what the Auditing IDE surfaces from bytecode alone
The 2023 Euler donation attack, rebuilt from deployed bytecode on a pinned mainnet fork — what a bytecode-first pipeline surfaces before anyone reads the source.
Findings we publish against a specific target are written up as audit reports — each one carrying the verdict from replaying it on the pinned fork (EVM) or the captured account set (Solana).
Incident analysis
On-chain incidents rebuilt from deployed bytecode and replayed end to end on a fork pinned at the block where they happened.
- Starts fromdeployed bytecode
- Proofreplay on a pinned fork
Vulnerability research
Bug classes and the analysis that surfaces them — what a pattern looks like at bytecode level, named by pattern rather than by project.
- Focusthe pattern, not the project
- Proofa reproducible trace
Engineering
Notes from building the workbench itself: fork tooling, program analysis, and what breaks at execution depth — on EVM and Solana alike.
- Subjectour own tooling
- Written bythe team that builds it
Nothing is published until it replays.
Found something in our work?
If a post, a tool, or the platform itself has a security issue, we want the report — the disclosure process we ask others to follow is the one we follow ourselves.
Read the disclosure policy Read the disclosure policy