Research

Findings, replays, and field notes from the Trilocore team. We publish what we can reproduce: on-chain incidents rebuilt from deployed bytecode, and the tooling that makes them repeatable.

June 15, 2026 · Incident analysis · Ethereum / EVM

Re-auditing the Euler attack: what the Auditing IDE surfaces from bytecode alone

The 2023 Euler donation attack, rebuilt from deployed bytecode on a pinned mainnet fork — what a bytecode-first pipeline surfaces before anyone reads the source.


Findings we publish against a specific target are written up as audit reports — each one carrying the verdict from replaying it on the pinned fork (EVM) or the captured account set (Solana).

Incident analysis

On-chain incidents rebuilt from deployed bytecode and replayed end to end on a fork pinned at the block where they happened.

  • Starts fromdeployed bytecode
  • Proofreplay on a pinned fork

Vulnerability research

Bug classes and the analysis that surfaces them — what a pattern looks like at bytecode level, named by pattern rather than by project.

  • Focusthe pattern, not the project
  • Proofa reproducible trace

Engineering

Notes from building the workbench itself: fork tooling, program analysis, and what breaks at execution depth — on EVM and Solana alike.

  • Subjectour own tooling
  • Written bythe team that builds it

Found something in our work?

If a post, a tool, or the platform itself has a security issue, we want the report — the disclosure process we ask others to follow is the one we follow ourselves.

Read the disclosure policy Read the disclosure policy