# Research

> Security research from Trilocore — on-chain incidents rebuilt from deployed bytecode, and the tooling that makes them reproducible.

Findings, replays, and field notes from the Trilocore team. We publish what we can reproduce: on-chain incidents rebuilt from deployed bytecode, and the tooling that makes them repeatable.

June 15, 2026 · Incident analysis · Ethereum / EVM

## [Re-auditing the Euler attack: what the Auditing IDE surfaces from bytecode alone](https://trilocore.com/posts/euler-donation-retrospective)

The 2023 Euler donation attack, rebuilt from deployed bytecode on a pinned mainnet fork — what a bytecode-first pipeline surfaces before anyone reads the source.

---

[June 15, 2026Vulnerability research · Ethereum / EVMThe exploit hiding in dead code: orphan-block DELEGATECALL](https://trilocore.com/posts/orphan-block-delegatecall) [June 15, 2026Engineering · Ethereum / EVMFrom a fuzzer experiment to a security platform: the Trilocore story](https://trilocore.com/posts/from-monorepo-to-security-platform)

Findings we publish against a specific target are written up as [audit reports](https://platform.trilocore.com/docs/en/audits/) — each one carrying the verdict from replaying it on the pinned fork (EVM) or the captured account set (Solana).

### Incident analysis

On-chain incidents rebuilt from deployed bytecode and replayed end to end on a fork pinned at the block where they happened.

- Starts from: deployed bytecode
- Proof: replay on a pinned fork

### Vulnerability research

Bug classes and the analysis that surfaces them — what a pattern looks like at bytecode level, named by pattern rather than by project.

- Focus: the pattern, not the project
- Proof: a reproducible trace

### Engineering

Notes from building the workbench itself: fork tooling, program analysis, and what breaks at execution depth — on EVM and Solana alike.

- Subject: our own tooling
- Written by: the team that builds it

## Nothing is published until it replays.

[01RebuildStart from what the chain actually ran — the incident is reconstructed from deployed bytecode, not from a press account.](https://trilocore.com/platform/analysis-engine) [02PinThe session is pinned — an EVM fork at the block where it happened, or Solana account state captured as it stood — so every number in the post can be re-derived.](https://trilocore.com/platform/fork-environment) [03ReplayThe proof-of-concept must reproduce on that pinned fork (EVM) or captured account set (Solana) before the write-up is published.](https://trilocore.com/platform/auditing-ide) [04DiscloseAnything that still puts user funds at risk reaches the affected team first, under coordinated disclosure.](https://trilocore.com/security#disclosure)

## Found something in our work?

If a post, a tool, or the platform itself has a security issue, we want the report — the disclosure process we ask others to follow is the one we follow ourselves.

Read the disclosure policy [Read the disclosure policy](https://trilocore.com/security#disclosure)

---

[Canonical HTML version](https://trilocore.com/research/)
