<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>ack3 research</title><description>Technical articles and evidence-backed web3 security research from ack3.</description><link>https://ack3.ai/</link><language>en</language><item><title>Do Not Trust VS Code Extension Install Counts</title><link>https://ack3.ai/research/do-not-trust-vscode-extension-install-counts/</link><guid isPermaLink="true">https://ack3.ai/research/do-not-trust-vscode-extension-install-counts/</guid><description>VS Code extensions run with your permissions while installs and badges are weak trust signals. Learn how to audit, pin, allowlist, and contain them.</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Security research</category><category>developer-security</category><category>extensions</category><category>supply-chain</category><category>vs-code</category><author>Naoki Yoshida</author></item><item><title>How to Review Unfamiliar Repositories Without Trusting Them</title><link>https://ack3.ai/research/how-to-review-unfamiliar-repositories-without-trusting-them/</link><guid isPermaLink="true">https://ack3.ai/research/how-to-review-unfamiliar-repositories-without-trusting-them/</guid><description>A staged workflow for reviewing unfamiliar repositories with AI agents using read-only mounts, no credentials, restricted networks, and disposable sandboxes.</description><pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate><category>Technical guide</category><category>ai-agents</category><category>code-review</category><category>developer-security</category><category>sandboxing</category><category>supply-chain</category><author>Naoki Yoshida</author></item><item><title>Why AI-Assisted Smart Contract Testing Belongs in Python</title><link>https://ack3.ai/research/why-ai-assisted-smart-contract-testing-belongs-in-python/</link><guid isPermaLink="true">https://ack3.ai/research/why-ai-assisted-smart-contract-testing-belongs-in-python/</guid><description>Code corpora and current benchmarks show why AI-assisted Solidity tests benefit from Python, while human review stays focused on test logic.</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate><category>Security research</category><category>ai</category><category>code-generation</category><category>python</category><category>security</category><category>solidity</category><category>testing</category><category>wake</category><author>Naoki Yoshida</author></item><item><title>Wake Debugging Guide</title><link>https://ack3.ai/research/wake-debugging-guide/</link><guid isPermaLink="true">https://ack3.ai/research/wake-debugging-guide/</guid><description>Master Wake&apos;s debugging tools: console logging, Python fuzzing, ipdb integration, and performance profiling for Solidity smart contract development.</description><pubDate>Wed, 14 Jan 2026 00:00:00 GMT</pubDate><category>Technical guide</category><category>education</category><category>ethereum</category><category>solidity</category><category>tutorial</category><category>wake</category><author>Naoki Yoshida</author></item><item><title>EIP-712 Encoding in Wake Without Guesswork</title><link>https://ack3.ai/research/eip-712-encoding-in-wake-without-guesswork/</link><guid isPermaLink="true">https://ack3.ai/research/eip-712-encoding-in-wake-without-guesswork/</guid><description>Inspect EIP-712 type strings and preimage bytes in Wake to match Solidity exactly, catch schema errors early, and prove signatures before deployment.</description><pubDate>Thu, 18 Dec 2025 00:00:00 GMT</pubDate><category>Technical guide</category><category>education</category><category>ethereum</category><category>solidity</category><category>wake</category><author>Naoki Yoshida</author></item><item><title>Test Proxy Contracts Safely in Wake</title><link>https://ack3.ai/research/test-proxy-contracts-safely-in-wake/</link><guid isPermaLink="true">https://ack3.ai/research/test-proxy-contracts-safely-in-wake/</guid><description>Test upgradable proxy contracts in Wake&apos;s Python framework. Catch initialization bugs, storage collisions, and access control issues before mainnet.</description><pubDate>Tue, 16 Dec 2025 00:00:00 GMT</pubDate><category>Technical guide</category><category>education</category><category>ethereum</category><category>solidity</category><category>wake</category><author>Naoki Yoshida</author></item><item><title>Signing Data in Wake: Raw, Structured, and Hash Flows</title><link>https://ack3.ai/research/signing-data-in-wake-raw-structured-and-hash-flows/</link><guid isPermaLink="true">https://ack3.ai/research/signing-data-in-wake-raw-structured-and-hash-flows/</guid><description>Learn how to sign raw, structured, and hashed messages in Wake tests. Validate EIP-712, EIP-191, and permit flows with clear examples and reliable verification.</description><pubDate>Wed, 10 Dec 2025 00:00:00 GMT</pubDate><category>Technical guide</category><category>education</category><category>ethereum</category><category>solidity</category><category>wake</category><author>Naoki Yoshida</author></item><item><title>Balancer Incident Analysis and Differential Fuzzing</title><link>https://ack3.ai/research/balancer-incident-analysis-and-differential-fuzzing/</link><guid isPermaLink="true">https://ack3.ai/research/balancer-incident-analysis-and-differential-fuzzing/</guid><description>Learn how Balancer’s StableSwap math failed and how differential fuzzing in Python detects precision bugs in DeFi swap logic for safer smart contract design.</description><pubDate>Thu, 27 Nov 2025 00:00:00 GMT</pubDate><category>Incident analysis</category><category>education</category><category>ethereum</category><category>exploit</category><category>hack</category><category>smart-contract</category><category>wake</category><author>Naoki Yoshida</author></item><item><title>Mastering Wake Printers for Solidity Security Analysis</title><link>https://ack3.ai/research/mastering-wake-printers-for-solidity-security-analysis/</link><guid isPermaLink="true">https://ack3.ai/research/mastering-wake-printers-for-solidity-security-analysis/</guid><description>Learn how to build custom Wake printers for smart contract analysis, uncover vulnerabilities, and speed up Solidity security reviews.</description><pubDate>Thu, 06 Nov 2025 00:00:00 GMT</pubDate><category>Technical guide</category><category>education</category><category>ethereum</category><category>hack</category><category>printer</category><category>security</category><category>smart-contract</category><category>solidity</category><category>tutorial</category><category>wake</category><author>Naoki Yoshida</author></item><item><title>Vibe Fuzzing Guide for Wake’s Manually-Guided Fuzzing</title><link>https://ack3.ai/research/vibe-fuzzing-guide-for-wakes-manually-guided-fuzzing/</link><guid isPermaLink="true">https://ack3.ai/research/vibe-fuzzing-guide-for-wakes-manually-guided-fuzzing/</guid><description>Boost smart contract security with AI-guided fuzz testing in Wake. Learn what to automate, what to verify, and how to write effective tests in Python.</description><pubDate>Thu, 30 Oct 2025 00:00:00 GMT</pubDate><category>Technical guide</category><category>education</category><category>ethereum</category><category>mgf</category><category>security</category><category>solidity</category><category>tutorial</category><category>wake</category><author>Naoki Yoshida</author></item><item><title>Shrinking Algorithm Differences Between Foundry, Echidna, and Wake</title><link>https://ack3.ai/research/shrinking-algorithm-differences-between-foundry-echidna-and-wake/</link><guid isPermaLink="true">https://ack3.ai/research/shrinking-algorithm-differences-between-foundry-echidna-and-wake/</guid><description>Comparing how Foundry, Echidna, and Wake shrink fuzzing failures. Learn which tool offers the best balance of speed, precision, and debugging clarity.</description><pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate><category>Security research</category><category>education</category><category>ethereum</category><category>fuzz-testing</category><category>security</category><category>smart-contract</category><category>solidity</category><category>wake</category><author>Naoki Yoshida</author></item><item><title>A Beginner’s Guide to Manually Guided Fuzzing</title><link>https://ack3.ai/research/a-beginners-guide-to-manually-guided-fuzzing/</link><guid isPermaLink="true">https://ack3.ai/research/a-beginners-guide-to-manually-guided-fuzzing/</guid><description>Learn Manually Guided Fuzzing (MGF) with the Wake framework to find critical smart contract vulnerabilities through systematic testing and defined invariants.</description><pubDate>Tue, 09 Sep 2025 00:00:00 GMT</pubDate><category>Technical guide</category><category>education</category><category>ethereum</category><category>fuzz-testing</category><category>how-to</category><category>smart-contract</category><category>tutorial</category><category>wake</category><author>Naoki Yoshida</author></item><item><title>Uncovering Front Running Vulnerability with Manually Guided Fuzzing</title><link>https://ack3.ai/research/uncovering-front-running-vulnerability-with-manually-guided-fuzzing/</link><guid isPermaLink="true">https://ack3.ai/research/uncovering-front-running-vulnerability-with-manually-guided-fuzzing/</guid><description>Learn how Wake&apos;s Manually Guided Fuzzing detects front-running vulnerabilities using differential fuzzing. Includes real examples and best practices.</description><pubDate>Wed, 03 Sep 2025 00:00:00 GMT</pubDate><category>Security research</category><category>audit</category><category>education</category><category>ethereum</category><category>evm</category><category>how-to</category><category>smart-contract</category><category>solidity</category><category>tutorial</category><category>wake</category><author>Naoki Yoshida</author></item><item><title>Complete Reentrancy Hands-on Guide</title><link>https://ack3.ai/research/complete-reentrancy-hands-on-guide/</link><guid isPermaLink="true">https://ack3.ai/research/complete-reentrancy-hands-on-guide/</guid><description>This guide provides a comprehensive analysis of reentrancy vulnerabilities with examples. Learn how reentrancy works and how to identify it in real protocols.</description><pubDate>Thu, 21 Aug 2025 00:00:00 GMT</pubDate><category>Technical guide</category><category>education</category><category>ethereum</category><category>exploit</category><category>hack</category><category>how-to</category><category>smart-contract</category><category>solidity</category><category>tutorial</category><category>wake</category><author>Naoki Yoshida</author></item><item><title>Reentrancy Attack in ERC-1155</title><link>https://ack3.ai/research/reentrancy-attack-in-erc-1155/</link><guid isPermaLink="true">https://ack3.ai/research/reentrancy-attack-in-erc-1155/</guid><description>Learn how attackers can exploit reentrancy vulnerabilities in ERC-1155 implementations to drain vault contracts, with an example real-world attack scenario.</description><pubDate>Mon, 11 Aug 2025 00:00:00 GMT</pubDate><category>Technical guide</category><category>education</category><category>ethereum</category><category>exploit</category><category>hack</category><category>reentrancy-attack</category><category>tutorial</category><category>wake</category><author>Naoki Yoshida</author></item><item><title>Reentrancy Attack in ERC-721</title><link>https://ack3.ai/research/reentrancy-attack-in-erc-721/</link><guid isPermaLink="true">https://ack3.ai/research/reentrancy-attack-in-erc-721/</guid><description>In this article, we&apos;ll examine how attackers can manipulate the _safeMint function&apos;s external call to bypass minting limits and drain NFT collections.</description><pubDate>Mon, 04 Aug 2025 00:00:00 GMT</pubDate><category>Technical guide</category><category>education</category><category>ethereum</category><category>exploit</category><category>hack</category><category>reentrancy-attack</category><category>solidity</category><category>tutorial</category><category>wake</category><author>Naoki Yoshida</author></item><item><title>GMX Hack Analysis &amp; Attack Scenarios with Wake</title><link>https://ack3.ai/research/gmx-hack-analysis-attack-scenarios-with-wake/</link><guid isPermaLink="true">https://ack3.ai/research/gmx-hack-analysis-attack-scenarios-with-wake/</guid><description>This analysis examines the 42M attack on the GMX protocol. We provide details of the vulnerability with a working reproduction of the attack scenario.</description><pubDate>Tue, 22 Jul 2025 00:00:00 GMT</pubDate><category>Incident analysis</category><category>education</category><category>ethereum</category><category>evm</category><category>exploit</category><category>hack</category><category>security</category><category>smart-contract</category><category>solidity</category><category>tutorial</category><category>wake</category><author>Naoki Yoshida</author></item><item><title>Reentrancy Attack in ERC-777</title><link>https://ack3.ai/research/reentrancy-attack-in-erc-777/</link><guid isPermaLink="true">https://ack3.ai/research/reentrancy-attack-in-erc-777/</guid><description>In this blog, we describe reentrancy attacks in the ERC-777 standard. ERC-777 is a standard for fungible tokens with a hook for transferring – learn more here.</description><pubDate>Fri, 25 Apr 2025 00:00:00 GMT</pubDate><category>Technical guide</category><category>education</category><category>ethereum</category><category>exploit</category><category>hack</category><category>reentrancy-attack</category><category>security</category><category>solidity</category><category>wake</category><author>Naoki Yoshida</author></item><item><title>Flash Loan Reentrancy Attack</title><link>https://ack3.ai/research/flash-loan-reentrancy-attack/</link><guid isPermaLink="true">https://ack3.ai/research/flash-loan-reentrancy-attack/</guid><description>Flash loans enable borrowing without collateral and repaying within a single transaction. While effective, they also introduce security risks – learn more here.</description><pubDate>Fri, 11 Apr 2025 00:00:00 GMT</pubDate><category>Technical guide</category><category>education</category><category>ethereum</category><category>exploit</category><category>hack</category><category>reentrancy-attack</category><category>security</category><category>solidity</category><category>wake</category><author>Naoki Yoshida</author></item><item><title>Cross-chain Reentrancy Attack</title><link>https://ack3.ai/research/cross-chain-reentrancy-attack/</link><guid isPermaLink="true">https://ack3.ai/research/cross-chain-reentrancy-attack/</guid><description>A cross-chain reentrancy attack is an exploit that targets smart contract function calls. Learn about this vulnerability to keep your code safe from attackers.</description><pubDate>Mon, 17 Mar 2025 00:00:00 GMT</pubDate><category>Technical guide</category><category>education</category><category>ethereum</category><category>hack</category><category>reentrancy-attack</category><category>security</category><category>wake</category><author>Naoki Yoshida</author></item><item><title>Read-only Reentrancy Attack</title><link>https://ack3.ai/research/read-only-reentrancy-attack/</link><guid isPermaLink="true">https://ack3.ai/research/read-only-reentrancy-attack/</guid><description>A read-only reentrancy attack manipulate a smart contracts to extract value. Let&apos;s take a closer look at this vulnerability and how to prevent it.</description><pubDate>Thu, 27 Feb 2025 00:00:00 GMT</pubDate><category>Technical guide</category><category>education</category><category>ethereum</category><category>exploit</category><category>hack</category><category>reentrancy-attack</category><category>tutorial</category><category>wake</category><author>Naoki Yoshida</author></item><item><title>Introducing Manually Guided Fuzzing: A New Approach in Smart Contract Testing</title><link>https://ack3.ai/research/introducing-manually-guided-fuzzing-a-new-approach-in-smart-contract-testing/</link><guid isPermaLink="true">https://ack3.ai/research/introducing-manually-guided-fuzzing-a-new-approach-in-smart-contract-testing/</guid><description>Learn how manually guided fuzzing combines stateful, white-box testing with flows and invariants to test complex smart contracts more efficiently.</description><pubDate>Thu, 12 Sep 2024 00:00:00 GMT</pubDate><category>Technical guide</category><category>announcements</category><category>audit</category><category>education</category><category>ethereum</category><category>fuzz-testing</category><category>smart-contract</category><category>wake</category><author>Josef Gattermayer</author></item><item><title>Safe Social Recovery Module</title><link>https://ack3.ai/research/safe-social-recovery-module/</link><guid isPermaLink="true">https://ack3.ai/research/safe-social-recovery-module/</guid><description>Safe Smart Accounts are the most audited and battle-tested smart contracts on Ethereum securing over $100 billion in assets. The Safe Social Recovery Module is a…</description><pubDate>Mon, 19 Aug 2024 00:00:00 GMT</pubDate><category>Audit summary</category><category>audit</category><category>audit-summary</category><category>candide</category><category>ethereum</category><category>safe</category><category>wake</category><author>Jan Kalivoda</author></item><item><title>Cross Contract Reentrancy Attack</title><link>https://ack3.ai/research/cross-contract-reentrancy-attack/</link><guid isPermaLink="true">https://ack3.ai/research/cross-contract-reentrancy-attack/</guid><description>This research article reviews how cross contract reentrancy attacks work, an attack example, and guidance on how to prevent cross contract reentrancy attacks.…</description><pubDate>Thu, 11 Jul 2024 00:00:00 GMT</pubDate><category>Technical guide</category><category>education</category><category>ethereum</category><category>exploit</category><category>hack</category><category>reentrancy-attack</category><category>tutorial</category><category>wake</category><author>Naoki Yoshida</author></item><item><title>Cross Function Reentrancy Attack</title><link>https://ack3.ai/research/cross-function-reentrancy-attack/</link><guid isPermaLink="true">https://ack3.ai/research/cross-function-reentrancy-attack/</guid><description>What is a cross function reentrancy attack? Cross-function reentrancy attacks use multiple functions to execute the attack, which can occur when inappropriate…</description><pubDate>Thu, 04 Jul 2024 00:00:00 GMT</pubDate><category>Technical guide</category><category>education</category><category>ethereum</category><category>exploit</category><category>hack</category><category>reentrancy-attack</category><category>tutorial</category><category>wake</category><author>Naoki Yoshida</author></item><item><title>Single Function Reentrancy Attack</title><link>https://ack3.ai/research/single-function-reentrancy-attack/</link><guid isPermaLink="true">https://ack3.ai/research/single-function-reentrancy-attack/</guid><description>What is a reentrancy attack? A reentrancy attack is very specific to smart contracts due to the nature of external calls. When a contract interacts with another…</description><pubDate>Thu, 20 Jun 2024 00:00:00 GMT</pubDate><category>Technical guide</category><category>education</category><category>ethereum</category><category>exploit</category><category>hack</category><category>reentrancy-attack</category><category>tutorial</category><category>wake</category><author>Naoki Yoshida</author></item><item><title>Wake ERC-4337 Detector</title><link>https://ack3.ai/research/wake-erc-4337-detector/</link><guid isPermaLink="true">https://ack3.ai/research/wake-erc-4337-detector/</guid><description>Ackee is finalizing an ERC-4337 detector to identify the use of forbidden opcodes and storage access, turning a very labor-intensive manual review into an automated…</description><pubDate>Wed, 15 May 2024 00:00:00 GMT</pubDate><category>Security research</category><category>detector</category><category>erc-4337</category><category>ethereum</category><category>safe</category><category>solidity</category><category>wake</category><author>Michal Převrátil</author></item><item><title>On the wave of CI/CD for Web3</title><link>https://ack3.ai/research/on-the-wave-of-ci-cd-for-web3/</link><guid isPermaLink="true">https://ack3.ai/research/on-the-wave-of-ci-cd-for-web3/</guid><description>So you want to write and deploy a smart contract, huh? Let’s set up this environment for a sample project from scratch</description><pubDate>Thu, 07 Dec 2023 00:00:00 GMT</pubDate><category>Technical guide</category><category>education</category><category>ethereum</category><category>how-to</category><category>solidity</category><category>tutorial</category><category>wake</category><author>Jan Kalivoda</author></item><item><title>List of Ackee Blockchain Public Audits</title><link>https://ack3.ai/research/list-of-ackee-blockchain-public-audits/</link><guid isPermaLink="true">https://ack3.ai/research/list-of-ackee-blockchain-public-audits/</guid><description>An archived index of Ackee Blockchain public Ethereum, EVM, and Solana audit summaries, covering 41 organizations and 66 linked entries.</description><pubDate>Sat, 20 May 2023 00:00:00 GMT</pubDate><category>Security research</category><category>audit</category><category>ethereum</category><category>evm</category><category>security</category><category>smart-contract</category><category>solana</category><author>Josef Gattermayer</author></item><item><title>How to prepare for a smart contract audit</title><link>https://ack3.ai/research/how-to-prepare-for-a-smart-contract-audit-2/</link><guid isPermaLink="true">https://ack3.ai/research/how-to-prepare-for-a-smart-contract-audit-2/</guid><description>How to prepare for a smart contract audit The pre-audit part is essential for a smooth audit, and we will now guide you through it.</description><pubDate>Fri, 17 Mar 2023 00:00:00 GMT</pubDate><category>Technical guide</category><category>education</category><category>ethereum</category><category>how-to</category><category>solidity</category><category>wake</category><author>Jan Kalivoda</author></item><item><title>Testing Axelar contracts using open-source tools</title><link>https://ack3.ai/research/testing-axelar-contracts-using-open-source-tools/</link><guid isPermaLink="true">https://ack3.ai/research/testing-axelar-contracts-using-open-source-tools/</guid><description>Building projects on top of cross-chain solutions may lead to security issues in the code. Open-source tools can automatically detect many issues or help test the…</description><pubDate>Fri, 11 Nov 2022 00:00:00 GMT</pubDate><category>Security research</category><category>axelar</category><category>developer-tooling</category><category>ethereum</category><category>evm</category><category>open-source</category><category>security</category><category>smart-contract</category><category>solidity</category><category>vs-code</category><category>wake</category><author>Michal Převrátil</author></item></channel></rss>