SecLat Blog

Insights on security and trust in Web3

Explore articles about audits, mitigation strategies, and lessons from our smart contract security team.

Recent posts

Mike B. - SecLat SecurityAugust 28, 2026

Ethernaut Level 3 Walkthrough: Exploiting Weak On-Chain Randomness in Solidity

In this article, we will analyze and solve Ethernaut Level 3: Coin Flip.

Read article
Tadeo - SecLat SecurityAugust 26, 2026

An Oracle Does Not Need to Be Broken to Liquidate You: How Thin Liquidity, a Short TWAP, and Leverage Triggered Morpho Liquidations

How a thin DeFi market feeding a short TWAP can turn PT, YT, looped leverage, and health factors into a liquidation risk, and how teams can reduce it.

Read article
Tadeo - SecLat SecurityAugust 21, 2026

How Six Failures Turned a MAYAChain Outbound Bug Into a Pool Drain

A technical breakdown of how transaction-voter state, outbound matching, subsidy accounting, and pool math compounded into a MAYAChain exploit.

Read article
Tadeo - SecLat SecurityAugust 17, 2026

When a blockchain rolls back: the Harmony ONE exploit and the cost of recovery

What Harmony's planned rollback after unauthorized ONE issuance teaches protocol teams about finality, operational disruption, and incident readiness.

Read article
Mike B. - SecLat SecurityAugust 14, 2026

Ethernaut Level 2 Walkthrough: Exploiting a Misnamed Constructor in Solidity

In this article, we will analyze and solve Ethernaut Level 2: Fallout.

Read article
Tadeo - SecLat SecurityAugust 13, 2026

BTCPay Server remote Lightning access: treat node credentials as emergency secrets

What BTCPay Server operators should do after the August 2026 active attack affecting remote LND access, including patching, credential rotation, and review steps.

Read article
Mike B. - SecLat SecurityAugust 12, 2026

Ethernaut Level 1 Walkthrough: Exploiting Access Control in Solidity

In this article, we will analyze and solve Ethernaut Level 1: Fallback.

Read article
Tadeo - SecLat SecurityAugust 11, 2026

Coldcard and the risk that starts before signing

The reported Coldcard incident shows why key security depends on entropy, build configuration, and a prepared response.

Read article
Tadeo - SecLat SecurityJuly 31, 2026

Your Smart Contract Can Be Bug-Free and Still Get Hacked: Five Attack Surfaces Audits Cannot Ignore

Five security surfaces protocol teams should include in a review, beyond smart contract logic.

Read article
SECLAT - Security & Audit

SECLAT - Expertos en seguridad blockchain y auditorías de contratos inteligentes.

Estadísticas Clave

200+
Contratos Auditados
0
Incidentes Críticos
20+
Clientes Satisfechos
$100M+
Protegidos

Contactanos

Si buscas una auditoría de seguridad o una consulta, Contactanos.

© 2026 SECLAT Security. Todos los derechos reservados.