Arsen

Arsen

Home
Archive
About
How to hack a Bitcoin light client?
Three merkle proofs verify the structure. The fourth check is a substring search on a field the miner fills in by hand.
Sep 7 • Arsen

August 2026

How to get wrecked via Solana RPC.
An off-chain service asked the chain how an account was created. Anyone could change the answer for one lamport, and the whole backfill queue stalled.
Aug 31 • Arsen
How Correct Code Loses Money
Every function did exactly what it was written to do.
Aug 21 • Arsen

February 2026

Ignore 85% of the code if you want critical bugs
New codebase? The question must be: How do I find the 5% of code that can kill the protocol?
Feb 8 • Arsen
© 2026 Arsen. Web3 Security · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture