Execution-first security research

We don't flag vulnerabilities.
We prove them.

OmniGuardLabs is a smart-contract security research institution. Every finding ships with a signed, independently replayable exploit receipt — the flaw executed on a real EVM fork, moving real value. Description is not proof. Execution is.

21 / 32exploits re-proven on fork
$2.03Bpublic losses re-proven
143execution-verified classes
Featured research

The case we re-executed

Auditors describe an incident. We reproduce it — on a forked chain, with a receipt anyone can replay.

Vulnerability ResearchArithmetic / roundingCross-chain · 6 chains

How $128M Drained From Balancer Across Six Chains — and How We Re-Proved It on a Fork

A November 2024 arithmetic-precision flaw in Balancer V2 drained ~$128M in under half an hour, simultaneously across six chains running the same code. Balances were nudged onto a rounding boundary, then batched swaps compounded the tiny errors into a full drain. Eleven audits missed it. We forked each chain at the incident block, replayed the path, and read the resulting state change.

Static review missed it because the bug isn't a pattern — it's a property of the math under real state. The defense has to be execution.
Research programs

What we research

PROGRAM 01

Cross-chain replication

One codebase on N chains means one flaw drains N chains at once. We normalize effects across VMs and replay multi-chain.

PROGRAM 02

Arithmetic & rounding exactness

Compounding rounding, share/accounting drift, invariant breaks — proven exact, not sampled.

PROGRAM 03

Payload-host / EtherHiding

Contracts that store attacker payloads by role, not name — confirmed on forked storage.

PROGRAM 04

Execution-labeled corpus

Public datasets are candidates only. Every label is produced by execution.

Tool

Screener

Paste a contract. We fork the chain and attempt the exploit — you get a verdict backed by a replay receipt, not a pattern guess.

Example result — connect your engine endpoint to populate live
ClassLayerSeverityVerdictReceipt
arith.rounding_boundaryL1/L2CRITICALDRAINABLE0x9f…
access.owner_overrideL1HIGHnot reachable0x3a…
reentrancy.read_onlyL1MEDnot reachable
Tool

Honeypot check

We don't read the code and guess. We fork the chain and attempt the sell — if the tokens can't leave, it's a honeypot, proven.

Example result — connect your engine endpoint to populate live
Sell attempt✗ BLOCKED
buysucceedssellreverts (transfer blocked)taxbuy 3% · sell 100%verdictHONEYPOT — proven on forkreceipt0x7c… (signed on run)
Sample receipt format · values from the live run
Tool

Copy-trade check

Before you mirror a wallet, we replay what following it would actually do to your balance under real state.

Example result — connect your engine endpoint to populate live
SignalFindingVerdict
Recent positions4 of 12 tokens are proven honeypotshigh risk
Exit behaviorsells before followers canfront-runs
Net follower P&L (replayed)−38% over 30davoid
Knowledge asset

Proof Wall

Every vulnerability class we score is re-proven on a real fork. Scope and methodology stay private; the classification and the proofs are public.

143
Verified classes
21/32
Historical exploits re-proven
$2.03B
Public losses re-proven
Vulnerability classLayerSeverityVerdict
arith.rounding_boundary.compoundingL1/L2CRITICALre-proven ($128M)
access.owner_overrideL1CRITICALre-proven
oracle.price_manipulationL1CRITICALre-proven
approval.permit_abuseL1HIGHre-proven
reentrancy.read_onlyL1HIGHre-proven
payload_host.etherhidingL1HIGHexecuted-confirmed
xchain.replicationL1/L2CRITICAL6-chain replay

Excerpt of the public class registry. Full registry lists all 143 classes with layer and severity.

Publications

Incidents

Each incident written up as research — dated, attributed, receipt-backed.

Sep 19, 2026Balancer V2: $128M across six chains, re-proven on forkVulnerability Research
Sep 2026Why static audits miss compounding rounding — and execution doesn'tMethod
Sep 2026Execution-labeled corpora: candidates vs. ground truthCorpus
Sep 2026Payload-host detection by role, confirmed on forked storageDetector
How we work

Methodology

The principle is public; the mechanics stay private. We prove, we don't guess.

01 · FORK

Fork real state

We fork the chain at the relevant block against frozen state — no network, deterministic.

02 · EXECUTE

Attempt the exploit

We replay the path on a real EVM and read the resulting state change — the effect, not the pattern.

03 · VERDICT

Read, don't assert

The verdict comes from measured state, three-valued (drainable / safe / inconclusive). Inconclusive never counts.

04 · RECEIPT

Sign & replay

Each finding carries a signed receipt anyone can independently replay. That is the deliverable.

We publish the taxonomy and the proofs; exploit mechanics and detector internals stay private. Findings are responsibly disclosed before publication.

Research

Research library

Standing programs and receipt-backed writeups from an execution-first institution.

Vulnerability Research6 chains

Balancer V2 — $128M, six chains, re-proven on a fork

Our flagship re-proof: the rounding-boundary compounding drain, re-executed on each affected chain with a signed receipt. The full writeup pairs the public incident record with our execution-verified result.

About

An execution-first research institution

OmniGuardLabs builds instruments, not opinions. Where the industry describes vulnerabilities, we execute them on a real EVM fork and hand you a signed receipt you — or anyone — can replay. Our research programs target the loss-bearing classes of modern DeFi: cross-chain replication, arithmetic exactness, payload-host, and the execution-labeled corpus that keeps every number honest.

Responsible disclosure

Findings are disclosed to affected teams before publication.

Private methodology

The taxonomy and proofs are public; mechanics stay private.

Independently replayable

Every claim ships with a receipt anyone can re-run.

Get PROVEN

Proof, not opinions

Pick the level of execution-verified coverage your protocol needs.

Screen

Free
per address
  • Screener verdict
  • Honeypot check
  • Public class registry
Run the Screener

Proven

Contact
per protocol
  • Full fork-replay proofs
  • Signed replay receipts
  • Cross-chain (6-chain) coverage
  • Continuous rescan on new classes
Talk to research

Institution

Custom
per estate
  • Everything in Proven
  • Execution-labeled corpus access
  • Private research engagements
  • Disclosure support
Contact us