Security research on decentralised infrastructure at the layer contract audits don't reach: transport, kernel, and node resource.
The attacks that take a validator off consensus often produce no syscall, no log line and no alert. We reproduce them, publish them, and build enforcement that runs at kernel ingress — before the packet reaches userspace.
- nrdax-python — CLI and API for NRDAX, the registry of node-resource attack techniques. 500+ catalogued, 100+ reproduced first-hand across 39 chains and protocols, crosswalked to MITRE AADAPT.
pip install nrdax - nr-ibsr — shadow-mode XDP/eBPF traffic collector. The rehearsal layer for earned autonomy.
- slashr-front — multi-chain validator penalty tracker. Live at slashr.dev.
- nullrabbit-advisories — operator-facing advisories and writeups.
- On Earned Autonomy — how a machine defender earns enforcement authority from its own shadow-mode record, rather than from a vendor's accuracy claim.
10.5281/zenodo.18406828 - NRDAX — a mechanism-defined taxonomy for network-boundary and node-resource attacks on decentralised infrastructure. nrdax-paper
1,000+ adversarial capture bundles across 38 network stacks, published on Hugging Face. Capture format is specified in nr-bundle-spec.
GitHub has attached technique NRDAX-T0205 to CVE-2023-39533.
Registry: nrdax.com · Research: nullrabbit.ai
Maintained by Simon Morley (@simonmorley), London. Security engagements and advisory: nullrabbit.ai