AI security · offensive research

AI security and penetration testing, as reproducible research.

SIRENBOW is an independent research group working on AI system security and full-stack penetration testing. We publish our methodologies, vulnerability analyses, and field reports in full — every conclusion traceable, every result verifiable.

Focus areas
AI · Web · Cloud · Blockchain · Mobile
Research
1 published, fully reproducible
Disclosure
CVSS · CWE · MITRE ATT&CK

Latest research

All research →
2026-07-23
The missing check: a full-chain post-mortem of the $7.54M Verus bridge exploit
The Verus↔Ethereum bridge was drained for a second time. The attacker spent 0 ETH on the Ethereum side and forged a single cross-chain import. The root cause is one line that was never written: the bridge checked that the data was intact, but never that the withdrawal was backed by equal value.
CROSS-CHAIN-BRIDGEVALUE-CONSERVATIONPOST-MORTEM
11 min

Practice areas

AI systems

Model abuse, prompt-injection paths, agent tool-use boundaries, and the systems wrapped around the model.

Web applications

Authorization models, authentication flows, injection classes, and pre-launch security review.

Cloud infrastructure

Identity and permission boundaries, network exposure, secret handling, and misconfiguration review.

Blockchain protocols

Bridge value-conservation, contract logic flaws, and public incident post-mortems with on-chain evidence.

Mobile

Client-side trust boundaries, local storage, transport security, and API surface review.

Security reports

All reports →