BlackHartBlackHart

Continuous security for DeFi.

Adversarial security research and risk intelligence for DeFi. We find exploitable bugs, prove them with working exploits, and track risk across DeFi protocols and the prediction markets built on top of them.

01 //
The Mission

Why we exist.

Billions in user funds sit in smart contracts that change constantly. New deployments, governance actions, oracle migrations, and shifting integrations all move a protocol's risk profile. A review that happens once a year cannot keep up with code that ships every week.

A point-in-time audit captures one snapshot and then goes stale the moment the next commit lands. Users, treasuries, and insurers are left without a reliable, ongoing signal for how safe a protocol is today.

BlackHart addresses that gap. We run adversarial research against live protocols to find exploitable bugs before attackers do, and we ship the fix. We publish a risk index (the BRI) scored across 12 security dimensions, and work directly with protocol teams on what we find. Each finding is proven with a working exploit on a mainnet fork and delivered with remediation as a merge-ready pull request — your team reviews and merges it, and we never hold your deploy or merge keys.

Protocols ship continuously. The security work that protects them should too.

That work starts free for everyone: the hacks feed, a per-protocol BRI and Shield rating, and redacted previews of lower-severity findings. From there, teams that want to work with us directly move into Direct Engagement — a private, outcome-based relationship with a direct line to our researchers — and then Vanguard, where a dedicated researcher monitors the protocol continuously and delivers fixes as merge-ready pull requests.

One principle never changes: when we find a live Critical or funds-at-risk issue, we disclose it to the protocol immediately and for free, through its existing channels. Safety is never gated behind a paywall.

That same engine now rates the integrity of individual prediction markets. Using one Forge Scale and one composite formula, a market-integrity score from 300 to 1000 measures how exposed an average trader is to informed flow, ambiguous resolution, and venue risk across six dimensions. A low score flags where to look harder.

02 //
Track Record
109

Protocols Analyzed

310+

Confirmed Vulnerabilities

108

Confirmed Criticals

109

Confirmed Highs

210+

Fork-Validated PoC Tests

100%

Criticals Backed by Exploits

verifiedThese numbers are drawn live from the BlackHart Oracle and grow with every protocol we score — together with the hack-intelligence feed, it's the risk-intelligence nervous system for DeFi. Every finding is fork-validated with a passing proof of concept: real exploits, real state, real value at risk.

03 //
What Makes Us Different
verified
verified

Proven on Mainnet Forks

Every finding ships with a working exploit run against the deployed contracts on a mainnet fork. If the proof of concept passes, the bug is real and the impact is measurable.

radar
radar

Continuous Coverage

We analyze your protocol on an ongoing basis. When the code, its dependencies, or market conditions change, we re-run the affected checks rather than wait for the next audit cycle.

account_tree

Compound Vulnerabilities

We focus on multi-step exploits where individually safe components combine into real risk: cross-contract interactions, economic attack paths, and state-dependent edge cases that single-contract reviews tend to miss.

handshake

Outcome-Based by Design

The relationship starts free and earns its way up. Direct Engagement is a private, outcome-based partnership with a direct line to our researchers — you pay for results, not hours. Vanguard adds a dedicated researcher, continuous coverage, and remediation delivered as merge-ready pull requests your team reviews and merges. We never hold your deploy or merge keys.

04 //
The Team

Founded by veterans.

BlackHart was founded by military veterans who spent their careers defending critical systems. The team pairs hands-on exploit development with in-house detection tooling and a working knowledge of DeFi protocol architecture. We approach every engagement the way an attacker would, and we work it to completion.

05 //
See Our Work
CriticalEuler Finance — $197M Hack, March 2023

See our work in action.

Our analysis of the Euler V1 exploit reconstructed all three critical vulnerabilities and the full multi-step attack path. View the threat map, findings, and validated proofs of concept.

View Euler V1 Analysisarrow_forward
$197M

Funds Drained

6

Primitives Found

1.00

Detection Confidence

1 TX

Atomic Exploit

Ready to protect your protocol?

Working exploits, staged patches, and ongoing coverage. Every finding is proven on a mainnet fork and ships with a fix.