PROOF,NOT OPINION.
AI made offense cheap — autonomous agents are already reading your code. Someone's pack will find your bug. Ours runs first: repo, site, or program id — Solana, EVM, or the web2↔web3 wiring — it finds the bug class, writes the exploit, runs it on a local validator — never mainnet —and anchors the verdict on-chain. Born at the Colosseum Crypto World's Fair — the pack that hunts this cohort's code. Proof, not opinion.

THE HUNT, END TO END
~40min — 2.5hYour contract, wallet or protocol — GitHub repo or on-chain program ID. Fetch and static lint run in seconds — no wallet, no signup, no sales call.
RESEARCH → ANALYZE → DEVIL → POC → REVIEW. Every hypothesis, dead-end and verdict streams live — you watch the reasoning, not a spinner.
Findings ship with an executable PoC (treatment drains, control blocks) and an on-chain attestation anchored to the exact bytes tested.
drained from Drift in 128 seconds — after the audit. Reports ship prose; Immunefi won't pay without a runnable exploit. Detection is commodity. Proof is the product.
THE PROOF STACK
probabilistic → calibrated → deterministicProbabilistic models hallucinate bugs — false positives. Statistical scanners sleep through them — false negatives. The pack uses each where it wins:
WHAT A $150K AUDIT SHIPS
vs what the pack shipsFor protocol teams about to wire five figures for a PDF — contracts, wallets, protocols. And for every team that already knows Immunefi pays for exploits, not prose.
- ✗ 8–16 week queue while your TVL sits exposed
- ✗ a PDF where most “findings” are informational noise
- ✗ you pay for triage — they never prove a thing executes
- ✗ expires silently the day you ship an upgrade
- ✓ hours, not months — you watch the hunt live
- ✓ executable PoCs — treatment drains, control blocks
- ✓ machine-enforced gate: no proof, no finding
- ✓ a receipt on-chain that expires when your program does
THE RECEIPT LIVES ON-CHAIN
Every finished hunt anchors a SHA-256 digest of the report — bound to the audited commit, the build digest and the hash-chained evidence journal — as a Solana memo. Tamper with either side and the digests diverge.
And the receipt knows when it's stale: the program upgrades, the digest stops matching, the attestation expires on its own.
▸ verify a receipt yourself — no trust in us required ↗
WHAT THE PACK HUNTS
BEYOND THE PROGRAM
THE DOBERMAN SEAL
proof you can put in your READMEFIELD LOG
every row is a real run- ▸ Audit only what you are authorized to audit — your own repo, or a program whose owner claims it. Anonymous hunts hit the allowlist, not random strangers.
- ▸ PoCs run on a local validator or a local fork. No attack transaction ever touches mainnet.
- ▸ Nothing is submitted automatically. A human reproduces the bug and files it through the official channel.
- ▸ Untrusted targets are cloned, never built — a third-party build.rs is arbitrary code execution.
cachorro-attested = this exact artifact was adversarially tested and here is the reproducible evidence, on-chain and revocable.
It is not a proof the program is safe. Verified builds have been hacked twice. We narrow the gap — reproduced PoCs, negative controls, bytes-bound digests — and say so out loud.
THE SKEPTIC SECTION
Free QUICK hunts for everyone building at the Fair — until Oct 12. After the hackathon the pack closes: engagement hunts become paid, keys-gated, priced against the audit you didn't buy — paid in SOL, verified on-chain.