COLOSSEUM · CRYPTO WORLD'S FAIR '26

PROOF,NOT OPINION.

AI made offense cheap — autonomous agents are already reading your code. Someone's pack will find your bug. Ours runs first: repo, site, or program id — Solana, EVM, or the web2↔web3 wiring — it finds the bug class, writes the exploit, runs it on a local validator — never mainnet —and anchors the verdict on-chain. Born at the Colosseum Crypto World's Fair — the pack that hunts this cohort's code. Proof, not opinion.

cachorro — the pack terminal
The cachorro — a wireframe guard dog in neon phosphor green, chained to a Solana program
$ unleash <target>
PACK MINDreplay of a real hunt
▊
open season — free QUICK hunts for the cohort until Oct 12|repo · site · program id — one input, all stacks|owner-claimed hunts earn the doberman seal|48 hunts logged|77 proven · 4 refuted by gate · 0 false positives shipped|15 receipts anchored on devnet|0 mainnet txs — local validator only|journal: hash-chained
~/

THE HUNT, END TO END

~40min — 2.5h
1
$ cachorro hunt <your-program>
POINT AT YOUR PROGRAM

Your contract, wallet or protocol — GitHub repo or on-chain program ID. Fetch and static lint run in seconds — no wallet, no signup, no sales call.

fetch 5s · static 7s
2
$ pack --stages research..review
WATCH THE PACK THINK

RESEARCH → ANALYZE → DEVIL → POC → REVIEW. Every hypothesis, dead-end and verdict streams live — you watch the reasoning, not a spinner.

reasoning, not a spinner
3
$ attest verify <sha256>
VERIFY THE RECEIPT

Findings ship with an executable PoC (treatment drains, control blocks) and an on-chain attestation anchored to the exact bytes tested.

anchored on-chain · revocable
$285M

drained from Drift in 128 seconds — after the audit. Reports ship prose; Immunefi won't pay without a runnable exploit. Detection is commodity. Proof is the product.

nothing promotes without proof — the gate is enforced by the machine, not the prompt
OBSERVATION
static lint + on-chain dump become typed graph nodes
● ENFORCED
HYPOTHESIS
each candidate carries a falsifier — what would disprove it
● ENFORCED
EXPERIMENT
treatment vs negative control on a local validator
● ENFORCED
VERIFIED
the gate refuses promotion without oracle SUPPORTS + reproduction
● ENFORCED
oracle verdict on the last hunt: SUPPORTS — treatment drained 5,000,000,000 lamports, control rejected with Custom(1)

THE PROOF STACK

probabilistic → calibrated → deterministic

Probabilistic models hallucinate bugs — false positives. Statistical scanners sleep through them — false negatives. The pack uses each where it wins:

PROPOSE
the model hunts
Research + analysis fan out for recall — semgrep sets the coverage floor, the model reads what patterns miss. It may be wrong; that's allowed here.
WEIGH
the judge calibrates
Every promoted claim gets a typed exploit-plausibility score from a System One judge — a probability, not prose. Dissent shows on the certificate.
PROVE
the machine disposes
Nothing ships without oracle verdict + reproduction on a local validator — treatment drains, control blocks. The gate is code, not a prompt.
then the pack audits itself: self-audit tripwires catch bias — promotion without proof, suspiciously-easy verification, confirmation collapse — and atlas coverage reports which vuln classes were actually exercised. flags become part of the receipt's journal.

WHAT A $150K AUDIT SHIPS

vs what the pack ships

For protocol teams about to wire five figures for a PDF — contracts, wallets, protocols. And for every team that already knows Immunefi pays for exploits, not prose.

THE FIRM
  • ✗ 8–16 week queue while your TVL sits exposed
  • ✗ a PDF where most “findings” are informational noise
  • ✗ you pay for triage — they never prove a thing executes
  • ✗ expires silently the day you ship an upgrade
THE PACK
  • ✓ hours, not months — you watch the hunt live
  • ✓ executable PoCs — treatment drains, control blocks
  • ✓ machine-enforced gate: no proof, no finding
  • ✓ a receipt on-chain that expires when your program does

THE RECEIPT LIVES ON-CHAIN

Every finished hunt anchors a SHA-256 digest of the report — bound to the audited commit, the build digest and the hash-chained evidence journal — as a Solana memo. Tamper with either side and the digests diverge.

And the receipt knows when it's stale: the program upgrades, the digest stops matching, the attestation expires on its own.

▸ verify a receipt yourself — no trust in us required ↗
A holographic attestation scroll chained on-chain
ATTESTATIONdevnet
memocachorro:v1:3987b6c4…
tx5QnooNTuvmjZ… ↗
recomputeddigest ✓ matches
verifyrecomputed → MATCH
trivial for your users to verify — hard for anyone to fake

WHAT THE PACK HUNTS

ACCOUNTS & AUTHORITY
Missing signer/owner checks, account substitution, type confusion, remaining_accounts abuse, duplicate mutable accounts — the classes that empty a vault in one instruction.
PDA · CPI · MATH
Seed collisions and init_if_needed reinit, unpinned program IDs on arbitrary CPI, introspection atomicity, share inflation, cast/rounding bugs, close & rent theft.
ORACLE · TOKEN-2022 · ZK
Stale/manipulable price feeds, mint↔vault binding, transfer hooks — plus on-chain verifier soundness, nullifier double-spend and root validation for zk programs.

BEYOND THE PROGRAM

BUSINESS LOGIC
The pack reasons about economic intent, not just patterns: who can move whose money, which invariant a vault actually relies on, what breaks when a keeper is honest-but-late. Share inflation, donation attacks, fee redirection — the bugs that are legal Rust and fatal economics.
WEB2↔WEB3 BRIDGE
SwissBorg lost 1M through an API-side authority reassignment no scanner saw. We map the off-chain trust surface — keeper keys, oracle wiring, admin ops, signing backends — and trace where an off-chain compromise becomes an on-chain drain.
HONEST CONFIDENCE
VERDE = exploit executed on a validator. AMARELO = structural evidence across a boundary we can't fully execute locally. detected-not-proven = toolchain said no. Every report ships a coverage map — what was exercised, not just what was found.
built for Solana startups: run us before the 50K audit, after every upgrade, and on the bridges between

THE DOBERMAN SEAL

proof you can put in your README
1
CLAIM
POST /api/claim/repo — commit the nonce we give you as CACHORRO.md. Now the pack knows it's yours.
2
HUNT
Drop your repo in the terminal above. The pack hunts it end to end — programs, wiring, business logic.
3
WEAR IT
Your report gets a public URL, an on-chain receipt, and an embeddable SVG badge. Verified-owner hunts show your name.
WHY ANOTHER LAYER
AUDIT FIRM
$20K–$150K · 4–8 week wait
Expert humans, point-in-time, one commit. The report expires the day you merge again. Zellic missed Wasabi; Neodyme audited Wormhole before $326M.
STATIC SCANNER
cheap · instant · noisy
Pattern-matching ships false-positive piles. The fourth alert is real — but you've learned to skim by the third.
CACHORRO
the layer between audits
Every claim must reproduce the exploit on a validator — treatment vs control — then the verdict anchors on-chain as a receipt anyone can verify. Maybes die at the gate; you get proofs or nothing.
we don't replace auditors — we make their work verifiable, and catch what slips between engagements

FIELD LOG

every row is a real run
REPLAYED EXPLOITvalidation — not vibes
Blind replay of the $52M Cashio exploit (Mar 2022): the pack re-found CRITICAL · infinite-mint on the pre-patch commit —PoC-verified on a mainnet fork — and the exploit got blocked on the patched commit. Treatment vs control on a real exploit.
RECENT HUNTS—
loading…
RULES OF ENGAGEMENT
  • ▸ Audit only what you are authorized to audit — your own repo, or a program whose owner claims it. Anonymous hunts hit the allowlist, not random strangers.
  • ▸ PoCs run on a local validator or a local fork. No attack transaction ever touches mainnet.
  • ▸ Nothing is submitted automatically. A human reproduces the bug and files it through the official channel.
  • ▸ Untrusted targets are cloned, never built — a third-party build.rs is arbitrary code execution.
WHAT ATTESTED MEANS

cachorro-attested = this exact artifact was adversarially tested and here is the reproducible evidence, on-chain and revocable.

It is not a proof the program is safe. Verified builds have been hacked twice. We narrow the gap — reproduced PoCs, negative controls, bytes-bound digests — and say so out loud.

THE SKEPTIC SECTION

"isn't this just an LLM reading code?"
Probabilistic models hallucinate bugs (false positives); statistical scanners sleep through them (false negatives). The pack couples both: the model proposes for recall, the machine disposes for precision — nothing becomes a finding without oracle verdict + reproduction.
"does it replace a human audit?"
No — and anyone who says otherwise is selling you noise. It's the verified floor under one: cheap, continuous, executable. Deep economic exploits still want a human brain.
"does it touch mainnet?"
Never. Every PoC runs on a local validator or fork. The only on-chain write is the memo receipt.
"who submits the bug?"
A human, after reproducing it — private disclosure to the owner, or the fix itself. Nothing auto-submits, nothing leaks: unclaimed targets stay anonymous codenames.
"why trust the receipt?"
Don't. Recompute the digest yourself — that's the whole point. /verify
your contract. your wallet. your protocol. your move.
TEST IT. PROVE IT. SHIP THE RECEIPT.

Free QUICK hunts for everyone building at the Fair — until Oct 12. After the hackathon the pack closes: engagement hunts become paid, keys-gated, priced against the audit you didn't buy — paid in SOL, verified on-chain.