Posts by Runtime Verification

The Engineered Chaos Bugs Fear

By Runtime VerificationJune 15th, 2026

Fuzzing is one of the most practical ways to find bugs that unit tests miss, especially in large code bases. At a basic level, a fuzzer repeatedly feeds a series of not-so-randomized inputs into a program with the objective of identifying crashes, failed assertions, unexpected behavior, or broken assumptions. Many modern languages now have good fuzzing support built into or near the standard developer workflow.

The Future of Safety for Software as a Medical Device (SaMD)

By Runtime VerificationJune 11th, 2026

A simple bug in the software running inside a pacemaker or an insulin pump is not just a crashed app but it could also put thousands of lives at risk. Software as a Medical Device has raised the stakes of every line of code, and the testing toolkit alone is no longer enough.

When the Software Holds but the Money Leaves Anyway

By Runtime VerificationJune 3rd, 2026

A technical analysis of the April 2026 KelpDAO bridge incident, in which $292M was lost despite every audited on-chain component performing exactly as specified, with the actual compromise occurring in the off-chain operational layer that surrounded them.

The risk of open source code: what the past still teaches us

By Runtime VerificationMay 18th, 2026

The most consequential security failures in privacy software rarely come from anyone being careless. They come from properties that held in one place and quietly stopped holding in another.

KelpDAO Audit Passed. $292M Left Anyway.

By Runtime VerificationApril 20th, 2026

On April 18, 2026, an attacker drained $292M from KelpDAO's Ethereum escrow in a single transaction. The OFTAdapter contract that released 116,500 rsETH did exactly what it was designed to do. No bug was exploited, no zero-day in LayerZero's on-chain code. The entire on-chain system was, by conventional security standards, clean.

Wonderland CTF 2026: Fixed Deposits Challenge Results by Runtime Verification

By Runtime VerificationApril 8th, 2026

Earlier this week, our team at Runtime Verification participated in Wonderland’s CTF, providing one of the challenges to snatch a piece of the $30,000 prize pool. We want to thank everyone who joined us and worked tirelessly to solve all the challenges (and congrats to the winning teams!).

Kontrol and Term Finance: Formal Verification Success Story Working with Bounded Loops

By Runtime VerificationDecember 2nd, 2024

Over the last 6 weeks, Runtime Verification and Term Finance have worked together to formally verify a series of properties that play a key role in the Term Finance’s Tokenized Strategy Protocol.

Meet the RV Team at DevCon

By Runtime VerificationNovember 6th, 2024

Our team is already in Thailand, ready to take over DevCon and the side events organized by different teams in the ecosystem! In this blog, we list all the events where our team will be speaking, how to get in touch with us and meet us, and update you on the latest developments in our tooling.

Introducing Komet: Smart Contract Testing & Verification Tool for Soroban, Created by Runtime Verification

By Runtime VerificationSeptember 19th, 2024

we’re excited to introduce our latest tool: Komet, a formal verification and fuzzing tool designed specifically for Soroban smart contracts on the Stellar blockchain.

With $33B TVL on the Line, Lido Turns to Runtime Verification for a Design Review

By Runtime VerificationSeptember 4th, 2024

Runtime Verification completed a design review of Lido's dual governance mechanism. This mechanism is the first of its kind, representing a monumental upgrade to the Lido governance model. This collaboration aimed to ensure that the new system, scheduled for testnet release in Q3 2024 and mainnet in Q4 2024, functions as intended and maintains the integrity and security of Lido’s $33 billion in total value locked (as of this writing).

Kontrol Integrated Verification of the Optimism Pausability Mechanism

By Runtime VerificationMay 16th, 2024

We are pleased to announce our recently completed work with Optimism and Kontrol integration into their CI. Having Kontrol as part of Optimism’s CI produces proof of correctness for critical properties of the code as it evolves.

Runtime Verification Audits Band Protocol’s Rust Implementation of the Band StandardReference Soroban Smart Contract

By Runtime VerificationMarch 29th, 2024

Runtime Verification is pleased to announce the audit completion of Band Protocol’s rust implementation of the Band Standard Reference Soroban Smart Contract. Band Protocol, built on top of Cosmos, is a cross-chain data oracle platform that aggregates and connects real-world data and APIs to smart contracts.

Have critical software that has to be right? Let's talk.

Get in touch
10+
Years in formal methods
NASA & Boeing
Early heritage, before blockchain
Trusted
By leading blockchain foundations