Category: Smart Contracts

The Engineered Chaos Bugs Fear

By Runtime VerificationJune 15th, 2026

Fuzzing is one of the most practical ways to find bugs that unit tests miss, especially in large code bases. At a basic level, a fuzzer repeatedly feeds a series of not-so-randomized inputs into a program with the objective of identifying crashes, failed assertions, unexpected behavior, or broken assumptions. Many modern languages now have good fuzzing support built into or near the standard developer workflow.

When the Software Holds but the Money Leaves Anyway

By Runtime VerificationJune 3rd, 2026

A technical analysis of the April 2026 KelpDAO bridge incident, in which $292M was lost despite every audited on-chain component performing exactly as specified, with the actual compromise occurring in the off-chain operational layer that surrounded them.

Wonderland CTF 2026: Fixed Deposits Challenge Results by Runtime Verification

By Runtime VerificationApril 8th, 2026

Earlier this week, our team at Runtime Verification participated in Wonderland’s CTF, providing one of the challenges to snatch a piece of the $30,000 prize pool. We want to thank everyone who joined us and worked tirelessly to solve all the challenges (and congrats to the winning teams!).

Kontrol and Term Finance: Formal Verification Success Story Working with Bounded Loops

By Runtime VerificationDecember 2nd, 2024

Over the last 6 weeks, Runtime Verification and Term Finance have worked together to formally verify a series of properties that play a key role in the Term Finance’s Tokenized Strategy Protocol.

Using Simbolik for Solidity Debugging

By Raoul SchaffranekNovember 4th, 2024

Explore how to leverage Simbolik for streamlined Solidity debugging. Learn to automate deployments, simulate user interactions, and create reusable debugging scenarios—all within Solidity.

Formally Verifying Loops: Part 2

By Raoul SchaffranekOctober 7th, 2024

This blog post continues our journey into formal verification of loops in Solidity and EVM smart contracts. It introduces loop invariants, a challenging but essential technique for reasoning about unbounded loops. We explore natural induction, apply pen-and-paper methods, and then leverage Kontrol to formally prove the equivalence of two Solidity functions, diving deep into EVM bytecode and formal verification tools.

Formally Verifying Loops: Part 1

By Raoul SchaffranekSeptember 26th, 2024

Explore the challenges of formal verification in Solidity and EVM smart contracts. Learn about the path explosion problem, bounded loop unrolling, and how tools like Certora Prover, Halmos, hevm, and Kontrol approach verifying loops in smart contracts.

On The Limitations of Audit Competitions

By Paul LenAugust 27th, 2024

Audit competitions have surged in popularity recently, with numerous platforms vying to connect projects with independent security researchers. The premise is straightforward: organizations offer a cash prize to attract auditors eager to scrutinize their code for vulnerabilities. While cost-effective, the evolving ecosystem necessitates a closer examination of the drawbacks inherent in relying solely on audit contests.

Testing ERC-20 Tokens Part 2: Advancing Benchmarking with Mutation Testing

By ERCxJanuary 29th, 2024

Runtime Verification and Certora partnered to compare and evaluate a set of testing tools for DeFi applications. In Part 1 of this blog post, we introduced the testing tools. In Part 2, we focus on the bug-detection capabilities of these tools. Specifically, we evaluate and compare them against each other by using mutation testing using Gambit.

Testing ERC-20 Tokens Part 1: An Arsenal for Bug Detection

By Runtime Verification & CertoraOctober 18th, 2023

Runtime Verification and Certora partnered to analyze a set of tools for detecting bugs in ERC-20 token contracts. In this series of two blog posts, we dive into the tools for detecting bugs in ERC-20 smart contracts.

Is my ERC-4626 vault token up to the standard?

By ERCxOctober 1st, 2023

How confident can we be in the behavior of the contracts? Do they follow the standards as required? With the permissionless nature of blockchains, anyone can write and deploy smart contracts in blockchain ecosystems. Thus, it is important to check that they conform to the standard requirements as stated in their respective ERC standard.

Using Foundry to Explore Upgradeable Contracts (Part 1)

By David KretzmerDecember 19th, 2022

Runtime Verification Inc applies formal methods to improve the safety, reliability, and correctness of computing systems for aerospace, automotive, and the blockchain.

Have critical software that has to be right? Let's talk.

Get in touch
10+
Years in formal methods
NASA & Boeing
Early heritage, before blockchain
Trusted
By leading blockchain foundations