Shinren security case studies — real findings, reproduced at the rung we actually reached.

Each study links to a public GitHub artifact. Findings are labelled at the rung actually proven (Observed, Reproduced, Runtime-confirmed, Reported, Remediated, Retested); severities are never inflated to manufacture a result.

Caller-supplied-authorizer vault drain — Zenith-options/contracts #120 (Soroban/Rust, CRITICAL, Runtime-confirmed)

A pre-mainnet Soroban options vault trusted a caller-supplied authorizer on the withdraw path, letting an attacker authorize a drain of another account's collateral. Elevated from source-level to Runtime-confirmed with a native cross-contract Soroban PoC (PASS), then reported responsibly. Public finding.

Governance vote-weight recycling — veracindarella/votechain-contracts #92 (Soroban/Rust, Runtime-confirmed)

Voting power was read from live balance with no per-proposal snapshot, so one 100-token stake drove 300 votes and defeated a 250 quorum. Confirmed with a cargo-test PoC against the real contracts; snapshot-at-creation remediation posted. Public finding.

ERC-20 pre-audit VERIFIED CLEAN — CallistoSecurity #90 (ZINZ, EVM, Retested)

solc-js recompile structurally matches the on-chain bytecode; interface enumerated as ERC-20 + Burnable with zero privileged selectors; delivered with a reproducible verify.py and its scope limitation stated plainly. An honest clean verdict backed by evidence, not assertion. Public finding.

Session-key scope hardening — Conrad-sudo/sh-protocol #1 / PR#2 (ERC-4337/7579, Merge-ready)

Per-key (target, selector) session-key scoping via an owner-signed EIP-712 SessionGrant. Merge-ready src/SessionGrantLib.sol was verified against the real ERC-4337/7579 Execution[] path with forge test 9/9 passing on solc 0.8.33. Public contribution.

Source-binding / identity-drift defect — open-trust-layer/protocol #35 (Reported)

On an invited external review of a frozen commit, the in-tree security policy routed reviewers to closed trackers for a superseded review target — a source-binding / identity-drift defect. Proposed a promotion-gate CI assertion so the documented review target always matches the reviewed source. Public finding.

Fail-open agent capability scope — Resomnium/cellos #1 (Reported)

Agent capability scope used an adversarially bypassable substring match and defaulted fail-open. Proposed a typed, segment-exact, fail-closed matcher plus a recomputable AuditEntry so authorization decisions are reproducible. Public finding.