Agentic security services

Find the failurebefore it moves value.

VulSight tests agent intent, financial authorization, and the infrastructure beneath each transaction. We return reachable failures as evidence your team can reproduce and fix.

  • Agent workflows
  • Payment controls
  • Blockchain infrastructure

Security scope

Choose the action that cannot be allowed to fail.

Starting point

A focused engagement starts with one consequential workflow and follows every route that can influence execution.

01

Agent workflow security

Control what context can make an agent do.

Test whether prompts, retrieved data, tools, identities, and multi-agent handoffs can expand authority or redirect a consequential action.
  • Direct and indirect prompt injection
  • Poisoned context and retrieval paths
  • Unsafe tool use and identity confusion
  • Excess permissions and approval bypass
  • Multi-agent delegation and handoffs
Primary outcomeAuthority map and exploit evidence
02

Agent payment security

Keep intent bound to financial execution.

Challenge the path from a principal mandate to the exact payload a customer signer receives, including the state changes around settlement.
  • Mandates, recipients, assets, and budgets
  • Policy decisions and approval gates
  • Signer isolation and payload binding
  • Revocation, expiry, and replay resistance
  • Failure, retry, and recovery behavior
Primary outcomeDecision path and control gaps
03

Financial infrastructure security

Test the systems beneath the transaction.

Trace high impact failure paths through the software, contracts, wallets, signers, and networks that agents depend on to move value.
  • Smart contract and protocol logic
  • Consensus and client behavior
  • Wallet, signer, and multisig boundaries
  • Bridges and cross-chain execution
  • Economic and state transition failures
Primary outcomeReachable failure paths

Engagement path

One path from threat model to verified fix.

Operating rule

Testing stays tied to reachable impact and the controls your team can change.

  1. 01

    Map the boundary

    Identify every input, identity, tool, policy, signer, and rail that can influence the action.

    OutputControl map
  2. 02

    Attack the workflow

    Run authorized cases against paths that can change authority, destination, amount, or execution.

    OutputValidated path
  3. 03

    Prove impact

    Capture the prerequisites, evidence, affected boundary, and reachable outcome for each finding.

    OutputEngineering finding
  4. 04

    Verify the fix

    Replay the original path and nearby variants against the proposed control.

    OutputRetest result
What your team receives

Evidence built for engineering decisions.

Each finding stays connected to its prerequisites, affected boundary, reachable impact, recommended control, and retest result.

  • 01Control boundary map
  • 02Validated findings
  • 03Reproduction evidence
  • 04Remediation guidance
  • 05Fix verification

Public evidence

Security work proven in systems that move value.

Disclosure boundary

Rankings, advisories, and platform acknowledgements show the work behind our practice. Confidential technical details stay private.

Leaderboard record

Independent public rankings

Every position links directly to its public source.

Official advisoryHigh

CVE-2026-26314

Geth denial of service via a malicious peer message

A specially crafted message can force an affected node to shut down or crash.
Open the official advisory
Surface
Go Ethereum peer message handling
Impact
Node shutdown or crash
Outcome
Fixed in Geth 1.16.9 and 1.17.0
Credit
Waleed Ahmed, VulSight
Selected findings

High impact paths, shown within disclosure limits.

Select a finding to inspect the impact, evidence status, and public acknowledgement where one is available.

Public platform recordcritical

Smart contracts / Immunefi

Reward$300K

Critical vulnerability with fund loss impact

A flaw in smart contract logic exposed more than $100M in TVL to potential fund loss. The project and exploit path remain confidential.

Value at risk
$100M+ TVL
Classification
Critical
Disclosure
Project withheld

Engagement questions

Scope the work before testing starts.

Start with the action, the systems that can influence it, and the outcome that must never happen. Keep credentials and production secrets out of the first message.

Discuss the scope
What can VulSight test?

VulSight can test AI agent workflows, payment authorization paths, policy engines, tools, signers, blockchain clients, wallets, smart contracts, and related infrastructure within an agreed scope.

Can testing happen before funds move?

Yes. A shadow mode engagement can replay realistic cases without releasing signing authority or moving production funds.

What does our team receive?

Your team receives a control map, validated findings, reproduction evidence, remediation guidance, and a retest result when updated controls are available.

Do you need our keys?

No. Raw private keys and production credentials should remain in customer controlled systems. Testing uses an agreed environment and least privilege access.

Start with one critical workflow

Show us where an agent can move value.

Share the action, available tools, signer, and outcome that must never happen. We will define a safe scope before testing begins.

Discuss your workflow