Firmware Supply Chain - Reproducible Builds and Code Signing

Firmware Supply Chain - Reproducible Builds and Code Signing

A signed firmware binary proves who built it, not what it was built from. How reproducible builds, deterministic toolchains and on-device signature checks close that gap, using the COLDCARD firmware as a worked example.

15 minute read
Cross-Chain Bridge Hacks - Ten Incidents, Five Failure Classes

Cross-Chain Bridge Hacks - Ten Incidents, Five Failure Classes

A comparative analysis of ten major cross-chain bridge exploits between 2021 and 2026, grouped into five failure classes, covering the architecture of each bridge, the root cause of each failure, and the destination of the stolen funds.

41 minute read
COLDCARD Firmware - Architecture and Security Model

COLDCARD Firmware - Architecture and Security Model

How the COLDCARD hardware wallet firmware works - the bootloader/MicroPython split, dual secure elements, PIN key stretching, trick PINs, signed firmware, and reproducible builds.

26 minute read
Rundler — Inside Alchemy's ERC-4337 Bundler

Rundler — Inside Alchemy's ERC-4337 Bundler

How Rundler implements an ERC-4337 bundler in Rust — the Pool, Builder and RPC tasks, mempool simulation and reputation, the bundle sender state machine, gas estimation, signature aggregation and multi-entry-point support.

29 minute read