Differential fuzzing for Vyper
Our fuzzing work includes differential compiler fuzzers for Vyper.
COMPILER SECURITY
We’ve worked with a number of different compiler targets. We’re partnered with Vyper to audit their compiler, and we reviewed the Move compiler rewrite on behalf of Aptos.
WHY OTTERSEC
WHAT WE BRING
Fuzzing is one of our core disciplines, and compilers are one of the platforms we audit.
Our fuzzing work includes differential compiler fuzzers for Vyper.
Our rBPF JIT fuzzers resulted in multiple denial of service and integrity issues.
Our Move VM bytecode fuzzers resulted in over half a dozen crashes.
Our research covers a timeline and postmortem for the Vyper compiler bug, Solidity compiler memory safety, and how a 12-year-old g++ bug took down Solidity.
OUR AUDITING PROCESS
We’ll discuss your goals, timeline, and security needs to see whether we’re a fit.
We’ll send an MNDA and look at repositories within scope to understand the details of your project and requests.
We’ll deliver a quote based on our expected duration, potential vulnerabilities, and the overall complexity of your project.
PROOF
“As a blockchain, speed, scalability, and security are critical to our everyday operations. OtterSec's responsiveness, attentiveness, and talent are second-to-none when it comes to securing Solana's core code.”
GET STARTED
Tell us which compiler targets matter and where the highest-risk parts live. We will route the request to the right security team.
Get an audit