<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Halborn Security Disclosures</title>
    <link>https://www.halborn.com/disclosures</link>
    <description>Security advisories, vulnerability disclosures, and security research from Halborn's team of cybersecurity experts.</description>
    <language>en-us</language>
    <lastBuildDate>Wed, 13 May 2026 00:10:21 GMT</lastBuildDate>
    <atom:link href="https://www.halborn.com/disclosures/feed.xml" rel="self" type="application/rss+xml"/>
    <image>
      <url>https://www.halborn.com/halborn-logo.png</url>
      <title>Halborn Disclosures</title>
      <link>https://www.halborn.com/disclosures</link>
    </image>
    
    <item>
      <title>Halborn “Rab13s” Vulnerability Discovery In Dogecoin and 280+ Networks</title>
      <link>https://www.halborn.com/disclosures/rab13s-vulnerability-dogecoin</link>
      <guid isPermaLink="true">https://www.halborn.com/disclosures/rab13s-vulnerability-dogecoin</guid>
      <pubDate>Mon, 12 Jun 2023 13:44:25 GMT</pubDate>
      <description>During an audit of the Dogecoin open-source codebase back in March 2022, Halborn researchers — led by Halborn Senior Offensive Security Engineer Hossam Mohamed — identified several critical and exploitable vulnerabilities. The most critical of these — codenamed Rab13s — was discovered to have far-re...</description>
      <category>Security Disclosure</category>
    </item>
    <item>
      <title>Halborn Discovers Zero-Day Vulnerability in CosmWasm Smart Contracts Across 20+ Blockchains</title>
      <link>https://www.halborn.com/disclosures/halborn-discovers-zero-day-vulnerability-in-cosmwasm</link>
      <guid isPermaLink="true">https://www.halborn.com/disclosures/halborn-discovers-zero-day-vulnerability-in-cosmwasm</guid>
      <pubDate>Fri, 03 Mar 2023 17:02:11 GMT</pubDate>
      <description>Luis Quispe Gonzales, a security researcher at Halborn discovered a zero-day vulnerability arising from the lack of normalization of addresses in Bech32 specification (a format for SegWit addresses) in CosmWasm, which allows an attacker to bypass validity checks or break storage keys under certain c...</description>
      <category>Security Disclosure</category>
    </item>
    <item>
      <title>Vulnerability Disclosure Policy</title>
      <link>https://www.halborn.com/disclosures/disclosure-policy</link>
      <guid isPermaLink="true">https://www.halborn.com/disclosures/disclosure-policy</guid>
      <pubDate>Thu, 02 Mar 2023 18:03:42 GMT</pubDate>
      <description>Scope of Vulnerability Disclosure PolicyHalborn’s vulnerability disclosure policy primarily addresses the following three situations:Vulnerabilities discovered by Halborn that affect other entitiesVulnerabilities reported to Halborn that affect other entitiesVulnerabilities reported to Halborn that ...</description>
      <category>Security Disclosure</category>
    </item>
    <item>
      <title>Halborn Cadence (Flow) Vulnerability Discovery </title>
      <link>https://www.halborn.com/disclosures/halborn-cadence-flow-vulnerability-discovery</link>
      <guid isPermaLink="true">https://www.halborn.com/disclosures/halborn-cadence-flow-vulnerability-discovery</guid>
      <pubDate>Wed, 15 Feb 2023 15:54:52 GMT</pubDate>
      <description>IntroductionHalborn security researcher Ferran Celades identified a vulnerability in the Secure Cadence update to Cadence during an audit engagement with Dapper Labs.&amp;nbsp; This vulnerability affected how the Flow blockchain managed resources.&amp;nbsp; Halborn has worked with Cadence to deploy an updat...</description>
      <category>Security Disclosure</category>
    </item>
    <item>
      <title>Halborn MetaMask “Demonic” Vulnerability Discovery</title>
      <link>https://www.halborn.com/disclosures/demonic-vulnerability</link>
      <guid isPermaLink="true">https://www.halborn.com/disclosures/demonic-vulnerability</guid>
      <pubDate>Wed, 15 Feb 2023 15:54:32 GMT</pubDate>
      <description>IntroductionThe Demonic Vulnerability (CVE-2022-32969) was discovered by Halborn and we have worked with MetaMask, Phantom, Brave, xDefi, and others to help the community remediate the issue. This announcement on June 15, 2022 follows a good faith effort to contact all affected teams and assist in m...</description>
      <category>Security Disclosure</category>
    </item>
  </channel>
</rss>