Blog
Notes on onchain detection, exploit patterns, and why security tooling should stay read-only.
·Snitch Team
The mempool is where exploits die
By the time a block confirms, the funds are gone. Here is what changes when you move detection one block earlier.
·Snitch Team
Diff the bytecode, or miss the upgrade that drains you
Most drains are not clever. They are a proxy upgrade that quietly adds a mint path. If you never diff the deployed code, you never see it.
·Snitch Team
Security tools should not hold your keys
The safest monitoring tool is one that cannot move your funds even if it is fully compromised. That constraint shapes how we built Snitch.