File size: 2,260 Bytes
84ea05f
 
0a83605
738ac80
c1bb7d3
84ea05f
 
0a83605
84ea05f
e1bdbc3
ee04066
 
 
 
 
 
 
 
 
 
 
0a83605
 
 
ee04066
 
 
 
 
0a83605
 
ee04066
 
 
 
 
 
 
 
 
0a83605
 
 
 
ee04066
 
 
84ea05f
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
---
license: mit
title: README
sdk: static
emoji: 🚀
colorFrom: pink
colorTo: purple
pinned: false
---

# NullRabbit Labs

**Autonomous defence for decentralised networks.**

NullRabbit Labs is the research arm of NullRabbit, a defensive security company building autonomous protection for blockchain validator infrastructure. We watch the outside of the perimeter: the network-layer attack surface that validator daemons expose to the open internet.

This organisation publishes the datasets, models, and interactive artefacts that come out of our research. Everything here is versioned, pre-registered, and audited on close.

## What we work on

- **Network-layer anomaly detection** against validator RPC, gossip, and consensus surfaces
- **Bundle format** - an open, chain-agnostic representation of network traffic for security ML ([nr-bundle-spec](https://github.com/NullRabbitLabs/nr-bundle-spec))
- **Earned autonomy framework** - governance layer for autonomous defensive systems ([Zenodo DOI 10.5281/zenodo.18406828](https://doi.org/10.5281/zenodo.18406828))
- **Iterative leak-surface peeling** - pre-registered ML methodology for adversarially robust security models

## Coordinated disclosures

NullRabbit's research feeds a coordinated-disclosure track. Published advisories sit on [nullrabbit.ai](https://nullrabbit.ai).

- **NR-2026-001** - Agave RPC architectural findings (Solana), 2026-05-12
- **NR-2026-002** - Sui Indexer-Alt findings, embargoed to 2026-06-20

## Methodology

Every model on this page is trained against a versioned, immutable corpus and a pre-registered design document. Audits run on close against sanity floors, per-feature audit trails, and falsification holdouts. Where an audit fires, training halts, the design is re-registered, and the prior version is retracted in writing.

Corpus versions are increment-only. Published checkpoints reference the exact corpus version and pre-registration document used.

## Links

- Website - [nullrabbit.ai](https://nullrabbit.ai)
- GitHub - [NullRabbitLabs](https://github.com/NullRabbitLabs)
- X - [@NullRabbitLabs](https://x.com/NullRabbitLabs)
- Earned autonomy paper - [Zenodo](https://doi.org/10.5281/zenodo.18406828)

## Contact

Research enquiries: simon@nullrabbit.ai