What we doO que fazemos01 ProofProva02 MethodMétodo03 PricingPreços04 Contact05
bluewave · adversarial review · 2026
Marble statue blindfolded with a klein-blue band reading wave in gold leaf, gold dripping
offensive security for connected systems · 2026segurança ofensiva para sistemas conectados · 2026
offensive security · web · api · cloud · ai · web3segurança ofensiva · web · api · cloud · ia · web3

Find the break before they do.Ache a brecha antes deles.

We find and prove the attack path across your connected systems: from public API to cloud, from prompt to tool, from contract to treasury.A gente acha e prova o caminho de ataque nos seus sistemas conectados: da API pública até a cloud, do prompt até a ferramenta, do contrato até a tesouraria.

Every finding reproducedTodo achado reproduzido Every path explainedTodo caminho explicado One free retest includedUm reteste grátis incluído
the problemo problema

Your security stack is bigger than your security team.O seu stack de segurança é maior que o seu time de segurança.

Web, APIs, cloud, AI agents and contracts are one connected system. An attacker chains a small flaw in one part into real damage in another. Almost nobody tests the whole chain.Web, APIs, cloud, agentes de IA e contratos são um sistema só. Um atacante encadeia uma falha pequena numa parte até virar dano real em outra. Quase ninguém testa a cadeia inteira.
the differencea diferença

Attackers don't see your tools. They see the chain.Atacantes não veem suas ferramentas. Veem a cadeia.

web public api auth service ai agent cloud role tool call impacttakeover one exposed surface one path to real impact
We find the shortest path from your exposed surface to real business impact. The chain, not the isolated bug.A gente acha o caminho mais curto da sua superfície exposta até o impacto real no negócio. A cadeia, não o bug isolado.
why it matterspor que importa

Audited and still breachedAuditado e ainda invadido

In 135 DeFi incidents studied in 2026, 94.4% of the losses came through paths no audit had looked at. Auditing a component is not the same as attacking the system.Em 135 incidentes DeFi estudados em 2026, 94,4% das perdas vieram por caminhos que nenhuma auditoria olhou. Auditar um componente não é o mesmo que atacar o sistema.

what we sello que vendemos

The path, provenO caminho, provado

Not "you have an XSS". How an attacker gets from your public API to a customer account, or from a leaked key to your cloud. Reproduced end to end, with the business impact spelled out.Não "você tem um XSS". Como um atacante vai da sua API pública até a conta de um cliente, ou de uma chave vazada até a sua cloud. Reproduzido ponta a ponta, com o impacto no negócio explícito.

three offers, by problemtrês ofertas, por problema

One attack path. Every surface it touches.Um caminho de ataque. Toda superfície que ele toca.

01 · application attackweb · api · cloud
public api auth cloud role account
Break the application and prove the path to impact.Quebre a aplicação e prove o caminho até o impacto.Your websites, APIs and the cloud they run on. We break in and chain what we find into real impact: account takeover, cloud compromise. AWS, GCP, Azure, Kubernetes.Seus sites, APIs e a cloud onde rodam. A gente invade e encadeia o que acha em impacto real: account takeover, comprometimento de cloud. AWS, GCP, Azure, Kubernetes.
02 · ai agent red teamai · agents
prompt reasoning tool action
Test what your AI can be made to do.Teste o que dá pra fazer a sua IA fazer.Your chatbots, copilots and agents. We make them ignore their rules, leak data or take actions they should not, with adaptive multi-turn attacks a standard test never runs.Seus chatbots, copilots e agentes. A gente faz eles ignorarem as regras, vazarem dado ou executarem ações que não deviam, com ataques adaptativos multi-turno que teste padrão nunca roda.
03 · protocol attackcontracts · infra
call missing auth treasury
Prove how an attacker can move value.Prove como um atacante move valor.Adversarial validation around the audit: the contract plus the application and infrastructure around it. If a flaw can move funds, we prove it on a testnet fork, with the transaction as evidence. Soroban/Stellar and EVM.Validação adversarial em volta da auditoria: o contrato mais a aplicação e a infra ao redor. Se uma falha move fundos, a gente prova num fork de testnet, com a transação como evidência. Soroban/Stellar e EVM.
proof, not tool logosprova, não logo de ferramenta

Impact, not a vulnerability list.Impacto, não lista de vulnerabilidade.

bluewave / proof of impactweb3 · testnet
1,000,000moved in four callsmovidos em quatro chamadas
targetlive treasury contractcontrato de tesouraria vivo
vectormissing authorization checkcheck de autorização faltando
chain4 black-box calls4 chamadas black-box
evidenceon-chain ledgerledger on-chain
reproduced retested
bluewave / proof of impactai · measured
98%harmful state still insideestado danoso ainda por dentro
targeta model that refuses every harmful requestum modelo que recusa todo pedido danoso
vectorinternal probe below the refusalprobe interno abaixo da recusa
findingthe refusal is a shella recusa é casca
evidencemeasured, reproduciblemedido, reproduzível
reproduced paper
bluewave / proof of impactweb2 · capability
4 hopspublic api to account takeoverda api pública ao account takeover
entrya public endpointum endpoint público
vectoran authorization flawuma falha de autorização
chaina privileged actionuma ação privilegiada
evidenceproven end to end on your systemsprovado ponta a ponta nos seus sistemas
mapped exploited safely
DeFi audit-scope figures: ack3 H1 2026 DeFi Incident Dataset, arXiv:2608.13792 (135 incidents, US$ 940M in losses).Dados de escopo de auditoria DeFi: ack3 H1 2026 DeFi Incident Dataset, arXiv:2608.13792 (135 incidentes, US$ 940M em perdas).
pricingpreços

One attack. Three sizes.Um ataque. Três tamanhos.

full pricingpreços completos
focused attackataque focado

US$ 3,500

One surface: a web app, an API, an AI application or a single contract scope. 3 to 5 days. Findings reproduced, report, remediation guidance, one free retest.Uma superfície: um app web, uma API, uma aplicação de IA ou um contrato. 3 a 5 dias. Achados reproduzidos, relatório, orientação de correção, um reteste grátis.

full attack · most engagementsataque completo · a maioria

US$ 7,500

Web + API + cloud, or AI + tools + data, or protocol + application. 5 to 10 days. Attack-chain analysis, manual exploitation, proof of impact, remediation, free retest.Web + API + cloud, ou IA + ferramentas + dados, ou protocolo + aplicação. 5 a 10 dias. Análise da cadeia de ataque, exploração manual, prova de impacto, correção, reteste grátis.

adversarial campaigncampanha adversarial

from US$ 15,000a partir de US$ 15.000

Several surfaces and the paths between them: web, cloud, AI agents, protocol. Deeper chaining and custom research. Scoped per engagement.Várias superfícies e os caminhos entre elas: web, cloud, agentes de IA, protocolo. Encadeamento mais fundo e pesquisa sob medida. Escopado por trabalho.

Retest US$ 1,500, included in every engagement above. Quarterly adversarial retest US$ 3,000 to 5,000. Attack program: four campaigns a year, US$ 12,000.Reteste US$ 1.500, incluído em todo trabalho acima. Reteste adversarial trimestral US$ 3.000 a 5.000. Programa de ataque: quatro campanhas por ano, US$ 12.000.
going deeperindo mais fundo

How we attack each surface, and the evidence behind it.Como atacamos cada superfície, e a evidência por trás.

The web and cloud method, the seven ways we break an AI's reasoning, the Soroban audit classes, the measured attack rates and our research paper are on one page.O método de web e cloud, as sete formas de quebrar o raciocínio de uma IA, as classes de auditoria Soroban, as taxas de ataque medidas e o nosso paper estão numa página só.

Read the methodLer o método
BOLA · OWASP API #1 · broken authorization · confused deputy · SSRF to cloud metadata · credential chain to cloud · choke over jewel · audit the chokepoint, not the crown jewel · Capital One · 2019 · 100M+ · SSRF to IMDS · 629 tests · 97 user tasks · benchmark NaiveCredulousAgent · LASM 7-layer grid · prompt · context · retrieval · tool · memory · identity · principal · GCG · AutoDAN · adaptive probes · jailbreak depth · InjecAgent · indirect prompt injection · zero action outside perimeter · V = Δ(B₀,B₀) · declared vs observed gap · R = T·A·W·M·B · outside-in composition · Virtuals Protocol · nov/2024 · US$ 500k · first public agent-fraud case · Bittensor · jul/2024 · US$ 8M · malicious pypi · supply chain ·   
initial analysis · análise inicial · freegratuita
Talk to a specialistFale com um especialista
Telegram