Incident workspace

Cross-domain Message Validation Weakness

A fictional research disclosure models a cross-domain receiver that validates message shape but not the expected origin domain.

Phase 1 · Fictional Content

Fictional data used to validate the TraceFi interface. This is not a real security incident.

Replay Lab

Non-executable replay material only.

Replay type
Static Code Walkthrough
Replay status
Available
Execution label
Non-executable
Environment
Annotated fictional code

Requirements

  • Browser reading only

Limitations

  • Research-only record
  • No executable bridge fixture
  • No real bridge message data

Investigation lab not packaged yet

This prototype incident does not include a curated browser IDE lab. Review the incident overview, evidence, and Learn Mode while the lab package is planned.

Interactive Foundry Challenge Preview

This phase is non-functional. There is no editor, terminal, runner, scoring persistence, API, wallet, RPC endpoint, or code execution.

Verification State

Verification: ReviewedLast verified: