Half Ounce Research runs one capability, certified adversarial verification, and applies it to zero-knowledge proof systems, post-quantum signature verifiers and open questions in mathematics. Every finding travels with a machine-checkable witness that the client replays in their own verifier, without trusting the software that found it.
Each of these lanes reduces to the same computation:
given a map A : prover messages → verifier checks find the lightest x ≠ 0 with A(x) = 0 outside the intended relation or prove that none exists below a bound
The map is a verifier's acceptance rule as built, and its kernel is what that verifier cannot see: a second witness for the same public input, a transcript it cannot tell from an honest one, a second encoding of one signature. A reading of the code looks for what is missing; the kernel shows what is extra. The lightest such element is the adversary's cheapest deviation; the work is to find it and prove the measurement, or to prove that none exists below a bound. For a stabilizer code the computation is literal; for a circuit, a transcript or an encoding it is the framing of the question, and the certificate carries the claim.
The bugs cited are public examples of each class, credited to their discoverers. None is a finding of this program.
ml-dsa crate accepted repeated hint indices where FIPS 204 requires strictly
increasing ones, so one valid signature had two encodings.
A specification review asks whether the constraints the design calls for are present; it is a reading, and can miss what it was not told to look for. This is a search: the cheapest input the verifier, as built, accepts and the relation forbids. Each finding ships as the witness itself, a short checker in standard-library Python that reads it, and the replay command. The client runs the witness through their own verifier; if it accepts, the finding stands on the client's tooling, and nothing of this program's needs to be trusted. Where nothing exists below the bound, that ships as a certificate too — a statement about that map and that bound, not a security proof of the whole system.
The security record to date: confirmed critical-severity soundness findings in zero-knowledge proof systems and post-quantum cryptography implementations, disclosed responsibly. Findings go privately to the vendor; no live exploit is published; no finding of this program is named or described on this page.
Write to daniel@halfounce.io naming the proof system or signature scheme, its verifier, and where the source can be read. Audit firms may write to the same address.