Sign in

MLabs

@mlabs-consulting.bsky.social
8 followers 1 following 9 posts

Software consultancy. Identity and secrets infrastructure: PKI and certificate lifecycle, managed Keycloak, Vault, OpenBao. We write and verify Haskell, Rust, TypeScript. We write and audit Cardano smart contracts - Aiken, Plutarch, Plinth. www.mlabs.city

PostsRepliesMedia
MLabs @mlabs-consulting.bsky.social · 29/09/2026
One Cardano transaction can spend several script outputs at once. If each validator only checks that it got paid, a single payment can satisfy all of them. That's multiple satisfaction, and our audit write-up walks through one. www.mlabs.city/blog/from-bu... #Cardano
mlabs.city
From Bugs to Breakthroughs: Auditing Cardano Smart Contracts
Why Cardano smart contracts need independent auditing, the risks that subtle on-chain interactions create, and how a rigorous audit finds them first.
100
MLabs @mlabs-consulting.bsky.social · 28/09/2026
A failing QuickCheck property is only as useful as its counter-example. Without a shrinker, a random failure can be too big to read. With one, QuickCheck cuts it down to a small input that still fails. www.mlabs.city/blog/masteri... #Haskell #QuickCheck
mlabs.city
Mastering QuickCheck: Advanced yet Practical Techniques for Property-Based Testing
Practical techniques for property-based testing in Haskell with QuickCheck, and how to avoid the pitfalls that make it harder to use than it should be.
000
MLabs @mlabs-consulting.bsky.social · 24/09/2026
If checking an item needs an API to answer, the API's operator is the trust anchor and the blockchain is decoration. That rule shaped ProofTap, an NFC-to-Cardano verification app whose smart contracts we wrote. www.mlabs.city/blog/proofta... #Cardano #SmartContracts
mlabs.city
Cardano smart contracts behind ProofTap — MLabs case study
MLabs wrote the Cardano smart contracts behind ProofTap, an NFC platform that links physical items to publicly verifiable records. What an on-chain record has to do before a stranger's tap means anyth...
100
MLabs @mlabs-consulting.bsky.social · 23/09/2026
Review was built for code that looks wrong when it is wrong. Agent-written code compiles and reads cleanly, so it passes a skim. The bugs that survive are the plausible ones. They surface when the code runs against a QuickCheck property someone stated.
000
MLabs @mlabs-consulting.bsky.social · 21/09/2026
Verification is a claim about strangers. If checking a record needs an API to answer, that operator is the trust anchor and the chain is decoration. Whether you write it in Aiken or Plutarch, the question is the same: what has to be true with nobody's server involved?
000
MLabs @mlabs-consulting.bsky.social · 14/09/2026
We tried to reproduce the Keycloak upgrade horror story. We killed the migration mid-run twice. No lock was left behind; the next start finished in 13s. What broke it 3/3 was PgBouncer in transaction pooling, the common default. The migration log said success; the version record never moved.
mlabs.city
The Keycloak upgrade failure everyone describes, and its real cause
We could not reproduce Keycloak
000
MLabs @mlabs-consulting.bsky.social · 14/09/2026
We're a software consultancy. We maintain the security infrastructure your team owns but nobody owns: PKI and certificate lifecycle, managed Keycloak, Vault, OpenBao. We write and verify codebases in Haskell, Rust, TypeScript. We write and audit smart contracts.
161