NODE-CONSTANT//SRF-01 · COBALTHARDEN
WICK / 04//45.5°N · 73.5°W
← SURFACES/SRF-01HARDEN
Core Verification

Cobalt

Formal proof for critical infrastructure.

Formal verification engine for C, C++, RTOS, embedded systems, and cryptographic libraries. Cobalt identifies vulnerabilities with formal evidence under defined execution conditions — not guessed through heuristics. Every finding is backed by a Z3 constraint proof showing the exact input that triggers failure.

25+
Confirmed CVEs
19
Vuln Classes
7
Target Domains
§ SPECIFICATION
Input
  • C / C++ source code or binary
  • RTOS firmware images
  • Build configuration + compilation flags
  • Optional: threat model / attack surface definition
Constraints Verified
  • Buffer boundary invariants
  • Integer arithmetic overflow conditions
  • Null pointer dereference paths
  • Use-after-free reachability
  • Format string injection paths
  • Cryptographic timing side-channels
Output
  • Z3 SMT-LIB2 proof artifact per finding
  • Vulnerability class + CWE mapping
  • Exploitability analysis with witness values
  • Remediation path with formal verification of fix
§ SAMPLE PROOF ARTIFACT
ARTIFACT // COBALT-WOLF-01FAILURE DETECTED
// SAMPLE PROOF — COBALT ENGINE

wolfSSL DH key parsing — integer overflow

TargetwolfSSL 5.6.x
Conditionkey_len = 0xFFFFFFF4 → alloc_size wraps to 4 bytes
VerdictSAT
SummaryHeap write-out-of-bounds. PR merged upstream.
StatusReview-ready
→ View full artifact repository
§ FIELD VALIDATION
#TargetVulnerability ClassStatus
01wolfSSL
Integer Overflow
Integer OverflowPR Merged
02NASA cFS
Stack Overflow
Stack OverflowACK Amazon
03Mosquitto
Buffer Overflow
Buffer Overflow2× CVE Filed
04libupnp
Stack Overflow
Stack OverflowCVE-2026-41682
05lwIP
Integer Overflow
Integer OverflowCVE Filed
06Mongoose
Buffer Overflow
Buffer OverflowCVE Filed
07llama.cpp
Heap Overflow
Heap OverflowCVE Filed
08Mozilla NSS
Timing Channel
Timing ChannelFixed
Run Cobalt on your system.

Formal engagement starts with a technical intake. We scope, configure, and deliver a proof artifact within the agreed SLA.

Request Briefing →