Independent Security Research · EST. 2025

We find what vendors bury.

When software vendors silently patch critical flaws without telling the people at risk, we document it, translate it, and put it in front of regulators with the authority to act.

Live Telemetry
Patches Analyzed4,121
Undisclosed4,103
Disclosure Rate0.44%
CVEs Filed162
Ecosystems9 Active
Capital At Risk$7.16B

A vulnerability gets fixed in a commit. No CVE. No advisory. No notification. The vendor is safe. Everyone running the old version is not.

This is the dominant pattern in modern software security — almost entirely invisible to the people best positioned to stop it. Regulators have the authority. They lack the technical capacity to use it. Security firms have the capacity. They sell assurance to the same vendors creating the problem.

Whitenbaker exists to close that gap. We detect silent patches at scale, prove the security impact, and translate the evidence into a form that securities regulators, privacy commissioners, and consumer protection bodies can act on the day they receive it.

4,103 Silent Patches Security fixes merged across 9 production codebases with no public advisory, no CVE, and no downstream notification.
$7.16B Capital Exposed Publicly traded value dependent on infrastructure currently running known-vulnerable versions of analyzed software.
0.44% Industry Compliance Share of fixed security flaws that received the public disclosure expected under standard vulnerability handling practice.
50+ Downstream Networks Forks, integrations, and dependent systems left exposed because the upstream vendor chose silence over notification.
From The Casework

Selected dossiers.

Every figure on this page is anchored in active research. Below is a sampling of the public-facing record. Specific findings, attribution, and chain-of-custody material are available under engagement.

Dossier 01 · Consensus Infrastructure

Consensus Infrastructure Compromise

A critical flaw in widely deployed consensus infrastructure renders its primary safety mechanism inoperative. Every downstream network inheriting this library is exposed to conditions the system was specifically designed to prevent.

SeverityCVSS 9.3 Critical
Disclosure162 MITRE CVEs Filed
Affected12+ Chains
StatusActive
Dossier 02 · Authentication Layer

Identity Provider Configuration Drift

Twenty-six confirmed findings across a single authentication codebase. Each was silently corrected upstream without notification to the operators running prior versions in production.

Findings26 Confirmed
DisclosureCVE-2026-37171 + 150 Filed
SurfaceSaaS · Self-Hosted
StatusEmbargoed
Dossier 03 · Secrets Management

Defense Bypass in Secrets Platform

A previously patched defense contains a timing gap that allows the mitigation to be bypassed entirely. The vendor believed the issue was resolved. It was not.

ClassDefense Bypass
DisclosureMITRE Direct
SurfaceProduction
StatusFiled
Dossier 04 · Observability Platform

Privilege Boundary Exposure

An exposed internal interface leaks the privilege boundaries of the platform, enabling an attacker to map the path from low-privilege account to administrative control of monitored infrastructure.

ClassPrivEsc · Disclosure
DisclosureCoordinated
SurfaceOSS · Hosted
StatusPublic
Who We Serve

Built for the people with authority to act.

For Maintainers

Your dependencies have secrets.

The libraries you ship contain silently patched vulnerabilities that were never publicly disclosed. Your users inherit the exposure. You inherit the liability.

Priced on TVL · From 1 basis point
For Attestors

Your audit passed. The exploit still happened.

70% of 2024 crypto exploits hit contracts with a clean prior audit. Not because the audit was wrong — because the vulnerability didn’t exist in any public database.

Priced on annual billings · From 50 basis points
For Founders

You raised the round. Now secure what it built.

Investor-ready risk reporting built on upstream patch intelligence that doesn’t exist in any public database. Know what your stack is hiding before your next audit does.

Priced on last round · From 2 basis points
For Investors

Your diligence is incomplete.

The protocol’s audit is clean. Their public CVE count is zero. Their upstream dependency chain has 47 undisclosed fixes. Your thesis doesn’t account for what isn’t public.

Priced on crypto AUM · From 2 basis points
For Underwriters

Your models are missing half the data.

DeFi insurance premiums priced against incomplete risk databases. Protocols are financially rewarded for hiding vulnerabilities from you. We close the gap.

Priced on coverage volume · From 3 basis points
For Regulators

Full dataset. Unrestricted.

Securities regulators and financial supervisory authorities receive unrestricted access to the silent patch intelligence feed. Market transparency should not be gated from the people responsible for it.

Supervisory bodies · Unrestricted access
The Method · Three Phases

From deceptive remediation to enforcement.

The work moves in three phases. Each produces an artifact the next phase depends on. Each is operational across every engagement we take.

Phase I01 / 03

Detect.

We find what vendors chose to bury.

ScopeCross-Ecosystem
CadenceContinuous
OutputEvidence Chain

Proprietary tooling monitors nine ecosystems for security patches that were never disclosed. When a vendor fixes a vulnerability and tells no one, we know.

When the evidence is reproducible and material, we have a case.

The Instrumentation

Continuous monitoring of the projects whose silent failures would compound furthest downstream.

Phase II02 / 03

Translate.

One finding, two artifacts, three voices.

AudienceRegulators
FormatDual-Track
StandardCourt-Ready

A vulnerability report written for engineers does not move a securities regulator. A summary written for a regulator does not survive defense counsel. Both need to exist, in lockstep.

The technical brief carries the proof. The regulatory brief carries the consequence.

The Deliverable

Everything the receiving body needs to act on the day they open it.

Phase III03 / 03

Escalate.

From vendor inbox to subpoena power.

PathRegulatory
SupportEnd To End
OutcomeEnforcement

Most disclosure programs end at the email. The vendor patches quietly and the public record stays silent. We break the pattern by moving the destination.

We route findings to the body whose mandate is implicated, in its working language.

The Engagement

We stay through clarifying questions, supplementary filings, and where appropriate, testimony.

Whitenbaker Labs

The arsenal.

Four instruments built for the work no off-the-shelf platform was designed to do. Each is in active use across current engagements.

WB-01 · DetectionOperational

Ghost Patch Scanner

Identifies security fixes that vendors buried without disclosure. Operates continuously across nine ecosystems. The output is a list of vulnerabilities your infrastructure inherited without your knowledge.

ContinuousAcross 9 Ecosystems
WB-02 · MappingOperational

Cascade Engine

Quantifies downstream exposure when an upstream vendor silently patches. Produces a precise map of who is vulnerable, to what, and for how long. The output is the enforcement case, ready for regulators.

Propagation50+ Networks Tracked
WB-03 · Active DefenseOperational

Hydra Deception Platform

Active defense infrastructure that responds to intrusion in real time. Built for operators who have outgrown passive monitoring and need adaptive tradecraft in production environments.

ReactiveAdaptive Tradecraft
WB-04 · EnforcementOperational

Regulatory Filing Pipeline

End-to-end workflow from vulnerability discovery to regulatory submission. Identifies jurisdiction, prepares filings in the receiving body’s working language, and tracks enforcement outcomes through to resolution.

End To EndMulti-Jurisdiction
Engage

If you have authority, we have the evidence.

Initial consultation free. All pricing published. No sales theater.

drew@whitenbaker.com