
NullRabbit is a security research and engineering company that provides an AI-powered, eBPF-enforced security layer for decentralized networks. The platform maps, predicts, and drops hostile peer-to-peer inputs and resource-exhaustion attacks at the kernel level before they cause node failure or availability loss. It combines active internet-wide scanning, live telemetry, and incident response to build autonomous defenses for blockchain and validator infrastructure.
Funding
Funding not disclosed
Founders
Product
Problem
Decentralized networks are vulnerable at the transport layer, where traditional security tools fail to understand libp2p gossip, QUIC handshake floods, or peer-to-peer memory exhaustion. A single malicious packet can take a network node offline, and conventional monitoring or contract audits never see the attack coming.
Solution
NullRabbit provides an AI-powered, eBPF-enforced security layer for decentralized networks that maps, predicts, and drops hostile P2P inputs and resource-exhaustion attacks at the kernel before they cause node failure or availability loss. The platform combines intelligence feeds with kernel-level enforcement, using a four-stage pipeline: map the technique, predict the anomaly, drop the packet, and propagate the countermeasure across the mesh. NullRabbit also operates an active internet scanning programme to identify vulnerabilities in publicly exposed infrastructure, and offers incident response services where operators can send packet captures, crash traces, and validator incident timelines for reproduction and classification.
Target Audience
Primary customers are operators of decentralized network infrastructure, including blockchain validators, node operators, and security teams responsible for maintaining the availability and integrity of P2P networks.
Features
- eBPF-enforced kernel-level packet dropping that blocks hostile inputs before they reach user space
- AI-powered anomaly prediction that maps attack techniques and anticipates resource-exhaustion patterns
- Four-stage defense pipeline: map, predict, drop, and propagate countermeasures across the network mesh
- Non-intrusive internet scanning programme that identifies open ports, service banners, TLS configurations, and protocol-level metadata on publicly exposed infrastructure
- Incident response service that reproduces attack mechanisms from packet captures, crash traces, and validator incident timelines, classifying them in the NRDAX system
- Public scanner IP list and opt-out API for operators to exclude their infrastructure from scanning