Security Audit

Evidence for code that holds value.

Manual review, AI-assisted analysis, adversarial testing, and formal verification for critical Web3 systems.

We follow every path where value or authority can move.

A secure language removes entire bug classes. It does not replace adversarial review of custom business logic.

Access and capabilities

Privileged paths, capability ownership, visibility, and every function that can change protected state.

Asset lifecycle

Creation, transfer, wrapping, destruction, recovery, and the invariants that must survive each transition.

Economic logic

Pricing, accounting, rounding, incentives, and adversarial transaction sequences against the intended model.

Integrations and upgrades

Trust boundaries across packages, oracles, dependencies, migration paths, and operational controls.

AI-assisted analysis

Targeted agents help reviewers trace complex call paths and test more hypotheses without replacing human judgment.

Formal verification

Critical properties are specified precisely and proved against the implementation for suitable engagements.

Findings, written out in full.

Incident analysis

0 writeups

Incident writeups are being prepared.

A review built for remediation.

  1. 01

    Model the system

    Map actors, assets, trust boundaries, invariants, and the exact commit included in scope.

  2. 02

    Break the assumptions

    Probe authorization, state transitions, and economic edge cases with manual review, targeted tests, and formal methods.

  3. 03

    Report with evidence

    Record impact, affected code, a reproducible path, severity rationale, and a practical fix for every finding.

  4. 04

    Verify the fix

    Review the remediation commit and mark each finding as resolved, acknowledged, or still open.

Put an adversarial reviewer on the critical path.

Send the repository, target commit, documentation, and expected launch window. We will reply with scope and availability.

Request an audit