Systems languages
- Rust
- C
- C++
- Zig
BLOCKCHAIN PROTOCOL & INFRASTRUCTURE SECURITY REVIEWS
Security reviews for custom chains, rollup stacks, runtimes, virtual machines, node clients, consensus, validator logic, bridges, and the infrastructure around them.
Technology coverage
From established protocol SDKs and rollup frameworks to custom chains, we review the code and architecture beneath the application layer.
Don’t see your stack?
This list is representative, not exhaustive.
Review surface
Timing
Challenge the threat model while core safety and liveness choices can change.
Before testnet, mainnet, or a major protocol release.
Before a runtime module, bridge, consensus change, or critical integration.
For an upgrade, migration, incident review, or ongoing assurance program.
Process
Identify actors, assets, safety and liveness properties, deployment assumptions, and inherited components.
Trace validation, transitions, privileges, upgrades, and cross-boundary dependencies.
Analyze implementation, configuration, and attack paths at the layers in scope.
Work through findings and provide technical and decision-level outputs for the launch or change.
Outputs / What you receive
A summary of actors, trust boundaries, state, messages, and inherited assumptions.
Safety, liveness, integrity, or operational impact with exploit or failure scenarios.
Practical changes and verification status where agreed in scope.
Where required, an executive view for launch, governance, or risk decisions.
Typical engagement team
The exact team depends on the scope. Every engagement has a principal who owns it from scoping through delivery, joined by the specialists the system calls for, and whoever is assigned is named in your proposal.

Founder & Partner
Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.

Specialist Advisor
Secured funding, custody, APIs, and on-chain systems at Kraken. Has reviewed 60+ Web3 projects across DeFi, L1s, bridges, oracles, and other critical infrastructure.

Principal Advisor
Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.
Currently
Head of Security, Agora
$45B+ in volume
Inspectable proof
Each card shows one highlighted finding, not the full result. Open the report for every finding and its severity.
Pallet Pass Security Review
DoS of The Main Functionality Through Session Key Hijacking
NEAR Intents Security Review
Potential Funds Stealing From Users Via Repeating Failed Intents
Relaychain and Matrixchain Security Review
DoS of Fuel Tank Mutation
Claims Pallet Security Review
DoS of Claiming Functionality
FAQ
Yes. Scope can include custom Layer 1, Layer 2, rollup, and appchain architecture; runtime and VM logic; node and client code; consensus; networking; validator operations; upgrades; and integrations.
Yes. Public work and team experience include Substrate and Rust-based systems.
Yes. Bridge security often spans contracts, verification, relayers, validators, oracles, services, key management, and operations.
A smart contract review focuses on application-level logic. A blockchain systems review reaches into the chain, runtime, virtual machine, node, consensus, networking, and operational layers.
Related services
Next step
Share the architecture, codebase, threat model, release stage, and the safety or liveness decisions the review must support.
Discuss your scope