Languages & contract stacks
- Solidity
- Rust
- Move
- DAML
- Cairo
- Stylus
- CosmWasm
- Tact
- FunC
- Tolk
- Vyper
- Sway
- ink!
SMART CONTRACT SECURITY REVIEWS
Manual, threat-led reviews of smart contracts and on-chain systems. We examine business logic, permissions, accounting, integrations, economics, and upgrade paths against the ways the system can actually fail.
Technology coverage
From established smart-contract stacks to emerging runtimes, we review the technology your protocol is built on.
Don’t see your stack?
This list is representative, not exhaustive.
Review surface
Timing
When code, tests, and expected behavior are stable enough for focused review.
When changed state, permissions, accounting, or integrations could invalidate earlier assurance.
When a bridge, oracle, token, custody flow, exchange, or protocol changes the trust model.
When the system needs independent review of the failure path and remediation.
Process
Confirm repositories, commits, deployment targets, architecture, roles, critical flows, and expected behavior.
Identify assets, actors, privileged paths, dependencies, and conditions that must always hold.
Perform manual analysis and targeted testing appropriate to the codebase and risk.
Work through findings and verify agreed in-scope fixes before final status.
Outputs / What you receive
Severity, impact, affected paths, evidence, and practical remediation guidance.
How a weakness can be reached and what an attacker or faulty state could achieve.
Scope, system context, methodology, findings, limitations, and final status.
Where agreed in scope, re-review of fixes and updated finding status.
Typical engagement team
The exact team depends on the scope. Every engagement has a principal who owns it from scoping through delivery, joined by the specialists the system calls for, and whoever is assigned is named in your proposal.

Founder & Partner
Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.

Specialist Advisor
Offensive security specialist with 10+ years and 100+ public audits across eight ecosystems. At ING and Binance, worked across red teaming, exploit development, infrastructure, and high-scale digital asset systems.

Specialist Advisor
Security engineer and trainer with around 10 years across application and protocol security. At ZKsync, reviewed Solidity, account abstraction, and Rust, then built AI-assisted vulnerability-analysis workflows.
Inspectable proof
Each card shows one highlighted finding, not the full result. Open the report for every finding and its severity.
SWEAT NEP-141 Token Security Review
LookupMap adapter can undercharge storage for selected accounts
Onchain Orderbook and Perpetual Trading Security Review
Order Placement with Negative/Zero Margin Ratio Is Possible
Pallet Pass Security Review
DoS of The Main Functionality Through Session Key Hijacking
FAQ
Yes. Buyers often use audit and security review for the same category. We use review to make clear that the work considers behavior, architecture, integrations, and operations as well as source code.
We review Solidity, Rust, Move, DAML, Cairo, Stylus, CosmWasm, Tact, FunC, Tolk, Vyper, Sway, ink!, and other smart-contract stacks across EVM chains, NEAR, Solana, Sui, Aptos, Canton, Polkadot, Cosmos, and TON.
The review is most efficient when critical behavior, documentation, tests, and the target commit are stable. Design questions can be reviewed earlier.
Yes, when the surrounding system and inherited assumptions can be understood.
We include a remediation check where agreed in scope and distinguish fixed, partially fixed, accepted, and unresolved findings.
Related services
Next step
Share the repository, target commit, architecture, documentation, launch date, and known risk areas. We will propose a focused review scope.
Discuss your scope