Languages & contract stacks
Solidity
Rust
Move
DAML
Cairo
Stylus
CosmWasm
Tact
FunC
Tolk
Vyper
Swayink!
Go
C
C++
TypeScript
JavaScript
Java
Kotlin
C#
Python
We review how contracts move funds, enforce permissions, and handle upgrades and integrations.
Technology coverage
Language support depends on the target chain and contract SDK.
This list is not exhaustive.
Share the target chain, contract language, and the assets or permissions at stake.
What we review
Expected behavior, state transitions, edge cases, invariants, and failure conditions.
Balances, rounding, precision, settlement, fees, rewards, and value conservation.
Authorization, governance, admin paths, initialization, proxies, and upgrade controls.
Cross-contract calls, tokens, callbacks, price feeds, and dependency failures.
Incentive failures, front-running, MEV, manipulation, griefing, and insolvency.
Configuration, privileged actions, recovery paths, monitoring, and release controls.
Timing
When code, tests, and expected behavior are stable enough for focused review.
When changed state, permissions, accounting, or integrations could invalidate earlier assurance.
Review how a new bridge, oracle, or counterparty changes the system’s trust assumptions.
When the system needs independent review of the failure path and remediation.
Our approach
Agree the scope and target commit. Map assets, roles, trust boundaries, and the ways an attacker could reach them.
Follow how funds and permissions move through the contracts. Document the security properties each flow must preserve.
Examine attack paths through manual review and targeted testing. Add security tests to your repo so your team can rerun them.
We always verify fixes through retesting, record unresolved findings, and tie the principal’s signed opinion to the reviewed commit and supporting evidence.
What you receive
Findings ranked by impact and likelihood, with affected code, evidence, and remediation guidance.
Actors, trust boundaries, and attack scenarios, including those blocked by existing controls.
Contract flows showing how funds and permissions move, with the security properties each flow must preserve.
Each security property, its test result, and the evidence your team can use to check future changes.
Regression tests alongside the code, so your engineers can verify fixes and check future changes.
The principal’s conclusions, tied to the reviewed commit, scope, and evidence.
Your review team
A principal leads each engagement. Your proposal names the specialists assigned to the scope.
Founder & Partner
Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.
Specialist Advisor
Offensive security specialist with 10+ years of experience, 100+ public audits across 8+ ecosystems, and OSCP, OSCE, eWPT, and eWPTX certifications. At ING and Binance, worked across red teaming, exploit development, infrastructure, and high-scale digital asset systems.
Specialist Advisor
Security engineer and trainer with around 10 years of experience across application and protocol security. At ZKsync, reviewed Solidity and Rust code, including account abstraction, then built AI-assisted vulnerability-analysis workflows.
Published reports
Each report includes the full findings and severity ratings.
SWEAT NEP-141 Token Security Review
High LookupMap adapter can undercharge storage for selected accounts
Onchain Orderbook and Perpetual Trading Security Review
Critical Order Placement with Negative/Zero Margin Ratio Is Possible
NEAR Intents Security Review
Medium Potential Funds Stealing From Users Via Repeating Failed Intents
FAQ
To scope the review, we need access to the contract code alongside its purpose, target commit, planned launch date, and your main concerns. Documentation, tests, and details of integrations help us define the scope and estimate the effort.
We review Solidity, Rust, Move, DAML, Cairo, Stylus, CosmWasm, Tact, FunC, Tolk, Vyper, Sway, ink!, and other smart-contract stacks across EVM chains, NEAR, Solana, Sui, Aptos, Canton, Polkadot, Cosmos, and TON.
The review is most efficient when critical behavior, documentation, tests, and the target commit are stable. Design questions can be reviewed earlier.
Yes, when the surrounding system and inherited assumptions can be understood.
Yes. We always provide remediation guidance and verify fixes through retesting. The final report distinguishes fixed, partially fixed, accepted, and unresolved findings.
Code size is one factor. Contract complexity, integrations, documentation, and the testing needed to check the system’s behavior also affect the effort. Fix verification and retesting are always included. The proposal defines the review scope and retesting schedule.
Describe your contracts, planned changes, and launch date. We will propose a review scope.
Discuss your scope