Before a mainnet launch or upgrade
Review once behaviour is stable enough to test, while changes are still cheap.
Solutions · Protocols & Networks
We review contracts, runtimes, consensus, and bridges across EVM and non-EVM systems, and publish the results.
When this fits
Review once behaviour is stable enough to test, while changes are still cheap.
A new dependency moves your trust boundary whether or not anyone redrew it.
Reconstruct the failure path and establish what else shares its shape.
Arrive with findings already resolved rather than discovered by someone else.
Where it breaks
A contract bug moves funds immediately. A runtime bug is inherited by every contract above it. Matching the review to the layer is most of the work.
Every layer fails differently. The review has to match the layer.
Permissions, state transitions, accounting, upgrade paths, and economic assumptions.
Virtual machines, gas and resource metering, host functions, and node client behaviour.
Validator incentives, safety and liveness, reorg handling, and upgrade coordination.
Message verification, relayer assumptions, replay, and what a compromised chain can claim.
Published work
Highlighted findings from published reports, not the reports themselves. Each card opens the full report it came from, where every finding and its severity is listed.
Recommended starting engagements
Start here for contract logic, permissions, accounting, and upgrades. Most of our published reports are this work.
Explore service → Also relevantUse this when the risk is beneath the application layer, in runtimes, consensus, nodes, or bridges.
Explore service → Also relevantUse this for the off-chain code around the protocol: indexers, relayers, backends, and clients.
Explore service →Typical engagement team
The people who usually take protocol work, picked for the ecosystems involved rather than who happens to be free.
The exact team depends on the scope. Every engagement has a principal who owns it from scoping through delivery, joined by the specialists the system calls for, and whoever is assigned is named in your proposal.

Specialist Advisor
Secured funding, custody, APIs, and on-chain systems at Kraken. Has reviewed 60+ Web3 projects across DeFi, L1s, bridges, oracles, and other critical infrastructure.

Specialist Advisor
Offensive security specialist with 10+ years and 100+ public audits across eight ecosystems. At ING and Binance, worked across red teaming, exploit development, infrastructure, and high-scale digital asset systems.

Specialist Advisor
Security engineer and trainer with around 10 years across application and protocol security. At ZKsync, reviewed Solidity, account abstraction, and Rust, then built AI-assisted vulnerability-analysis workflows.

Principal Advisor
Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.
Currently
Head of Security, Agora
$45B+ in volume
Other organizations we work with
Share the repository, target commit, architecture, and launch date. We will reply with the next questions and a likely scope. If a review is not the right next step, we will say so.
Discuss your scope