SanadSquad

Service

Blockchain security audits

Manual, line-by-line review of smart contract systems across multiple chains. Senior Auditors in each engagement, AI detectors, available fuzzing and formal verification services, as well as continuous support.

What we are looking for

Making sure the protocol is safe, checking every possible scenario.

Broken invariants

The properties the protocol assumes always hold. We write them down, then try to violate them.

Accounting and rounding

Rounding that favours the caller, fees applied on the wrong side of a division, share inflation on an empty vault.

Access control and privilege

Roles that can be escalated, initializers left callable, upgrade paths that hand an admin more authority than intended.

Oracle and price manipulation

Spot prices read from pools that can be moved inside one transaction, stale feeds with no freshness check.

Cross-contract and reentrancy

Reexecuting same operation before it ends, read-only reentrancy checking, cross blockchain compitability check.

Economic and incentive design

Reviewing Flows that are individually correct but jointly exploitable like donation attacks, first-depositor advantage.

How an engagement runs

Six stages from the first read and understanding of the project, ending with a final detailed report about the engagement.

  1. Scoping

    We read the codebase, its architecture, the docs, and any previous reports before quoting. You get confirmation of what is in scope, the fixed price, the duration, and the number of researchers who will be on it.

  2. Pre-audit

    A first pass over the critical paths to surface the obvious issues early, supported by our own AI detectors. This is a preparation before starting the deep manual review.

  3. Security audit

    The engaged researchers work through the codebase, checking it line by line, checking the implementation against what the documentation provides, and testing whether any stated invariant can be broken, a possible loss of funds, fraud attack, DoS, greifying, etc...

  4. Fuzzing and formal verificationPremium

    Where the engagement calls for it, researchers who specialise in it build a fuzzing suite and formal verification implement the setup and run the invariants against it.

  5. Mitigation review

    You implement the fix for each issue, we review each one. Not only that the original issue is solved, but that the fix has not opened a new issue somewhere else.

  6. Continuous support

    The channel stays open after the report is delivered. Questions, changes, or a second opinion before you deploy.

Supported Blockchains

All EVM Chains as well as Non-EVM chains like Solana and SUI.

  • Ethereum
  • Solana
  • Polygon
  • Arbitrum
  • Avalanche
  • BNB Chain
  • Monad
  • SUI

Tell us what you are building.

Send the repo, the spec, or a paragraph describing the system. We reply with scope, timeline, and a fixed price.