Broken invariants
The properties the protocol assumes always hold. We write them down, then try to violate them.
Service
Manual, line-by-line review of smart contract systems across multiple chains. Senior Auditors in each engagement, AI detectors, available fuzzing and formal verification services, as well as continuous support.
Making sure the protocol is safe, checking every possible scenario.
The properties the protocol assumes always hold. We write them down, then try to violate them.
Rounding that favours the caller, fees applied on the wrong side of a division, share inflation on an empty vault.
Roles that can be escalated, initializers left callable, upgrade paths that hand an admin more authority than intended.
Spot prices read from pools that can be moved inside one transaction, stale feeds with no freshness check.
Reexecuting same operation before it ends, read-only reentrancy checking, cross blockchain compitability check.
Reviewing Flows that are individually correct but jointly exploitable like donation attacks, first-depositor advantage.
Six stages from the first read and understanding of the project, ending with a final detailed report about the engagement.
We read the codebase, its architecture, the docs, and any previous reports before quoting. You get confirmation of what is in scope, the fixed price, the duration, and the number of researchers who will be on it.
A first pass over the critical paths to surface the obvious issues early, supported by our own AI detectors. This is a preparation before starting the deep manual review.
The engaged researchers work through the codebase, checking it line by line, checking the implementation against what the documentation provides, and testing whether any stated invariant can be broken, a possible loss of funds, fraud attack, DoS, greifying, etc...
Where the engagement calls for it, researchers who specialise in it build a fuzzing suite and formal verification implement the setup and run the invariants against it.
You implement the fix for each issue, we review each one. Not only that the original issue is solved, but that the fix has not opened a new issue somewhere else.
The channel stays open after the report is delivered. Questions, changes, or a second opinion before you deploy.
All EVM Chains as well as Non-EVM chains like Solana and SUI.
Send the repo, the spec, or a paragraph describing the system. We reply with scope, timeline, and a fixed price.