Infrastructures
Blockchain infrastructure, node and validator setups, SDKs, and Layer 1 systems.
Service
Simulated real-world attacks against web applications, APIs, blockchain infrastructures, SDKs, and web3 off-chain components.
Different software requires different methods. We cover the following systems.
Blockchain infrastructure, node and validator setups, SDKs, and Layer 1 systems.
The off-chain half of an on-chain system: wallets, bridge SDKs, and key management services.
Web and mobile applications, checking DoS attacks, broken authorization, phishing surface.
Four stages from the first read and understanding of the project, ending with a final detailed report about the engagement.
We read the codebase, its architecture, the docs, and any previous reports before quoting. You get confirmation of what is in scope, the fixed price, the duration, and the number of researchers who will be on it.
Automated and AI-assisted scanners map the system: every flow, every entry point, and any already-known issue in the stack you depend on are getting caught at this stage.
Researchers work through the codebase and attack it with different attack surface including denial of service, broken authorization, data exfiltration by simulating a real adversary.
You implement the fix for each issue, we review each one. Not only that the original issue is solved, but that the fix has not opened a new issue somewhere else.
Send the repo, the spec, or a paragraph describing the system. We reply with scope, timeline, and a fixed price.