What we audit
We secure protocol code, infrastructure, and ecosystem integrations across the chains and platforms where risk moves fastest.
We’ve worked extensively with the Solana Foundation on auditing the Solana Core code, along with Account Compression.
Our experience doesn’t end there: we’ve taken this deep knowledge and applied it to our audits on a number of well-known protocols building within the ecosystem, including Marginfi, Parcl, Jupiter, Mayan, Jito, Ellipsis Phoenix, Raydium, Tensor, Squads, Kamino, GooseFX, Pyth, and more.
We offer white-box and black-box testing based on each project’s needs. Our research examines the large, underexplored Web2 attack surfaces that remain in many Web3 applications. Read the analysis.
We’ve also done extensive research into MetaMask’s Snaps sandboxing environment. You can learn more about this research and other work we’ve done on our blog.
We’ve built out our own tooling, and developed a novel verification framework for Solana. We’ve also worked with the Aptos core team to formally verify their standard library.
Fuzzing is one of our core disciplines. Our work includes:
- Differential compiler fuzzers for Vyper
- Novel differential transactional fuzzers for Solana validators (leading to multiple critical denial of service findings)
- rBPF JIT fuzzers (resulting in multiple denial of service and integrity issues)
- Move VM bytecode fuzzers (resulting in over half a dozen crashes)
How we audit
Different systems call for different techniques. We pick the mix that fits yours.
Our auditing process
We keep the work focused and the communication clear, from the first scoping call to the final report.
Get secured now.
We work with leading teams across multiple blockchains. Put the same collaborative approach to work on your protocol.
Get secured now