For banks, exchanges, custodians, and protocol teams

Security for digital assets and financial infrastructure.

You work directly with a principal who helps define the scope, brings in the right specialists, and stays involved through delivery.

$30B+volume secured
200+audits across the team
13published cryptography papers

Client feedback

What clients say about the work.

“Timur is one of the most competent auditors, specialising in Rust-based smart contract environments. He has assisted several teams in the NEAR ecosystem over the past few years and it’s been a pleasure seeing him work with teams across many stages and domains.”
@chronear VP of Growth, NEAR Foundation
“We have been working with Timur Güvenkaya for years. One of the most qualified teams in space. If you're in crypto, your top priority should be making sure nobody looses money. Security is your job. If you want to do it well, you might want to reach out to Guvenkaya.”
Alex Shevchenko Co-founder and CEO @ Aurora Labs and NEAR Intents
“We worked with a few known security ‘brands’ in the past. Timur Güvenkaya and his team are different. They understand that security is a continuous process rather than a one-off contract audit. They think about a wider perimeter and work in an extremely agile fashion. Most of our work now goes to them.”
Oleg Fomenko Co-Founder and CEO at Sweat Economy
“Guvenkaya are The Auditors. Deep expertise in Rust and smart contracts combined with a hands-on, iterative approach makes them a go-to partner for serious projects. They don’t just look for bugs. They help to build robust systems from the ground up. We’ve trusted them with multiple audits across different stages and continue to rely on their judgment and precision.”
Arseny Mitin Protocol Tech Lead, Aurora, NEAR Protocol

The team

Meet the team.

Explore the team’s public profiles, experience, and published work.

Timur Güvenkaya portrait

Timur Güvenkaya

Founder & Partner

Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.

Timur Güvenkaya portrait

Timur Güvenkaya

Founder & Partner

Timur founded Guvenkaya after seeing teams reduce security to code review while their real risk spans architecture, infrastructure, operations, custody, and launch decisions. Before Guvenkaya, he established and led a security engineering practice for complex blockchain systems, specializing in Rust-based and non-EVM ecosystems including Substrate and NEAR. Earlier at Invicti, he helped build enterprise vulnerability-scanning and security detection engines used by Fortune 50 companies and public-sector organizations.
LinkedIn
Müjde Nur Asgarli Güvenkaya portrait

Müjde Nur Asgarli Güvenkaya

Growth & Marketing Partner

Leads growth through performance marketing, data-led strategy, and audience planning. Her agency work spans healthcare and e-commerce brands across multiple markets.

Müjde Nur Asgarli Güvenkaya portrait

Müjde Nur Asgarli Güvenkaya

Growth & Marketing Partner

Müjde leads growth and marketing, bringing hands-on agency experience in performance marketing, data-led strategy, and audience-specific campaign planning. On the agency side she has worked with major brands across healthcare, e-commerce, and other sectors, translating business goals into focused growth strategies for different markets and audiences. She holds a Bachelor's degree in International Affairs and a Master's in Business Administration.
LinkedIn
Piotr Cielas portrait

Piotr Cielas

Principal Advisor

Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.

Piotr Cielas portrait

Piotr Cielas

Principal Advisor

Piotr is Head of Security at Agora, where he oversees information security, data protection, and corporate IT risk management. He brings both industry and consulting experience, having led information security advisory engagements and security program development for global financial institutions and large organizations. Earlier in his career, Piotr was a Senior Cybersecurity Consultant at Ernst & Young (EY), leading security assessments across financial services, healthcare, and government. He holds CEH, OSCP, and OSWE certifications, has contributed to the CVE program, and is the inventor of multiple U.S. patents related to information security and blockchain technology.
LinkedIn
Paul Vijender portrait

Paul Vijender

Specialist Advisor

Head of Security at Gauntlet, with experience in product security, IAM, cloud, DevSecOps, and blockchain. Previously held security roles at Tensor, EY, Broadcom, and ADP.

Paul Vijender portrait

Paul Vijender

Specialist Advisor

Paul is Head of Security at Gauntlet, a hands-on security leader experienced in building and operating security teams for digital asset systems. His experience spans product security, identity and access management, cloud and network security, data loss prevention, DevSecOps, blockchain security, and compliance. He has advised and delivered engagements for Fortune 500 firms, big-tech companies, and frontier-technology startups across crypto and AI. Earlier he was Head of Security at Tensor and a Senior Cybersecurity Manager at EY, and held security roles at Broadcom and ADP. He holds the CISM certification.
LinkedIn
Michal Bajor portrait

Michal Bajor

Specialist Advisor

Security specialist with 60+ Web3 reviews across DeFi, L1s, bridges, oracles, and other critical infrastructure. At Kraken, worked on the security of funding services, custody, APIs, and on-chain systems.

Michal Bajor portrait

Michal Bajor

Specialist Advisor

Michal is a security expert with a Master's in ICT, three published research papers, and active academic research in blockchain technology. He has reviewed 60+ Web3 projects across DeFi, L1 systems, bridges, oracles, and other critical ecosystem components. At Kraken, he was responsible for security across crypto and fiat funding services, custody, B2B APIs, on-chain monitoring, smart-contract risk, and architectural and compliance reviews. Earlier at EY, he conducted web application penetration tests, participated in red-team activities, and worked across defensive security responsibilities; at Cisco, he supported Security Advisory penetration-testing work and internal cybersecurity training.
LinkedIn
Manuel B. Santos portrait

Manuel B. Santos

Specialist Advisor

Cryptography engineer with a Ph.D. in Information Security and 13 published research articles. Worked on post-quantum cryptography at Tectonic and on MPC and zkTLS at Nillion, where he contributed to Nada and wrote technical reports on threshold ECDSA.

Manuel B. Santos portrait

Manuel B. Santos

Specialist Advisor

Manuel is a cryptography engineer doing applied research in post-quantum cryptography, secure multiparty computation, and zkTLS. He holds a Ph.D. in Information Security from Instituto Superior Técnico, University of Lisbon, and an M.Sc. in Applied Mathematics from Imperial College London, with 13 published research articles across quantum oblivious transfer, privacy-preserving computation, and post-quantum blockchain design. He worked on post-quantum cryptography at Tectonic and on MPC and zkTLS at Nillion, where he contributed to Nada, a language for secure multiparty computation, and authored technical reports on threshold ECDSA. Earlier he was a Quantum Cryptography Researcher at Tekever.
LinkedIn
Georgii Plotnikov portrait

Georgii Plotnikov

Specialist Advisor

CEO at Inferara and designer of Inference, a language that combines executable code with formal specifications. Leads its Rust compiler development and previously built Code Inspector and security analysis tools at OpenZeppelin.

Georgii Plotnikov portrait

Georgii Plotnikov

Specialist Advisor

Georgii is CEO at Inferara and the designer of Inference, a statically typed, high-assurance language built so executable programs and formal specifications can live in the same source. The language uses a deterministic, WebAssembly-aligned execution model with verification-only specification blocks. He led the Rust implementation of the infc compiler, which produces optimized WebAssembly for execution and Rocq theorem obligations for formal verification. He also leads development of a Stellar smart-contract decompiler. Previously, as Lead Security Tooling Developer at OpenZeppelin, he designed and implemented the foundation of Code Inspector, the Defender code-analysis module, shipping GitHub-integrated analysis that grew beyond 130 static-analysis rules. His work spans reentrancy and unsafe-call detection, vulnerable-dependency and standards checks, contract fingerprinting, fuzz-target identification, and LLM-driven vulnerability analysis, with static-analysis tools in Python and Rust for Solidity, Rust-based DSLs, and Midnight Compact.
LinkedIn
Łukasz Mikuła portrait

Łukasz Mikuła

Specialist Advisor

Offensive security specialist with 10+ years of experience, 100+ public audits across 8+ ecosystems, and OSCP, OSCE, eWPT, and eWPTX certifications. At ING and Binance, worked across red teaming, exploit development, infrastructure, and high-scale digital asset systems.

Łukasz Mikuła portrait

Łukasz Mikuła

Specialist Advisor

Łukasz is a security researcher with 10+ years in offensive security and a public portfolio of 100+ audits across 8+ ecosystems. His smart-contract work spans EVM/Solidity, Move, Rust-based ecosystems, CosmWasm, Solana, Substrate, and TON, including assessments for Coinbase, MegaETH, Kyber, Jupiter, Zilliqa, IOTA, and Initia Move. At ING, he worked across web application and infrastructure penetration testing, red-team work, exploit development, reverse engineering, mobile security, adversary simulation, and smart-device testing. At Binance, he worked on security concerns for high-scale digital asset systems. He holds the OSCP, OSCE, eWPT, and eWPTX certifications and has CVE disclosures affecting IBM, Oracle, F5, Dell, and Red Hat.
LinkedIn
José C. Ramírez portrait

José C. Ramírez

Specialist Advisor

Security engineer and trainer with around 10 years of experience across application and protocol security. At ZKsync, reviewed Solidity and Rust code, including account abstraction, then built AI-assisted vulnerability-analysis workflows.

José C. Ramírez portrait

José C. Ramírez

Specialist Advisor

José is a security engineer and technical trainer specializing in smart contract and blockchain security, with around 10 years of experience across offensive security, application security, and security review. At ZKsync, he reviewed code, architecture, and design across Solidity/EVM, account abstraction, protocol-level security, and Rust-based components, later building AI-assisted workflows for vulnerability discovery and protocol security analysis. He has participated in smart contract audits across CosmWasm, EVM, and NEAR and holds OSCP, CREST CRT, AWS Certified Security, and AWS Certified Solutions Architect certifications. José has also delivered university courses, guest lectures, and workshops on blockchain and smart contract security, including at the University of Málaga and with the University of Porto.
LinkedIn

Team credentials

  • OSCP
  • OSCE
  • OSWE
  • CREST Registered Tester (CRT)
  • CISM
  • AWS Certified Security Specialty
  • AWS Certified Solutions Architect Associate
  • eWPT
  • eWPTX

Public work

Read the findings before you hire us.

Full reports with findings, evidence, and remediation status.

NEAR / Defuse Labs

NEAR Intents Security Review

Medium Potential Funds Stealing From Users Via Repeating Failed Intents

  • NEAR
  • Intents
  • Rust
View report

Sweat Economy

SWEAT NEP-141 Token Security Review

High LookupMap adapter can undercharge storage for selected accounts

  • NEAR
  • Smart contract
  • Rust
View report

Spin Finance

Onchain Orderbook and Perpetual Trading Security Review

Critical Order Placement with Negative/Zero Margin Ratio Is Possible

  • NEAR
  • Smart contract
  • Rust
View report

Virto Network

Pallet Pass Security Review

High DoS of The Main Functionality Through Session Key Hijacking

  • Polkadot
  • Substrate
  • Rust
View report
All reports

Our approach

Named before you sign.

Your quote names the principal and specialists assigned to your engagement.

You scope the work with a principal

Your principal defines the scope with you, checks the findings, and stays involved through delivery.

You work with experienced security leaders

Our team brings experience from exchanges, protocols, and security product companies. Our advisors also lead security teams at other companies.

You work with specialists who understand your system

We match your review team to what you are building. For a custody review, your team includes a custody specialist.

How an engagement runs

From quote to ongoing support.

  1. Before work starts

    1. A quote that names your team

      Once the scope is settled, we send a quote with the duration, the commit to be reviewed, and the names and bios of your review team. Every engagement has one principal and as many specialists as the scope needs.

      • Principal leads
    2. Contracts and a shared channel

      You sign a master services agreement and a statement of work. Half the fee is due before the review starts, half when you receive the report. We then open a shared channel on your preferred platform, such as Slack or Telegram, for all communication with the team.

      • Principal leads
    3. Optional
      Kickoff walkthrough

      If the code is complex, we may ask your engineers for a call to walk us through it before the review starts.

      • Specialists lead
      • Principal assists
  2. Day one

    1. Threat model first

      On the first day, the team named in your quote maps attack paths, the invariants your system must hold, and its critical flows.

      • STRIDE
      • NIST SP 800-30
      • Guvenkaya assessment framework
      • Principal leads
      • Specialists assist
  3. During the review

    1. Manual review, backed by AI tooling

      Specialists review the code by hand and run our own AI skills and test harnesses against it. The principal checks findings as they come in.

      • Specialists lead
      • Principal assists
    2. Tests, invariants, and evidence

      As we review, we add security tests and new invariants to your repository and record each check in an evidence bundle, so every finding can be traced back to what we ran.

      • Specialists lead
      • Principal assists
    3. Serious findings, reported early

      We tell you about Critical, High, and Medium issues as soon as we find them, so you can start fixing before the review ends.

      • Specialists lead
      • Principal assists
  4. At delivery

    1. Confidential report

      Specialists write the report, and the principal reviews it before it reaches you. It opens with a plain-language conclusion, then sets out every finding, the order to fix them in, and our assurance opinion on the reviewed commit.

      • Threat model
      • Invariants and flows tested
      • Scope boundaries
      • Evidence appendix
      • Specialists lead
      • Principal assists
    2. Security package

      Everything else goes into your repository. Tests for open findings fail on purpose and pass once the fix is in, so your team can track remediation by running the suite.

      • Security tests
      • Test documentation
      • Markdown copy of the report
      • Remediation skill (optional)
      • Specialists lead
      • Principal assists
  5. After delivery

    1. Remediation and a free retest

      We help you plan and prioritize fixes. When they are in, we retest them at no charge and issue a public report that records each fix and carries the principal's signature. You can share it with your users and partners.

      • Specialists lead
      • Principal assists
    2. Optional
      Next scope or ongoing work

      If the review points to other areas worth checking, we scope the next engagement with you. Teams that want us on hand for longer can move to a retainer or buy a block of days.

      • Penetration testing
      • OpSec review
      • Key management review
      • Infrastructure review
      • Principal leads
    3. Ongoing support

      After the engagement ends, you can keep bringing us your security questions at no charge.*

      • Principal leads
      • Specialists assist

* Within fair use: questions as they come up, not a daily queue.

What you receive

More than a findings report.

A report-only audit ends with a list of findings. Ours also adds security tests to your repository that your team can keep running after the engagement ends.*

Deliverables from a Guvenkaya code security review compared with an engagement limited to a findings report.
Deliverable Guvenkaya Report-only audit
Findings report Yes Yes
Threat model Yes No
Record of flows and security properties tested Yes No
Invariant register Yes No
Evidence appendix What we ran to reach each finding, so your team can check it. Yes No
Security tests in your repo Each test comes with docs on what it covers and how to run it. Yes No
Markdown copy of the report A plain-text version of the report that AI tools can parse. Yes No
Remediation skill for AI agents An optional skill that lets your AI agents recheck findings, verify fixes, and prioritize work. Yes No
Signed public report after retest Records each fix and carries the principal's signature. Yours to share. Yes No

* These deliverables apply to code security reviews. For other engagements, we agree on deliverables when defining the scope.

Services

Start with what you need to secure.

Describe your system or the change you are planning. We'll help define the scope.

Smart Contract Security Reviews

Find flaws in contract logic, permissions, accounting, and upgrades before they put funds at risk.

  • Permissions & accounting
  • Protocol logic
  • Integrations
Explore

Blockchain Protocol & Infrastructure Reviews

Review custom chains, runtimes, nodes, consensus, and bridges beneath the application layer.

  • Custom chains
  • Runtimes & VMs
  • Nodes
  • Consensus
Explore

Penetration Testing

Test the attack paths that connect web, mobile, APIs, cloud, identity, and infrastructure.

  • Web & mobile
  • APIs & backends
  • Cloud
  • Infrastructure
Explore

Signing & Custody Security Reviews

Review key generation, signing approvals, key use, and recovery across MPC, HSM, multisig, and custody platforms.

  • MPC
  • HSM
  • Multisig
  • Key lifecycle
Explore

Secure Code Reviews

Find security flaws in critical code, including authorization, business logic, and state changes.

  • Authorization
  • Business logic
  • State changes
Explore

Secure Architecture & Process Design

Design or assess critical systems, workflows, integrations, and operating controls before implementation or a major change.

  • Trust boundaries
  • System integrations
  • Operating controls
Explore

Not sure which one fits?

Tell us your main concern and we’ll help you choose a starting point.

Discuss your system

Training

Technical training &
security exercises

Choose training on Rust, Substrate, and NEAR, or workshops, tabletop exercises, and key-ceremony rehearsals tailored to your systems.

Discuss training

Tell us what you need to secure.

Describe your system, main concern, and deadline. We'll reply with scoping questions and a proposed next step.

Discuss your scope contact@guvenkaya.co