For banks, exchanges, custodians, and protocol teams

Security for digital assets and financial infrastructure.

You work directly with a principal who helps define the scope, brings in the right specialists, and stays involved through delivery.

$30B+volume secured
200+audits across the team
13published cryptography papers

Client feedback

What clients say about the work.

“Timur is one of the most competent auditors, specialising in Rust-based smart contract environments. He has assisted several teams in the NEAR ecosystem over the past few years and it’s been a pleasure seeing him work with teams across many stages and domains.”
@chronear VP of Growth, NEAR Foundation
“We worked with a few known security ‘brands’ in the past. Timur Güvenkaya and his team are different. They understand that security is a continuous process rather than a one-off contract audit. They think about a wider perimeter and work in an extremely agile fashion. Most of our work now goes to them.”
Oleg Fomenko Co-Founder and CEO at Sweat Economy
“Guvenkaya are The Auditors. Deep expertise in Rust and smart contracts combined with a hands-on, iterative approach makes them a go-to partner for serious projects. They don’t just look for bugs. They help to build robust systems from the ground up. We’ve trusted them with multiple audits across different stages and continue to rely on their judgment and precision.”
Arseny Mitin Protocol Tech Lead, Aurora, NEAR Protocol

The team

Meet the team.

Explore the team’s public profiles, experience, and published work.

Timur Güvenkaya portrait

Timur Güvenkaya

Founder & Partner

Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.

Timur Güvenkaya portrait

Timur Güvenkaya

Founder & Partner

Timur founded Guvenkaya after seeing teams reduce security to code review while their real risk spans architecture, infrastructure, operations, custody, and launch decisions. Before Guvenkaya, he established and led a security engineering practice for complex blockchain systems, specializing in Rust-based and non-EVM ecosystems including Substrate and NEAR. Earlier at Invicti, he helped build enterprise vulnerability-scanning and security detection engines used by Fortune 50 companies and public-sector organizations.
LinkedIn
Müjde Nur Asgarli Güvenkaya portrait

Müjde Nur Asgarli Güvenkaya

Growth & Marketing Partner

Leads growth through performance marketing, data-led strategy, and audience planning. Her agency work spans healthcare and e-commerce brands across multiple markets.

Müjde Nur Asgarli Güvenkaya portrait

Müjde Nur Asgarli Güvenkaya

Growth & Marketing Partner

Müjde leads growth and marketing, bringing hands-on agency experience in performance marketing, data-led strategy, and audience-specific campaign planning. On the agency side she has worked with major brands across healthcare, e-commerce, and other sectors, translating business goals into focused growth strategies for different markets and audiences. She holds a Bachelor's degree in International Affairs and a Master's in Business Administration.
LinkedIn
Piotr Cielas portrait

Piotr Cielas

Principal Advisor

Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.

Piotr Cielas portrait

Piotr Cielas

Principal Advisor

Piotr is Head of Security at Agora, where he oversees information security, data protection, and corporate IT risk management. He brings both industry and consulting experience, having led information security advisory engagements and security program development for global financial institutions and large organizations. Earlier in his career, Piotr was a Senior Cybersecurity Consultant at Ernst & Young (EY), leading security assessments across financial services, healthcare, and government. He holds CEH, OSCP, and OSWE certifications, has contributed to the CVE program, and is the inventor of multiple U.S. patents related to information security and blockchain technology.
LinkedIn
Paul Vijender portrait

Paul Vijender

Specialist Advisor

Head of Security at Gauntlet, with experience in product security, IAM, cloud, DevSecOps, and blockchain. Previously held security roles at Tensor, EY, Broadcom, and ADP.

Paul Vijender portrait

Paul Vijender

Specialist Advisor

Paul is Head of Security at Gauntlet, a hands-on security leader experienced in building and operating security teams for digital asset systems. His experience spans product security, identity and access management, cloud and network security, data loss prevention, DevSecOps, blockchain security, and compliance. He has advised and delivered engagements for Fortune 500 firms, big-tech companies, and frontier-technology startups across crypto and AI. Earlier he was Head of Security at Tensor and a Senior Cybersecurity Manager at EY, and held security roles at Broadcom and ADP. He holds the CISM certification.
LinkedIn
Michal Bajor portrait

Michal Bajor

Specialist Advisor

Security specialist with 60+ Web3 reviews across DeFi, L1s, bridges, oracles, and other critical infrastructure. At Kraken, worked on the security of funding services, custody, APIs, and on-chain systems.

Michal Bajor portrait

Michal Bajor

Specialist Advisor

Michal is a security expert with a Master's in ICT, three published research papers, and active academic research in blockchain technology. He has reviewed 60+ Web3 projects across DeFi, L1 systems, bridges, oracles, and other critical ecosystem components. At Kraken, he was responsible for security across crypto and fiat funding services, custody, B2B APIs, on-chain monitoring, smart-contract risk, and architectural and compliance reviews. Earlier at EY, he conducted web application penetration tests, participated in red-team activities, and worked across defensive security responsibilities; at Cisco, he supported Security Advisory penetration-testing work and internal cybersecurity training.
LinkedIn
Manuel B. Santos portrait

Manuel B. Santos

Specialist Advisor

Cryptography engineer with a Ph.D. in Information Security and 13 published research articles. Worked on post-quantum cryptography at Tectonic and on MPC and zkTLS at Nillion, where he contributed to Nada and wrote technical reports on threshold ECDSA.

Manuel B. Santos portrait

Manuel B. Santos

Specialist Advisor

Manuel is a cryptography engineer doing applied research in post-quantum cryptography, secure multiparty computation, and zkTLS. He holds a Ph.D. in Information Security from Instituto Superior Técnico, University of Lisbon, and an M.Sc. in Applied Mathematics from Imperial College London, with 13 published research articles across quantum oblivious transfer, privacy-preserving computation, and post-quantum blockchain design. He worked on post-quantum cryptography at Tectonic and on MPC and zkTLS at Nillion, where he contributed to Nada, a language for secure multiparty computation, and authored technical reports on threshold ECDSA. Earlier he was a Quantum Cryptography Researcher at Tekever.
LinkedIn
Georgii Plotnikov portrait

Georgii Plotnikov

Specialist Advisor

CEO at Inferara and designer of Inference, a language that combines executable code with formal specifications. Leads its Rust compiler development and previously built Code Inspector and security analysis tools at OpenZeppelin.

Georgii Plotnikov portrait

Georgii Plotnikov

Specialist Advisor

Georgii is CEO at Inferara and the designer of Inference, a statically typed, high-assurance language built so executable programs and formal specifications can live in the same source. The language uses a deterministic, WebAssembly-aligned execution model with verification-only specification blocks. He led the Rust implementation of the infc compiler, which produces optimized WebAssembly for execution and Rocq theorem obligations for formal verification. He also leads development of a Stellar smart-contract decompiler. Previously, as Lead Security Tooling Developer at OpenZeppelin, he designed and implemented the foundation of Code Inspector, the Defender code-analysis module, shipping GitHub-integrated analysis that grew beyond 130 static-analysis rules. His work spans reentrancy and unsafe-call detection, vulnerable-dependency and standards checks, contract fingerprinting, fuzz-target identification, and LLM-driven vulnerability analysis, with static-analysis tools in Python and Rust for Solidity, Rust-based DSLs, and Midnight Compact.
LinkedIn
Łukasz Mikuła portrait

Łukasz Mikuła

Specialist Advisor

Offensive security specialist with 10+ years of experience, 100+ public audits across 8+ ecosystems, and OSCP, OSCE, eWPT, and eWPTX certifications. At ING and Binance, worked across red teaming, exploit development, infrastructure, and high-scale digital asset systems.

Łukasz Mikuła portrait

Łukasz Mikuła

Specialist Advisor

Łukasz is a security researcher with 10+ years in offensive security and a public portfolio of 100+ audits across 8+ ecosystems. His smart-contract work spans EVM/Solidity, Move, Rust-based ecosystems, CosmWasm, Solana, Substrate, and TON, including assessments for Coinbase, MegaETH, Kyber, Jupiter, Zilliqa, IOTA, and Initia Move. At ING, he worked across web application and infrastructure penetration testing, red-team work, exploit development, reverse engineering, mobile security, adversary simulation, and smart-device testing. At Binance, he worked on security concerns for high-scale digital asset systems. He holds the OSCP, OSCE, eWPT, and eWPTX certifications and has CVE disclosures affecting IBM, Oracle, F5, Dell, and Red Hat.
LinkedIn
José C. Ramírez portrait

José C. Ramírez

Specialist Advisor

Security engineer and trainer with around 10 years of experience across application and protocol security. At ZKsync, reviewed Solidity and Rust code, including account abstraction, then built AI-assisted vulnerability-analysis workflows.

José C. Ramírez portrait

José C. Ramírez

Specialist Advisor

José is a security engineer and technical trainer specializing in smart contract and blockchain security, with around 10 years of experience across offensive security, application security, and security review. At ZKsync, he reviewed code, architecture, and design across Solidity/EVM, account abstraction, protocol-level security, and Rust-based components, later building AI-assisted workflows for vulnerability discovery and protocol security analysis. He has participated in smart contract audits across CosmWasm, EVM, and NEAR and holds OSCP, CREST CRT, AWS Certified Security, and AWS Certified Solutions Architect certifications. José has also delivered university courses, guest lectures, and workshops on blockchain and smart contract security, including at the University of Málaga and with the University of Porto.
LinkedIn

Team credentials

  • OSCP
  • OSCE
  • OSWE
  • CREST Registered Tester (CRT)
  • CISM
  • AWS Certified Security Specialty
  • AWS Certified Solutions Architect Associate
  • eWPT
  • eWPTX

Public work

Read the findings before you hire us.

Full reports with findings, evidence, and remediation status.

NEAR / Defuse Labs

NEAR Intents Security Review

Medium Potential Funds Stealing From Users Via Repeating Failed Intents

  • NEAR
  • Intents
  • Rust
View report

Sweat Economy

SWEAT NEP-141 Token Security Review

High LookupMap adapter can undercharge storage for selected accounts

  • NEAR
  • Smart contract
  • Rust
View report

Spin Finance

Onchain Orderbook and Perpetual Trading Security Review

Critical Order Placement with Negative/Zero Margin Ratio Is Possible

  • NEAR
  • Smart contract
  • Rust
View report

Virto Network

Pallet Pass Security Review

High DoS of The Main Functionality Through Session Key Hijacking

  • Polkadot
  • Substrate
  • Rust
View report
All reports

Our approach

Named before you sign.

Your proposal names the principal and specialists assigned to your engagement.

You scope the work with a principal

Your principal defines the scope with you, checks the findings, and stays involved through delivery.

You work with experienced security leaders

Our team brings experience from exchanges, protocols, and security product companies. Our advisors also lead security teams at other companies.

You work with specialists who understand your system

We match your review team to what you are building. For a custody review, your team includes a custody specialist.

What you receive

Findings, remediation guidance, and reusable tests.*

A documented threat model and security tests your team can rerun as the code changes.

Deliverables from a Guvenkaya code security review compared with an engagement limited to a findings report.
Deliverable Guvenkaya Report-only audit
Findings report Yes Yes
Threat model Yes No
Record of flows and security properties tested Yes No
Invariant register Yes No
Security tests in your repo Yes No
Signed opinion on a reviewed commit Yes No

* These deliverables apply to code security reviews. For other engagements, we agree on deliverables when defining the scope.

Discuss your scope

Services

Start with what you need to secure.

Describe your system or the change you are planning. We'll help define the scope.

Smart Contract Security Reviews

Find flaws in contract logic, permissions, accounting, and upgrades before they put funds at risk.

  • Permissions & accounting
  • Protocol logic
  • Integrations
Explore

Blockchain Protocol & Infrastructure Reviews

Review custom chains, runtimes, nodes, consensus, and bridges beneath the application layer.

  • Custom chains
  • Runtimes & VMs
  • Nodes
  • Consensus
Explore

Penetration Testing

Test the attack paths that connect web, mobile, APIs, cloud, identity, and infrastructure.

  • Web & mobile
  • APIs & backends
  • Cloud
  • Infrastructure
Explore

Signing & Custody Security Reviews

Review key generation, signing approvals, key use, and recovery across MPC, HSM, multisig, and custody platforms.

  • MPC
  • HSM
  • Multisig
  • Key lifecycle
Explore

Secure Code Reviews

Find security flaws in critical code, including authorization, business logic, and state changes.

  • Authorization
  • Business logic
  • State changes
Explore

Secure Architecture & Process Design

Design or assess critical systems, workflows, integrations, and operating controls before implementation or a major change.

  • Trust boundaries
  • System integrations
  • Operating controls
Explore

Not sure which one fits?

Tell us your main concern and we’ll help you choose a starting point.

Discuss your system

Training

Technical training &
security exercises

Choose training on Rust, Substrate, and NEAR, or workshops, tabletop exercises, and key-ceremony rehearsals tailored to your systems.

Discuss training

Tell us what you need to secure.

Describe your system, main concern, and deadline. We'll reply with scoping questions and a proposed next step.

Discuss your scope contact@guvenkaya.co