BLOCKCHAIN PROTOCOL & INFRASTRUCTURE SECURITY REVIEWS

Review the chain, runtime, and execution layer beneath the application.

Security reviews for custom chains, rollup stacks, runtimes, virtual machines, node clients, consensus, validator logic, bridges, and the infrastructure around them.

Technology coverage

Languages, stacks, and execution environments we review.

From established protocol SDKs and rollup frameworks to custom chains, we review the code and architecture beneath the application layer.

Systems languages

  • Rust
  • C
  • C++
  • Zig

Protocol stacks & frameworks

  • Substrate / Polkadot SDK
  • Custom chain
  • Arbitrum (Nitro / Orbit)
  • OP Stack
  • ZK Stack
  • Cosmos SDK
  • Reth
  • Commonware
  • Tendermint

Virtual machines & execution

  • EVM-compatible
  • SVM-compatible
  • Move VM-compatible
  • WASM-based
  • RISC-V-based
  • Bespoke VMs & execution engines

Don’t see your stack?

This list is representative, not exhaustive.

Discuss your scope

Review surface

Review the layers that determine safety, liveness, and control.

A security review tracing a test message through blockchain protocol boundaries, consensus, runtime, execution, a finding, and verified control
  1. 01 Consensus & finality Safety assumptions, liveness failures, validator behavior, fork handling, and recovery.
  2. 02 Runtime & state transition State-machine logic, invariants, authorization, economics, resource limits, and upgrades.
  3. 03 Virtual machines & execution Instruction semantics, bytecode validation, host interfaces, metering, determinism, memory safety, sandboxing, and state-transition correctness.
  4. 04 Node & client Parsing, storage, concurrency, memory safety, validation, and error handling.
  5. 05 Networking & RPC Peer behavior, message validation, denial of service, exposure, rate limits, and trust boundaries.
  6. 06 Critical operators Keys, privilege, deployment, monitoring, and failover for validators, sequencers, and relayers.
  7. 07 Bridges & integrations Message verification, cross-domain assumptions, relayers, oracles, wallets, and off-chain boundaries.
  8. 08 Governance & upgrades Proposal, approval, activation, rollback, emergency control, and recovery.

Timing

When to bring Guvenkaya in

During architecture

Challenge the threat model while core safety and liveness choices can change.

Before release

Before testnet, mainnet, or a major protocol release.

Before a critical change

Before a runtime module, bridge, consensus change, or critical integration.

During assurance

For an upgrade, migration, incident review, or ongoing assurance program.

Process

From system assumptions to launch-ready decisions.

  1. 01

    Define the system

    Identify actors, assets, safety and liveness properties, deployment assumptions, and inherited components.

  2. 02

    Map state and messages

    Trace validation, transitions, privileges, upgrades, and cross-boundary dependencies.

  3. 03

    Review adversarial behavior

    Analyze implementation, configuration, and attack paths at the layers in scope.

  4. 04

    Resolve, verify, and brief

    Work through findings and provide technical and decision-level outputs for the launch or change.

Outputs / What you receive

Clear findings, practical fixes, and a report your team can use.

Protocol trust model

A summary of actors, trust boundaries, state, messages, and inherited assumptions.

Prioritized findings

Safety, liveness, integrity, or operational impact with exploit or failure scenarios.

Remediation guidance

Practical changes and verification status where agreed in scope.

Decision-ready summary

Where required, an executive view for launch, governance, or risk decisions.

Typical engagement team

Who typically leads this work

The exact team depends on the scope. Every engagement has a principal who owns it from scoping through delivery, joined by the specialists the system calls for, and whoever is assigned is named in your proposal.

Timur Güvenkaya portrait

Timur Güvenkaya

Founder & Partner

Led a security engineering practice for Rust and non-EVM systems across Substrate and NEAR. Earlier, built vulnerability-detection engines at Invicti used by Fortune 50 and public-sector organizations.

Michal Bajor portrait

Michal Bajor

Specialist Advisor

Secured funding, custody, APIs, and on-chain systems at Kraken. Has reviewed 60+ Web3 projects across DeFi, L1s, bridges, oracles, and other critical infrastructure.

Piotr Cielas portrait

Piotr Cielas

Principal Advisor

Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.

Currently

Head of Security, Agora

$45B+ in volume

Meet the full team

Inspectable proof

Relevant public work

Each card shows one highlighted finding, not the full result. Open the report for every finding and its severity.

Substrate pallet Public report

Virto Network

Pallet Pass Security Review

Selected public finding High

DoS of The Main Functionality Through Session Key Hijacking

  • Polkadot
  • Substrate pallet
  • Rust
View report ↗
Protocol Public report

NEAR / Defuse Labs

NEAR Intents Security Review

Selected public finding Medium

Potential Funds Stealing From Users Via Repeating Failed Intents

  • NEAR
  • Intents
  • Protocol
View report ↗
Substrate Layer-1 Public report

Enjin

Relaychain and Matrixchain Security Review

Selected finding Critical

DoS of Fuel Tank Mutation

  • Polkadot
  • Substrate
  • Rust
Report held private at client request
Substrate pallet Public report

Enjin

Claims Pallet Security Review

Selected finding Critical

DoS of Claiming Functionality

  • Polkadot
  • Substrate pallet
  • Rust
Report held private at client request
View all public reports

FAQ

Questions before scoping

Do you review custom chains?

Yes. Scope can include custom Layer 1, Layer 2, rollup, and appchain architecture; runtime and VM logic; node and client code; consensus; networking; validator operations; upgrades; and integrations.

Do you review Substrate pallets and runtimes?

Yes. Public work and team experience include Substrate and Rust-based systems.

Can a bridge review sit on this page?

Yes. Bridge security often spans contracts, verification, relayers, validators, oracles, services, key management, and operations.

How is this different from a smart contract audit?

A smart contract review focuses on application-level logic. A blockchain systems review reaches into the chain, runtime, virtual machine, node, consensus, networking, and operational layers.

Related services

Next step

Bring us the system, not only the repository.

Share the architecture, codebase, threat model, release stage, and the safety or liveness decisions the review must support.

Discuss your scope