Solutions · Protocols & Networks

Ship a protocol whose trust assumptions survive contact with users.

We review contracts, runtimes, consensus, and bridges across EVM and non-EVM systems, and publish the results.

When this fits

When protocol teams bring us in.

Before a mainnet launch or upgrade

Review once behaviour is stable enough to test, while changes are still cheap.

When a bridge or integration changes what you trust

A new dependency moves your trust boundary whether or not anyone redrew it.

After an incident or a near miss

Reconstruct the failure path and establish what else shares its shape.

Before an ecosystem or exchange review

Arrive with findings already resolved rather than discovered by someone else.

Where it breaks

Four layers, four different ways to lose.

A contract bug moves funds immediately. A runtime bug is inherited by every contract above it. Matching the review to the layer is most of the work.

Four layers of a protocol stack, contracts through bridges, each showing the review that covers it and the failure it produces when nobody does

Every layer fails differently. The review has to match the layer.

01

Contract logic & accounting

Permissions, state transitions, accounting, upgrade paths, and economic assumptions.

02

Runtime & execution

Virtual machines, gas and resource metering, host functions, and node client behaviour.

03

Consensus & finality

Validator incentives, safety and liveness, reorg handling, and upgrade coordination.

04

Bridges & cross-chain trust

Message verification, relayer assumptions, replay, and what a compromised chain can claim.

Published work

Read the findings before you hire us.

All reports →

Recommended starting engagements

Choose the best starting point.

Typical engagement team

Who typically leads this work

The people who usually take protocol work, picked for the ecosystems involved rather than who happens to be free.

The exact team depends on the scope. Every engagement has a principal who owns it from scoping through delivery, joined by the specialists the system calls for, and whoever is assigned is named in your proposal.

Michal Bajor portrait

Michal Bajor

Specialist Advisor

Secured funding, custody, APIs, and on-chain systems at Kraken. Has reviewed 60+ Web3 projects across DeFi, L1s, bridges, oracles, and other critical infrastructure.

Łukasz Mikuła portrait

Łukasz Mikuła

Specialist Advisor

Offensive security specialist with 10+ years and 100+ public audits across eight ecosystems. At ING and Binance, worked across red teaming, exploit development, infrastructure, and high-scale digital asset systems.

José C. Ramírez portrait

José C. Ramírez

Specialist Advisor

Security engineer and trainer with around 10 years across application and protocol security. At ZKsync, reviewed Solidity, account abstraction, and Rust, then built AI-assisted vulnerability-analysis workflows.

Piotr Cielas portrait

Piotr Cielas

Principal Advisor

Head of Security at Agora, responsible for security, data protection, and corporate IT risk. Earlier at EY, led assessments across financial services, healthcare, and government.

Currently

Head of Security, Agora

$45B+ in volume

Meet the full team

Other organizations we work with

Tell us what you need to secure.

Share the repository, target commit, architecture, and launch date. We will reply with the next questions and a likely scope. If a review is not the right next step, we will say so.

Discuss your scope