CYBERSECURITY · BLOCKCHAIN · CRYPTOGRAPHY
Find the weakness.
Strengthen the code.
We specialise in blockchain and cryptocurrency vulnerability research, helping developers and open-source maintainers identify, validate, and remediate complex software flaws.

CODE-FIRST SECURITY
Deep review.
Actionable findings.
We combine manual code review, static analysis, and carefully validated testing to investigate security assumptions, logic errors, and cryptographic implementation risks.
Research is performed within an agreed scope. Findings are shared privately with the responsible team, with evidence that supports practical remediation.
AREAS OF FOCUS
- Wallet key handling, entropy & signing flows
- Transaction validation & protocol logic
- Access controls & trust boundaries
- Unsafe parsing, arithmetic & memory handling
- Cryptographic integration & implementation errors
AN AUDIT YOU CAN ACT ON
Evidence before assumptions.
01
Scope the review
Agree on repositories, commit references, components, threat assumptions, and authorised testing boundaries.
02
Investigate & validate
Trace sensitive code paths and validate suspected weaknesses in a controlled environment.
03
Report & remediate
Document affected code, root cause, impact, reproduction steps, and recommended fixes.
04
Review the fix
Check the agreed remediation against the original finding and identify relevant regression checks.
Supporting a more secure
decentralised ecosystem.
Our objective is to help software developers and open-source maintainers harden their codebases through proactive vulnerability research. We are interested in research collaborations, including a proposed collaboration with the Daybreak program, to explore advanced cybersecurity models for deep code auditing and static analysis.
This is a proposed collaboration; no active Daybreak partnership or endorsement is claimed.
A LITTLE MORE CLARITY
Good questions.
Clear answers.
What does an audit report include?
An agreed report can include the reviewed scope, affected code references, severity and impact, root-cause analysis, controlled reproduction steps, and remediation recommendations. Coverage and retesting are defined in the engagement.
How do we share sensitive code?
Start by emailing a high-level description. We will agree on confidentiality, access, and a suitable transfer method before you share private repositories or sensitive technical material. Do not email private keys or recovery phrases.
Does an audit guarantee that software is secure?
An audit evaluates an agreed scope at a point in time. It can reduce risk and reveal important weaknesses, but cannot guarantee the absence of all vulnerabilities.
LET’S WORK TOGETHER
Let’s define your audit scope.
Tell us about the repository, technology stack, and the components you would like reviewed.
