Smart contract audit
Line-by-line audit of smart contracts and protocol logic before deployment: manual review, invariant testing and review of the fixes.
AI, Web3 and cryptography
Review of cryptographic design and implementation: protocols, key management, signatures and the generation of random values.
AI, Web3 and cryptography
Cryptography rarely fails because an algorithm is broken. It fails in the details around it: a nonce that repeats, a random generator seeded with the time, a signature that is verified but not bound to its context, a key that is derived correctly and then written to a log.
These failures are silent. The system works, the tests pass, and a private key can be recovered from the signatures it has already published. We review the design for what it assumes and the implementation for whether the assumptions hold, and we test the output where mathematics allows a verdict: signatures, random values and ciphertexts.
01Scope
02Approach
We read the specification and state the security properties the design claims and the assumptions it depends on.
The code is compared with the design. We look at how libraries are used and where the implementation departs from what the design requires.
Signatures, nonces and random values produced by the system are analysed for bias, reuse and structure, using lattice and statistical methods.
Where a weakness is exploitable, we demonstrate it on test keys generated for the purpose. Keys that protect real assets are never the target of a demonstration.
03
04
05Standards
Requirements an application is verified against.
OWASP Foundation
Security requirements for mobile applications.
OWASP Foundation
Class of weakness behind every finding.
The MITRE Corporation
Severity score and vector of every finding.
FIRST
06Questions
Yes. The library is rarely the problem. The way it is called, the parameters it receives and what happens to keys before and after the call are where the errors are.
No. We work with test keys and with public outputs such as signatures. If the analysis of public data shows that a production key is at risk, you are informed at once and the key is not reconstructed.
Yes, and it is the cheapest moment to do it. A design flaw found before implementation costs a document change.
08Request
Reference
Keep the reference: we name it in all further communication with you.
We never ask for payment, passwords or remote access in the first reply.