Auditoría de smart contracts y la dApp que los rodea. Las clases que efectivamente drenan protocolos: reentrancy, flashloan + oracle manipulation, MEV / sandwich, upgrade pattern bypass, signature replay, integer over/underflow en libs viejas. Cada finding viene con PoC en Foundry o Hardhat — corre contra tu fork. Audit of smart contracts and the surrounding dApp. The classes that actually drain protocols: reentrancy, flashloan + oracle manipulation, MEV / sandwich, upgrade pattern bypass, signature replay, integer over/underflow in old libs. Every finding ships with a Foundry or Hardhat PoC — runs against your fork.
No buscamos un constructor mal escrito. Buscamos las cadenas de 3-4 hops que vacían el pool mientras todos los tests pasan. We don't hunt a bad constructor. We hunt the 3-4 hop chains that empty the pool while every test passes.
El check-effects-interactions está prolijo en withdraw() pero claimReward() hace la transferencia antes de actualizar state. Re-enter por ahí → drain. Check-effects-interactions is tidy in withdraw() but claimReward() transfers before updating state. Re-enter through that → drain.
El protocolo lee precio de Uniswap V2 spot. Flashloan masivo → mover el price → liquidación / borrow inflado → repagar flashloan → ganancia. Si no usás TWAP, es asunto de tiempo. Protocol reads spot price from Uniswap V2. Massive flashloan → move the price → liquidation / inflated borrow → repay flashloan → profit. If you don't use TWAP, it's a matter of time.
Implementation deployada sin _disableInitializers(). Cualquiera puede llamar initialize() en la implementation → ownership de la implementation → vector para hijack del proxy. Implementation deployed without _disableInitializers(). Anyone can call initialize() on the implementation → ownership of the implementation → vector for proxy hijack.
EIP-712 sin chainId en el domain separator. Firma válida en Polygon → replay en BNB Chain. Bridges, permit-based DEXes y NFT marketplaces afectados. EIP-712 with no chainId in the domain separator. Signature valid on Polygon → replay on BNB Chain. Bridges, permit-based DEXes and NFT marketplaces affected.
El frontend permite swap con minAmountOut: 0. El bot del mempool detecta y sandwichea. Tu usuario pierde 30%. Reportable como bug, no como feature. Frontend allows swap with minAmountOut: 0. Mempool bot detects and sandwiches. Your user loses 30%. Reportable as a bug, not a feature.
El validador del bridge confía en un set de signers. Una sola key comprometida (filtrada en logs, .env, GitHub) → drain del bridge. Cross-chain. Irreversible. Bridge validator trusts a signer set. One leaked key (logs, .env, GitHub) → bridge drain. Cross-chain. Irreversible.
Smart contracts + dApp completa. Las clases del SWC Registry + las que no figuran. Foundry / Hardhat PoC por cada finding. Entry point para todo protocolo. Smart contracts + full dApp. SWC Registry classes + the ones that don't make the list. Foundry / Hardhat PoC per finding. Entry point for every protocol.
● NEW S/03 · desdefrom $2.990Para la API off-chain: indexers, RPC proxies, wallet APIs. Si tu protocolo tiene backend, el backend tiene clases tradicionales que pueden tumbar el frontend. For the off-chain API: indexers, RPC proxies, wallet APIs. If your protocol has a backend, it has traditional classes that can take down the frontend.
S/04 · desdefrom $2.490Wallets móviles. Key management, deep-link hijack, WalletConnect session abuse, deeplink-based dApp impersonation. Mobile wallets. Key management, deep-link hijack, WalletConnect session abuse, deeplink-based dApp impersonation.
S/08 · desdefrom $9.990Simulación adversarial completa. Para protocolos con TVL alto donde un phishing al equipo deploy puede comprometer el multisig. Full adversarial simulation. For high-TVL protocols where phishing the deploy team can compromise the multisig.
◆ FLAGSHIP5-7 días de engagement. Cada finding viene con PoC en Foundry que ejecuta el ataque contra tu fork. Reporte final firmado, attestation pública opcional. Retest a 30 días incluido. 5-7 day engagement. Every finding ships with a Foundry PoC that runs the attack against your fork. Signed final report, optional public attestation. 30-day retest included.