Business logic gaps
The code can compile, pass unit tests and still let an attacker take an unintended path through the protocol.
Can lead to direct loss of funds, unintended minting or draining.
Smart contract audits
Independent smart contract auditor and security researcher. Helping teams ship safer protocols through in-depth audits, threat modeling and practical security advice.
Trusted by
A security mindset across the stack
Understand the protocol. Challenge every assumption.01 Why teams bring me in
The expensive bugs tend to live where assumptions, privileges, accounting and edge-case state transitions meet.
The code can compile, pass unit tests and still let an attacker take an unintended path through the protocol.
Can lead to direct loss of funds, unintended minting or draining.
Roles, blacklists, upgrade paths and admin assumptions often fail at the edges rather than on the happy path.
Can result in unauthorized control or bypassed restrictions.
Rounding, share math, stale state and cross-function sequencing can break value conservation without looking dramatic.
Can lead to value leakage, unfair asset distribution or insolvency.
A large test suite can prove what was tested. It cannot prove the right adversarial questions were asked.
Can leave an untested attack path and costly exploits after launch.
02 Security services
A focused review for teams that want an early security read before committing to a full audit.
A scoped security audit for code approaching freeze, mainnet launch, or a meaningful upgrade.
For teams shipping changes too often to treat security as a once-a-year event.
A clear process.
A stronger protocol.
Code, context & assumptions
Logic, attack paths & impact
Clear findings & fix review
03 Curated findings & wins
I prefer verifiable security work over inflated vanity metrics. These are selected public results from competitive audits and security research.
Identified a path allowing restricted stakers to bypass FULL_RESTRICTED_STAKER_ROLE blacklist enforcement.
Reviewed Starknet staking logic in a public CodeHawks competition.
Identified a condition where a malicious validator could submit a vote extension shorter than 65 bytes and crash SEDA chain nodes.
Identified a path that could bypass intended JIT penalties and cause protocol revenue loss.
04 Security notes
Tests describe expected behavior. Security review also asks how valid operations can be combined in unexpected ways. Trace sequences across deposit, withdrawal, liquidation and privileged actions, then ask which assumptions survive.
Check who benefits from rounding and whether the same action can be repeated. Review conversions between assets and shares in both directions, especially for empty pools, small deposits and changing exchange rates.
List what each privileged role can do, how it is granted and how it is removed. Include upgrade powers, emergency controls and external dependencies. The protocol’s security model should make those trust assumptions explicit.
05 Before we get started
Have something else in mind?
Let’s talk about your protocol ↗
Share the repository, the commit or branch you want reviewed, documentation, the intended scope and your preferred timeline. A short explanation of the protocol and its key trust assumptions helps define the engagement.
They depend on the codebase, complexity, documentation and depth of review needed. We’ll discuss those details and agree on the scope and schedule before work begins.
Yes. A review before launch can help identify design and implementation issues while they are easier to address. A stable codebase and clear documentation make the review more effective.
No review can guarantee the absence of vulnerabilities. An audit is one layer of security, alongside careful design, testing, monitoring and a considered incident response plan.
Disclosure expectations and report sharing can be agreed before the review. Sensitive findings should be addressed through a coordinated process that gives the team time to investigate and remediate.
Get your code reviewed
Preparing for launch, an upgrade, or a meaningful smart-contract change? Send the scope and I’ll review the repository, timing and likely engagement fit.
audits@uqaabsecurity.com