auditing bridges so you don't have to
tracking patterns across bridge and protocol exploits. focused on verification model failures, upgrade authority gaps, and operational security breakdowns.
nothing public yet. working on it.
โ cross-chain message verification: DVN trust assumptions, guardian set management, ISM configurations
โ upgrade authority chains: who actually controls the proxy, and how many steps between an EOA and your funds
โ multisig operational security: what the threshold protects and what it doesn't
โ pricing function invariants: split invariance, rounding direction, oracle manipulation
โ contract lifecycle security: the gap between "audited" and "safe in production for 3 years"
your bridge's security page is lying to you โ bridge trust score framework
proxy upgrade patterns โ a field guide
what your multisig threshold actually protects