0xrivet

0xrivet

auditing bridges so you don't have to

research

tracking patterns across bridge and protocol exploits. focused on verification model failures, upgrade authority gaps, and operational security breakdowns.

disclosures

nothing public yet. working on it.

areas of interest

โ€” cross-chain message verification: DVN trust assumptions, guardian set management, ISM configurations
โ€” upgrade authority chains: who actually controls the proxy, and how many steps between an EOA and your funds
โ€” multisig operational security: what the threshold protects and what it doesn't
โ€” pricing function invariants: split invariance, rounding direction, oracle manipulation
โ€” contract lifecycle security: the gap between "audited" and "safe in production for 3 years"

related writing

your bridge's security page is lying to you โ€” bridge trust score framework
proxy upgrade patterns โ€” a field guide
what your multisig threshold actually protects