// 02 · AUDIT REPORTS
Reports
Public security reviews. Every finding listed here was confirmed with a proof of concept and re-verified after the fix.
MultiSigTimelock Security Review
Review of a 3 of 5 multisig with a value based timelock. The owner can stack the signers alone and token transfers skip the wait.
Damn Vulnerable DeFi
Security reviews of the Damn Vulnerable DeFi v4 challenges, each audited as a standalone protocol with findings backed by a Foundry PoC.
18 challenge solutions →
Gas Bad NFT Marketplace Audit Report
Audit of an assembly based NFT marketplace. NFTs sent to the contract are locked forever, and buyers can overpay.
MathMasters Audit Report
Audit of a fixed point math library. mulWadUp rounds up on the wrong value, and sqrt checks the wrong side of a shift.
Boss Bridge Security Audit Report
Audit of an L1/L2 token bridge. Deposits accept any from address and drain approvers, and withdrawal signatures replay forever.
ThunderLoan Audit Report
Audit of an upgradeable flash loan protocol. A storage collision pushes the fee to 100% on upgrade, and a deposit path steals the loan.
T-Swap Audit Report
Audit of a constant product AMM. _swap gives away a free token every 10 swaps, draining LPs and breaking the x * y = k invariant.
SNARKeling Treasure Hunt Audit Report
Audit of a ZK (Noir) treasure hunt. A wrong variable in the claimed check lets one valid proof drain the whole 100 ETH prize pool.
President Elector: RankedChoice Audit
Audit of an onchain ranked choice vote. Broken EIP-712 signature checks, no replay protection, and an election can start right at deploy.
PuppyRaffle Audit Report
Audit of a raffle protocol. A reentrancy drain in refund(), weak block randomness in selectWinner(), plus a fee overflow and a DoS.
PasswordStore Initial Audit Report
Review of a single user onchain password store. The private password is readable from storage, and setPassword has no access control.
0x00
No reports matched. The bug is elsewhere.