# Zealynx Security > Zealynx Security is a boutique Web3 security firm founded by Carlos Vendrell Felici, based in Wroclaw, Poland. We specialize in smart contract audits, AI/LLM security audits, and dApp penetration testing for DeFi, GameFi, and RWA protocols. ## What Makes Zealynx Different - **Multi-chain expertise**: Solidity (EVM), Rust (Solana), Cairo (Starknet), Sway (Fuel) - **AI security pioneers**: One of the first firms offering MCP security audits and AI red teaming for LLM-integrated applications - **Competitive audit track record**: Top-5 finishes in CodeHawks and Sherlock contests - **Methodology**: Defense-in-depth workflow combining manual review, fuzz testing, formal verification, and AI-assisted analysis. See the [published audit methodology](https://www.zealynx.io/methodology) for the full multi-layer process, severity matrix, and 6-axis finding rubric used on every engagement. - **Transparent pricing**: Published audit pricing benchmarks and ROI data ## Core Services ### Smart Contract Audits Full-scope security reviews for blockchain protocols: - [Solidity Audit](https://www.zealynx.io/services/smart-contract-audits/solidity-audit): EVM chains (Ethereum, Arbitrum, Optimism, Base, Polygon) - [Rust/Solana Audit](https://www.zealynx.io/services/smart-contract-audits/solana-audit): Anchor and native Solana programs - [Cairo Audit](https://www.zealynx.io/services/smart-contract-audits/cairo-audit): Starknet contracts - [Sway Audit](https://www.zealynx.io/services/smart-contract-audits/sway-audit): Fuel Network contracts ### AI & LLM Security Security assessments for AI-integrated applications: - [AI Red Team Audit](https://www.zealynx.io/services/ai-audits/ai-red-team-audit): Adversarial testing of LLM-based systems, prompt injection, jailbreak, data exfiltration - [MCP Security Audit](https://www.zealynx.io/services/ai-audits/mcp-security-audit): Security review of Model Context Protocol server implementations ### Application Security - [TypeScript Audit](https://www.zealynx.io/services/application-security-audits/typescript-audit): Frontend and backend Web3 application security - [Pentesting](https://www.zealynx.io/services/application-security-audits/pentesting): Full-stack dApp penetration testing - [Web3 Wallet Security](https://www.zealynx.io/services/application-security-audits/web3-wallet-security): Wallet integration and transaction signing security ### Smart Contract Development - [Solidity Development](https://www.zealynx.io/services/smart-contract-development/solidity-development) - [Solana Development](https://www.zealynx.io/services/smart-contract-development/solana-development) ### Free Tools - [Solidity nSLOC Counter](https://www.zealynx.io/tools/nsloc): Free GitHub repository based Solidity normalized Source Lines of Code counter. Public repositories work without login. Private repositories use GitHub App authorization. Results include a non-binding audit planning range. ## Published Audit Reports Curated public catalogue of smart contract audits and Web3 application pentests at [/audits](https://www.zealynx.io/audits). 22 reports + 245 individual finding pages, each one a citable artifact with TechArticle and FAQPage structured data. ### Audit Methodology - [Zealynx Audit Methodology](https://www.zealynx.io/methodology): Multi-layer methodology combining manual review with custom Foundry invariant fuzzing, mutation testing, stateful fuzzing, and symbolic execution. Includes the 3x3 Impact x Likelihood severity matrix and the 6-axis finding rubric (severity, impact, likelihood, method, complexity, exploitability) published on every report. ### Flagship Reports Each finding has its own permalinkable URL at `/audits/[client]/[report]/findings/[id]`. Use these when citing specific vulnerability patterns or asking about real-world audit examples. - [Lido Finance Community Staking Module](https://www.zealynx.io/audits/lido-finance/community-staking-module-q3-2024): LST/staking audit, co-audit with Shieldify - [BadgerDAO Staked eBTC](https://www.zealynx.io/audits/badgerdao/staked-ebtc-q4-2024): vault/yield audit - [Aurora NEAR Connector](https://www.zealynx.io/audits/aurora/near-connector-q2-2024): cross-chain bridge between Ethereum and NEAR, co-audit with AuditOne - [Ribbon HealthFi Vault](https://www.zealynx.io/audits/ribbon/healthfi-vault-q2-2024): vault audit - [Redstone Oracle Protocol](https://www.zealynx.io/audits/redstone/oracle-protocol-q4-2024): oracle audit, co-audit with Codespect - [TokenTable Merkle Distributor](https://www.zealynx.io/audits/tokentable/merkle-token-distributor-q2-2025): token distribution, co-audit with Codespect - [Bastion Wallet Account Abstraction](https://www.zealynx.io/audits/bastion-wallet/account-abstraction-q1-2024): ERC-4337 account abstraction wallet, co-audit with Shieldify ### Recent Reports (2025-2026) - [Yada Coin Bridge Infrastructure](https://www.zealynx.io/audits/yada-coin/cross-chain-bridge-q1-2026): BNB to YadaCoin cross-chain bridge with KERI-inspired key registry - [Dripster Leveraged Prediction Vault](https://www.zealynx.io/audits/dripster/leveraged-prediction-vault-q2-2026): leveraged Polymarket positions vault on Polygon - [Dripster Offchain Pentest](https://www.zealynx.io/audits/dripster/offchain-pentest-q2-2026): TypeScript backend application pentest - [Fair Casino Solana Vault](https://www.zealynx.io/audits/fair-casino/solana-vault-program-q1-2026): Solana program audit with Ed25519 signature verification - [Nexalo Raffle Protocol](https://www.zealynx.io/audits/nexalo/raffle-protocol-q4-2025): autonomous on-chain raffle protocol with Chainlink VRF - [Microchain Binned-Liquidity AMM](https://www.zealynx.io/audits/microchain/binned-liquidity-amm-q3-2025): DEX/AMM on Fuel Network (Sway) - [Matchain Liquid Staking](https://www.zealynx.io/audits/matchain/liquid-staking-q2-2025): liquid staking module - [Matchain NFT Staking](https://www.zealynx.io/audits/matchain/nft-staking-q2-2025): NFT staking with EIP-712 authorization - [Ipal Network NFT Knowledge Marketplace](https://www.zealynx.io/audits/ipal-network/nft-knowledge-marketplace-q3-2025): NFT-gated access system - [Ample Protocol Staking](https://www.zealynx.io/audits/ample-protocol/ample-staking-q2-2025): staking protocol audit - [Paymatic Escrow Protocol](https://www.zealynx.io/audits/paymatic/escrow-protocol-q2-2025): payments/escrow audit - [Golden Grid Pixel Lottery](https://www.zealynx.io/audits/golden-grid/pixel-lottery-q4-2025): GameFi pixel lottery - [Monadex v1](https://www.zealynx.io/audits/monadex/monadex-v1-q3-2024): DEX with raffle mechanic - [Wedefin Index Fund](https://www.zealynx.io/audits/wedefin/index-fund-q2-2024): on-chain index fund - [RXT Token](https://www.zealynx.io/audits/rxt-token/nft-token-q4-2023): NFT token contract, co-audit with Soken ## Published Research & Resources ### Security Checklists (free, open-access) Practitioner-grade checklists used internally and published for the community: #### Smart Contract Checklists (EVM) - [EVM General Security Checklist](https://www.zealynx.io/resources/checklists/evm/general) - [Bridge Security Checklist: 100+ Critical Exploit Checks](https://www.zealynx.io/resources/checklists/evm/bridges) - [Stablecoin Security Checklist](https://www.zealynx.io/resources/checklists/evm/stablecoin) - [Proxy Upgradeability Security Checklist](https://www.zealynx.io/resources/checklists/evm/proxy) - [AMM/Price Oracle Security Checklist](https://www.zealynx.io/resources/checklists/evm/amm-price-oracle-security) - [GameFi Security Checklist](https://www.zealynx.io/resources/checklists/evm/gamefi) #### Smart Contract Checklists (Solana) - [Solana Security Checklist: 45 Critical Checks](https://www.zealynx.io/resources/checklists/solana/general) - [AI Security Checklist Hub](https://www.zealynx.io/resources/checklists/ai): LLM, MCP, and AI agent security checklists - [MCP Security Checklist: 24 Critical Checks](https://www.zealynx.io/resources/checklists/ai/mcp): Security review checklist for Model Context Protocol server implementations - [LLM Application Security Checklist](https://www.zealynx.io/resources/checklists/ai/llm-apps): Security checks for applications integrating large language models - [AI Model Security Checklist](https://www.zealynx.io/resources/checklists/ai/model): Security checklist for AI model deployment and inference #### AI & LLM Security Checklists - [AI Security Checklists (index)](https://www.zealynx.io/resources/checklists/ai): Overview of all AI security checklists - [MCP Security Checklist](https://www.zealynx.io/resources/checklists/ai/mcp): Critical security checks for Model Context Protocol server implementations - [LLM Application Security Checklist](https://www.zealynx.io/resources/checklists/ai/llm-apps): Security review checklist for applications built on top of large language models - [AI Model Security Checklist](https://www.zealynx.io/resources/checklists/ai/model): Security checklist for AI model deployment and integration - [Long-Lived Agent Security Checklist](https://www.zealynx.io/resources/checklists/ai/long-lived-agents): Security controls for delayed execution, memory persistence, credential scope, and unattended tool use - [Coding Agent Security Checklist](https://www.zealynx.io/resources/checklists/ai/coding-agents): Review checklist for autonomous coding agents with repository, shell, and CI access - [Agentic DeFi Security Checklist](https://www.zealynx.io/resources/checklists/ai/agentic-defi): Controls for AI agents that can read market state, prepare transactions, or influence DeFi operations ### Technical Blog (82 articles) Deep technical content written by the audit team, not AI-generated filler. #### Featured Hyperliquid Resources for Builders - [What Is HyperEVM? Hyperliquid Architecture Explained for Builders](https://www.zealynx.io/research/protocol-deep-dives/Understanding-Hyperliquid-Architecture-HyperBFT-HyperCore-HyperEVM-Part1): Builder-first architecture guide covering HyperBFT, HyperCore, HyperEVM, and where smart contract risk shows up before launch. - [What Is Hyperliquid? Developer Guide to APIs, SDKs & HyperEVM](https://www.zealynx.io/research/industry/What-Is-Hyperliquid-And-How-You-Can-Use-It): Practical developer guide to the Hyperliquid API, SDKs, and viable product ideas for teams building on HyperEVM. - Hyperliquid buyer-intent note: If you are preparing a HyperEVM launch, [request a review](https://www.zealynx.io/quote) or see Zealynx [smart contract audit services](https://www.zealynx.io/services/smart-contract-audits). #### Featured Uniswap v4 Resource for Builders - [Uniswap v4 Security Guide: Hooks, Risks, and Audit Path](https://www.zealynx.io/research/protocol-deep-dives/uniswap-v4): Builder-focused guide for hook callbacks, singleton PoolManager risk, flash accounting assumptions, custom fee logic, access control, and upgrade authority before liquidity reaches production. - Uniswap v4 buyer-intent note: If you are shipping a custom hook, pool manager integration, or singleton-aware router, run a fast pre launch pass in [Krait](https://krait.zealynx.io) and [request a Uniswap v4 security review](https://www.zealynx.io/quote) for the manual audit path. #### Featured Uniswap v3 Resource for Builders - [Uniswap v3 Security Guide: Concentrated Liquidity, Ticks, and Oracle Risk](https://www.zealynx.io/research/protocol-deep-dives/uniswap-v3): Builder-focused guide for concentrated liquidity ranges, tick math, fee tiers, NFT LP positions, oracle assumptions, and callback validation before a CLMM fork or integration reaches production. - Uniswap v3 buyer-intent note: If you are shipping concentrated liquidity, custom routing, or oracle dependent AMM logic, run a fast pre launch pass in [Krait](https://krait.zealynx.io) and [request a Uniswap v3 security review](https://www.zealynx.io/quote) for the manual audit path. #### Featured Curve Finance Resource for Builders - [What Is Curve Finance? StableSwap, crvUSD, Risks, and Security](https://www.zealynx.io/research/protocol-deep-dives/curve-finance-core-mechanics): Builder-focused guide for StableSwap math, metapool routing, rebasing asset edge cases, crvUSD and LLAMMA mechanics, and the integration risks teams should pressure test before launch. - Curve buyer-intent note: If you are shipping a stablecoin pool integration, metapool adapter, or oracle dependent Curve path, run a fast pre launch pass in [Krait](https://krait.zealynx.io) and [request a Curve security review](https://www.zealynx.io/quote) for the manual audit path. #### More technical research - [2025 DeFi Hacks: $3.4B Exploit Lessons](https://www.zealynx.io/research/industry/2025-exploit-lessons) - [MCP Security Checklist: 24 Critical Checks for AI Agents](https://www.zealynx.io/research/adversarial-security/mcp-security-checklist) - [Uniswap V1-V4 Security Series](https://www.zealynx.io/research/protocol-deep-dives/uniswap-v1) (4-part deep dive covering v3 concentrated liquidity and v4 hook security) - [Smart Contract Audit Pricing 2026](https://www.zealynx.io/research/audit-ops/audit-pricing-2026) - [EIP-7702 Wallet Security: What Auditors Check After Pectra](https://www.zealynx.io/research/smart-contracts/eip-7702-wallet-security): Builder focused guide to EIP-7702 delegate risks, phishing, replay, ERC-4337 composition, and wallet audit scope. - [Proxy Security Checklist: 33 Critical Upgradeability Checks](https://www.zealynx.io/research/smart-contracts/proxy-upgradeability-security-checklist) - [Cross Chain Bridge Security Checklist: 100+ Critical Exploit Checks](https://www.zealynx.io/research/smart-contracts/cross-chain-bridge-security-checklist): Builder focused bridge checklist for validator security, message verification, replay protection, oracle assumptions, emergency controls, and launch readiness. - [GameFi Security Checklist: 55+ Critical P2E Exploit Checks](https://www.zealynx.io/research/smart-contracts/gamefi-security-checklist) - [MiCA Regulation Security Guide for Crypto Founders](https://www.zealynx.io/research/industry/mica-regulation-security-guide-crypto-founders) - [AI Red Teaming: Security Auditor's Guide](https://www.zealynx.io/research/adversarial-security/ai-red-teaming-openclaw-security-guide) - [From EVM to SVM: Security Researcher's Guide to Solana](https://www.zealynx.io/research/smart-contracts/evm-to-svm-guide) - [Full blog archive](https://www.zealynx.io/research) ### Glossary - [Web3 Security Glossary](https://www.zealynx.io/glossary): 290+ blockchain and security terms with definitions ## Tools ### Free Developer Tools - [nSLOC Counter](https://www.zealynx.io/tools/nsloc): Free normalized Source Lines of Code counter for smart contracts (Solidity, Rust, Cairo). Instant line count with audit pricing estimate. ## Contact & Engagement - **Website**: https://www.zealynx.io - **Request a quote**: https://www.zealynx.io/quote - **X (Twitter)**: [@ZealynxSecurity](https://x.com/ZealynxSecurity) - **Founder**: [@TheBlockChainer](https://x.com/TheBlockChainer) (Carlos Vendrell Felici) - **Location**: Wroclaw, Poland (remote-first, serving global clients) ## Sitemap - [XML Sitemap](https://www.zealynx.io/sitemap.xml) - [RSS Feed](https://www.zealynx.io/api/rss)