Track 01 · On-chainSmart contract audit.
Line-by-line manual review, plus Slither, custom Foundry invariants, mutation testing, and Krait. EVM, Solana, Rust, Cairo, Sway.
- Reentrancy, access control, oracle and accounting risk
- Invariant and property-based testing
- Static analysis with custom detectors
- Mutation testing for coverage quality
Lead: Zealynx founder + auditor partner
Track 02 · Off-chainBackend, frontend, APIs.
Black-box and white-box pentest of your off-chain surface. Authentication, authorization, data exposure, and OWASP-style review, with focus on integration risk with the on-chain side.
- Auth, session, and key management review
- API surface and trust boundary analysis
- Signed payload generation paths
- Webhook and event-handling integrity
Lead: Zealynx in-house pentester (decade of senior web2 security)