White-box and black-box testing
We offer both approaches and choose based on each project’s needs.
WEB3 PENTESTING
We offer white-box and black-box testing based on each project’s needs. Our research examines the large, underexplored Web2 attack surfaces that remain in many Web3 applications.
WHAT WE TEST
Our research covers the Web2 layers that sit around on-chain code: authentication, sandboxes, and app backends.
We offer both approaches and choose based on each project’s needs.
Our research examines the large, underexplored Web2 attack surfaces that remain in many Web3 applications.
Our post “Subverting Web2 authentication in Web3” covers OAuth logic exploits and Supabase misconfigurations.
We’ve done extensive research into MetaMask’s Snaps sandboxing environment, published on our blog.
RESEARCH-DRIVEN TESTING
CLIENT FEEDBACK
“Their website says protecting Blockchain ideas, but their command of JavaScript is impressive. If you've got something that you think would be "too hard for pentesters to understand" - these folks will surprise you. They're not your average pentester.”
OUR PROCESS
We’ll discuss your goals, timeline, and security needs to see whether we’re a fit.
We’ll send an MNDA and look at repositories within scope to understand the details of your project and requests.
At completion, we will send you a report with our findings and suggestions for fixes.
PENTESTING FAQS
We offer white-box and black-box testing based on each project’s needs. Our research examines the large, underexplored Web2 attack surfaces that remain in many Web3 applications, and we’ve done extensive research into MetaMask’s Snaps sandboxing environment.
REQUEST A PENTEST
We work with leading teams across multiple blockchains. Put the same collaborative approach to work on your application.
Get an audit