BACKEND SECURITY

Security work for backends, custodians, and exchanges

We’ve worked with a wide range of projects, from qualified custodians to exchanges to mobile firmware. We’ve discovered bugs across these systems and published the research.

$1.00B+ Vulnerabilities patched120+ Projects audited$36.82B+ On-chain TVL secured

SERVICES

Where backend research meets audits

Off-chain systems are on our services page as their own category, next to Solana, EVM, DeFi, and bridges.

Exchanges and custodians

Our backend work spans qualified custodians, exchanges, and mobile firmware.

OAuth research

Our research on OAuth misconfigurations covers real cases where desktop and mobile differences left SDKs, exchanges, and wallets vulnerable.

Supply-chain research

Our posts on supply-chain attacks cover LavaMoat bypasses and practical defenses after the NPM supply-chain attack.

Pentesting

We offer white-box and black-box testing based on each project’s needs.

HOW WE AUDIT

How we start working together

  1. 01

    Initial discussion

    We’ll discuss your goals, timeline, and security needs to see whether we’re a fit.

  2. 02

    Info gathering

    We’ll send an MNDA and look at repositories within scope to understand the details of your project and requests.

  3. 03

    Kickoff

    We’ll begin the audit, share findings as they emerge, and ask questions as needed.

GET IN TOUCH

Bring your backend into scope

Tell us what you are building, where the highest-risk parts live, and when you need coverage. We will route the request to the right security team.

Get in touch