Vari reviews contracts, deployment config, cross-chain, frontend, backend and DNS as one attack surface — every finding ranked by real exploitability, with a concrete fix. Fixed quote in 24 hours. Report in 1–3 days. From $2,500.
Public repos: paste a link. Private: we'll send read-only invite steps after you write.
of losses at audited protocols in H1 2026 came from outside the audit's scope — keys, config, bridges, frontends and off-chain infrastructure.
ack3 H1 2026 incident dataset · 135 incidents · $940M lost · our breakdowns →
Bridge contracts audited and clean. Shipped with a 1-of-1 verifier; one compromised verifier forged a cross-chain message. Configuration, not code.
−$285MDrift Protocol · Apr 2026 · keysAudited by four firms. Social engineering reached two of five multisig signers; no timelock on admin transfers. Keys and operations, not code.
Private keys compromised in off-chain signing infrastructure — the backend around the contracts. Backend, not code.
One line of predictable RNG-fallback code sat unnoticed for five years until seeds were brute-forced at scale. Small flaw, catastrophic blast radius.
A launch, a listing or a raise does not survive a config, key, UI or DNS failure — and a contract-only review leaves every one of those surfaces untouched. This is the review of the system your users and your attackers actually touch. Point-in-time, residual risk stated, no "certified secure."
A typical smart-contract audit stops at the contracts. Vari reviews the whole surface an attacker sees, and checks the seams between layers — frontend ↔ contracts ↔ backend ↔ config. EVM (Solidity), Solana (Anchor/Rust) and Stacks (Clarity).
App URL and repos. Public: paste. Private: add VARI-Review as a read-only collaborator — we send the steps when we reply.
One number, one start date. Scope locks before we begin, so every hour is review. The clock starts when access lands.
Severity-ordered findings with impact, location and a concrete fix; one clarification round; publicly shareable with standard disclaimers.
One product = its whole stack. Several products together get a reduced per-product rate and one combined quote. Not sure which tier? Send it anyway — the quote is free.
Pre-launch or testnet: token, NFT, staking or vesting contracts and their deployment config. Minimal live surface, no backend.
1–2 contracts · single chain · light frontend
Quote StarterLive protocol holding user funds. Contracts, live config, cross-chain, dApp, backend and DNS. If users trust you with money, this is the engagement.
full dApp + backend · oracles · multi-contract · multi-chain
Quote FullLive but lean: a handful of contracts on one chain — token + staking, a simple vault, a single-market app — with a simple frontend and no meaningful backend.
≤5 contracts · single chain · no oracles
Quote StandardNot sure which tier fits? Send the repo and URL — the quote comes back the same day, free.
A review finds the exploit before you ship. Three ways to keep the coverage current after you do.
We re-test every finding after remediation and update the report. 30–40% of the original fee, same week.
Code and config change weekly; yesterday's clean report doesn't cover today's deployment. Each release diff and a live-config snapshot (plus DNS on Full) reviewed on a monthly retainer — from $1,200/mo after Starter, $2,500/mo after Standard, $5,000/mo after Full. Three-month minimum.
After a review, the same surfaces can be watched and, where you want it, enforced — config drift, DNS, and the pause / cap / allowlist paths already marked in your report. Available after an engagement and scoped separately. Roadmap, not a shrink-wrapped platform.
Recompute Safe transaction hashes, decode any EIP-712 request and read raw calldata — in your browser, nothing leaves the page.
Safe tx hash 0x9f…c21a ✓ matches EIP-712 domain v1.3.0 · chain 1 Calldata transfer(address,uint256) Risk recipient not in your address book
Seven-plus years building novel products from scratch — blockchains, DeFi protocols and stablecoins, architected end-to-end. Across the contracts he has built, reviewed and managed, more than $1B has moved on-chain. He is the founder and lead reviewer, and every finding in your report is reproduced, ranked and signed by a person — no report leaves here that a reviewer has not stood behind.
No. Tooling is used for coverage — static analysis, fuzzing, symbolic checks and our own detectors — the same way any serious firm uses Slither or a fuzzer. A person reproduces every finding, decides its severity and signs the report. Nothing reaches you that a reviewer has not stood behind.
Scope locks before we start, and the mechanical coverage work runs alongside the review rather than ahead of it — so reviewer time goes to logic, access control, configuration and cross-layer paths, where protocols actually get drained. Code that already holds funds can't wait weeks in a queue.
It is a point-in-time full-stack review of a specific commit and deployment, with residual risk stated plainly. That is what a serious review is. A logo from another firm is a separate purchase some teams make for distribution — it is not required for this work to count.
Each tier covers one product's full stack. A lending protocol plus separate vault, staking or vesting apps on their own domains is several products. Submit them together and you get a reduced per-product rate and a single combined quote.
Testing against live production systems, formal verification, continuous monitoring, and any guarantee or insurance. A review is a point-in-time assessment; residual risk is stated plainly in every report.
Links. Public repos: paste them. Private repos: add VARI-Review as a read-only collaborator when we reply — access is scoped to the review and removed after. No data is sold and the site runs no trackers.
A fixed number within 24 hours — free, no obligation. Three fields is all we need to start.
Prefer DMs? Telegram @va_rinder