Omnichain Stablecoin Protocol
A live omnichain stablecoin reviewed across contracts, configuration, cross-chain messaging, the dApp/backend, and DNS — 27 findings ranked by exploitability, each with a fix.
Real Vari reviews, published as client-anonymized samples. Same methodology, findings, severities and recommendations we deliver — with the audited party's identity removed so we can share the work openly. Six engagements · 244 findings · 219 with an executed proof of concept.
A live omnichain stablecoin reviewed across contracts, configuration, cross-chain messaging, the dApp/backend, and DNS — 27 findings ranked by exploitability, each with a fix.
A cross-chain RWA vault (BoringVault architecture) reviewed across contracts, configuration, and cross-chain messaging — surfacing a bridge path that bypasses KYC/cap controls, an administered-rate first-redeemer drain, and hot-key role concentration on admin paths.
A membership-gated fixed-term lending protocol. Pools custody no funds (peer-to-peer), so theft vectors were ruled out — the live risk is interest and fee accounting: a monthly overdue double-charge, a multi-lend proration overcharge, and terminal-default griefing.
A treasury-yield pool with an APR reward engine and factory. Two high-severity manager-privileged issues confirmed with exact arithmetic — a single-block drain of the shared reward reserve and a permanent overflow-brick with a self-locking reset — plus a KYC bypass on principal.
An upgradeable validator-node staking and reward distributor. Reward accounting is solvent-by-construction; the exploitable surface is owner/validator operational hazards — an unbounded node fee that permanently bricks rewards, a batch-revert griefing DoS, a validator-accounting desync, and a near-100% validator fee siphon.
Three production dApps reviewed across their frontends, backend API routes and — the part a contract-only audit never reaches — every wallet-signing flow, comparing what each screen promised against what the wallet was actually asked to sign. Among the findings: an unauthenticated endpoint that sends attacker-authored email from the client's own domain, a withdrawal path that asks for no wallet signature at all, and a fail-open admin session secret.
Contracts, config, cross-chain, frontend, backend and DNS — one review, ranked by exploitability, 1–3 days. From $2,500. Fixed quote within 24 hours, free.