Securing Cross-Chain Protocols. DM for security review @windhustler. About: burrasec.com/

Our focus over the past 6 months has been on improving the security services for our existing clients. We have massively improved our internal audit process, and we continue to work with the most talented security researchers.
10
818
Our researchers utilize AI, but we never want to rely on it too much. Every PoC, every exploit scenario — we make sure we understand everything 100%. Our mission is to secure the web3 space, and we'll use any tool available to make this mission succeed. We're here for the long run.
2
8
1,367
Our researchers are top-class, with some of them having 10+ years of software development experience. Lately, we've been doing more and more deployment script reviews, reviewing deployed contracts, analyzing codebases that are about to launch on new chains, and similar tasks. We're well-equipped to take on any task beyond your typical security review. DMs are open.
27
1,835
We've been working on solving the hardest problem in web3 security. How do you find the most complex vulnerabilities that slip through rounds of private audits, AI reviews, competitive audits, and bug bounties? Sometimes the simplest solution works best. Get the best whitehats in one room and let them collaborate freely.
3
39
2,510
Our greatest pride is contributing to the giants of our industry. We've helped secure: - @centrifuge: $1.3B+ TVL - @lifiprotocol: $60B+ total transfer value, biggest Bridge & DEX Aggregator in the space - @PancakeSwap: $2.9B+ TVL - @zama: one of the biggest players about to transform the privacy space
We have extensive experience reviewing cross-chain integrations. We have reviewed: - @LayerZero_Core - @axelar - @AcrossProtocol - @wormhole - @RelayProtocol - @chainlink CCIP - @eco - @gardenfi - @lifiprotocol Check out the reports at: github.com/burrasec/Security…. Reach out if you're building across multiple chains.
1
16
1,203
Some of our audits are fully collaborative, while others foster competition between researchers. There's no magic pill, and every engagement is different. We've been experimenting a lot with different modes of working. For every engagement, we think through what will yield the best results. Constant improvement and an iterative approach are our greatest strengths.
Biggest danger with AI is getting sloppier at everything you do. This can slip up on you if you're not vigilant. AI makes false claims while sounding confident. One of our core values is thoroughness. That means leaving no stone unturned — but it also means every reported issue has to be understood 100% and tested with a POC (Proof of Concept). We've read too many audit reports with false claims and wrongly identified issues. Making mistakes is normal, but in the final deliverable, we aim for assertiveness and confidence in all our claims.
2
15
612
We have extensive experience reviewing cross-chain integrations. We have reviewed: - @LayerZero_Core - @axelar - @AcrossProtocol - @wormhole - @RelayProtocol - @chainlink CCIP - @eco - @gardenfi - @lifiprotocol Check out the reports at: github.com/burrasec/Security…. Reach out if you're building across multiple chains.
1
1
27
2,316
Biggest danger with AI is getting sloppier at everything you do. This can slip up on you if you're not vigilant. AI makes false claims while sounding confident. One of our core values is thoroughness. That means leaving no stone unturned — but it also means every reported issue has to be understood 100% and tested with a POC (Proof of Concept). We've read too many audit reports with false claims and wrongly identified issues. Making mistakes is normal, but in the final deliverable, we aim for assertiveness and confidence in all our claims.
Researchers working on Burra Security audits are world-class. With competency and class, you'll often find ego. Researchers work independently, and during certain checkpoints throughout the audit, all researchers share their findings and brainstorm together — combining attack vectors, maximizing the outcome, and pushing for really complex issues. During these sessions, it's PARAMOUNT TO PUT EGO aside and focus on combining attack vectors, maximizing the impact of each issue, and making sure there are no false claims. Discussions around severity come last. That's our golden rule!
1
1
11
1,228
Researchers working on Burra Security audits are world-class. With competency and class, you'll often find ego. Researchers work independently, and during certain checkpoints throughout the audit, all researchers share their findings and brainstorm together — combining attack vectors, maximizing the outcome, and pushing for really complex issues. During these sessions, it's PARAMOUNT TO PUT EGO aside and focus on combining attack vectors, maximizing the impact of each issue, and making sure there are no false claims. Discussions around severity come last. That's our golden rule!
We try to keep our audits and all the bureaucracy around them dead simple. No introductory or close-out calls — we didn't find any value in having these. Unless there's a serious discussion happening, they're usually a waste of time. Instead, at the end of the audit (or at predefined points for longer engagements), each researcher provides their assessment of the work done: 1. On a scale of 1 (likely bugs remain) to 10 (low likelihood of bugs), how confident are you that no serious bugs remain? 2. Are there any contracts or areas you couldn't cover in depth? We collect feedback from every researcher and sum it up into a general assessment for the client. The purpose is two-fold. First, we keep each researcher accountable — they own their work at the end of the audit. The outcome is binary: either the project is ready for deployment, or they should spend more time securing their codebase. Second, the client gets a clear and honest picture of where they stand. Feedback from clients on this process has been very positive, and we'll keep doing it.
1
17
2,096
We try to keep our audits and all the bureaucracy around them dead simple. No introductory or close-out calls — we didn't find any value in having these. Unless there's a serious discussion happening, they're usually a waste of time. Instead, at the end of the audit (or at predefined points for longer engagements), each researcher provides their assessment of the work done: 1. On a scale of 1 (likely bugs remain) to 10 (low likelihood of bugs), how confident are you that no serious bugs remain? 2. Are there any contracts or areas you couldn't cover in depth? We collect feedback from every researcher and sum it up into a general assessment for the client. The purpose is two-fold. First, we keep each researcher accountable — they own their work at the end of the audit. The outcome is binary: either the project is ready for deployment, or they should spend more time securing their codebase. Second, the client gets a clear and honest picture of where they stand. Feedback from clients on this process has been very positive, and we'll keep doing it.
12
2,203
BurraSec retweeted
Centrifuge V3.1 has been under continuous review since August. @burraSec just closed out their third and final report ahead of launch. Security as an ongoing process.
We’ve been working with @centrifuge on a series of security audits since August 2025, ahead of their v3.1 launch. The focus were the cross-chain components of their system. The team has successfully resolved all the issues! Check out the reports: - LayerZero integration: github.com/burrasec/Security… - Initial v3.1 report: github.com/burrasec/Security… - Final v3.1 report: github.com/burrasec/Security…
3
4
38
2,758
I’m excited to announce the security partnership between @burraSec & @0xProbable - the onchain prediction market on the @BNBCHAIN.
2
21
16,743
Crosschain messaging protocol integrations we have reviewed so far with @burraSec: - @LayerZero_Core - @axelar - @AcrossProtocol - @wormhole - @RelayProtocol - @chainlink CCIP - @eco - @gardenfi Many more to come, keep an eye on our auditing portfolio page github.com/burrasec/Security…
8
8
64
4,347
Privacy is back in mainstream crypto, and @zama is one of the biggest innovators in this space. I'm proud to announce a security partnership between @burraSec and @zama!
6
2
39
3,674
Starting the week strong by reviewing @RelayProtocol integration that the team at LI.FI has built!
If you’ve ever sent tokens across chains, there’s a 99.99% chance you’ve interacted with LiFi. They’re the powerhouse DEX and bridge aggregator across a plethora of chains. I’m thrilled to announce a security partnership between @burraSec and @lifiprotocol. We’ll be reviewing ongoing changes to their system to ensure top-notch security!
1
1
16
2,572
We're starting a new security review with our friends @centrifuge today. It's a PR review for their LayerZero integration!
13
2,190
Check out the latest podcast episode of THE NETWORK PODCAST with @Montyly! Josselin is a leading expert in web3 security. He’s built security tools, guidelines, and influenced the direction of the web3 security space through his work at Trail Of Bits. topics: - Josselin’s background - Web2 vs Web3 security - Scaling Trail Of Bits - Slither - The role of AI in security - Static analysis vs LLMs - Open source tools and marketing - Evaluating blockchain security maturity - Tools and techniques projects should adopt to make their codebase resilient - Security review vs audit - Attracting researchers into the space - Starting a web3 security agency - Traits that make a great security researcher - Favorite books / Zero to One | The Coaching Habit YouTube link below
2
2
17
4,683
BurraSec retweeted
Intents are one of the strongest contenders for driving Web3 mass adoption. But how exactly do they remove UX complexity? How can they abstract away all the cross-chain interactions and logic? Here’s a sketch I made to illustrate the journey of an intent. Huge thanks to @burraSec and @octane_security teams for reviewing and sharing their feedback. Shout out to @windhustler for the insights!
7
11
58
5,603
BurraSec retweeted
Staking has launched on app.remilux.xyz Lock your Remilux. Earn Aura. Compete for prizes. 90d Lock — Eligible for Milady raffle in 10 days 60d Lock — Win exclusive 1/1 Remilux 30d Lock — Raffles include Common, Uncommon & Rare Remilux Security is a top priority. We engaged @octane_security to provide an AI-powered security analysis of the codebase along with a manual audit. @burraSec also provided a manual audit by @windhustler.
19
14
76
4,904