Client: "We've made some small changes to the contract, shouldn't affect the audit scope"
The small change:
- added 2000 lines of code
- new oracle
- new bridge
- upgradeable now
Bridges are still where the money leaks. Message verification, relayer trust, replay across chains. If you can't explain who can forge a message and why they can't, you haven't finished the review.
Want to connect with more auditors in our circle 🫡
If you do security reviews, comment below and tell us your main stack (Solidity, Rust, Move, something else)?
Building on Robinhood Chain? 🤔
Almost no protocols running bug bounties.
If you’re launching on a new chain, security should be part of the launch.
Fortunately, there have been no protocol hacks on RH Chain so far.
We’re working with teams across the eco to keep it that way.
AI finds the bugs that look like bugs. Auditors still find the ones that look like features. Use both, trust neither blindly, and keep a human on the final sign-off.
The most expensive line in a smart contract is usually the one the dev called "just a helper". Untested, unaudited, called from three places, holding the whole invariant together.
Invariant tests catch what unit tests can't: the bug that only shows up after 400 random calls in an order nobody wrote down. If a protocol ships without a fuzz suite, that's a finding on its own.
New audit in the Hyperliquid ecosystem: @pear_protocol 🤝
We reviewed their ERC-4626 vault and the off-chain logic behind it. Vault accounting, share math, access control, and how off-chain and on-chain interact.
Reports are out. Great working with the Pear team👇
1) github.com/shieldify-securit…
2) github.com/shieldify-securit…
The exploit you'll read about next month is sitting in a repo right now, deployed, unaudited, TVL climbing. Someone is going to find it. Might as well be you, on the right side of it.
How should a new, self-funded protocol approach security?
1. Internal audit
2. Document everything + fuzz test
3. Run multiple AI agents, triage findings
4. Get our experienced researchers to handle the manual audit
5. Fix everything & deploy safely
Nobody gets good at auditing by reading about auditing. You get good by staring at code for six hours, finding nothing, and coming back tomorrow. The finding is on day four. Keep going.
Want to level up your auditing? Read real reports. 160+ public security reviews from @shieldifysec across Solidity, Rust, Move, covering Account Abstraction, RWAs, DEXes, LPs, GameFI, Launchpads and more.
github.com/shieldify-securit…
A duplicate report means you were right, just not first. That's closer than most ever get. Skill isn't your bottleneck. Speed is.
Pick a strategy, optimize ruthlessly for speed, and never "just try" 👍