Security audits for high-assurance digital infrastructure: smart contracts, cryptography, protocols, and key management. Clear findings, open to talk.

Decentralized
1/4 @nullreturn_io completed a security audit of @launchnodes Canton KMS Driver. The reviewed component connects a Canton participant node with Azure Key Vault, and GCP KMS, supporting signing, encryption, and key wrap/unwrap operations without private key export.
1
2
6
265
1/4 @nullreturn_io completed a security audit of @launchnodes Canton KMS Driver. The reviewed component connects a Canton participant node with Azure Key Vault, and GCP KMS, supporting signing, encryption, and key wrap/unwrap operations without private key export.
1
2
6
265
3/4 Our review focused on • Canton KMS Driver API compliance • Azure Key Vault integration • signing flow and input semantics • DER/ASN.1 signature handling • key formats and curve compatibility • exception and retry behavior • RBAC,network controls,and logging assumptions
1
1
44
4/4 For @CantonNetwork infrastructure, security is not only about the code path. It is also about how keys are managed, how failures are handled, and how the component behaves under real production constraints.
1
15
NullReturn recently completed a private security review of a Canton KMS driver integration. The report remains confidential and the client is undisclosed, but the work reflects where we are expanding: high-assurance infra, cryptographic boundaries, and key management systems.
1
2
373
This type of review goes beyond standard smart contract auditing. It includes signing flows, KMS integration, API behavior, failure handling, deployment assumptions, and the trust boundary between protocol infrastructure and cloud key management.
1
1
35
We help teams secure systems where correctness and trust boundaries matter. Working on Canton, KMS integrations, protocols, smart contracts, or applied cryptography? We’re open to a conversation.
1
18
Using a crypto library does not automatically make a system cryptographically correct. Most crypto bugs happen in the integration layer: what gets signed, how keys rotate, how signatures are encoded, and how KMS behavior maps to production. Full post on LinkedIn⬇️:
1
2
69
NullReturn × 2xSwap Audit 1/4 Audit Release The @nullreturn_io team has completed a full smart contract security audit for @2xswap — a liquidation-free 2x leveraged swap protocol built on Ethereum.
2
2
6
523
3/4 Why this matters Protocols with leverage and pooled liquidity face unique attack surfaces: • First-depositor & rounding attacks • Oracle manipulation scenarios • Pool insolvency under extreme conditions • Gov & fee control risks
1
4
91
Audit outcome 📊 47 total findings ✅ 100% of Critical & High issues resolved Thanks to the 2xSwap team for strong collaboration and a security-first approach. 📄 Read the full report: 👉 @2xswap
4
80
We are proud of your trust!
2xSwap has been independently audited by Null Return @nullreturn_io. 35+ security fixes applied. Every critical and high severity finding resolved before mainnet launch. What this means for you: • Your deposits are protected by battle-tested OpenZeppelin standards • Price feeds are validated through Chainlink with built-in staleness checks • The protocol can automatically pause itself if it detects abnormal conditions • No admin keys exist. No one — including us — can touch your funds. The contracts are fully immutable, open-source, and verified on Etherscan. 2xswap.gitbook.io/2xswap-doc…
2
2
78
Null Return retweeted
Audits from BlockSec, 0xCommit, and Nullreturn hit different. Confidence matters in cross-chain.
1
2
77
Null Return retweeted
At DZap, security is not an add-on. It is built into the core Our smart contracts are audited by @BlockSecTeam, @nullreturn_io & @0xCommitAudits, helping ensure every swap and bridge interaction is reliable, safe, & seamless across chains. Try it now at DZap.io
30
3
24
4,492
Null Return retweeted
DeFi hacks have changed a lot in the last five years. If you’re building today, you need to understand how attacks work now, and where they actually show up in code and tooling. We’re hosting a livestream on modern DeFi attacks, including CPIMP attacks and GlassWorm. More details and registration below 👇
1
8
33
5,045
Web3 hacks in 2025–2026 taught us one thing: the most dangerous attacks don’t look like hacks anymore 🧵👇
1
1
52
5/6 Hard truth: Security ≠ “we passed an audit”. It’s: • audits • ops security • infra hardening • team awareness • continuous monitoring
1
1
38
6/6 Web3 is growing up. And growth always punishes negligence. If you’re building in Web3 — security is no longer optional.
1
35