Blindage

Blockchain

Blockchain security

We review smart contracts and the software around wallets and keys, and we reverse the malware that targets them.

The rules are the same as on every other line of work. The owner authorizes the testing, and we never sell cheats or bypasses.

Lines

What we test

Smart contract review

Contract source, or bytecode when there is no source. We check access control, external calls, arithmetic and casts, price inputs, signature handling, and the storage layout of upgradeable contracts.

reentrancy access control oracle manipulation proxy storage

Wallet drainers and crypto-stealers

Malware that goes after wallets and keys. We reverse the loader and the payload: clipboard address swapping, browser extension injection, seed phrase and keystore theft, and approval or permit phishing kits. Packers and VM-based obfuscation get the same treatment as in any other sample.

clipboard hijack seed phrase theft permit phishing

Web3 and on-chain games

Games that tie items, currency, or login to a wallet. We test where the client, the game server, and the chain disagree about who owns what, and whether a cheat can reach the signing flow, the wallet, or the in-game economy.

client trust item duplication signing flow

Transaction and bytecode analysis

Tracing transactions and decompiling EVM bytecode to explain what a contract or an attack did. We replay on a forked chain, so nothing touches live funds.

EVM bytecode transaction tracing forked chains

Key and signing infrastructure

How keys are generated, stored, and used to sign: hot wallets, signing services, and the code around them. We read the implementation and test what an attacker with a foothold on the host could reach.

key storage signing services host compromise

Reference

What we look for in contracts

Reentrancy
A contract makes an external call before it updates its own state. The callee re-enters and acts on the stale state.
Access control
A privileged function, such as upgrade, mint, or withdraw, can be called by an address that should not be able to.
Arithmetic and casts
An overflow, an underflow, or a silent truncation in a cast changes a balance or a price.
Oracle manipulation
The contract reads a price from a source that one transaction can move, such as a thin pool, and then acts on it.
Signature replay
A signed message is accepted twice, or on another chain, because it does not bind a nonce and a chain id.
Proxy storage collision
An upgradeable proxy and its implementation use the same storage slot for different variables.

Method

How we work on-chain

Static review

We read source and bytecode without deploying anything, and we decompile bytecode when there is no source.

Runtime on forked chains

We run attack paths against a local or forked chain, so a proof of concept shows the failure without spending real funds.

Malware in emulated environments

Wallet-stealer samples run in an emulated environment, the same way we handle any other hostile sample, with our in-house tools.

Scope and authorization

The owner authorizes the work in writing. For contracts, the scope names the addresses, the networks, and the commit or build we test.

You get a written report, proof-of-concept tests when the rules of engagement allow them, and a retest after you fix. Duration is set during scoping.

We only test with the owner's authorization. We never sell cheats or bypasses.

To start, send a scoping note. The other lines of work are on the services page.