Skip to content

Writing

Notes on smart contract security

Written when there is something specific worth writing up, not on a schedule. Mostly about how live protocols actually get drained, and what small teams can do between audits.

Security practice6 min read

Why audited code still gets exploited

Nobody touched the Curve pools for two years. The Vyper compiler bug that drained them was found anyway. Your attack surface moves even when your code doesn't.

Read →

Get your next deploy reviewed before it goes live

Send me your repo, your chain, and roughly how often you ship contract changes. You get a monthly number and a start date back, usually the same day.

No obligation, and no sales sequence. Ongoing Review runs for a 3-month minimum, then month to month with 30 days' notice.