We read the code that holds real value.
Independent, AI-augmented security research and coordinated disclosure for open-source wallets, Lightning, and the infrastructure people trust with their money.
A value the device never sees, reaching the signer — a rogue counterparty could redirect the output while every on-device check still passes. Representative of what we find; sanitized here, disclosed privately to the maintainer.
We audit the software people put money behind — and hand the fix to the people who own it.
Source-level review of wallets, hardware-wallet firmware, Lightning nodes, and the key-management and signing paths that decide whether funds stay yours. Breadth from automation, depth from a human confirming every finding against the real code before it leaves the door.
Four rules we don't bend.
Confirmed, not claimed
Every finding is reproduced against the actual source before it's sent. No speculation dressed up as a report.
We report what holds
A weak or already-known issue stays in the drawer. One report we can defend beats ten that waste your triage.
Maintainer first, always
Findings go privately to the team or program that owns the code. Nothing goes public ahead of a fix.
Plain about the method
Our research is AI-augmented and we say so, openly, in every report. Transparency is part of the work.
Where a missing check quietly becomes someone's lost funds.
Ship a wallet? Run a program? Let's talk.
Reports, questions, and coordinated-disclosure inquiries. PGP key on request.