# Eraikey Labs > Founder-led smart contract security audits by a whitehat researcher with public critical findings on Immunefi and multiple top-10 finishes on Sherlock and Code4rena. Covering EVM, Solana, Starknet, and Cosmos. ## Services - [Services](/services): Full-protocol audits, 3-day readiness reviews, and continuous security retainers - [Methodology](/services#methodology): Layered process combining manual review, static analysis, LLM-assisted deep review, and fuzzing - [Contact](/contact): Request a security review or introductory call ## Public work - [Proof](/proof): Verifiable findings, contest placements, and disclosed bounties - [Research](/research): Vulnerability patterns, security writeups, and research posts ## Research writeups - [Extra Finance rebasing accounting bug](/research/writeups/extra-finance-rebasing-staking-bug): High-severity staking accounting bug where rebasing tokens caused yield accrual to stop - [MUX low-level call liquidation issue](/research/writeups/mux-low-level-call-liquidation): Critical low-level call that could prevent repayments to lending pools - [Oasys ERC-721 bridge access control](/research/writeups/oasys-erc721-bridge-access-control): Critical missing ownership check enabling arbitrary NFT theft ## Vulnerability pattern catalog - [ERC-4626 share inflation via initial donation](/research/patterns/vaults/erc4626-donation-attack): Classic vault first-depositor attack - [Compound vs linear interest accrual mismatch](/research/patterns/lending/compound-vs-linear-interest-accrual): Lending accounting drift - [Cross-chain message replay via missing source-chain ID](/research/patterns/bridges/cross-chain-message-replay): Bridge replay surface across deployments ## About - [About](/about): Founder, background, and how the firm works