How I work with you
Engagement 1
Readiness Review
A fast, senior check of whether your codebase is ready to be audited
so your audit budget goes toward finding real bugs, not toward
flagging missing tests. For teams preparing for an audit.
Scope and pricing
- Scope
-
Test suite, invariants, architecture, scope readiness,
documentation, and low-hanging risks.
- Deliverable
-
Written readiness report with prioritized, actionable
recommendations.
- Benefits
-
Credited in full against a founder-led audit booked within 60
days.
- Timeline
- 3 working days.
- Price
- Fixed fee of $4,500.
This tells you what to fix before a deeper review, at a fraction of
the cost.
Engagement 2
Founder-Led Audit
A deep manual review led by Joe Stakey. I combine
automated tooling with the reasoning and whitehat instinct that uncovered bugs in protocols already audited by top-tier firms. Every confirmed finding ships with a working proof of concept, so the
fix is easy to verify.
Scoped to your full protocol, or focused on a single high-risk module.
Scope and pricing
- Scope
-
Full protocol, or one critical module. Includes threat modeling
and architecture review for pre-launch engagements.
- Deliverable
-
Severity-rated findings report, each finding with a working PoC
and clear remediation guidance. Fix verification on remediated
findings included.
- Timeline
-
Confirmed at scoping. Typical timelines:
- Full protocol: 2-8 weeks.
- Single module: 1-2 weeks.
- Price
-
Scoped per engagement, on codebase size, complexity, and
timeline. For larger or higher-risk scopes, a second senior
reviewer provides independent, four-eyes coverage.
The full weight of a top-ranked whitehat on the code that holds your
users' funds.
Engagement 3
Continuous Retainer
Protocols that ship continuously cannot realistically audit every
release. The conventional alternative, annual audits from rotating
teams, leaves months of unaudited code in production and forces
reviewers to re-learn your protocol every time.
A retainer gives you ongoing senior review against a codebase. The
reviewer who reads your code today is the same reviewer six months
from now. Context compounds.
Scope and pricing
- Scope
-
Diff and PR review against the audited codebase, architecture
consultation on new features, security advisory. Includes a
first-month onboarding deep-dive: protocol architecture, threat
model, prior audit findings review, and identification of the
highest-risk surfaces.
- Deliverable
-
Continuous PR review with SLA:
- Priority review: within 4 business hours
- Standard: 1 business day
Direct Telegram or Slack channel.
- Benefits
-
Priority scheduling on other engagements. 20% discount on a full
audit commissioned within 6 months.
- Timeline
-
Continuous. Month-to-month, 30 days' notice, minimum initial
term 3 months. Unused capacity rolls one month.
- Price
- From $6,000 per month, scoped to capacity.
- Not included
-
Full security audits of major new modules, incident response
beyond initial triage, and new-chain deployments. Each scoped
separately.
Best for live protocols shipping every few weeks, post-launch teams
between major audits, and protocols wanting a second senior partner
alongside their annual large-firm audit.
Methodology
Many audits sit somewhere on a spectrum from "senior manual read" to
"automated tooling pass." Both alone leave gaps. I run a layered process
where each stage catches what the previous one misses, anchored to a
curated catalog of exploit patterns I maintain across protocol types.
What I bring to a review
I have reviewed protocols across most DeFi categories. Lending, vaults,
AMMs, perps, derivatives, bridges, yield, liquid staking, cross-chain
messaging, appchain infrastructure. That experience compounds into a
catalog of failure modes, organized by protocol type, that shapes how I
approach a new codebase.
- Sharper scoping. Before kickoff, I map your codebase to
the failure modes I have seen in this protocol category — where value flows
in and out, which invariants can drift, which edges past incidents have
exploited. The review starts where the risk is.
- Findings anchored to precedent. Where a finding maps to
a real-world incident, the report cites it. Your engineers don't just see
"this is wrong": they see the same class of bug behind past protocol losses
in this category, and why yours is exposed to it.
- Better remediation. I have watched dozens of remediation
attempts ship — some hold, some fail under adversarial conditions. My guidance
draws from what actually worked in the real market, not from textbook patterns.
A curated public subset of the catalog is open in our
research section.
The review process
Every engagement runs through five stages, tightened over years of
bounty and audit work.
- Scoping and threat model. Docs, deploy scripts, the diff
since last audit. Trust boundaries, privileged actors, upgrade paths, external
dependencies.
- Automated static pass. Third party and custom detectors.
Clears known anti-patterns before deep review begins.
- Manual deep review. The core of the engagement. Reasoning
about invariants and edge cases, with LLM assistance for candidate invariants
and attack hypotheses.
- Fuzzing and symbolic checks. Invariants from stage 3 tested
mechanically. Broken properties feed back into stage 3 — the highest-impact
findings usually surface here.
- Triage, PoC, report. Every finding ships with a working
proof-of-concept. No PoC, no finding.
How an engagement runs
Founder-Led Audit
- First contact and scoping.
We walk the codebase and timeline together — a call, a Telegram thread,
whichever channel you prefer. I ask what you're building, what worries you,
what deadlines you're working against. If it's a fit, we move to a signed
NDA and I look at the code in scope.
- Quote.
Based on scope, complexity, and timeline, I send a proposal with fixed price
and dates. No obligation to accept.
- Kickoff. I begin the deep read against the agreed scope,
identifying the highest-risk surface first so review time goes where it
matters. Proof of Concepts are developed for confirmed issues. Findings
are filed live in a private repo as I go, with no report-dump at the end.
- Mid-review sync. A checkpoint on findings and direction,
so nothing surprises you in the final report.
- Draft report. Severity-rated findings, each with a PoC
and remediation guidance.
- Fix period. Your team remediates; I'm available for questions.
- Fix verification. I re-review the fixes, confirm they hold,
and check for regressions or partial mitigations.
- Final report. Clean, published to your standard. Sanitized
and public only with your explicit consent.
Readiness Review
Scoping, fixed quote, 3 working days of review with questions handled
async, written report delivered.
Retainer
Starts with an onboarding deep-dive into the protocol architecture,
threat model, prior audit findings, and highest-risk surfaces.
From there, PR review, and security advisory. You get priority
scheduling and a 20% discount on full audits.