Services

Deep senior security reviews, reasoning through the logic and economic paths that automated tooling and rushed audits miss. Coverage from pre-audit readiness through the review itself into continuous work after launch.

How I work with you

Engagement 1

Readiness Review

A fast, senior check of whether your codebase is ready to be audited so your audit budget goes toward finding real bugs, not toward flagging missing tests. For teams preparing for an audit.

Scope and pricing
Scope
Test suite, invariants, architecture, scope readiness, documentation, and low-hanging risks.
Deliverable
Written readiness report with prioritized, actionable recommendations.
Benefits
Credited in full against a founder-led audit booked within 60 days.
Timeline
3 working days.
Price
Fixed fee of $4,500.

This tells you what to fix before a deeper review, at a fraction of the cost.

Engagement 2

Founder-Led Audit

A deep manual review led by Joe Stakey. I combine automated tooling with the reasoning and whitehat instinct that uncovered bugs in protocols already audited by top-tier firms. Every confirmed finding ships with a working proof of concept, so the fix is easy to verify.

Scoped to your full protocol, or focused on a single high-risk module.

Scope and pricing
Scope
Full protocol, or one critical module. Includes threat modeling and architecture review for pre-launch engagements.
Deliverable
Severity-rated findings report, each finding with a working PoC and clear remediation guidance. Fix verification on remediated findings included.
Timeline
Confirmed at scoping. Typical timelines:
  • Full protocol: 2-8 weeks.
  • Single module: 1-2 weeks.
Price
Scoped per engagement, on codebase size, complexity, and timeline. For larger or higher-risk scopes, a second senior reviewer provides independent, four-eyes coverage.

The full weight of a top-ranked whitehat on the code that holds your users' funds.

Engagement 3

Continuous Retainer

Protocols that ship continuously cannot realistically audit every release. The conventional alternative, annual audits from rotating teams, leaves months of unaudited code in production and forces reviewers to re-learn your protocol every time.

A retainer gives you ongoing senior review against a codebase. The reviewer who reads your code today is the same reviewer six months from now. Context compounds.

Scope and pricing
Scope
Diff and PR review against the audited codebase, architecture consultation on new features, security advisory. Includes a first-month onboarding deep-dive: protocol architecture, threat model, prior audit findings review, and identification of the highest-risk surfaces.
Deliverable
Continuous PR review with SLA:
  • Priority review: within 4 business hours
  • Standard: 1 business day
Direct Telegram or Slack channel.
Benefits
Priority scheduling on other engagements. 20% discount on a full audit commissioned within 6 months.
Timeline
Continuous. Month-to-month, 30 days' notice, minimum initial term 3 months. Unused capacity rolls one month.
Price
From $6,000 per month, scoped to capacity.
Not included
Full security audits of major new modules, incident response beyond initial triage, and new-chain deployments. Each scoped separately.

Best for live protocols shipping every few weeks, post-launch teams between major audits, and protocols wanting a second senior partner alongside their annual large-firm audit.

Methodology

Many audits sit somewhere on a spectrum from "senior manual read" to "automated tooling pass." Both alone leave gaps. I run a layered process where each stage catches what the previous one misses, anchored to a curated catalog of exploit patterns I maintain across protocol types.

What I bring to a review

I have reviewed protocols across most DeFi categories. Lending, vaults, AMMs, perps, derivatives, bridges, yield, liquid staking, cross-chain messaging, appchain infrastructure. That experience compounds into a catalog of failure modes, organized by protocol type, that shapes how I approach a new codebase.

  • Sharper scoping. Before kickoff, I map your codebase to the failure modes I have seen in this protocol category — where value flows in and out, which invariants can drift, which edges past incidents have exploited. The review starts where the risk is.
  • Findings anchored to precedent. Where a finding maps to a real-world incident, the report cites it. Your engineers don't just see "this is wrong": they see the same class of bug behind past protocol losses in this category, and why yours is exposed to it.
  • Better remediation. I have watched dozens of remediation attempts ship — some hold, some fail under adversarial conditions. My guidance draws from what actually worked in the real market, not from textbook patterns.

A curated public subset of the catalog is open in our research section.

The review process

Every engagement runs through five stages, tightened over years of bounty and audit work.

  1. Scoping and threat model. Docs, deploy scripts, the diff since last audit. Trust boundaries, privileged actors, upgrade paths, external dependencies.
  2. Automated static pass. Third party and custom detectors. Clears known anti-patterns before deep review begins.
  3. Manual deep review. The core of the engagement. Reasoning about invariants and edge cases, with LLM assistance for candidate invariants and attack hypotheses.
  4. Fuzzing and symbolic checks. Invariants from stage 3 tested mechanically. Broken properties feed back into stage 3 — the highest-impact findings usually surface here.
  5. Triage, PoC, report. Every finding ships with a working proof-of-concept. No PoC, no finding.

How an engagement runs

Founder-Led Audit

  1. First contact and scoping. We walk the codebase and timeline together — a call, a Telegram thread, whichever channel you prefer. I ask what you're building, what worries you, what deadlines you're working against. If it's a fit, we move to a signed NDA and I look at the code in scope.
  2. Quote. Based on scope, complexity, and timeline, I send a proposal with fixed price and dates. No obligation to accept.
  3. Kickoff. I begin the deep read against the agreed scope, identifying the highest-risk surface first so review time goes where it matters. Proof of Concepts are developed for confirmed issues. Findings are filed live in a private repo as I go, with no report-dump at the end.
  4. Mid-review sync. A checkpoint on findings and direction, so nothing surprises you in the final report.
  5. Draft report. Severity-rated findings, each with a PoC and remediation guidance.
  6. Fix period. Your team remediates; I'm available for questions.
  7. Fix verification. I re-review the fixes, confirm they hold, and check for regressions or partial mitigations.
  8. Final report. Clean, published to your standard. Sanitized and public only with your explicit consent.

Readiness Review

Scoping, fixed quote, 3 working days of review with questions handled async, written report delivered.

Retainer

Starts with an onboarding deep-dive into the protocol architecture, threat model, prior audit findings, and highest-risk surfaces.

From there, PR review, and security advisory. You get priority scheduling and a 20% discount on full audits.

Want to discuss a project?