WEB3 PENTESTING

White-box and black-box pentesting for Web3 applications

We offer white-box and black-box testing based on each project’s needs. Our research examines the large, underexplored Web2 attack surfaces that remain in many Web3 applications.

$36.82B+ On-chain TVL secured$1.00B+ Vulnerabilities patched66% Core-severity findings

WHAT YOU GET

Pentesting backed by published research

Different systems call for different techniques. We pick the mix that fits yours.

Snaps sandbox research

We’ve done extensive research into MetaMask’s Snaps sandboxing environment, and partner with MetaMask for ongoing security research.

Snap audits

We’ve audited more than half a dozen Snaps from teams like Nocturne, Bayan, Drift, and Algorand.

Web2 bugs in web3 apps

Our “Web2 bug repellant instructions” post walks through web2 bugs found in web3 apps.

Authentication flaws

Our research on subverting Web2 authentication in Web3 covers OAuth logic exploits and Supabase misconfigurations.

WHY IT MATTERS

Web2 bugs live inside Web3 apps

  1. Testing scoped to each project’s needs, white-box or black-box.
  2. Research into the large, underexplored Web2 attack surfaces that remain in many Web3 applications.
  3. Published research on a property spoofing vulnerability in the MetaMask Snaps sandboxing layer.

READY TO START

Pentest the Web2 surface of your Web3 app

We work with leading teams across multiple blockchains. Put the same collaborative approach to work on your application.

Get an audit