ANALyzer69000 Security audits
12 audits in flight · 3 closing this week

Audits that read like
attack reports

Same forensics engine that powers Analyzer69000 — turned on your stack. Web, Web3, AI agents. Evidence-backed, retest included, paid in SOL or USDC.

9 chainsSolana + 8 EVM
OWASP · ASVSWSTG mapping
3–10 daysScoped before quote
SOL · USDCOn-chain receipt
01

Apps · APIs · cloud

Auth, payments, roles, uploads, business logic, abuse paths. SAST + dependency review default; active testing only inside signed staging scope.

Auth · CSRF · CORSSSRF · IDORUpload surfaceCloud configSupply chain
02

Smart contracts & dApps

EVM Solidity / Vyper. Solana Anchor & native programs. Launch mechanics, ownership, liquidity, admin power, deployer history, holder topology.

EVM + SVMLP burn / lockBundle & deployerWallet flowSignature surface
03

AI agents & workflows

Tool-call permission map, indirect prompt injection paths, PII leak, approval gates, rollback, handoff. Built by people who actually ship agents.

Tool permission mapPrompt injectionPII leakHuman-in-loopRollback
04

Boardroom-readable. Engineer-actionable.

Leadership gets the risk story. Developers get reproduction notes, traces, fix steps, and retest criteria. We down-rank claims we can't prove instead of padding the count.

ConfirmedLikelyInformationalNeeds validation
05

Pay only after we agree on scope.

No surprise wallet pops. We agree on scope, then issue a portal invoice. Each payment uses a 15-min intent + unique reference, verified on-chain before marking paid. Same flow as our boost checkout.

USDC stableSOL native15-min intent TTLReplay-protectedRetest included
Pricing · pay after scope

Pick the depth.

Same evidence-backed pipeline. Bigger tiers buy more depth, more chains, more time.

Surface
Single target
$2.5KUSDC · SOL

One app, contract, or agent flow. Pre-launch sanity pass.

  • SAST + dependency review
  • Top-10 risk class screen
  • Plain-English summary
  • 3-day turnaround
Pick surface →
Most picked
Standard
$8KUSDC · SOL

Full forensics-grade review across code, infra, on-chain and off-chain surfaces.

  • Code · infra · on/off-chain
  • Manual exploit hypothesis
  • Holder + bundle topology
  • Severity-ranked report + retest
Pick standard →
Pre-launch
Deep · Launch
$20K+USDC · SOL

Multi-contract, agent supply chain, deployer history, post-launch retest.

  • Multi-chain · multi-contract
  • Wallet flow + admin power
  • Public report (optional)
  • Post-launch retest included
Pick deep →
Common questions

What teams ask before signing.

Do you need access before I pay?
No. Intake is free. We agree on scope, exclusions, and authorization first; only then do we issue an invoice in your portal. Active testing only starts after payment.
Will you publish what you find?
Default is private. Reports stay inside the org-scoped portal. Public reports are opt-in per engagement and only after you sign off.
What if you don't find anything?
You still get the report. Documenting what was tested with evidence is part of the deliverable — we don't pad findings to look busy.
How is my code stored and protected?
Uploads go to encrypted, org-scoped storage that only you and the assigned analyst can access. Files are tied to your engagement only — not visible to other clients, not used for anything outside your review, and deleted on completion if you ask. Auditor access is logged.