SuperDroidsSuperDroids
Services

Senior security review for live protocols — in days, not months.

Three products. One free way in. Every price is on this page.

Start here · $0

Find out who can move your money.

A one-page map of your protocol's control plane, built from public chain data. Send an address; it comes back within 48 hours.

Who it's for. Any live protocol with an owner, a pauser, or an upgrade path.

Why free. It costs you nothing to verify we're real. The snapshot is the audition.

What you get
  • Every owner, role, and signer — thresholds, timelock delays, upgrade authority, emergency powers.
  • Two or three flagged findings, each tied to a real incident pattern.
  • One recommended next step.

Bring a contract address and chain. 48-hour turnaround.

54%

of 2025's crypto losses came from access-control failures — not code bugs (~13%).

Hacken 2025 Web3 Security Report

$577M

lost in April 2026 alone to signing and key compromise — Drift Protocol and KelpDAO.

TRM Labs

~1%

of upgradeable contracts ever upgrade. Your code froze at launch. Your keys, roles, and signers didn't.

arXiv 2406.05712

Flagship · Fixed price
$7,500 · 2 weeks

Your code got audited. Your keys didn't.

Access-control failure — compromised keys, deceived signers, over-powered roles — caused over half of last year's crypto losses. Audits don't cover that layer. This review does.

Who it's for. Live protocols with a treasury, TVL, or privileged roles — especially when investors and integrators start asking operational-security questions.

What you get
  • The full control-plane audit. Every role and permission, upgrade authority, timelock config vs. stated policy, emergency powers — and which privileged transactions executed.
  • The signing-operations review. Two interviews with your signers — never your devices, never your keys. Transaction flow, blind-signing exposure, multisig configuration, key handling, monitoring.
  • Findings with incident receipts. Every finding rated and tied to the incident class it matches. Fixes split into this-week wins and structural work.
  • A transaction-verification checklist your signers will actually use.
  • A SEAL posture page. Where you stand against the Security Alliance's multisig and treasury frameworks, control by control.
  • A saved baseline for quarterly re-checks.
Timeline
  1. Day 1Kickoff (30 min)
  2. Days 1–4On-chain mapping
  3. Days 4–7Signer interviews (2 × 60 min)
  4. Day 10Report + walkthrough call
What it isn't

Not a code audit. Not device forensics or phishing simulation. Not a certification — no honest party sells one.

30 minutes to scope. We'll ask who signs what.

The Access Re-check — $2,500/quarter. Signers rotate, roles accumulate, timelocks change. Every quarter we diff your control plane against baseline and walk you through it in 30 minutes. Review clients only.

Fixed prices. 50% to start, 50% on delivery; rush work 100% upfront. NDA signed same day on request.

Shipping something? · Fixed price
From $5,000 · 3–5 days

Senior eyes on the diff before it hits mainnet.

An upgrade, an integration, or your audit fix-set — reviewed against the audited baseline. A straight answer: what did this change re-open, and is it safe to ship?

Who it's for. Teams with a deploy date: fix verification, a queued upgrade, a new integration, a pre-listing check.

Small

3 business days
$5,000

≤ ~400 changed nSLOC, single module, no new external integrations.

Standard

5 business days
$7,500

≤ ~1,200 changed nSLOC, or full fix-set verification from an audit or contest.

Complex

5 business days
$12,000

New mechanism, oracle or upgrade-path changes, cross-contract surface — scoped same day.

Every tier includes
  • One named senior reviewer who read the code.
  • A PoC or written exploit reasoning per finding — never a scanner dump.
  • A risk-model memo: which audited assumptions the change re-opened.
  • A fix-verification pass within 30 days.
  • A report you can share with integrators.

Rush. 48-hour delivery on Small and Standard at +50%.

What it isn't

Not a full-system audit — a deep review of what changed. If your change outgrows a tier, we'll say so.

Bring the repo or PR link, baseline commit, and deadline — tier confirmed on the call.

The Security Retainer — $7,500/month. Two Release Reviews monthly, privileged-change review before execution, invariant and monitoring upkeep, a quarterly deep-dive, and a direct line. Three-month minimum. Two Standard reviews alone cost $15,000 — if you buy them that often, ask about the retainer.

Fixed prices. 50% to start, 50% on delivery; rush work 100% upfront. NDA signed same day on request.

How we handle your data.

We never touch or request key material, seed phrases, or credentials. Interviews over inspection; engagement notes deleted 30 days after delivery. If anyone claiming to be us ever asks for a key or a signature, it isn't us.

FAQ

Common questions.

Still have a question?

Email me directly and I'll respond within a business day.

Email Robert

Start with the free snapshot.

One page, public chain data, 48 hours. No repo access, no signup.