Home

Awesome

spearbit

<p align="center"> Request an audit by filling <a href="https://airtable.com/shrkxrtMKYJkLaXhT"> this form</a> or learn more at <a href="https://spearbit.com">Spearbit.com</a> </p> <br> <h1 class="center" style=""> Public Portfolio </h1>

Spearbit is a decentralized network of expert security engineers offering reviews and other security related services to Web3 projects with the goal of creating a stronger ecosystem. Our network has experience on every part of the blockchain technology stack, including but not limited to protocol design, smart contracts and the Solidity compiler. Spearbit brings in untapped security talent by enabling expert freelance auditors seeking flexibility to work on interesting projects together.

<br> <h3><ins>Table of Contents</ins></h3> <hr> <br>

Engagements

Note: All reports herein are published with the consent of our clients.

ProtocolDateReportTypeResearchers involved
Tradable FinanceJuly 2024:page_facing_up:DeFiLSR-Christoph Michel <br> LSR-0xIcingdeath <br> SR-Akshay Srivastav <br> SR-Cergyk
CentrifugeJuly 2024:page_facing_up:DeFiLSR-Gerard Persoon <br> LSR-Leastwood <br> SR-Devtooligan <br> ASR-Jonatas Martins
OverprotocolJune 2024:page_facing_up:Infrastructure, NodeLSR-Dtheo <br> LSR-Jtraglia <br> SR-Shotes
Pendle FinanceJune 2024:page_facing_up:Yield, DeFiLSR-hyh <br> LSR-Kurt Barry <br> SR-Xiaoming90 <br> ASR-Mario Poneder
BaseJune 2024:page_facing_up:Proofs, DisputesLSR-Xmxanuel <br> LSR-Desmond Ho <br> SR-0xLadboy <br> SR-Cryptara
DelvJune 2024:page_facing_up:DeFi, YieldLSR-Saw-Mon and Natalie
FastlaneJuly 2024:page_facing_up:DeFi, MEVLSR-Gerard Persoon <br> LSR-Riley Holterhus <br> SR-Blockdev
EulerApril 2024:page_facing_up:DeFiLSR-Christoph Michel <br> LSR-Emanuele Ricci <br> SR-M4rio.eth <br> JSR-Christos Pap <br> JSR-David Chaparro
EulerApril 2024:page_facing_up:DeFiLSR-Christoph Michel <br> LSR-Emanuele Ricci <br> SR-M4rio.eth <br> JSR-Christos Pap <br> JSR-David Chaparro
EulerApril 2024:page_facing_up:DeFi, OracleLSR-Christoph Michel <br> LSR-Emanuele Ricci <br> SR-M4rio.eth <br> JSR-Christos Pap <br> JSR-David Chaparro
SizeApril 2024:page_facing_up:DeFi, LendingLSR-hyh <br> LSR-Leastwood <br> SR-Slowfi <br> ASR-0x4non
DelvMarch 2024:page_facing_up:DeFi, YieldLSR-Saw-Mon and Natalie <br> LSR-Christoph Michel <br> SR-M4rio.eth <br> JSR-David Chaparro
DelvFebruary 2024:page_facing_up:DeFi, YieldLSR-Saw-Mon and Natalie <br> LSR-Christoph Michel <br> SR-M4rio.eth <br> JSR-David Chaparro
Huma FinanceJanuary 2024:page_facing_up:Lending, DeFiLSR-Leastwood <br> LSR-Saw-Mon and Natalie <br> SR-Kankodu <br> ASR-Jonatas Martins
AxiomDecember 2023Data availability, ContractsLSR-Desmond Ho <br> LSR-Riley Holterhus <br> SR-Blockdev <br> JSR-Lucas Goiriz <br> JSR-David Chaparro
LlamaDecember 2023:page_facing_up:Governance, VotingLSR-Noah Marconi <br> SR-Xmxanuel
VelodromeNovember 2023:page_facing_up:DeFi, DEXLSR-D-Nice <br> LSR-Optimum <br> SR-Alex The Entreprenerd <br> ASR-Jeiwan
RedactedNovember 2023:page_facing_up:InfrastructureLSR-Parithosh <br> LSR-Rafael Matias
SphinxNovember 2023:page_facing_up:InfrastructureLSR-Desmond Ho <br> LSR-Saw-Mon and Natalie <br> SR-M4rio.eth <br> JSR-David Chaparro <br> JSR-Sabnock
AxiomOctober 2023Data availability, ZK circuitsLSR-CPerezz <br> LSR-Eduard Sanou <br> SR-Kyle Charbonnet
BrahmaOctober 2023:page_facing_up:DeFiLSR-Saw-Mon and Natalie <br> LSR-Gerard Persoon <br> SR-Xiaoming90 <br> SR-Philogy
AxiomOctober 2023Data availability, ContractsLSR-Desmond Ho <br> LSR-Riley Holterhus <br> SR-Blockdev <br> JSR-Lucas Goiriz <br> JSR-David Chaparro
zkSyncOctober 2023:page_facing_up:ZKLSR-Wilson Nguyen <br> LSR-Nirvan
Liquid CollectiveSeptember 2023:page_facing_up:Liquid Staking, Enterprise Grade Staking<br> LSR-Optimum <br> LSR-Saw-Mon and Natalie <br> SR-Xiaoming90 <br> JSR-Ellahi
AxiomSeptember 2023Data availability, ZK circuitsLSR-CPerezz <br> LSR-Eduard Sanou <br> SR-Kyle Charbonnet
RedactedAugust 2023Web2, Back-EndLSR-Christoph Michel <br> SR-High_byte
RedactedJuly 2023DeFi, Liquid StakingLSR-Rajeev <br> LSR-0x52 <br> SR-Slowfi <br> JSR-Ayeslick
PrimitiveJuly 2023:page_facing_up:DeFi, Portfolio ManagementLSR-Kurt Barry <br> LSR-Christoph Michel
AlchemyJuly 2023Smart Contract WalletLSR-Gerard Persoon <br> LSR-Riley Holterhus <br> SR-Blockdev <br> JSR-Christos Pap
NFTXJuly 2023NFT, AMM and LendingLSR-hyh <br> LSR-Optimum <br> SR-cccz <br> ASR-Jonatas Martins
Liquid CollectiveJuly 2023:page_facing_up:Liquid Staking, Enterprise Grade StakingLSR-Optimum <br> SR-Xiaoming90
AstariaJuly 2023:page_facing_up:NFT, LiquidityLSR-Saw-Mon and Natalie <br> LSR-Jonah1005 <br> SR-Blockdev
BadgerDAOJune 2023DeFi, StablecoinLSR-Leastwood <br> LSR-hyh <br> SR-Emanuele Ricci <br> JSR-Calvin Boehr <br> JSR-Hagrid
DelvJune 2023:page_facing_up:DeFi, YieldLSR-Saw-Mon and Natalie <br> LSR-Christoph Michel <br> SR-M4rio.eth <br> JSR-David Chaparro
FloodJune 2023DeFi, DEX AggregatorLSR-Rajeev <br> LSR-Noah Marconi <br> SR-r0bert <br> JSR-Bahurum <br> JSR-Nicolás Bevilacqua
OpenSeaJune 2023NFT, SeaDropLSR-Saw-Mon and Natalie <br> LSR-Harikrishnan Mulackal
Nouns DAOJune 2023:page_facing_up:NFT, GovernanceLSR-Rajeev <br> LSR-hyh <br> SR-r0bert <br> JSR-Christos Pap <br> JSR-TCHKVSKY
MorphoJune 2023DeFi, Lending and BorrowingLSR-Christoph Michel <br> SR-Emanuele Ricci <br> SR-JayJonah8 <br> JSR-Yldp <br> JSR-EBaizel
Redacted CartelMay 2023DeFi, Bribes Marketplace. SEAL engagementLSR-Optimum <br> LSR-0x52 <br> SR-High_byte <br> JSR-Sabnock <br> JSR-Maxime Viard <br> JSR-David Chaparro
BarnbridgeMay 2023DeFi, Tokenized Risk Protocol. SEAL engagementLSR-Leastwood <br> LSR-Riley Holterhus <br> SR-DefSec <br> ASR-Pashov Krum <br> ASR-0x4non <br> ASR-Jonatas Martins <br> JSR-TheMystery
PrimitiveMay 2023DeFi, Portfolio ManagementLSR-Kurt Barry <br> LSR-Christoph Michel
Liquid CollectiveMay 2023:page_facing_up:Liquid Staking, Enterprise Grade StakingLSR-Saw-Mon and Natalie <br> SR-Xiaoming90
LlamaMay 2023:page_facing_up:DeFi & NFT, GovernanceLSR-Noah Marconi <br> SR-M4rio.eth <br> SR-Xmxanuel <br> JSR-Parth Patel <br> JSR-TheMystery
MorphoApril 2023:page_facing_up:DeFi, Lending and BorrowingLSR-Christoph Michel <br> SR-Emanuele Ricci <br> SR-JayJonah8 <br> JSR-Yldp <br> JSR-EBaizel
KilnApril 2023Liquid Staking, Enterprise Grade StakingLSR-Optimum <br> LSR-Saw-Mon and Natalie <br> SR-Xiaoming90 <br> ASR-0x4non
KilnApril 2023Liquid Staking, Enterprise Grade StakingLSR-Optimum <br> LSR-Saw-Mon and Natalie <br> SR-Xiaoming90 <br> ASR-0x4non
Opensea ProApril 2023NFT, Marketplace AggregatorLSR-Saw-Mon and Natalie <br> LSR-Christoph Michel <br> JSR-Lucas Goiriz <br> JSR-David Chaparro
WaterfallApril 2023NFT, Prediction MarketsLSR-Desmond Ho <br> LSR-Riley Holterhus <br> SR-Csanuragjain <br> JSR-Maxime Viard <br> JSR-Christos Pap
Polygon zkEVM - ProtocolMarch 20231 2 3zkEVMLSR-Alex Beregszaszi) <br> LSR-Andrei Maiboroda <br> LSR-Christian Reitwiessner <br> LSR-(Leo Alt) <br> LSR-Pawel Bylica
Polygon zkEVM - BridgeMarch 2023:page_facing_up:zkEVMLSR-Gerard Persoon <br> LSR-Leastwood <br> SR-Csanuragjain <br> SR-Xiaoming90 <br> ASR-Pashov Krum
Polygon zkEVM - CryptographyMarch 2023:page_facing_up:zkEVMLSR-Wilson Nguyen <br> LSR-Nirvan <br> LSR-Thibaut Schaeffer
PrimitiveMarch 2023:page_facing_up:DeFi, Portfolio ManagementLSR-Kurt Barry <br> LSR-Christoph Michel <br> SR-M4rio.eth <br> JSR-Sabnock
Liquid CollectiveMarch 2023:page_facing_up:Liquid Staking, Enterprise Grade StakingLSR-Optimum <br> LSR-Saw-Mon and Natalie <br> SR-Xiaoming90 <br> JSR-Ellahi <br> JSR-Matt Eccentricexit
LI.FIMarch 2023:page_facing_up:Aggregator, Bridge & DEXLSR-Gerard Persoon <br> LSR-Jonah1005 <br> SR-DefSec <br> SR-Blockdev
MorphoFebruary 2023DeFi, Lending and BorrowingLSR-Christoph Michel <br> SR-Emanuele Ricci <br> SR-JayJonah8 <br> JSR-Yldp <br> JSR-EBaizel
VelodromeFebruary 2023:page_facing_up:DeFi, DEXLSR-Leastwood <br> LSR-Jonah1005 <br> SR-Xiaoming90 <br> SR-Alex The Entreprenerd <br> JSR-0xNazgul
SudoswapFebruary 2023:page_facing_up:DeFi, P2P NFT SwapsLSR-Gerard Persoon <br> LSR-Rajeev <br> SR-Shodan <br> JSR-Lucas Goiriz <br> JSR-David Chaparro
Cron FinanceJanuary 2023:page_facing_up:DeFi, TWAMMLSR-Kurt Barry <br> LSR-Noah Marconi <br> SR-M4rio.eth <br> JSR-Calvin Boehr <br> JSR-Christos Pap
LooksrareJanuary 2023:page_facing_up:NFT, MarketplaceLSR-Optimum <br> LSR-Saw-Mon and Natalie <br> SR-Riley Holterhus <br> JSR-Maxime Viard
CloberJanuary 2023:page_facing_up:DeFi, DEXLSR-Christoph Michel <br> LSR-Desmond Ho <br> SR-Throttle <br> JSR-grmpyninja <br> JSR-Taek Lee
GoldfinchDecember 2022DeFi, Credit ProtocolLSR-D-Nice <br> LSR-Optimum <br> JSR-TCHKVSKY
OpenSeaDecember 2022:page_facing_up:NFT, SeaportLSR-Saw-Mon and Natalie <br> LSR-Harikrishnan Mulackal <br> SR-Dravee <br> JSR-Ellahi <br> Consultant-Alex Beregszaszi
PaladinNovember 2022DeFi, Yield Vaults. SEAL engagementLSR-Rajeev <br> SR-Patrickd <br> JSR-Zarf <br> JSR-Andy Li <br> JSR-TCHKVSKY <br> 0xNazgul <br> JSR-merkleplant <br> JSR-Maxime Viard <br> JSR-Christos Pap
AstariaNovember 2022:page_facing_up:NFT, LiquidityLSR-Noah Marconi <br> LSR-Saw-Mon and Natalie <br> SR-Zach Obront <br> ASR-Blockdev
GoldfinchNovember 2022DeFi, Credit ProtocolLSR-D-Nice <br> LSR-Optimum <br> JSR-TCHKVSKY
MorphoNovember 2022:page_facing_up:DeFi, Lending and BorrowingLSR-Christoph Michel <br> SR-Emanuele Ricci <br> SR-JayJonah8 <br> JSR-Yldp <br> JSR-EBaizel
Liquid CollectiveNovember 2022:page_facing_up:Liquid Staking, Enterprise Grade StakingLSR-Optimum <br> SR-Emanuele Ricci <br> JSR-Ellahi <br> JSR-Matt Eccentricexit
GoldfinchOctober 2022DeFi, Credit ProtocolLSR-D-Nice <br> LSR-Optimum <br> JSR-TCHKVSKY
ConnextOctober 2022:page_facing_up:Bridge, Cross Chain LiquidityLSR-Saw-Mon and Natalie <br> LSR-Gerard Persoon <br> SR-Csanuragjain <br> SR-Xiaoming90 <br> ASR-Blockdev
MapleOctober 2022:page_facing_up:DeFi, Borrowing & LendingLSR-Christoph Michel <br> LSR-Leastwood <br> SR-Riley Holterhus <br> JSR-Devtooligan <br> JSR-Jonatas Martins
OpenSeaOctober 2022NFT, MarketplaceLSR-Saw-Mon and Natalie <br> LSR-Christoph Michel
OptimismOctober 2022L2, Merkle TrieLSR-Kurt Barry <br> SR-Patrickd
GoldfinchSeptember 2022DeFi, Credit ProtocolLSR-D-Nice <br> LSR-Optimum <br> Apprentice-TCHKVSKY
OpenSeaSeptember 2022NFT, MarketplaceLSR-Saw-Mon and Natalie <br> LSR-Harikrishnan Mulackal <br> SR-Dravee <br> Apprentice-Devansh Batham <br> Apprentice-Parth Patel
OpenSeaAugust 2022:page_facing_up:NFT, MarketplaceLSR-Saw-Mon and Natalie <br> LSR-Harikrishnan Mulackal <br> SR-Dravee <br> Apprentice-Devansh Batham <br> Apprentice-Parth Patel
Liquid CollectiveAugust 2022:page_facing_up:Liquid Staking, Enterprise Grade StakingLSR-Optimum <br> LSR-Saw-Mon and Natalie <br> SR-Emanuele Ricci <br> Apprentice-Ellahi <br> Apprentice-Matt Eccentricexit
GoldfinchAugust 2022DeFi, Credit ProtocolLSR-D-Nice <br> LSR-Optimum <br> Apprentice-TCHKVSKY
LI.FIAugust 2022:page_facing_up:Aggregator, Bridge & DEXLSR-Gerard Persoon <br> LSR-Jonah1005 <br> SR-DefSec <br> Apprentice-Blockdev
RibbonAugust 2022DeFi, Option VaultsLSR-Christoph Michel <br> LSR-Optimum <br> SR-JayJonah8 <br> SR-M4rio.eth <br>Apprentice-grmpyninja <br> Apprentice-Ellahi
OptimismAugust 2022:page_facing_up:L2, AutomationLSR-Noah Marconi <br> SR-Emanuele Ricci <br> Apprentice-Hrishikesh Bhat <br> Apprentice-0xNazgul
ConnextJuly 2022Bridge, Cross Chain LiquidityLSR-Leastwood <br> LSR-Jonah1005 <br> QO-Gerard Persoon <br> Apprentice-Blockdev <br> Apprentice-Tqts <br> Consultant-Happenwah
GoldfinchJuly 2022DeFi, Credit ProtocolLSR-Optimum<br> LSR-Noah Marconi <br> Apprentice-TCHKVSKY
ExponentJuly 2022DeFi, Token Equity. SEAL engagementLSR-Rajeev <br> LSR-Desmond Ho <br> Apprentice-Miguel Palhas <br> Apprentice-Jonatas Martins <br> Apprentice-Hagrid <br> Apprentice-Calvin Boehr <br> Apprentice-Balag3 <br> Apprentice-Tqts <br> Apprentice-Maxime Viard
OpenSeaJuly 2022NFT, SeaportLSR-Leo Alt <br> LSR-Alex Beregszaszi <br> LSR-Harikrishnan Mulackal
Paradigm Art GobblersJuly 2022:page_facing_up:NFT, ArtLSR-Kurt Barry <br> LSR-Leo Alt <br> LSR-Harikrishnan Mulackal <br> SR-Emanuele Ricci <br> SR-Patrickd <br> Apprentice-Hrishikesh Bhat <br> Apprentice-Devansh Batham <br> Consultant-Alex Beregszaszi
OlympusDAOJune 2022DeFi, Staking & BondingLSR-Christoph Michel<br> LSR-Desmond Ho <br> SR-Blackscale <br> Apprentice-Jonatas Martins <br> Apprentice-Hagrid
ConnextJune 2022:page_facing_up:Bridge, Cross Chain Liquidity. C4 fix reviewLSR-Leastwood <br> LSR-Jonah1005 <br> QO-Gerard Persoon <br> Apprentice-Blockdev <br> Apprentice-Tqts
OpenSeaJune 2022NFT, SeaportLSR-Alex Beregszaszi <br> LSR-Harikrishnan Mulackal <br> LSR-Gerard Persoon <br> LSR-Leo Alt <br> LSR-Christoph Michel <br> SR-Throttle <br> Apprentice-Miguel Palhas
OpenSeaJune 2022NFT, Seaport. C4 fix reviewLSR-Alex Beregszaszi <br> LSR-Harikrishnan Mulackal <br> LSR-Gerard Persoon <br> LSR-Leo Alt <br> LSR-Christoph Michel <br> SR-Throttle <br> Apprentice-Miguel Palhas
GauntletMay 2022:page_facing_up:DeFi, Financial ModelingLSR-Gerard Persoon <br> LSR-Eric Wang <br> SR-Emanuele Ricci <br> Apprentice-Devansh Batham
GoldfinchMay 2022DeFi, Credit ProtocolLSR-D-Nice <br> LSR-Optimum <br> Apprentice-TCHKVSKY
PorterMay 2022:page_facing_up:DeFi, BondsLSR-Brock Elmore<br> SR-DefSec <br> SR-Satyam Agrawal<br> Apprentice-grmpyninja<br> Apprentice-Blockdev
TimelessApril 2022:page_facing_up:DeFi, Perpetual Yield TokensLSR-Christoph Michel <br> SR-JayJonah8 <br> Apprentice-Calvin Boehr <br> Apprentice-Sleepy
PaladinApril 2022:page_facing_up:DeFi, Governance LendingLSR-Gerard Persoon <br> SR-JayJonah8 <br> SR-DefSec <br> Apprentice-Devansh Batham
OptimismApril 2022L2, Merkle TrieLSR-Kurt Barry <br> LSR-Eric Wang <br> LSR-Guido Vranken <br> Apprentice-Patrickd <br> Apprentice-Tqts
MorphoMarch 2022:page_facing_up:DeFi, Lending and BorrowingLSR-Christoph Michel <br> SR-Emanuele Ricci <br> SR-Hack3r-Om <br> SR-JayJonah8
TracerFebruary 2022:page_facing_up:DeFi, Perpetual PoolsLSR-Gerard Persoon <br> LSR-Christoph Michel <br> SR-Emanuele Ricci <br> SR-RustyRabbit
POAPFebrurary 2022NFT, Bridge. Private Audit---
LockeFebrurary 2022:page_facing_up:DeFi, AMMLSR-Eric Wang <br> LSR-Harikrishnan Mulackal <br> SR-Mukesh Jaiswal
OverlayFebrurary 2022:page_facing_up:DeFi, Markets on streams of dataLSR-Mudit Gupta <br> LSR-Gerard Persoon <br> LSR-Harikrishnan Mulackal
SudoswapJanuary 2022:page_facing_up:DeFi, P2P NFT SwapsLSR-Gerard Persoon <br> LSR-Mudit Gupta <br> LSR-Max Goodman
SenseJanuary 2022:page_facing_up:DeFi, Fixed YieldLSR-Gerard Persoon <br> LSR-D-Nice <br> LSR-Max Goodman <br> Consultant-Kurt Barry
POAPDecember 2021NFT, Badges. Private Audit---
POAPDecember 2021WEB2 NFT, Badges. Private Audit---
BrinkNovember 2021:page_facing_up:DeFi, AutomationLSR-Harikrishnan Mulackal <br> LSR-Alex Beregszaszi <br> LSR-Gerard Persoon
BrinkNovember 2021:page_facing_up:DeFi, AutomationLSR-Gerard Persoon<br> LSR-Harikrishnan Mulackal <br> LSR-Max Goodman
<br> <br>

Competitions

CompetitionDateRankingLinks of interest
Code4rena OpenSea20 May 2022—4 June, 2022#1Leaderboard
Paradigm CTF, SpearbitVanguardAugust 20-21, 2022#11Leaderboard
Paradigm CTF, SpearbitRearguardAugust 20-21, 2022#52Leaderboard
<br> <br>

Responsible Disclosure

Note: Auditors keep 100% of the bounty

ProtocolDateLinks of interestAuditors involved
BalancerMay 2022Twitter announcement, Balancer articleGerard Persoon, Eric Wang
<br> <br>

Content

List of public talks and seminars

NameAdditional Resources
Numerical Analysis for DeFi Audits: Kurt BarrySlides
Economic Security with fmrmfSlides
Security Education and Assessment Lab with RajeevVideo
Deep Dive Into Seaport with 0ageSlides
Optimal Front Running Attacks & How to Stop Them with Max ResnickSlides
From Exploit to Recovery: Unraveling DeFi Incidents with SpreekSlides
Community Workshop: Zach ObrontSlides
How to Foundry 2.0Demo
EVM Through HUFF: DevtooliganSlides, Demo
ZK Series: Intro with Porter AdamsSlides
Community Workshop: Riley HolterhusSlides
EVM Seminar: 7 things about the EVMSlides
OpenSeacurity with SpearbitShow notes
The Bridge Risk Framework SeminarL2 Bridge Risk Framework
Fuzzing Tools Series: Certora Prover--
Fuzzing Tools Series: EchidnaEchidna Spearbit Demo
Forta Introduction Seminar--
Simple Security Toolkit WalkthroughSimple Security Toolkit
Spearbit at TrustX: Languages--
Spearbit at TrustX: Simplify Solidity Code with Sorted Contracts and Security Risk--
Understanding Bridge Security with Connext's Arjun Bhuptani--
How to FoundryFoundry Book
<br>

Bridges

Title
Bridge Security Introduction
Bridge Security Checklist
<br>

Spearbook

Public Spearbit documentation meant for clients <br> <a href="https://hackmd.io/@spearbit/rJB2dPGwq"> <img src="https://user-images.githubusercontent.com/47452703/185889688-ec310afb-ca57-4bef-b12d-a19007a1fb46.png" width="200" height="300"/> </a>

<br> <br>

Core Team

Have any questions? Reach out to the core team directly at core-team [at] spearbit [dot] com !