Use complementary methods
Manual review and automated tools surface different failure modes. I used them together rather than treating one scanner as the audit.
Case 07 · Smart contract security
The review followed permissions, balances and unusual state changes.
I performed smart contract security reviews for exchange and DeFi engagements through FearsOff, combining manual analysis, automated tooling and remediation guidance.
Delivered audits and remediation guidance for engagements covering Crypto.com exchange contracts, HTX integration modules and Smardex AMM and liquidity contracts.
A successful transaction is only one path through a contract. A useful review needs to challenge permissions, accounting and adversarial state transitions, then explain what the team should change.
Reviewed contract behavior, authorization boundaries and paths that affect assets.
Used Slither, Mythril, Echidna and Manticore, with formal verification techniques on critical functions.
Delivered findings with remediation and gas-optimization guidance for engineering teams.
Identify the assets, privileged roles and state transitions that define the contract’s trust boundaries.
Assets + permissions + state transitionsThe review starts from what must remain true.Combine manual reasoning with automated tools to search for paths that violate those assumptions.
Manual review + adversarial testsTool output needs interpretation in the contract’s context.Connect a suspected issue to a specific affected asset, permission or accounting path and prioritize its consequence.
Issue → reachable behavior → impactA finding must explain why the behavior matters.Translate the technical finding into concrete implementation guidance for the team responsible for the contract.
Finding + remediation recommendationThe report must be usable by the engineers fixing the code.Manual review and automated tools surface different failure modes. I used them together rather than treating one scanner as the audit.
Reports connect the issue, consequence and proposed remediation so the delivery team can act on them.
Client scope and methods are recorded in my CV. Engagements were performed through FearsOff.
The workflow above explains my approach without revealing confidential reports, exploit details or unremediated findings.
Engagements delivered through FearsOff, as documented in my CV; the named organizations describe audit scope.
Audit reports and vulnerability details remain confidential.