● Available for Q3 2026 EVM audits

EVM smart-contract security,
automated depth + human judgment.

Independent security reviews for Ethereum and EVM L2 protocols. I pair ODIN — an automated static-analysis and invariant-fuzzing pipeline — with hands-on manual review, so you get broad coverage and real exploit reasoning. Free scoping, quote within 24 hours.

Services

Focused on EVM / Solidity — Ethereum, Arbitrum, Optimism, Base, Polygon, Scroll.

Pre-mainnet audit

Full review of your contracts at a frozen commit: logic flaws, economic/accounting bugs, access control, oracle and bridge risk — with proof-of-concept where it matters.

Differential / upgrade review

Targeted review of changes since your last audit — ideal before an upgrade or new module ships.

Invariant fuzzing

Foundry invariant harnesses that state what must always hold (solvency, no-free-profit, share-price monotonicity) and fuzz to break them — the class of bug that actually drains funds.

Continuous monitoring

After launch, ODIN watches for risky on-chain activity and newly deployed components so issues surface early.

How an engagement works

Transparent, fixed-scope, fast.

1

Free scoping (24h). Send the repo/docs, a commit hash and rough LoC. You get a written scope, timeline and fixed quote — no commitment.

2

Review. Automated pass (static analysis + invariant fuzzing) to map the surface, then manual deep-dive on the money paths and economic logic.

3

Report. Findings by severity with impact, proof-of-concept, and concrete fixes.

4

Fix review. I re-check your remediations against the original findings, included in the engagement.

The ODIN pipeline

Why automated tooling + manual review beats either alone.

Breadth, automated

Slither/Mythril static analysis and continuous scanning cover the whole surface fast, so manual time goes to the bugs that matter.

Economic bugs, fuzzed

Fork-mode invariant fuzzing targets the high-payout classes — rounding/precision, share inflation, solvency — against real on-chain state.

Judgment, human

Every candidate is validated by hand: is it exploitable by an unprivileged user? Is there real loss? That gate is what makes a report worth reading.

Indicative pricing

Fixed-scope, quoted per engagement. Often eligible for ecosystem audit subsidies.

ScopeLines of codeTypical feeTimeline
Small contract< 500$5k – $8k3–5 days
Medium protocol500 – 2,000$10k – $20k1–2 weeks
Large protocol2,000 – 5,000$20k – $40k2–3 weeks
Complex system5,000+from $40k3–4 weeks

Request a free scoping

Send your repo or docs, a commit hash and rough LoC — quote back within 24 hours.

Email WolfSec

Callum Fitzgerald · Independent EVM security researcher · United Kingdom