Material findings
Loss of funds, frozen assets, unauthorised privilege. Style and informational notes stay brief.
Security reviews · EVM
Independent smart contract security reviews for Ethereum and EVM protocols. Fixed scope, written findings, remediation verification.
Risk reduction you can show investors and your community — focused on issues that affect funds or protocol integrity.
Loss of funds, frozen assets, unauthorised privilege. Style and informational notes stay brief.
Material issues include a concrete exploit path or runnable proof so your team can reproduce the risk.
After you patch, we re-check the diff against the original findings. Included in the fee.
Nothing starts until you approve a written quote against a commit hash.
Scoping — free, within 24 hours. Repository, commit, approximate size. You receive scope, fee and timeline.
Review. Analysis of the agreed contracts: logic, access control, accounting assumptions, upgrades and signatures.
Report. Severity-graded findings with impact, remediation guidance and proof where material.
Verification. Confirmation that remediations close the reported issues.
Coverage combines automated analysis with human review of paths that move value. We work only in Solidity on Ethereum and EVM networks — we do not take Solana, Move or Cairo engagements.
USD. Final fee depends on complexity. Written quote before work begins.
| Engagement | Scope | Fee | Timeline |
|---|---|---|---|
| Differential review | Change-set or under ~300 lines | $1,500 – $3,000 | 2–3 business days |
| Small review | Under ~500 lines | $3,000 – $5,500 | 3–5 business days |
| Protocol review | ~500 – 2,000 lines | $6,500 – $12,000 | 1–2 weeks |
| Large review | ~2,000 – 5,000 lines | $12,000 – $25,000 | 2–3 weeks |
| Complex systems | 5,000+ lines or multi-repo | From $25,000 | By agreement |
| Monitoring | Agreed post-deployment checks | From $399 / month | Ongoing |
Ecosystem audit subsidies may reduce net cost on eligible projects. Mention this during scoping if relevant.
No. A review reduces risk within the agreed scope and commit. Absolute safety cannot be claimed.
Callum Fitzgerald, operating as WolfSec from the United Kingdom. The person who reviews the code signs the report.
Solidity / EVM only. If the project is primarily another stack, we decline rather than overclaim.
No obligation. Reply within 24 hours with scope, fee and timeline.
Send repository URL, commit hash, approximate size and target launch date.
Direct
callumfitzgerald2000@gmail.com
United Kingdom