Services · The hardware wallet
ContractsThat hold up
Solidity on Ethereum, Polygon, Base and Arbitrum. Anchor programs on Solana. Written with tests first, because a redeploy is not a hotfix once value is on the line.
- Solidity
- Foundry
- Anchor
- ERC-721
- SPL
- wagmi

Token contracts, NFT collections, staking, and the unglamorous plumbing around them: indexers, signature flows, wallet connection that works on a phone browser. We write Foundry tests including the adversarial cases, run static analysis, and do a self-audit pass before anything touches mainnet. For anything holding real money we will tell you to get a second audit, and help you prepare for it.
What you get
- Contracts with a Foundry or Anchor test suite, including the attack cases
- Deployment scripts, verified sources and an upgrade or migration plan
- A frontend that connects, signs and recovers from a rejected transaction gracefully
- A self-audit write-up with known limitations stated honestly
How it goes
01 · Model the moneyWho can call what, who holds the keys, what happens on the worst day. Written before a line of Solidity.
02 · Write tests firstThe adversarial cases go in before the happy path. Reentrancy, rounding, access control, paused states.
03 · Testnet and reviewDeploy, run the flows with real wallets, static analysis, self-audit, then a written list of what we are still uneasy about.
04 · MainnetVerified sources, a deployment record, and monitoring on the addresses that matter.
What changes
Code an auditor can read
Named, commented, tested. A second audit costs less when the first pass was done properly.
A frontend that survives mobile
Most Web3 projects lose users at wallet connect. That is a solvable engineering problem.
No surprise admin keys
Every privileged function is listed in the handover, with who holds it.
Work from this bench
Straight answers
- Do you audit other people's contracts?
- We review them and report, but we are not a substitute for a named audit firm on a contract holding significant value. We will say so plainly.
- Which chain should we use?
- Usually the one your users already have a wallet on. We will push back if the chain choice is driven by a grant rather than by the product.
- Can you do the NFT mint mechanics?
- Yes: allowlists, reveal, royalties, and the indexer and frontend around them. The BAYC teardown in this studio's archive exists because we take the reference seriously.
- Do we need a blockchain for this at all?
- Often not, and we will say so. The honest test is whether multiple parties who do not trust each other need to agree on the same record without a middle party. If one company controls the data, a database is cheaper, faster and easier to fix.
- What happens if a bug is found after deployment?
- That depends entirely on decisions made before deployment, which is why they get taken deliberately. Either an upgrade path exists — and somebody holds those keys, which is its own risk to disclose — or the contract is immutable and the response is a migration.
- Can you audit a contract somebody else wrote?
- Yes, and that is a large part of this work. An independent review before launch is the only review that helps, because after deployment the code is public to everyone including whoever wants the funds.
All services
Tell us the problem in plain words.Book the intro call



