Real Engagements · Concrete Controls · Verified Outcomes

CASE STUDIES

Anonymised examples from live audit engagements. What we found, how bad it was, the blast radius, and the controls that closed it.

All
Web3 / DeFi
Cloud Security
Compliance
DevSecOps

Web3 / DeFi

Lending Protocol — Pre-Launch Audit

Chain: Ethereum + Arbitrum
Scope: 14 contracts, ~8,200 LoC
Duration: 3 weeks
TVL at Risk: $12 M (projected)

Finding Distribution

Critical
1
High
3
Medium
4
Low / Info
9

Context

A DeFi lending protocol approaching mainnet launch asked for a full audit covering collateral management, liquidation logic, oracle integration, and cross-chain message handling. The team had internal tests but no prior external security review.

Critical LND-001 — Reentrancy in Liquidation Callback

The liquidate() function issued an external callback to the liquidator's contract before updating the borrower's collateral balance. A malicious liquidator could recurse into liquidate() and drain the collateral pool in a single transaction.

Impact: Total collateral pool drain
Likelihood: High — trivial to exploit post-launch
Blast Radius: All depositors; $12 M projected TVL
Fix: Checks-effects-interactions pattern + OpenZeppelin ReentrancyGuard
High LND-004 — Oracle Price Staleness: No Freshness Check

The Chainlink oracle integration fetched latestAnswer() without checking the updatedAt timestamp. If a feed goes stale during a network congestion event, the protocol continues operating on an outdated price — enabling under-collateralised borrows.

Impact: Under-collateralised borrow attacks
Likelihood: Medium — requires feed outage window
Blast Radius: Entire lending pool for affected assets
Fix: Enforce updatedAt > block.timestamp - MAX_STALENESS; revert on stale data

How We Worked

Manual review covered the business logic. Automated static analysis (Slither + custom rules) ran concurrently. We then forked Ethereum mainnet and replicated the reentrancy attack in a local environment — the PoC drained 100% of simulated collateral in one transaction. The team patched all criticals and highs within four days; we re-tested and issued a signed completion letter before launch.

✓ All Criticals Resolved ✓ PoC Exploit Demonstrated ✓ Mainnet Fork Verified ✓ Launch Cleared

Cloud Security

Fintech SaaS — AWS IAM & Network Review

Platform: AWS (multi-account)
Scope: 4 accounts, 220+ IAM roles
Duration: 2 weeks
Data at Risk: PII for 180 K users

Finding Distribution

Critical
2
High
7
Medium
11
Low / Info
18

Context

A Series A fintech preparing for SOC 2 Type II certification needed an external review of their AWS environment before the auditor's fieldwork window. The engineering team had grown fast; IAM policies had accumulated without a systematic review process.

Critical IAM-001 — Wildcard Managed Policy on CI/CD Role

The GitHub Actions deployment role had an attached customer-managed policy granting "Action":"*" on "Resource":"*" in the production account. A compromised repository secret or a malicious PR merge would give an attacker full account control.

Impact: Full account takeover, data exfiltration
Likelihood: High — secrets in CI logs exposed in 2 incidents
Blast Radius: All S3 buckets, RDS, Secrets Manager, 180 K user PII
Fix: Scope to specific deploy actions + target ARNs; rotate all CI secrets; enable MFA-delete on S3
High NET-003 — Security Group Allows SSH 0.0.0.0/0 on Production

Port 22 open to the internet on 11 EC2 instances in the production VPC. No bastion host. Key-pair authentication only — no MFA enforcement. Any brute-force or credential-stuffing attack has a direct path to the instance layer.

Impact: Lateral movement within VPC, data access
Likelihood: Medium — automated scanners probe this daily
Blast Radius: 3 VPC subnets, all production instances
Fix: Restrict to bastion CIDR; deploy AWS Systems Manager Session Manager; enforce MFA

DevSecOps Remediation

Beyond the point-in-time findings, we wired a continuous control: an AWS Config rule that fires an SNS alert whenever a new IAM policy is attached with a wildcard action. We also added a GitHub Actions step that runs a policy-linting check on every pull request touching IAM Terraform — criticals block merge, highs create a GitHub issue automatically.

The SOC 2 auditor saw the Config rule as satisfying CC6.3 (access control reviews) on an ongoing basis, reducing their sample testing burden significantly.

✓ 2 Criticals Closed in 72 hrs ✓ SOC 2 CC6.3 Evidence Automated ✓ IAM Lint Gate Deployed ✓ RBAC Matrix Delivered

Compliance / DevSecOps

HealthTech Platform — SOC 2 + HIPAA-Aligned Evidence Automation

Platform: GCP + Kubernetes
Scope: SOC 2 Type II + HIPAA Security Rule
Duration: 6 weeks
Controls Automated: 34 of 38 in scope

Control Coverage

Automated
34
Manual
4

Context

A health data platform had passed SOC 2 Type I but was failing to keep up with evidence collection for the Type II window. The compliance team was manually exporting CSV files, screenshots, and access logs every quarter — a two-week exercise that was error-prone and couldn't keep pace with their monthly release cadence.

Gap CC7.2 — Log Retention: No Automated Evidence

CloudTrail logs were retained correctly, but there was no automated proof sent to the auditor's evidence portal. A manual export was performed quarterly, but three of the last four exports had missing date ranges — flagged by the Type I auditor as a significant finding.

Impact: Audit failure; potential certification lapse
Likelihood: Certain — confirmed gap
Fix: GCP Log Router → Cloud Storage → Vanta/Drata export pipeline; automated daily artefact with SHA-256 hash

What We Built

We implemented a continuous compliance pipeline using Terraform and Cloud Run. Every 24 hours, a scheduled job pulls access logs, IAM change events, and system configuration snapshots, hashes each artefact, and pushes it to a locked GCS bucket with object versioning and retention policies. The same job writes a JSON manifest to the compliance platform's API.

For controls that couldn't be automated — annual security training completion, vendor contract reviews — we built a lightweight workflow in Jira that assigns tasks, collects sign-offs, and archives the evidence document automatically.

The Type II audit fieldwork was completed in three days rather than three weeks. The auditor's sampling was satisfied entirely by the automated artefact repository.

✓ 34/38 Controls Automated ✓ Audit Fieldwork: 3 Days vs 3 Weeks ✓ SOC 2 Type II Issued ✓ Zero Manual Evidence Gaps

DevSecOps

Web3 Infrastructure Team — Secure SDLC Pipeline

Stack: GitHub Actions + Foundry + Node.js
Scope: Monorepo, 6 services, 4 contracts
Duration: 4 weeks
Pipeline Coverage: 100% of deploy branches

Issues Caught Pre-Production

Critical
1
High
4
Medium
12

Context

A multi-chain infrastructure team was shipping weekly contract upgrades and API releases. Security reviews were happening ad hoc — sometimes before launch, sometimes after. One high-severity access control bug had slipped to mainnet and required an emergency pause-and-migrate. They wanted security baked into every deploy, not bolted on after.

Pipeline Architecture We Deployed

Every pull request into main now runs five sequential security jobs before a merge is allowed:

  • SAST: Slither with custom detectors for their protocol-specific patterns; Semgrep for Node.js API layer
  • Dependency scan: npm audit + Snyk for JavaScript; cargo-audit for any Rust tooling
  • Secret detection: Trufflehog scans every commit diff — blocks if a private key or API token pattern is found
  • Fuzzing delta: Foundry fuzzing runs 50,000 calls against any function touched in the PR diff
  • RBAC regression: A custom script compares the proposed access control matrix against a signed golden file — any privilege escalation fails the check

Critical and High findings block merge with an inline PR comment explaining the finding, blast radius, and the specific line to fix. Medium findings create a labelled GitHub issue assigned to the author.

The first week after deployment, the pipeline caught a missing onlyOwner modifier on an upgrade function — a critical that would have gone to mainnet under the old process.

✓ 1 Critical Caught Pre-Deploy ✓ 0 Security Issues to Mainnet in 6 Months ✓ 100% PR Coverage ✓ RBAC Gate Active

WANT A SIMILAR ENGAGEMENT?

Tell us your system and scope. We'll send a no-obligation proposal with a realistic timeline and a fixed price within 48 hours.

View Pricing Get a Proposal