Autonomous, invariant-directed security review

Panoptes continuously reviews smart contracts, bridges, and zero-knowledge circuits, and the identity, auth, and access-control systems around them. Across chains and beyond. Detection only. Never exploits.

Book a call

Including real consensus-verification gaps in a live cross-chain bridge that has moved $100M+ across its routes.

By the numbers

160+

Targets reviewed

250+

Directed audit passes

205

Vulnerability classes

31

Ecosystems covered

24

Confirmed findings

Billions

Aggregate TVL reviewed

1 Critical4 High9 Medium10 Low

The majority of targets returned an honest CLEAN / NOT-FOUND verdict.

Selected findings

Real results, on live systems, across very different surfaces.

Responsibly disclosed · Detection only

Human-in-the-loop calibration of a live cross-chain bridge finding

Class
Consensus and finality verification (state-forgery)
Exposure
A live cross-chain bridge that has moved $100M+ across its routes

Real consensus-verification gaps in the non-flagship light clients (missing finality, quorum and threshold checks), confirmed at code level, in a bridge marketed on trustless consensus verification. The flagship zk path reviewed clean.

Calibration. The AI pass rated the gaps critical; a human reviewer traced reachability and corrected to an honest, conditional rating, with real-world impact bounded by an access-control configuration not determinable from source.

What stands. After the downgrade, a real gap remains between the security the bridge officially claims and what its non-flagship clients actually verify. The headline severity was overstated; the underlying gap was not.

Responsibly disclosed, privately. Detection only.

Token standards

High-severity accounting break in a live, previously-exploited token deployment

Coordinated disclosure. Detection only.

Coverage

A selection of targets reviewed across chains and the systems around them.

Bridges & Cross-chain Messaging

18
WormholeWormhole NTTHyperlaneAxelarCelerdeBridgeLayerZero v2Chainlink CCIPHopSnowbridgeGravity BridgeHyperbridgeAcrossChainflipLombardHyperliquidEverclearMayan

Light Clients & Consensus

7
Composable/centauriNEAR Rainbow BridgeSP1-HeliosSP1-Blobstreamop-succinctPolymerLorenzo

ZK Circuits

7
PenumbraAleo snarkVMScroll zkEVMAzteczkSync Erazk-kitzk-email

L2 Settlement, Rollups & Fault Proofs

8
zkSync EraScrollLineaStarkGateTaikoDymensionOP Stack dispute gameCannon fault proofs

Restaking, Vaults & DA

6
EigenLayerEigenDASymbioticJito RestakingSatLayerPell

Bitcoin: SPV, Bridges & Staking

14
BabylonCitrea/ClementineinterBTCNomicBEVMMezoStacks sBTCBOBBotanixMerlinBool NetworkHemiSolvBTCBedrock uniBTC

Solana / SVM DeFi

3
Drift v2Jito RestakingMayan

Cosmos DeFi, Oracles & ICQ

8
NeutronStridepSTAKEQuicksilverQuasarUmeeElysdYdX v4

Lending, LST, Perps & Oracles

16
MorphoPendleEthenaPythLidoRenzoKarakKaminoMarginFiMarinadeSanctumStargate v2Polygon zkEVMCelestiaBeaconKittBTC v2

Token Standards & Families

11
ERC-20ERC-404 / DN404 / BT404Solidly / ve(3,3)xERC20 / OFTAxelar ITSSuperchainERC20CCTP V2USDT0ERC-4626 / MetaMorphoERC721A / ERC721CstETH / wstETH

Account Abstraction (ERC-4337)

4
Coinbase Smart WalletSafe4337ModuleKernel (ZeroDev)Alchemy Modular Account

Web2: Identity, Auth & Access-control

9
SAMLJWT / JWS / JWEOAuth2 / OIDCCedarOpenFGASpiceDB (Zanzibar)OPA / RegoCasbinSPIFFE / SPIRE

Web2: Server-side Application Security

7
SSRFSSTIUnsafe deserializationCommand injectionPath traversalXXEHTTP request smuggling

AVS & Restaking Middleware

5
EigenLayerSymbioticKarakJito RestakingAltLayer MACH

ZK Proof Systems & zkVMs

4
SP1RISC ZeroGroth16 / PLONK verifiersrecursion / aggregation

AI Agents & Autonomous Systems

4
AI-agent frameworksMCP tool-useautonomous on-chain agentsauto-signers

Hardware Wallets & Secure Signers

4
Ledger app-ethereumTrezor firmwareBitBox02EIP-7702 / clear-signing

Across EVM, Solana/SVM, Move, Cosmos, Substrate, Bitcoin, ZK circuits (Halo2, Noir, R1CS, PLONK), and Web2 identity and access-control stacks.

Operating Principles

How we keep security and trust.

Detection-Only

No exploit code. No autonomous on-chain action. Pure analysis and reporting.

Human-in-the-Loop

Every finding is triaged by a security professional before it leaves the system.

Responsible Disclosure

Reported privately through project channels before any public detail.

Engagements

Start free, scale to whatever your code needs. Every engagement is scoped to you.

Free

Start with a Scout pass

A teaser diff-scan of your repo. No call, no commitment. See what Panoptes flags before you spend a cent.

Full Audit

End-to-end review of a protocol across every execution environment it touches.

From $25,000

Final scope set on a short call.

Continuous Monitoring

Your live code on the watchlist: every release re-reviewed, with alerts the moment new risk appears.

Recurring

Billed monthly, scoped to your code.

Spot Review

A focused pass on a single contract, circuit, or change set before you ship.

From $2,500

Final scope set on a short call.

Retainer

Priority access for reviews and questions as you ship.

Scoped quote

Priced after a short call.

The Scout pass is on us. Everything beyond it is paid, and worth it: a fraction of what a single missed vulnerability costs.

About Panoptes

Chris Zemmel

Founder and Security Researcher

Builder of Panoptes with a background in backend, security engineering, and non-custodial crypto infrastructure. Focused on keeping the blockchain ecosystem secure and accountable.

Watching every chain, and the systems around them

So the check that is supposed to hold is never the thing that breaks.

Detection-only · Human-in-the-loop · Responsible disclosure