Panoptes continuously reviews smart contracts, bridges, and zero-knowledge circuits, and the identity, auth, and access-control systems around them. Across chains and beyond. Detection only. Never exploits.
Including real consensus-verification gaps in a live cross-chain bridge that has moved $100M+ across its routes.
Targets reviewed
Directed audit passes
Vulnerability classes
Ecosystems covered
Confirmed findings
Aggregate TVL reviewed
The majority of targets returned an honest CLEAN / NOT-FOUND verdict.
Real results, on live systems, across very different surfaces.
Real consensus-verification gaps in the non-flagship light clients (missing finality, quorum and threshold checks), confirmed at code level, in a bridge marketed on trustless consensus verification. The flagship zk path reviewed clean.
Calibration. The AI pass rated the gaps critical; a human reviewer traced reachability and corrected to an honest, conditional rating, with real-world impact bounded by an access-control configuration not determinable from source.
What stands. After the downgrade, a real gap remains between the security the bridge officially claims and what its non-flagship clients actually verify. The headline severity was overstated; the underlying gap was not.
Responsibly disclosed, privately. Detection only.
Coordinated disclosure. Detection only.
A selection of targets reviewed across chains and the systems around them.
Across EVM, Solana/SVM, Move, Cosmos, Substrate, Bitcoin, ZK circuits (Halo2, Noir, R1CS, PLONK), and Web2 identity and access-control stacks.
How we keep security and trust.
No exploit code. No autonomous on-chain action. Pure analysis and reporting.
Every finding is triaged by a security professional before it leaves the system.
Reported privately through project channels before any public detail.
Start free, scale to whatever your code needs. Every engagement is scoped to you.
A teaser diff-scan of your repo. No call, no commitment. See what Panoptes flags before you spend a cent.
End-to-end review of a protocol across every execution environment it touches.
Final scope set on a short call.
Your live code on the watchlist: every release re-reviewed, with alerts the moment new risk appears.
Billed monthly, scoped to your code.
A focused pass on a single contract, circuit, or change set before you ship.
Final scope set on a short call.
Priority access for reviews and questions as you ship.
Priced after a short call.
The Scout pass is on us. Everything beyond it is paid, and worth it: a fraction of what a single missed vulnerability costs.
Founder and Security Researcher
Builder of Panoptes with a background in backend, security engineering, and non-custodial crypto infrastructure. Focused on keeping the blockchain ecosystem secure and accountable.
So the check that is supposed to hold is never the thing that breaks.
Detection-only · Human-in-the-loop · Responsible disclosure