Book. Secure. Relax.

We're a security partner for Web3 protocols. The audit is the core of what we do. Operational security reviews, continuous audits, and a vCISO keep you covered the rest of the time.

Illustration of three figures booking a service, securing a lock, and relaxing
600+
engagements completed since 2017
50+
senior security researchers
9+/10
average client rating

Trusted by the best

Client logoClient logoClient logoClient logoClient logoClient logoClient logoClient logoClient logoClient logoClient logoClient logoClient logoClient logoClient logo

Our approach

Security doesn't end at the report

A protocol audit can come back clean while the deployment key sits in a Slack message. A multisig can be implemented perfectly while the signing ceremony is a mess. Most failures cross layers, so our coverage does too.

Protocols

White papers, specs, mechanisms, governance, source code. The design-level threats and the invariants that have to hold. This is where our audits live.

Systems

How the protocol is built and run: infrastructure, CI/CD, deployment, key management. A compromised CI job is how a clean codebase ships a malicious release.

Organisations

Who can actually touch the assets, and how the team works day to day. The human side, where a lot of the real risk lives.

The useful question isn't "which service do you need?" It's "which parts of your threat surface are covered, and which aren't?" Our TRACE threat modelling framework maps every engagement to what it covers.

Methodology

TRACE. One threat model, three layers.

TRACE is our threat modelling methodology for teams that don't have a clean security perimeter. We built it through our Web3 work and published it openly under CC BY 4.0.

TThreat actorsWho would attack, and why
RRolesWho holds authority over assets
AAssetsWhat must be protected
CCritical invariantsProperties that must always hold
EEdgesTrust boundaries & transitions
Explore TRACE View on GitHub
Private beta

Pre-Audit Agent

Point it at a repository and it hands back an audit-readiness score, the risky spots, a sense of the complexity, and the audit package that fits, before you ever talk to us. Open to beta users for now.

About the agent
Live

Op-Sec Academy

A free, open library on the operational side of security: multisig design, key management, governance, and TRACE. The part audits don't reach.

Visit the Academy

In partnership with SEAL

SEAL operational security certification

We're an accredited firm for the Security Alliance (SEAL) operational security certification program. We assess your protocol against the SEAL framework, and when you pass, SEAL issues a verifiable on-chain attestation through the Ethereum Attestation Service.

The certification covers the operational side, where most of the real losses start. An attestation says you've put the practices in place. It doesn't claim your code is bug-free, and we wouldn't either.

Multisig OpsTreasury OpsIncident ResponseDevOps & InfrastructureDNS & RegistrarIdentity & Accounts
See the framework How we assess
Security Alliance (SEAL) Accredited assessment firm

Our specializations

We audit all components of Web3

EVM (Solidity)SolanaCosmos (CosmWasm)Polkadot/Substrate (ink!)Stellar (Soroban)RustConsensus Protocols/Light ClientsVirtual MachinesCryptographic PrimitivesZK CircuitsNoirCairo (Starknet)DeFiLiquid Staking/RestakingCross-Chain Bridges/SequencersOff-chain Infrastructure

Get a quote

Tell us about your project and we will get back to you within one business day.

Testimonials

What our clients say

Meet our team

50+ senior security researchers

Our researchers hold Master's and PhDs in Computer Science, Cryptography, Economics, Engineering, and Finance. We work with a distributed pool of the industry's best security experts, allowing us to expand on demand. Below are selected profiles.

Dr. Stefan Beyer

Dr. Stefan Beyer

Co-Founder & Managing Director

  • Leads Oak Security’s operational security services and blockchain infrastructure reviews.
  • 20+ years in distributed systems and cybersecurity; smart contract auditor since 2017.
  • PhD in Operating Systems; expert in consensus protocols like PBFT.
Philip Stanislaus

Philip Stanislaus

Co-Founder & Managing Director

  • MPhil in Economics from Cambridge; active in blockchain engineering since 2018.
  • Architected Polkadot pallets, Cosmos SDK modules, and bridges across ecosystems.
  • Oversees internal audit processes and security standards at Oak Security.
Christian Vari

Christian Vari

Head of Audit Operations

  • Master’s in Cybersecurity and Blockchain; specialized in distributed systems, Rust, and Go.
  • 150+ audits including Cosmos SDK, Interchain Security, Stellar, CosmWasm VM, Filecoin EVM, and Move contracts.
  • Former engineer at IBM/HCL working on distributed systems and schedulers.
Kateryna Yakovenko

Kateryna Yakovenko

Delivery Manager

  • Business Analyst & Project Manager with a degree in Applied Mathematics.
  • Coordinates auditors and clients and serves as the bridge between them to deliver audits and audit reports.
  • Led digital system design for the Ukrainian Border Guard Service.
Bernd

Bernd

Lead Blockchain Security Auditor

  • Completed 100+ audits across DeFi, wallets, bridges, and VMs (e.g., FEVM).
  • Top-ranked on Code4rena, Sherlock, and CodeHawks, with 17 top-3 placements including 7 first-place finishes.
  • Specialized in Solidity, Rust, Go, the Cosmos ecosystem, and complex bridging protocols.
Jakub Heba

Jakub Heba

Senior Blockchain Security Auditor

  • 9+ years in cybersecurity, including 3.5 years in Web3 security and blockchain auditing.
  • Conducted 130+ audits across smart contracts, L1 blockchains, and off-chain components.
  • Expert in low-level exploit development, penetration testing, and niche blockchain languages.
SuWu

SuWu

Senior Blockchain Security Auditor

  • Conducted 100+ audits across Cosmos, Solana, NEAR, and Cadence/FunC.
  • OSCP & OSWE certified; ranked in Google’s Top 100 VRP hackers.
  • Background in Web2 pentesting, bug bounties, and L2 vulnerability research.
Dr. Jan Philipp Fritsche

Dr. Jan Philipp Fritsche

Head of Economics Advisory

  • PhD in Economics; former advisor to the ECB, Deutsche Bank, and European Parliament.
  • 10+ years in risk modeling, econometrics, and macro-financial systems.
  • Leads Oak Security’s economics advisory services; reviewed 40+ blockchain protocols.
Nadim Kobeissi

Nadim Kobeissi

Applied Cryptographer

  • PhD in formal verification; performed 250+ security audits.
  • Built cryptographic tools and authored peer-reviewed research on ZK and messaging.
  • Certified cryptography expert (France); former professor at NYU Paris, current professor at AUB.
Björn Hanneke

Björn Hanneke

Economist

  • Blockchain researcher and PhD candidate specializing in token design and incentive mechanisms.
  • Investigates attack vectors in token economies, including airdrop resilience and manipulation risks.
  • 8+ years advising financial institutions on digital transformation and market innovation.
Matthew Miles

Matthew Miles

Senior Blockchain Security Auditor

  • 7+ years in blockchain R&D; led 50+ audits across L1s, ZKPs, and identity protocols.
  • Expert in Solidity, Rust, Go, and cryptographic primitives (SNARKs, STARKs, KZG, BLS).
  • Speaker at Google & Microsoft; co-authored papers on secure execution frameworks.
Colin Kelly

Colin Kelly

Senior Blockchain Security Auditor

  • Degree in Cybersecurity and Risk Analysis from Penn State; active in security since 2017.
  • Previous purple team consulting for Fortune 500 clients and cloud security engineering.
  • 100+ audits covering Cosmos SDK chains, CosmWasm contracts, Solana programs, and protocol design reviews.
Lukasz Mikula

Lukasz Mikula

Senior Blockchain Security Auditor

  • 10+ years in offensive cybersecurity, including 3.5+ years auditing smart contracts.
  • Audited 80+ projects across EVM, Rust (CosmWasm, Solana, Substrate), Move, and TON.
  • Holds OSCP, OSCE, eWPTXv2 and CVEs; top 10 placements in Code4rena and Sherlock.
Kirill Taran

Kirill Taran

Senior Blockchain Security Auditor

  • Master’s in Mathematics and Software Engineering; 5+ years in Rust/Web3 (Substrate, CosmWasm, IBC).
  • Former JetBrains researcher in formal verification; worked at Parity Technologies on EVM compatibility.
  • 30+ audits focusing on L1 networks, interoperability, light clients, and bridges.
Mario Poneder

Mario Poneder

Smart Contract Security Researcher

  • Master’s in Technical Physics; multiple top finishes in Web3 bug bounty contests.
  • Reviewed 60+ protocols across EVM, Substrate, Starknet, Solana, and NEAR, protecting $8B+ TVL.
  • Broad engineering background in C/C++, Rust, Python, GPU computing, and simulations.

Values

Why teams choose Oak

Founder-led

Without VC funding, we have focused on sustainable growth without compromising on quality.

Agile

Our global pool of vetted senior security researchers allows us to expand on demand.

Relentless

Redundancy by design. Our work is conducted by multiple security researchers independently and simultaneously.

Reliable

We've been in the game since 2017, with many of the industry's top security experts, including PhD economists and cryptographers.

In the press

Press logoPress logoPress logoPress logoPress logoPress logo

Subscribe to our newsletter

Security research, audit insights, and ecosystem analysis — straight to your inbox.