Full-stack security review · 1–3 days · fixed price

Your contracts were audited. The rest of your stack wasn't.

Vari reviews contracts, deployment config, cross-chain, frontend, backend and DNS as one attack surface — every finding ranked by real exploitability, with a concrete fix. Fixed quote in 24 hours. Report in 1–3 days. From $2,500.

Public repos: paste a link. Private: we'll send read-only invite steps after you write.

Published review · redacted sample2026-04

Cross-chain RWA vault

Contracts · deployment config · cross-chain messaging · Full tier · 32 findings, each with a fix

Critical0
High2
Medium2
Low4
Info0
  • HighBridge path bypasses KYC and cap controlscross-chain
  • HighAdministered-rate first-redeemer draincontracts
  • MedHot-key role concentration on admin pathsconfig
  • + 5 more · each with impact, location and fix · full PDF on the reviews page
$1B+moved on-chain through contracts we've built, reviewed or run
7+ yrsarchitecting blockchains, DeFi protocols and stablecoins end-to-end
244findings across 6 published reviews, all redacted and public
219of those findings backed by an executed proof of concept, each with a fix
The problem

Audits scope the code. Attackers don't.

94%

of losses at audited protocols in H1 2026 came from outside the audit's scope — keys, config, bridges, frontends and off-chain infrastructure.

ack3 H1 2026 incident dataset · 135 incidents · $940M lost · our breakdowns →

−$292MKelp DAO · Apr 2026 · bridge

Bridge contracts audited and clean. Shipped with a 1-of-1 verifier; one compromised verifier forged a cross-chain message. Configuration, not code.

−$285MDrift Protocol · Apr 2026 · keys

Audited by four firms. Social engineering reached two of five multisig signers; no timelock on admin transfers. Keys and operations, not code.

−$40MStep Finance · Jan 2026 · backend

Private keys compromised in off-chain signing infrastructure — the backend around the contracts. Backend, not code.

−$130M+Coldcard · Aug 2026 · one line

One line of predictable RNG-fallback code sat unnoticed for five years until seeds were brute-forced at scale. Small flaw, catastrophic blast radius.

Who this is for

An audited vault with an EOA admin, a max-approve UI, or an unlocked domain is still a company-ending event.

A launch, a listing or a raise does not survive a config, key, UI or DNS failure — and a contract-only review leaves every one of those surfaces untouched. This is the review of the system your users and your attackers actually touch. Point-in-time, residual risk stated, no "certified secure."

What we cover

Six layers. One engagement. One ranked report.

A typical smart-contract audit stops at the contracts. Vari reviews the whole surface an attacker sees, and checks the seams between layers — frontend ↔ contracts ↔ backend ↔ config. EVM (Solidity), Solana (Anchor/Rust) and Stacks (Clarity).

Six layers of a protocol; a typical audit covers the contracts only, Vari covers all six Frontend & signing UIwhat users actually sign Backend / API / indexerkeepers, allocators, signers Cross-chain messagingverifier thresholds, bridge paths Smart contractslogic, access control, upgrades Deployment & configadmin keys, multisig, timelocks, oracles DNS & domainDNSSEC, DMARC, CAA, registrar TYPICAL AUDIT VARI · EVERY LAYER
  • Smart contractslogic, access control, upgrade authority, known vulnerability classes
    audit ✓ · vari ✓
  • Deployment & configproxies, admin keys, multisig thresholds, timelocks, verifier and oracle config — read live from chain
    vari only
  • Cross-chain messagingDVN / verifier thresholds, bridge paths, peer configuration
    vari only
  • Frontend & signing UIwhat users actually sign; look-alike domains; wallet flows
    vari only
  • Backend / API / indexerkeepers, allocators, signers, admin routes, secrets
    vari only
  • DNS & domainDNSSEC, DMARC, CAA, registrar lock, chain of trust
    vari only
Turnaround3–6 weeks1–3 days
Pricingby line countfixed by tier
Reportranked by exploitability · fix for every finding · publicly shareable
How it works

Three steps. No procurement theatre.

Day 0

Send links

App URL and repos. Public: paste. Private: add VARI-Review as a read-only collaborator — we send the steps when we reply.

Within 24h

Fixed quote

One number, one start date. Scope locks before we begin, so every hour is review. The clock starts when access lands.

Day 1–3

Ranked report + fixes

Severity-ordered findings with impact, location and a concrete fix; one clarification round; publicly shareable with standard disclaimers.

Pricing

Fixed by tier, not by line count.

One product = its whole stack. Several products together get a reduced per-product rate and one combined quote. Not sure which tier? Send it anyway — the quote is free.

Starter
$2,500–4,5001–2 days

Pre-launch or testnet: token, NFT, staking or vesting contracts and their deployment config. Minimal live surface, no backend.

1–2 contracts · single chain · light frontend

Quote Starter
Standard
$6,000–12,0002–3 days

Live but lean: a handful of contracts on one chain — token + staking, a simple vault, a single-market app — with a simple frontend and no meaningful backend.

≤5 contracts · single chain · no oracles

Quote Standard

Not sure which tier fits? Send the repo and URL — the quote comes back the same day, free.

After the review

An audit ends at deploy. Attacks don't.

A review finds the exploit before you ship. Three ways to keep the coverage current after you do.

Re-review

Verify the fixes

We re-test every finding after remediation and update the report. 30–40% of the original fee, same week.

Delta retainer

Every release re-reviewed

Code and config change weekly; yesterday's clean report doesn't cover today's deployment. Each release diff and a live-config snapshot (plus DNS on Full) reviewed on a monthly retainer — from $1,200/mo after Starter, $2,500/mo after Standard, $5,000/mo after Full. Three-month minimum.

Runtime guards · roadmap

Watch the surfaces after you ship

After a review, the same surfaces can be watched and, where you want it, enforced — config drift, DNS, and the pause / cap / allowlist paths already marked in your report. Available after an engagement and scoped separately. Roadmap, not a shrink-wrapped platform.

Free tool · no signup

Decode what your wallet is about to sign.

Recompute Safe transaction hashes, decode any EIP-712 request and read raw calldata — in your browser, nothing leaves the page.

Safe tx hash   0x9f…c21a ✓ matches
EIP-712        domain v1.3.0 · chain 1
Calldata       transfer(address,uint256)
Risk           recipient not in your address book
Varinder Singh, founder and lead reviewer at VariVarinder SinghFounder & lead reviewer
Chain architectureStablecoinsDeFiCross-chain
Who reviews your code

Built by someone who has shipped what you're shipping.

Seven-plus years building novel products from scratch — blockchains, DeFi protocols and stablecoins, architected end-to-end. Across the contracts he has built, reviewed and managed, more than $1B has moved on-chain. He is the founder and lead reviewer, and every finding in your report is reproduced, ranked and signed by a person — no report leaves here that a reviewer has not stood behind.

Fair questions

What you'd ask before paying.

Is this an "AI audit"?

No. Tooling is used for coverage — static analysis, fuzzing, symbolic checks and our own detectors — the same way any serious firm uses Slither or a fuzzer. A person reproduces every finding, decides its severity and signs the report. Nothing reaches you that a reviewer has not stood behind.

Can 1–3 days be thorough?

Scope locks before we start, and the mechanical coverage work runs alongside the review rather than ahead of it — so reviewer time goes to logic, access control, configuration and cross-layer paths, where protocols actually get drained. Code that already holds funds can't wait weeks in a queue.

Is this a real audit?

It is a point-in-time full-stack review of a specific commit and deployment, with residual risk stated plainly. That is what a serious review is. A logo from another firm is a separate purchase some teams make for distribution — it is not required for this work to count.

I have more than one product — how is that priced?

Each tier covers one product's full stack. A lending protocol plus separate vault, staking or vesting apps on their own domains is several products. Submit them together and you get a reduced per-product rate and a single combined quote.

What's out of scope?

Testing against live production systems, formal verification, continuous monitoring, and any guarantee or insurance. A review is a point-in-time assessment; residual risk is stated plainly in every report.

What do you need from us?

Links. Public repos: paste them. Private repos: add VARI-Review as a read-only collaborator when we reply — access is scoped to the review and removed after. No data is sold and the site runs no trackers.

Get a fixed quote

Tell us what you're shipping.

A fixed number within 24 hours — free, no obligation. Three fields is all we need to start.

Prefer DMs? Telegram @va_rinder

We reply within 24 hours. By submitting you agree we may use your details to respond, as described in our privacy policy. No trackers, no data resale.