PUBLISHED WORK

Reviews

Real Vari reviews, published as client-anonymized samples. Same methodology, findings, severities, and recommendations we deliver — with the audited party's identity removed so we can share the work openly. Every layer we cover, on display.

REDACTED SAMPLES. Client identity and identifying scope details are removed and shown as      — the underlying text is stripped from the file, not just hidden. Clients receive the full-identity version to publish or upload wherever they like.
Published reviews // 06
▣ REDACTED FULL TIER FULL-STACK

Omnichain Stablecoin Protocol

Full-stack security review + economic modeling · 2026-08
Scope
5 layers
On-chain
Live-verified
Findings
35 total
Layers reviewed
Smart contractsDeployment / configCross-chainFrontend / backend / APIDNS / DNSSEC

A live omnichain stablecoin reviewed across contracts, configuration, cross-chain messaging, the dApp/backend, and DNS — plus a quantitative economic-modeling addendum covering bank-run, reflexive-depeg, collateral-drift, and tranche-run dynamics beyond what a code audit reaches.

Findings by severity
CRITICAL
0
HIGH
3
MEDIUM
7
LOW
13
INFO
12
▣ REDACTEDFULL TIERBoringVault-based · multi-chain

Cross-Chain RWA Vault

Full-stack review + penetration test + economic modeling · 2026-04
Findings
8
Exploits
6
On-chain
Multi-chain
Layers reviewed
Smart contractsDeployment / configCross-chain

A cross-chain RWA vault (BoringVault architecture) reviewed across contracts, configuration, and cross-chain messaging, then adversarially penetration-tested — surfacing a bridge path that bypasses KYC/cap controls, an administered-rate first-redeemer drain, and hot-key role concentration. Includes an economic addendum modeling the NAV-gap ratchet and the first-redeemer race.

Findings by severity
CRITICAL
0
HIGH
2
MEDIUM
2
LOW
4
INFO
0
▣ REDACTEDFULL TIERFixed-term uncollateralized lending

Membership-Gated Lending Protocol

Full-stack review + penetration test + economic modeling · 2026-04
Findings
7
Exploits
6
Funds
Peer-to-peer
Layers reviewed
Smart contractsDeployment / config

A membership-gated fixed-term lending protocol reviewed and penetration-tested. Pools custody no funds (peer-to-peer), so theft vectors were refuted — the live risk is interest/fee accounting: a monthly overdue double-charge and a multi-lend proration overcharge, plus terminal-default griefing. The addendum models borrower overpayment and default loss-given-default.

Findings by severity
CRITICAL
0
HIGH
0
MEDIUM
1
LOW
4
INFO
2
▣ REDACTEDFULL TIERAPR reward engine + factory

Treasury-Yield Pool

Full-stack review + penetration test + economic modeling · 2026-05
Findings
7
Exploits
5
Upgrade
Beacon
Layers reviewed
Smart contractsDeployment / config

A treasury-yield pool with an APR reward engine and factory. Penetration testing confirmed two high-severity manager-privileged exploits with exact arithmetic — a single-block drain of the shared reward reserve and a permanent overflow-brick with a self-locking reset — plus a KYC bypass on principal. The addendum models reserve runway and the unbounded-rate drain.

Findings by severity
CRITICAL
0
HIGH
1
MEDIUM
2
LOW
3
INFO
1
▣ REDACTEDSTANDARD TIERNode staking · reward distributor

Validator Staking & Rewards

Review + penetration test + economic note · 2026-05
Findings
8
Exploits
6
Reward math
Solvent
Layers reviewed
Smart contracts

An upgradeable validator-node staking and reward distributor. Reward accounting is solvent-by-construction; the exploitable surface is owner/validator operational hazards — an unbounded node fee that permanently bricks rewards, a batch-revert griefing DoS, and a validator-accounting desync — plus a near-100% validator fee siphon. A short economic note covers the reward/liveness coupling.

Findings by severity
CRITICAL
0
HIGH
0
MEDIUM
3
LOW
4
INFO
1
▣ REDACTEDAPP TRACK3 dApps · domains / DNSSEC

dApp Frontends & DNS

Application + DNS review + penetration test · 2026-05
Findings
10
Exploits
4
DNSSEC
Chain checked
Layers reviewed
Frontend / backend / APIDNS / DNSSEC

Three dApp frontends plus the domains that front them. No committed secrets and admin routes properly signature-gated, but penetration testing confirmed two high-severity app exploits — an unauthenticated branded-email phishing endpoint and a fail-open admin session secret — alongside a broken DNSSEC chain (DS missing at the registrar) and weak DMARC/DKIM. Includes the SEAL operational scorecard and a DNSViz chain-of-trust table.

Findings by severity
CRITICAL
0
HIGH
2
MEDIUM
3
LOW
4
INFO
1
MORE REVIEWS AS THEY PUBLISH. Each engagement adds a redacted report — and, for funds-at-risk protocols, an economic modeling addendum — here.

Want your stack reviewed?

Every layer, one review — contracts, config, frontend, backend, and DNS. Days, not months. A fraction of traditional audit cost.