Smart contract logic
Authorization, invariants, asset accounting, upgrades, external calls, and protocol-specific execution paths.
WEB3 SECURITY
Forge reviews Web3 systems across contracts, runtime flows, transaction paths, and integration boundaries, then ties every reportable claim to reproducible evidence.
Services
Forge reviews Web3 systems across contracts, runtime flows, transaction paths, and integration boundaries — then ties every reportable claim to reproducible evidence.
Authorization, invariants, asset accounting, upgrades, external calls, and protocol-specific execution paths.
Calldata construction, UI-only assumptions, API boundaries, replay resistance, and transaction-path integrity.
Connection flows, signature requests, user intent, approval safety, RPC assumptions, and signing-context clarity.
Trust boundaries, operational dependencies, governance controls, incentives, and assumptions that affect systemic risk.
How your contracts actually behave: access control, state transitions, asset accounting, upgrade paths, and the protocol-specific assumptions that can lose funds, break permissions, or corrupt system integrity — reviewed against your intended design, not just in isolation.
The paths where users actually sign: frontend transaction construction, wallet prompts and signing flows, RPC and API trust boundaries, and the off-chain assumptions that meet on-chain execution. We trace what a user is really approving, not just what the UI says.
How failures propagate: protocol architecture, infrastructure boundaries, governance controls, incentives, and economic assumptions that decide whether a single bug stays contained or cascades across contracts, integrations, and operations.
Findings you can act on: clear fix guidance tied to validated root causes, with reporting that supports engineering remediation, retesting, and whatever responsible-disclosure requirements your engagement or bounty program requires.
Deliverables
No raw scanner dumps. Every engagement ends with a scoped report you can hand to your engineers.
Engagement
The engagement starts with your scope and ends with validated findings and a retest of your fixes. You get checkpoints throughout — not a black box.
Tell us the project name, repositories or deployed apps, the surfaces you want reviewed, your timeline, and any confidentiality needs. Email contact@forgew3s.com to start.
We confirm the authorized boundaries, flag what's in and out of scope, and return a clear engagement shape: review focus, expected depth, timeline, and cost. No work begins until you approve.
During the review you get progress checkpoints, not a black box. We surface anything urgent — an actively exploitable issue — immediately through the agreed channel.
You receive a scoped report: each finding with reproduction, evidence, impact, severity rationale, and fix guidance — not a raw scanner dump.
After your team remediates, we retest the fixes against the original reproduction to confirm the issue is closed — not just patched around.
Benchmark
Forge does not report scanner output as truth. A candidate must be scoped, reproduced, evidenced, and tied to defensible impact before it's treated as a finding.