WEB3 SECURITY

Web3 security reviews that hold up under scrutiny.

Forge reviews Web3 systems across contracts, runtime flows, transaction paths, and integration boundaries, then ties every reportable claim to reproducible evidence.

Services

One connected attack surface, reviewed end to end.

Forge reviews Web3 systems across contracts, runtime flows, transaction paths, and integration boundaries — then ties every reportable claim to reproducible evidence.

Smart contract logic

Authorization, invariants, asset accounting, upgrades, external calls, and protocol-specific execution paths.

dApp and frontend transaction flows

Calldata construction, UI-only assumptions, API boundaries, replay resistance, and transaction-path integrity.

Wallet and signing interactions

Connection flows, signature requests, user intent, approval safety, RPC assumptions, and signing-context clarity.

Architecture, boundaries, and economic assumptions

Trust boundaries, operational dependencies, governance controls, incentives, and assumptions that affect systemic risk.

Smart Contract and Protocol Logic Review

How your contracts actually behave: access control, state transitions, asset accounting, upgrade paths, and the protocol-specific assumptions that can lose funds, break permissions, or corrupt system integrity — reviewed against your intended design, not just in isolation.

dApp and Wallet Interaction Security

The paths where users actually sign: frontend transaction construction, wallet prompts and signing flows, RPC and API trust boundaries, and the off-chain assumptions that meet on-chain execution. We trace what a user is really approving, not just what the UI says.

Architecture and Assumption Review

How failures propagate: protocol architecture, infrastructure boundaries, governance controls, incentives, and economic assumptions that decide whether a single bug stays contained or cascades across contracts, integrations, and operations.

Remediation and Disclosure Support

Findings you can act on: clear fix guidance tied to validated root causes, with reporting that supports engineering remediation, retesting, and whatever responsible-disclosure requirements your engagement or bounty program requires.

Deliverables

What you actually get back.

No raw scanner dumps. Every engagement ends with a scoped report you can hand to your engineers.

  • Validated findings, each with reproduction steps — not unfiltered scanner output.
  • An evidence packet per finding — the transactions, traces, or test artifacts that prove the issue.
  • Severity rationale tied to real impact — funds at risk, blast radius, trigger conditions.
  • Practical remediation guidance written for engineers, plus retest support after fixes.
  • A scoped report delivered through your agreed channel, with responsible-disclosure handling where relevant.

Engagement

How a review works, from your side.

The engagement starts with your scope and ends with validated findings and a retest of your fixes. You get checkpoints throughout — not a black box.

01

You send scope

Tell us the project name, repositories or deployed apps, the surfaces you want reviewed, your timeline, and any confidentiality needs. Email contact@forgew3s.com to start.

02

We confirm fit and quote

We confirm the authorized boundaries, flag what's in and out of scope, and return a clear engagement shape: review focus, expected depth, timeline, and cost. No work begins until you approve.

03

Review with updates

During the review you get progress checkpoints, not a black box. We surface anything urgent — an actively exploitable issue — immediately through the agreed channel.

04

Validated findings delivered

You receive a scoped report: each finding with reproduction, evidence, impact, severity rationale, and fix guidance — not a raw scanner dump.

05

Retest of fixes

After your team remediates, we retest the fixes against the original reproduction to confirm the issue is closed — not just patched around.

Benchmark

The standard a finding has to meet.

Forge does not report scanner output as truth. A candidate must be scoped, reproduced, evidenced, and tied to defensible impact before it's treated as a finding.

  • Scope before testing
  • Evidence before assertion
  • Reproduction before severity
  • Proof before reporting
  • Responsible disclosure before publicity

Ready to scope a review?