ABOUT FORGE

Founder-led Web3 security, human-in-the-loop.

Forge Web3 Security is an independent security practice focused on full-protocol review, evidence-backed vulnerability analysis, mitigation guidance, and responsible disclosure.

The founder

Forge is founder-led — final scope interpretation, test approval, evidence review, impact analysis, and severity judgment sit with a human, not a pipeline.

What Forge is built for

Forge exists to investigate how decentralized systems behave across contracts, interfaces, wallets, transactions, infrastructure, and human-operated workflows.

The goal is not to generate large volumes of speculative findings. It is to produce technically defensible conclusions that developers and decision-makers can act on.

Forge does not promise absolute security, use fake validation, or treat unsupported severity guesses as findings.

Human-in-the-loop security work

Automated tools and language models accelerate review, organize evidence, and surface patterns that warrant deeper investigation. They do not independently decide whether a vulnerability is valid or reportable.

Forge keeps final scope interpretation, test approval, evidence review, impact analysis, severity judgment, and reporting under disciplined human oversight.

This keeps the AI-assisted approach transparent — without making Forge sound like an automated scanner service.

  • Evidence-backed review
  • Full-protocol attack-surface thinking
  • Human-verified security claims
  • Responsible disclosure by default
  • No unsupported certainty
  • Client-facing mitigation guidance

Public posture