BulkSender
Batch token distribution contract. Found a critical issue in the transfer accounting before it reached production.
- Date
- February 2026
- Status
- Completed
- Issues found
- 1 critical
Taking new audits — limited slots each month
An independent security review of your Solidity or Vyper contracts on any EVM chain. Fixed pricing from €250, a written report in 3–10 days, and a concrete fix for every finding.
You deal directly with the person reading your code — no account managers, no six-week queue, no hourly overruns. If the review turns up nothing above informational severity, you get a full refund and keep the report.
Prefer to look first? Read two published audit reports before you contact me.
Chains: Ethereum · Base · Ronin · BNB Chain · Polygon · any EVM-compatible chain
Client feedback
Every engagement on this page is public: the client, the testimonial, and the report itself. You can verify the work before you hire me.
More updates on X“We just wrapped a smart contract audit for KoinArcade — huge thanks to @_Alex_Cipher for the review.”
KoinArcade
Smart contract security review
What's included
The same six things on every tier. Only the scope and the depth of follow-up change with the price.
Every contract in scope read by a human, not a scanner dump. Automated tools are a starting point here, never the deliverable.
Reward maths, fee accounting, oracle assumptions, and the sequences of legal transactions that quietly drain a protocol.
Findings arrive with a reproducible test that demonstrates the issue, so your team can confirm severity in minutes.
Critical through informational, each finding with impact, likelihood, affected lines, and a concrete remediation step.
I stay reachable while you patch. Questions about a finding or a proposed fix get answered, not queued.
On the Audit + Retest tier your fixes are re-reviewed and you receive a final report you can publish to investors and users.
Process
Five steps from first message to signed-off code. You always know which one we are on and what lands next.
A short call to walk through your contracts, chain setup, and deadline. You leave with a fixed price and a delivery date, not an estimate.
Line-by-line reading of the codebase, then targeted analysis of the parts that hold value: accounting, access control, reward maths, and external calls.
I write proof-of-concept tests for the paths I think break, so findings arrive with evidence attached instead of a maybe.
A written report with severity ratings, reproduction steps, and a concrete fix for each issue. Then I stay reachable while you patch.
On the Audit + Retest tier I re-review your fixes and issue a final sign-off report you can share with your investors or community.
Pricing
Fixed prices, published up front. Pick the tier that matches your scope and the number confirmed on our scoping call is the number you pay.
These are introductory prices while I build out my library of public audit reports. They go up after the next five engagements — the rate you book at is the rate you keep for that engagement.
€250fixed
Single contract review, up to 200 lines.
€900fixed
Full multi-contract audit with a written report and severity ratings.
€1,600fixed
Full audit plus a post-fix retest and a final sign-off report.
From €2,000
Protocols above roughly 1,500 lines, multi-module systems, or anything needing a longer engagement.
Quoted on scope after a call. Same process, same deliverables, same guarantees — the timeline and price just match the size of the job.
If the review surfaces nothing above informational severity, you get a full refund and keep the report anyway. You should not have to pay to find out there was nothing to find.
The number agreed on the scoping call is the number you pay. No hourly overruns, no scope-creep invoices, no surprise line items after delivery.
Your code and findings are never published or shared without your written permission. NDA on request, signed before you send anything.
Every tier includes a manual code review, exploit testing, a written findings report with severity ratings, and follow-up support while you patch.
Final pricing is confirmed after a brief scoping call based on actual contract complexity. Larger codebases are quoted individually — see the full service breakdown.
Published work
Full reports from past engagements, published with client permission. This is exactly the format and depth you receive.
Batch token distribution contract. Found a critical issue in the transfer accounting before it reached production.
On-chain arcade with player payouts. Reviewed game logic, payout accounting, and randomness handling.
Send me your repo, chain, and deadline. You get a fixed price and a delivery date back — usually the same day.
No obligation, and a full refund if the review finds nothing above informational severity. If your scope is outside what I cover, I will say so on the call.
About

I'm Adomas Venslovas — Alex Cipher — a blockchain security researcher with three years of experience auditing smart contracts for DeFi and GameFi protocols across EVM-compatible chains.
My work centres on the parts of a protocol that actually hold value: staking contracts, AMM logic, token flows, reward systems, and the business logic that turns a well-written contract into an exploitable one when nobody reviews it end to end.
I have a verified Code4rena M-01 finding, identified a critical vulnerability in BulkSender, and have made responsible disclosures to live Ronin protocols. On every engagement the goal is the same: a high-signal report with clear remediation guidance, not a checklist printout.
Languages
Solidity, Vyper, Foundry test suites
Security analysis
Manual review, exploit proof-of-concepts, invariant reasoning
Specialisation
DeFi staking, AMM mechanics, GameFi protocol architecture, business logic vulnerabilities
Chains
Ethereum, Base, Ronin, BNB Chain, Polygon, and any EVM-compatible chain
Beyond client work
Built “Never Poor Again”, an auditor's playground CTF for the security community, and compete regularly in CTFs solving complex on-chain security challenges.
View the CTF on GitHubActive security researcher on Code4rena with a verified medium-severity finding and payouts from competitive audit contests.
View my Code4rena profileWriting
How I think about smart contract risk, written up so you can judge the reasoning before you buy the report.
Real market rates for independent auditors, boutique firms, and top-tier firms — and the variables that actually move the number.
The checklist I run against a codebase before an audit begins — access control, accounting, oracles, upgrades, and the questions to answer before you hand anything over.
Scope sections, severity ratings, and why 'acknowledged' means the bug is still there. How to judge an audit report instead of skimming the summary table.
FAQ
The questions founders ask before booking a review. If yours isn't here, email me and I'll answer it directly.
A single-contract Code Review is €250, a full Protocol Audit is €900, and Audit + Retest is €1,600. Larger codebases start from €2,000 and are quoted on scope. Final pricing is confirmed after a brief scoping call, so you know the number before any work starts. These are introductory rates while I build out my public report library.
Three days for a Code Review, seven for a Protocol Audit, and ten for Audit + Retest. Because I take a limited number of engagements at a time, your review starts when I say it does rather than sitting in a firm's queue for weeks.
Solidity and Vyper on any EVM-compatible chain, including Ethereum, Base, Ronin, BNB Chain, and Polygon. Most of my work is DeFi mechanics and GameFi protocol logic.
A written report listing every finding with a severity rating, an explanation of how it is exploited, and a concrete remediation step. You also get follow-up support to ask questions while you implement the fixes.
You work directly with the person reading your code, not an account manager. That means faster turnaround, transparent fixed pricing, and a reviewer who has the context to discuss your protocol's economics rather than only its syntax.
Pricing is confirmed after the scoping call, and payment is arranged before the review begins. There are no hourly overruns: the number agreed on the call is the number you pay.
Then you get a full refund and keep the report anyway. If a review surfaces nothing above informational severity, you should not be out of pocket for it — that risk sits with me, not with you.
Yes. Randomness handling, payout accounting, house-edge logic, and reward emission are a core focus, and I have published guidance on gambling dApp security specifically.
Yes. Two full reports from past engagements, BulkSender and KoinArcade, are published on this site so you can judge the depth and formatting before you commit to anything.