Ensuring a Secure Web3 World
Full-stack blockchain security provider. Elite auditors protecting billions in on-chain assets through comprehensive audits, penetration testing, and security research.
Assets secured
Vulnerabilities found
Trusted By
Leading Web3 Projects
























































What We Do
Security Services
End-to-end security solutions for protocols, chains, and infrastructure
Smart Contract Audit
Comprehensive security audits for EVM, Solana, Sui, Aptos, and more.
Chain Audit
L1/L2 protocol security from consensus to VM implementation.
Wallet Audit
Browser extensions, mobile wallets, and custody solutions.
Web3 Penetration Testing
Infrastructure, API, and application security testing.
Track Record
Security Metrics
Customer Satisfaction
On-Chain Security
Vulnerabilities Patched
Detection Accuracy
Testimonials
What Our Clients Say
Founder
Twelve years breaking things — on your side of the table.
Nolan started in enterprise security at Huawei and 360, co-founded Numencyber to take that work on-chain, and now runs ExVul. The same instincts that found bugs in carrier infrastructure now go looking for them in your contracts.
Security expert
Huawei
Security expert
360
Co-founder
Numencyber
Founder
ExVul
From the blog
View allJuly 29, 2026
Source Says 50. Bytecode Says 0: The Sui Move Compiler Bug That Could Silently Drop Payments
Smart contracts execute bytecode, not the source developers review. We investigate a fixed Sui Move match-lowering bug that could erase a value-flow branch, turning a modeled 50-unit credit into 0 while still producing valid, verifiable bytecode.
May 29, 2026
Sui Mainnet Halt of May 28, 2026: An Address Balance Gas Underflow Post-Mortem
A deep post-mortem of the May 28, 2026 Sui mainnet stall: a single missing case at the seam of Address Balance and coin reservations let a failed transaction emit a poisoned accumulator Split, underflowing the per-checkpoint settlement system transaction and halting every validator.
April 9, 2026
HB Token Exploit Analysis: ~$193K Lost to AMM Reserve Manipulation via Reward Path
On April 7, 2026, HB Token on BSC was exploited for ~$193,936 USDT. The attacker leveraged a structural flaw in the protocol's reward distribution mechanism — tightly coupled with live AMM reserve mutations — to distort internal spot pricing and drain the pool.
Get Started
Secure Your Protocol Today
Don't leave your protocol unprotected — reach out to our team of experts to start discussing a security audit.
Assets secured
Vulnerabilities found
