Audits
Smart contract and operational security work is done through Adevar Labs. The list below is public firm work, not a personal credit list.
These are public Adevar Labs audit reports only. Many engagements remain private and are not listed.
Listed for illustration of Adevar Labs public work. Catalin may not have participated in every engagement shown.
Adevar also runs opsec audits (multisig operations, treasury, incident response, DevOps, identity controls) and is a SEAL Certifications partner undergoing accreditation with Security Alliance.
Audit Approach
Public Adevar Labs assessments run through four passes: source review, invariants, incentive design, and attacker models.
01
Manual review
Line-by-line code review and vulnerability analysis. Account checks, privilege boundaries, and control flow before any automated pass.
02
Fuzzing
Property-based tests and invariant checking against states the happy path never reaches. Uncommon execution paths and adversarial input.
03
Economic security
Mechanism design and incentive review. Insolvency, griefing, MEV, and assumptions that hold in code but fail once markets get involved.
04
Threat modeling
Adversary paths, trust boundaries, and abuse cases. What a motivated attacker does with admin keys, oracles, and cross-program invocation.
Public Adevar Labs assessments: GitHub · adevarlabs.com/reports. Inquiries via adevarlabs.com.