Senior security review for live protocols — in days, not months.
Your audit covered the code. I review who can move your money, how transactions get signed, and what your next release re-opens.
Ten years engineering, two at Trail of Bits — the person on the report does the work.

access snapshot — 0x7a3f…c9e2 (ethereum)
owner: Safe 3/5
2 signers overlap with deployer EOA
pauser: single EOA
← the pattern behind Munchables, Radiant
upgrade: proxy admin, 12h timelock
emergency: guardian withdraw, no timelock
recommended next step:
signer interviews — blind-signing
exposure unreviewedYour code froze at launch. Everything else kept moving.
Signers rotate, roles accumulate, releases ship. Audited protocols get drained in three places — and none of them is the audited code.
Who can move your money
Owners, pausers, upgrade authority. Access-control failure — not code — caused 54% of last year's losses (Hacken).
How transactions get signed
Bybit lost $1.4B to one blind-signed transaction. Compromised keys took $577M more in April (TRM Labs).
What you ship next
Every upgrade re-opens audited assumptions — and nobody re-checks the diff against the audited baseline.
Three products. One free way in.
Every price on the page. Start free.
The Access Snapshot
A one-page map of every owner, role, and signer — built from public chain data.
The Signing & Access Review
Your code got audited. Your keys didn't. The full control-plane audit, plus a hard look at how transactions get signed.
The Release Review
Senior eyes on the diff before mainnet, against your audited baseline. Safe to ship?
The Security Retainer — $7,500/month. Two Release Reviews monthly plus a direct line. Ask about the retainer.
Kickoff to report in ten business days.
The flagship review: fixed price, fixed timeline, no scope creep.
What the Signing & Access Review looks like.
Book the reviewMap the control plane
Every owner, role, and signer across your contracts — thresholds, timelocks, upgrade authority, emergency powers. All from public chain data.
Days 1–4
Review how signing works
Two interviews with your signers — never your devices, never your keys. Transaction flow, blind-signing exposure, key handling.
Days 4–7
Findings with incident receipts
Every finding tied to the incident class it matches. Fixes split into this-week wins and structural work, walked through on a call.
Day 10
AI-assisted where it helps. Human-reviewed where it matters.
I use AI to accelerate role and permission mapping, privileged-transaction review, release-diff triage, signing-flow analysis, and incident-pattern matching. The output is not raw AI noise: findings are validated with human review, PoCs, or written exploit reasoning.
AI can flag what's exposed.
PoCs and interviews prove whether it matters.
A human decides what goes in the report.

Robert Schneider
robert@superdroids.co
The reviewer is the firm.
Most protocols that get drained were audited. The losses come from keys, over-powered roles, and how transactions get signed — and from what ships after the report.
SuperDroids reviews that layer. You work with me directly — no account managers, no junior pass-through.
Common questions.
Quick answers to what most teams ask before booking.
Still have a question?
Email me directly and I'll respond within a business day.
Find out who can move your money.
The free Access Snapshot: one page, public chain data, back in 48 hours.