SuperDroidsSuperDroids

Senior security review for live protocols — in days, not months.

Your audit covered the code. I review who can move your money, how transactions get signed, and what your next release re-opens.

Ten years engineering, two at Trail of Bits — the person on the report does the work.

An editor reviewing a Morpho-Midnight smart contract — Certora specs, passing Foundry tests, and an AI agent discussing liquidation and test-coverage risk.
access snapshot — 0x7a3f…c9e2 (ethereum)

owner:     Safe 3/5
    2 signers overlap with deployer EOA
pauser:    single EOA
    ← the pattern behind Munchables, Radiant
upgrade:   proxy admin, 12h timelock
emergency: guardian withdraw, no timelock

recommended next step:
    signer interviews — blind-signing
    exposure unreviewed

Your code froze at launch. Everything else kept moving.

Signers rotate, roles accumulate, releases ship. Audited protocols get drained in three places — and none of them is the audited code.

Who can move your money

Owners, pausers, upgrade authority. Access-control failure — not code — caused 54% of last year's losses (Hacken).

How transactions get signed

Bybit lost $1.4B to one blind-signed transaction. Compromised keys took $577M more in April (TRM Labs).

What you ship next

Every upgrade re-opens audited assumptions — and nobody re-checks the diff against the audited baseline.

Kickoff to report in ten business days.

The flagship review: fixed price, fixed timeline, no scope creep.

What the Signing & Access Review looks like.

Book the review
01Map

Map the control plane

Every owner, role, and signer across your contracts — thresholds, timelocks, upgrade authority, emergency powers. All from public chain data.

40%

Days 1–4

02Interview

Review how signing works

Two interviews with your signers — never your devices, never your keys. Transaction flow, blind-signing exposure, key handling.

70%

Days 4–7

03Report

Findings with incident receipts

Every finding tied to the incident class it matches. Fixes split into this-week wins and structural work, walked through on a call.

100%

Day 10

AI-assisted where it helps. Human-reviewed where it matters.

I use AI to accelerate role and permission mapping, privileged-transaction review, release-diff triage, signing-flow analysis, and incident-pattern matching. The output is not raw AI noise: findings are validated with human review, PoCs, or written exploit reasoning.

01

AI can flag what's exposed.

02

PoCs and interviews prove whether it matters.

03

A human decides what goes in the report.

Robert Schneider

Robert Schneider

robert@superdroids.co

The reviewer is the firm.

Most protocols that get drained were audited. The losses come from keys, over-powered roles, and how transactions get signed — and from what ships after the report.

SuperDroids reviews that layer. You work with me directly — no account managers, no junior pass-through.

FAQ

Common questions.

Quick answers to what most teams ask before booking.

Still have a question?

Email me directly and I'll respond within a business day.

Email Robert

Find out who can move your money.

The free Access Snapshot: one page, public chain data, back in 48 hours.