Web3 Hybrid Security.

Auditor × Tooling .

1st place Ronin. Top-10 on four more Code4rena contests. 27 published QA reports.

CONTESTS + ENGAGEMENTS 40+ engagements and audit contests · Jul 2024 → present
Ronin Reserve Morpheus Blackhole Flex Perp Axelar Phi Virtuals Monad Swafe Megapot Hybra Finance Flare Olas K2 Monetrix
./about

Auditor × Tooling.

Blue Eyes Security was built around two things: an auditor who knows what to investigate, and proprietary in-house tooling that makes the investigation scale.

After two years in the contest space, the edge has proven to be the combination of both.

Founded by Auditor_Nate, who has been hunting bugs full-time since July 2024. Body of work includes five top-10 Code4rena contest finishes and 27 published QA reports — produced through Team PolarizedLight, a contest-focused auditing team.

Blue Eyes Security extends that practice into private engagements. Solidity and Rust smart contract audits — including Stellar/Soroban — are the core offering: fixed-scope, manually reviewed, every finding backed by a working proof-of-concept. Engagements concentrate where funds actually break: accounting, precision, and invariant violations — in Solidity and Rust codebases.

./track_record

Code4rena contest platform
results.

Contest findings credited across Phi, Reserve, Ronin, Axelar Network, Chakra, Morpheus, Flex Perpetuals, Virtuals Protocol, Blackhole, Megapot, Concrete, Lambo.win — plus many more across multiple contest platforms. Every finish is produced by Team PolarizedLight and verifiable on the public leaderboard.

FIG.01 Contest ranks · Code4rena jul 2024 → present
#1 #3 #5 #7 #10
#01 Ronin
#04 Blackhole
#04 Flex Perp
#06 Morpheus
#07 Reserve
peak finish · 1st place top-10 finishes
FIG.02 QA report distribution 27 published · C4
0 A-grade
0 B-grade
A-grade 0 reports · 40.7%
B-grade 0 reports · 59.3%
total 0 reports · 100%
PROFILE verifiable
@PolarizedLight

Full contest history, rank pages, and QA report links available on Code4rena’s public leaderboard.

View profile
./services

Fixed scope. Fixed quote.

Four ways to engage — every one delivered end to end by the same auditor.

Pricing scales with audited lines of code and complexity — you get one fixed quote at scoping, and it does not move after kickoff. Every audit includes one remediation review round within 30 days of report delivery.

Entry point

Pre-audit readiness review

A short preparation pass ahead of a full audit: threat-model sketch, assumption map, prioritized pre-audit fix list, and a scope recommendation for the follow-on review — so the audit starts on code that is actually ready for it.

  • Timeline2–4 days
  • DeliverableReadiness memo + scope plan
  • Next stepAudit scoped from the memo
Focused

Focused review

Fixed-scope audit of a contained codebase — a single component, an upgrade, a new feature. Manual review backed by proprietary tooling, severity calibrated against real-world impact, and every High and Medium finding shipped with an executable proof of concept.

  • ScopeContained codebase
  • Timeline~1 week
  • QuoteFixed at scoping
Flagship

Protocol review

The full audit for a protocol heading to mainnet. Everything in the focused review, plus protocol-level invariant analysis — accounting identities, conservation properties, rounding direction discipline — cross-contract interaction review, and a mid-engagement findings call.

  • ScopeFull protocol
  • Timeline2–3 weeks
  • QuoteFixed at scoping
Yours to keep

Invariant suite handover

Not an audit — a CI-ready invariant test suite your team keeps. Protocol invariants identified, documented in plain English, wired into executable fuzz tests, and handed over with documentation and a walkthrough call.

  • Timeline1–2 weeks
  • DeliverableTest suite + handover doc
  • QuoteScoped to protocol size
./process

Four core steps.

A hybrid approach: one auditor, proprietary tooling, every finding verified before it ships.

  1. 01 /04

    Scope + kickoff

    Discovery call — meet both the team and the code. Scope is anchored to a specific commit hash, documentation reviewed, protocol walkthrough done, and a direct communications channel opened between auditor and team.

  2. 02 /04

    Investigation

    Manual review and proprietary tooling work the code in parallel. Candidate findings surface from both; the auditor triages every one, investigates leads, and follows threads until the deepest issues are on the table.

  3. 03 /04

    Verification + calibration

    Every High and Medium finding must survive an executable proof-of-concept that demonstrates the actual harm — what can’t be demonstrated is downgraded or cut. Severity is calibrated against real-world impact, not theory.

  4. 04 /04

    Report + remediation

    Full report with finding write-ups, reproducible PoCs, and concrete fix guidance. Confirmed Criticals are flagged within 24 hours — never held for the report. One remediation review round included within 30 days of delivery.

./availability

One protocol at a time.

Engagements run serially — one codebase gets full attention, then the next. Windows are claimed in order, so the queue position you inquire at is the one you get.

sys.status accepting-inquiries
engagement state
current window · jun 2026 committed
next full-audit window · jul 2026 one slot · unclaimed
readiness review can start within days
Claim the window discovery call · 30 min · no commit
./contact

Start a conversation.

Send a message with the protocol, target scope, and any deadline you’re working toward. A direct reply follows within 24 hours.