Public audits · curated

Audits.

Public engagements delivered as Zealynx (founded 2023) and as contractor for partner firms. Click into any report for the full write-up; click into a finding for the citable artifact.

41 audits total · 31 by Zealynx · 10 by Carlos (Bloqarl) as contractor (Cyfrin · Pashov Audit Group · Sherlock · Codespect · Composable Security)

Reports published
41since 2023
Findings identified
463across 41
Critical + High
76all remediated

Findings by severity

463 total
463FINDINGS

Reports by chain

41 total
41REPORTS

Reports by protocol type

41 total
41REPORTS
41 of 41 reports
DripsterOffchain · Typescript
2026-04-29

Dripster Backend Pentesting

Prediction Markets

Backend pentest of the Dripster NestJS API, covering auth, business logic, rate limiting, and Polymarket integration. 21 issues identified (1 High, 4 Medium); 13 fixed during the engagement.

0C1H4M11L5I
TypescriptZealynx2026-04-29
DripsterPolygon · Solidity
2026-04-28

Dripster Leveraged Prediction Vault

Prediction Markets

Custodial USDC vault opening leveraged Polymarket positions on Polygon. 17 issues identified (2 Medium, no Critical/High); 9 fixed, 8 acknowledged.

0C0H2M7L8I
SolidityZealynx2026-04-28
Yada CoinBNB · Solidity
2026-03-05

YadaCoin Bridge Infrastructure

Bridges / Cross-chain

BNB ↔ YadaCoin cross-chain bridge with KERI key registry and ERC-2612 permits. 28 issues identified (3 Critical, 2 High); all fixed before mainnet.

3C2H4M16L3I
SolidityZealynx2026-03-05
Fair LabsOffchain · Typescript
2026-01-27

Fair Casino Core Pentest

GameFi

TypeScript backend and provably-fair pentest for Fair Casino. 13 issues identified (4 High, 6 Medium, 3 Low), all fixed and verified.

0C4H6M3L0I
TypescriptZealynx2026-01-27
Fair LabsOffchain · Typescript
2026-01-27

Fair Casino Swap Pentest

GameFi

Follow-on pentest of the Fair Casino SOL→FAIR swap flow. 2 High issues identified in the WebSocket confirmation layer, both fixed and verified.

0C2H0M0L0I
TypescriptZealynx2026-01-27
Fair LabsSolana · Rust
2026-01-19

Fair Casino Solana Vault Program

Vaults / Yield

Solana vault program with PDA token custody and Ed25519 instruction introspection. 5 issues identified (1 High, 1 Medium, 3 Low), all fixed and verified.

0C1H1M3L0I
RustZealynx2026-01-19
NovaswapOffchain · Typescript
2026-01-17

Novaswap Blackbox Pentest

DEX / AMM

Blackbox pentest of the Novaswap frontend and Mynth API endpoints. 9 issues identified (1 Medium, 4 Low, 4 Informational), all fixed and verified.

0C0H1M4L4I
TypescriptZealynx2026-01-17
SpicenetOffchain · Typescript
2026-01-15

Spicenet TypeScript Audit

Bridges / Cross-chain

TypeScript audit via Pashov Audit Group. Report not public.

Private report
Typescriptvia Pashov Audit Group2026-01-15
NexaloEthereum · Solidity
2025-12-22

Nexalo Smart Contract Audit

GameFi

Autonomous on-chain raffle protocol with Chainlink VRF, multi-level referrals, vesting, and BTC treasury. 22 issues identified (3 Critical, 5 High); 14 fixed and 8 acknowledged.

3C5H10M4L0I
SolidityZealynx2025-12-22
Golden GridApeChain · Solidity
2025-11-17

Golden Grid Smart Contract Audit

GameFi

Solidity audit of a decentralized pixel-lottery protocol with Chainlink VRF and shareholder rewards. 10 issues identified (1 Critical, 3 High); all C/H/M/L addressed.

1C3H1M4L1I
SolidityZealynx2025-11-17
SodaxNear · Rust
2025-11-01

Sodax Cross-Chain Intent Protocol

Bridges / Cross-chain

Cross-chain intent protocol audit via Sherlock. Engagement details under NDA.

Private report
Rustvia Sherlock2025-11-01
HyperlinesOffchain · Typescript
2025-10-09

Hyperlines TypeScript Audit and Pentest

DEX / AMM

TypeScript audit and pentest for Hyperlines (IPAL Network). 11 issues identified (3 High, 7 Medium, 1 Informational), 10 fixed and 1 acknowledged.

0C3H7M0L1I
TypescriptZealynx2025-10-09
How we audit. Multi-layer methodology combining manual review, custom Foundry invariants, mutation testing, stateful fuzzing, and symbolic execution. Each layer calibrated against a seeded bug before its passing result is trusted.
Read methodology →
Need this level of review for your protocol? Send the repo and launch context, get a private audit scope, or check whether a grant can subsidize the engagement before you commit budget.
ZEALYNX SECURITY · public audit catalogue
41 reports · last published 2026-04-29