Audits for Move, Rust, EVM. Oracle/DeFi focus. And full-stack cyber—pentests, red team, DFIR. Book via DM.

Joined September 2025
8 Photos and videos
Pinned Tweet
🧵 Our competitive audit results speak for themselves. Here's how VulSight ranked against hundreds of top security researchers. 👇
3
2
23
3,442
3 days at @ethconf 2026 NYC. Security lens takeaway: the attack surface just expanded a lot. - agents now hold keys. - agents now move money. - stablecoin credit ratings are onchain. - RWAs at $31.8B. and almost nobody talked about privacy.
2
8
292
VulSight retweeted
Another one for team @VulsightSec . A week after hitting Top 10 on @immunefi , a $40K bounty on @HackenProof . The work compounds.
Another big one for @VulsightSec. $40,000 earned on HackenProof 🔥 Not the first big win - and clearly not the last. Huge congratulations from the HackenProof team!
3
2
95
2,719
VulSight retweeted
Another big one for @VulsightSec. $40,000 earned on HackenProof 🔥 Not the first big win - and clearly not the last. Huge congratulations from the HackenProof team!
5
3
153
6,069
A lot of security firms will tell you what they're capable of. The ones worth hiring let the work tell you. Ours says: → Top 10 on the @immunefi 2026 Whitehat Leaderboard 🛡️ → 100 audits across EVM, Move & Rust → $845K in bug bounties → A CVE (CVE-2026-26314) in Ethereum's Geth client → Ranked #16 all-time on @cantinaxyz Global Leaderboard → Peaked at Top 3 on Immunefi earlier this year The codebase doesn't lie. Neither does the leaderboard.
5
3
97
4,349
🌴 The @VulsightSec team has landed in Miami for @consensus2026! May 5–7 | Miami Beach Convention Center If you're building in Web3, let's talk: 🔐 Smart Contract Audits 🛡️ Protocol/Infra Security Audits 🤝 Security Partnerships DM us to grab coffee or meet up on the beach. ☀️ #consensus2026 #Miami #web3 #Security
1
4
767
Most Web3 teams ship fast and patch later. The ones that last? They build security into the architecture from day one. We're working with builders who think in threat models, not just token models. If you're building onchain and want your code rock solid before mainnet, let's talk. DMs open.
2
306
Vulsight team is at @ParisBlockWeek 2026! 🇫🇷 100 audits completed. $845K in bug bounties. $2B secured in TVL. Top 15 All time on Cantina leaderboard. A published CVE (CVE-2026-26314) DoS on Ethereum's Geth codebase. Securing protocols across EVM, Move and Rust. With thousands of finance leaders, policymakers, and builders in one place, we're excited to talk about what matters most: making Web3 safer for everyone. Let's connect — DMs are open.
5
462
VulSight retweeted
They found the vulnerability. They didn’t patch it. $101M gone. At @VulSight, we don’t just find the breach, we make sure it gets fixed. I am at PBW, Carrousel du Louvre. It’s not too late for your protocol. Let’s make sure your assets remain safe 🤝 let’s connect !
A security assessment commissioned by the Louvre years before October’s robbery of $101 million in jewels sketched out how a moving truck could access the museum’s second floor on.wsj.com/453kMpJ
2
4
476
VulSight retweeted
Your Stack Is Split Across Move, EVM, Rust, and ZK 4 ecosystems. Each fails in very different ways. 1. EVM → reentrancy variants accounting/invariant bugs 2. Move → resource lifecycle bugs cross-module interaction failures. 3. ZK → under-constrained circuits. 4. Rust on Solana → PDA validation gaps CPI guard bypasses. A generalist who's "pretty good" at four ecosystems misses the bugs specialists catch. One ecosystem specialist can't help you when your stack spans two. If your protocol spans more than one ecosystem and needs a team that can audit across the full stack. Feel free to reach out to us.
2
3
36
1,845
VulSight retweeted
Day 1 at @EthCC Cannes. If you're here and shipping code to mainnet, come say hi. @VulsightSec breaks things so attackers can't: Top 15 All-Time on Cantina | Geth Critical CVE $845K in bounties | $2B TVL secured 100 private audits EVM, Move, Rust, Cairo, DAML We're here all week, let's connect. #Ethcc #Ethereum #Cannes #Smartcontractsecurity
1
13
756
VulSight retweeted
At EthCC[9] in Cannes this week. I'm here with @VulsightSec a security team that found a critical vulnerability in Geth last month, ranked #1 and #2 in competitive audits against 400 researchers, and secured $2B in protocol value. They don't run automated tools. They review your code line by line with one question: how do I break this? If you're launching, upgrading, or raising and security is on your roadmap, come say hi. I'll be at the main conference and side events all week. vulsight.com #EthCC9 #Web3 #Security #Audit #DeFi #Blockchain
1
2
7
363
The Vulsight team is heading to Cannes for @EthCC[9]! 🇫🇷 Whether you're a builder, founder, VC, or ecosystem team who takes protocol security seriously, we'd love to connect! DMs open — or find us at the Palais 🤝 #EthCC
1
17
971
You can't just translate Solidity intuition to Move and that's exactly what most audit firms are doing. The @SuiNetwork @AptosLabs @movement_xyz ecosystem is growing fast, but security coverage is way behind. Most firms either don't touch Move or outsource it to someone who learned the language last month. The object-centric model is fundamentally different from EVM. That gap is going to cost projects real money. We've been deep in Move codebases long enough to know that the bugs here don't look like anything you'd catch with an EVM mindset.
2
1
32
1,661
Honest question for protocol founders: When you pick an auditor, what actually matters to you? Price? Timeline? Track record? The specific auditor assigned to your codebase? Curious because we keep hearing different answers depending on the ecosystem.
2
6
922
Protocols trust VulSight because we compete in the open. Our rankings on @cantinaxyz , @HackenProof and @immunefi are public, anyone can verify them. We don't ask you to trust us, we let you verify.
1
1
16
951
Most audit firms fall into 3 buckets: 1. Template auditors: run tools, slap a report on it 2. Manual reviewers: solid readers, but that's the ceiling 3. Research-driven: custom test cases, formal verification, economic attack modeling We built VulSight around #3. Top 15 all-time on Cantina. 2nd place on Aave V3 Aptos. A Geth CVE on the wall. The approach speaks for itself.
2
1
21
1,557
Tell us you're a smart contract auditor without telling us you're a smart contract auditor: Our Cantina ranking has more credibility than our social lives. We trust math more than people. We filed a CVE before lunch. And we still double-check our own transfers. Your turn 👇
1
4
653
100 audits completed Top 15 all-time on Cantina $500K in bug bounties A CVE on Ethereum's Geth client. We don't just review code. We break it before someone else does. If your protocol is heading to mainnet and you want auditors who compete at the highest level... DMs are open. Or reply here. We read everything. 🔒
2
2
50
2,442
The Move ecosystem has a massive security auditor shortage. We ranked 🏆#2 out of 409 researchers on AAVE's v3 Aptos audit competition. If you're building on Aptos or Sui, you already know how rare real Move expertise is. We’re among the few who truly get it.
1
49
2,523
🧵 Most audit firms audit smart contracts. We audit systems. Here's why that difference matters and what gets missed when your auditor only reads Solidity. 👇
2
1
11
1,103
Deployment and upgrade pipelines are attack vectors too. Proxy misconfiguration. Unprotected initializers. Admin key exposure during migration. The most secure contract in the world means nothing if the deployment process is compromised.
1
1
305
Full-stack security isn't a buzzword for us. It's how we found a consensus-level bug in Ethereum's most used client. Your protocol is only as secure as its weakest layer. If you want an audit that covers every surface to break into your codebase before the attackers do. DMs are open.
1
263