# Hexens > Hexens is a cybersecurity firm securing critical infrastructure across blockchain protocols, AI and agentic systems, cryptographic implementations, and traditional enterprise networks. 300+ audits completed. Zero post-audit exploits. $120B+ in assets under audited code. 91% client retention. This document is the full text of the Hexens website, consolidated into a single Markdown file for ingestion by large language models and AI agents. The shorter index file is available at https://hexens.io/llms.txt. --- ## About Hexens Hexens is a cybersecurity firm operating at the intersection of frontier security research and practical implementation review. The firm runs five service practices: blockchain security, AI and agentic security, cryptography security, application and network security, and security consultancy. The security and R&D team consists of CTF champions, bug bounty leaderboard veterans, and vulnerability researchers with track records of breaking systems considered unbreakable. Engineers hold certifications including OSCP, OSCE3, OSWE, OSEP, OSMR, OSED, CRTL, ISO 27001 LA, CISSP, eCPTXv2, and AATHIR. Every audit engagement deploys two independent teams of senior engineers working in parallel against the same scope. The teams converge on findings only after independent assessment. Where findings overlap, confirmation is established. Where they diverge, single-team blind spots are surfaced. Hexens publishes original vulnerability research through responsible disclosure with affected parties. In addition to audit and advisory services, the firm operates five security products: Glider, Glider Monitor, Token Risks API, DeFi Risks, and Remedy. The firm is headquartered in London, United Kingdom, at 71-75 Shelton Street, Covent Garden, WC2H 9JQ. Primary contact: info@hexens.io --- ## Track Record - 300+ audit engagements completed - Zero post-audit exploits across all client engagements - $120 billion in digital assets under audited code - 91% client retention rate - 90% of audit reports contain critical or high-severity findings - 5+ years of continuous operation The zero-exploit record across hundreds of engagements with high-value targets establishes consistency rather than coincidence. Most clients work with Hexens continuously across multiple codebases, protocol upgrades, and product launches. --- ## Services ### Blockchain Security Hexens secures critical infrastructure in Web3: smart contracts, ZK circuits, cryptographic primitives, L1 and L2 blockchains, and centralized exchanges. Reviews are conducted by multiple independent teams per engagement. Senior engineers are armed with frontier AI models that extend code coverage across massive codebases and surface non-obvious interaction patterns at a depth that manual-only review cannot match. Languages and environments covered include Solidity, Rust, Move, Vyper, and Cairo. The practice has completed 300+ engagements with zero client exploits. Capabilities: - Smart Contract Audit (Solidity, Rust, Move, Vyper, Cairo) - L1 and L2 Blockchain Security Review - Centralized Exchange Security Assessment - Hardware and Software Wallet Audit - DeFi Protocol Security Review - Bridge and Cross-Chain Security - TEE Application Security Review URL: https://hexens.io/services/blockchain-security ### AI & Agentic Security AI agents are executing transactions, pushing code, managing infrastructure, and making autonomous decisions with real money at stake. Hexens audits the systems the rest of the industry is still learning to name: agentic commerce protocols, MCP server deployments, LLM-powered applications, vibe-coded products, privacy-preserving AI, and autonomous systems operating in high-stakes environments. The methodology and engineering team that performs blockchain audits also performs AI security reviews. Capabilities: - AI Agent Security Audit - Agentic Commerce and Payment Protocol Security - MCP Server and Tool Integration Security - LLM Application Security Assessment - Vibe-Coded Application Security Audit - MLOps Pipeline and Model Supply Chain Security - AI Red Teaming URL: https://hexens.io/services/ai-ml-security ### Cryptography Security The cryptographic layer is where implementation-level flaws carry catastrophic, often irreversible consequences. A single underconstrained signal in a ZK circuit can drain an entire protocol in one transaction. Fully homomorphic encryption schemes are vulnerable to parameter misconfiguration and silent plaintext leakage. Multi-party computation protocols are susceptible to malicious abort and input inconsistency. Hexens researchers operate at the mathematical layer where most auditors stop reading: proving systems, circuit constraint validation, field arithmetic, trusted setup ceremonies. Reviews are armed with frontier AI that enables exhaustive exploration of constraint systems with thousands of gates. Frameworks covered include Circom, Halo2, Plonky2 and Plonky3, Noir, Gnark, Zokrates, PIL, zkASM, and Cairo. Capabilities: - ZK Circuit Security Audit (SNARKs and STARKs) - FHE Implementation Review - MPC Protocol Security Assessment - Cryptographic Primitive Implementation Audit - Proving System Implementation Review - Post-Quantum Cryptography Assessment URL: https://hexens.io/services/cryptography-security ### Application & Network Security The attack surface is the entire digital presence. Hexens performs full-scope penetration testing, APT simulation, application security reviews, and infrastructure assessments where blockchain meets traditional systems. Engagements cover blockchain-adjacent infrastructure and traditional enterprise environments. Every engagement is AI-augmented: senior OSCP, OSCE, and OSWE certified engineers direct frontier models to extend reconnaissance, map attack paths, and generate adversarial scenarios. Capabilities: - APT Simulation and Red Teaming - Web Application Penetration Testing - Mobile Application Security Assessment - Source Code Review - API Security Testing - Cloud Infrastructure Security Audit - Network Penetration Testing URL: https://hexens.io/services/application-network-security ### Security Consultancy Security that begins before the first line of code and extends beyond the audit report. Hexens consultants are senior engineers who break protocols, now directing frontier AI to accelerate analysis and expand coverage across complex infrastructure. The practice covers architecture design, threat modeling, compliance readiness, and operational security. Compliance frameworks covered include SOC 2, ISO 27001, MiCA, and DORA. Capabilities: - System Architecture Review - Threat Modeling and Risk Assessment - Compliance and Certification Advisory - DevSecOps Integration - DDoS Resilience Assessment - Social Engineering Training and Testing URL: https://hexens.io/services/security-consultancy --- ## Methodology ### Two Teams Per Engagement Every Hexens engagement runs two independent teams against the same target. Multiple senior engineers per team. Exclusive project focus, with no auditor splitting attention across three clients in parallel. The teams work independently, then converge. Where findings overlap, confirmation is established. Where they do not overlap, the engagement has surfaced what a single-team audit would have missed entirely. The methodology is the structural reason behind the zero-exploit track record across 300+ engagements. ### Senior Engineers Only The Hexens team consists exclusively of senior security engineers. Members are CTF champions, bug bounty leaderboard veterans, and vulnerability researchers with track records of finding critical issues in industry-leading systems. Team members have collectively won 30+ international competitions and earned millions in bug bounties. ### AI-Augmented Review Every engagement is augmented with frontier AI models. The AI extends code coverage across large codebases, surfaces non-obvious interaction patterns, and enables exhaustive exploration of constraint systems with thousands of gates. AI does not replace manual review by senior engineers. It expands what senior engineers can cover within an engagement window. ### Certifications Team certifications include: - OSCP (Offensive Security Certified Professional) - OSCE3 (Offensive Security Certified Expert 3) - OSWE (Offensive Security Web Expert) - OSEP (Offensive Security Experienced Penetration Tester) - OSMR (Offensive Security MacOS Researcher) - OSED (Offensive Security Exploit Developer) - CRTL (Certified Red Team Lead) - ISO 27001 LA (ISO/IEC 27001 Lead Auditor) - CISSP (Certified Information Systems Security Professional) - eCPTXv2 (Certified Penetration Tester eXtreme v2) - AATHIR (Advanced APT Threat Hunting & Incident Response) --- ## Solutions ### Glider Glider is a smart contract code query engine. It enables searching on-chain code by function, pattern, or behavior, rather than by address or signature. The engine tags, labels, and categorizes smart contract data at scale, surfacing patterns that were previously impossible to identify across large numbers of deployed contracts. Use cases include tracking new deployments, analyzing existing protocols, and hunting for vulnerability patterns across the entire on-chain code base. $200 million in on-chain assets have been protected through Glider queries to date. A public IDE is available at https://glide.r.xyz. Claude Skills integration is enabled and documented at https://github.com/Hexens/glider-skills. URL: https://hexens.io/solutions/glider ### Glider Monitor Glider Monitor is the first Continuous Threat Exposure Management (CTEM) system built for Web3. One intelligence engine ingests every vulnerability the industry produces, known and new, and runs it against your contracts before, during, and after an attack. The product is designed to prevent, detect, and react to the most common ways protocols get hacked. Capabilities include continuous replay of the full vulnerability knowledge base against deployed contracts, real-time capture of live exploitation and key leaks, a real-time dependency and DeFi risk graph with live alerts, and custom per-block invariant checks with instant breach alerts. Alerts are delivered via Telegram, Slack, and custom webhooks. A free Community Tier is available. URL: https://hexens.io/solutions/glider-monitor ### Token Risks API Token Risks API delivers live token risk scoring powered by audit-grade data. Every token is assessed for contract vulnerabilities, ownership risks, liquidity traps, and manipulation vectors. The API delivers precise, actionable ratings that platforms integrate directly into their user-facing risk surfaces. The system can operate in strict SAST mode or Hybrid mode combining AI with SAST. The Hybrid mode achieves the most precise results by combining static analysis correctness with AI-driven pattern recognition. CoinStats has integrated Token Risks API to deliver reliable, real-time risk analysis of digital assets to end users. The integration surfaces token-level security data at the point of investment decision, rather than after the fact. URL: https://hexens.io/solutions/token-risks-api Playground: https://hexens.io/solutions/token-risks-api/playground ### DeFi Risks DeFi Risks delivers protocol-level risk analysis built on Glider's underlying query engine. URL: https://hexens.io/solutions/defi-risks ### Remedy Remedy is an expert-triaged bug bounty platform built for projects that require signal over noise. Every submission is reviewed by senior security engineers. There is no AI gatekeeping and no noise. The platform is powered by Engram, a zero-knowledge proof of duplicates system. Engram provides transparency on duplicate submissions that no other platform currently offers. $5.5 million in active rewards is available across listed programs. The platform integrates with Slack and Jira. Programs gain exposure to the top security research community from day one. Public-facing site: https://r.xyz Programs: https://r.xyz/bug-bounty/programs For organizations: https://r.xyz/bug-bounty/for-organizations --- ## Original Vulnerability Research Hexens publishes original vulnerability research through responsible disclosure with affected parties. The research hub is at https://hexens.io/research. ### Arbitrary Struct Hijack in Aptos Move VM Published July 2026. TL;DR -- A stale type-tag cache in the Aptos Move VM lets a recycled StructNameIndex map to the wrong StructTag after a partial cache flush, enabling storage-level type confusion. An attacker aligns a look-alike struct onto a victim resource and reads/writes its storage slot -- draining vaults, stealing capabilities, and forging cross-chain messages. Severity: Critical. URL: https://hexens.io/research/aptos-hijack-bug ### Tricking the Polygon bridge into withdrawals by forging transaction proofs Published March 2026. This is a disclosure of a vulnerability in the Polygon Plasma bridge. The vulnerability has been fixed since July 2024 and the fix has been pushed to the vulnerable library as well. URL: https://hexens.io/research/polygon-bridge-forging-transaction-proofs ### TSTORE Poison: The Solidity Compiler Bug That Silently Corrupts Storage Published February 2026. TL;DR -- A cache key collision in the Solidity compiler's via-ir code generator causes delete on transient variables to emit sstore instead of tstore, or conversely causes persistent delete to emit tstore instead of sstore. The direction depends on function selector ordering -- neither direction is safe. URL: https://hexens.io/research/solidity-compiler-bug-tstore-poison --- ## Technical Blog The Hexens blog publishes technical writing on smart contract security, zero-knowledge cryptography, FHE, MPC, applied cryptography, and AI security. URL: https://hexens.io/blog ### Blog Articles - [Quantum Key Distribution: From Theory to Real-World Attacks](https://hexens.io/blog/quantum-key-distribution) - [Glider by Hexens: The Code Query Engine for Smart Contract Security at Scale](https://hexens.io/blog/glider-hexens-code-query-engine-smart-contract-security) - [The Exploit Is the Disclosure: Why On-Chain Hacks Spread Faster Than Patches](https://hexens.io/blog/the-exploit-is-the-disclosure) - [Understanding Differential Privacy: Part 2](https://hexens.io/blog/dp-part2) - [Understanding Differential Privacy: Part 1](https://hexens.io/blog/dp-part1) - [Gröbner Bases in Cryptanalysis Part2: Attacking Poseidon](https://hexens.io/blog/groebner-basis-part2) - [Gröbner Bases in Cryptanalysis Part 1: The Underlying Algebra](https://hexens.io/blog/groebner-basis-part1) - [Encrypted Vector Databases Without Sacrificing Search](https://hexens.io/blog/vector-databases) - [Secure Federated Learning with Cryptography](https://hexens.io/blog/secure-fl) - [Attacks on Threshold Schemes: Part 2](https://hexens.io/blog/mpc-attacks-p2) - [Attacks on Threshold Schemes: Part 1](https://hexens.io/blog/mpc-attacks-p1) - [Constructing and Breaking SIDH](https://hexens.io/blog/sidh) - [A Comparison of zkVM DSLs: Halo2, Zirgen, and Plonky3](https://hexens.io/blog/zkvm-dsls) - [The Ethereum Proximity Prize: Reed–Solomon Codes and MCA](https://hexens.io/blog/proximity-gaps) - [Token Risk Scanning for Traders: Glider Flags 20+ on-chain risks others miss.](https://hexens.io/blog/Glider-Token-Risk-Scanning-for-Traders) - [MHE from RLWE: When MPC Meets Homomorphic Encryption](https://hexens.io/blog/mhe-from-rlwe) - [Generalized BFV in Practice](https://hexens.io/blog/gbfv) - [One Ciphertext, Many Messages: SIMD operations in FHE](https://hexens.io/blog/simd-in-fhe) - [Zero-Knowledge Proofs in Real Life: Privacy Tech Beyond Blockchain](https://hexens.io/blog/zk-usecases-in-real-life) - [Subgroup Pitfalls in zk-Proofs and Real-World Exploits](https://hexens.io/blog/subgroup-attack-exploits) - [Glider API Sets a New Benchmark in Smart Contract Risk Detection](https://hexens.io/blog/glider-api-new-benchmark-in-smart-contract-security) - [Zero Knowledge in STARKs](https://hexens.io/blog/zk-in-starks) - [Social Engineering. Examining the Most Vulnerable Part - Humans](https://hexens.io/blog/social-engineering-red-teaming) - [One Tiny Error, Massive Impact: Inside EigenPods' Critical Merkle Bug](https://hexens.io/blog/critical-eigenpods-bug) - [HEXENS: A YEAR IN REVIEW](https://hexens.io/blog/2023-year-in-review) - [HEXENS DOUBLES DOWN ON ITS COMMITMENT TO QUALITY SECURITY SERVICE WITH A WHITE-HAT APPRECIATION AWARD](https://hexens.io/blog/white-hat-appreciation-award) - [The Web3 Security Engineer's Arsenal: Must-Have Tools for Auditing Smart Contracts](https://hexens.io/blog/toolkit-for-web3-security-engineers) - [The Security Challenges in Building zkEVM](https://hexens.io/blog/auditing-zkevm) - [Solving 'Spot The Bug' Challenge: Attacks on Weak Elliptic Curves Explained](https://hexens.io/blog/spot-the-bug-challenge-3) - [Solving the 'Spot the Bug' Challenge: Integer commitment bug in Smart Contract](https://hexens.io/blog/spot-the-bug-challenge) - [The Hexens team](https://hexens.io/blog/hexens-team) - [Blockchain Security Company Hexens Raises $4.2 million in Seed Funding Led by IOSG Ventures](https://hexens.io/blog/funding-round) - [5 Smart Contract Security Tips Against Cyberattacks](https://hexens.io/blog/security-tips) - [All about Smart Contract Audit](https://hexens.io/blog/all-about-smart-contract-audit) - [DeFi: Top 10 biggest hacks](https://hexens.io/blog/defi-hacks) - [Ethereum: What you should know before you invest](https://hexens.io/blog/ethereum) - [How to Safeguard Your Crypto Wallet](https://hexens.io/blog/crypto-wallet) - [Most Popular Blockchain Security Issues and Possible Attacks](https://hexens.io/blog/possible-blockchain-attacks) - [Most Popular DeFi Security Risks](https://hexens.io/blog/defi-security) - [What is NFT: A Go-to Guide](https://hexens.io/blog/nft-guide) - [NFT Security: Potential Risks and Vulnerabilities](https://hexens.io/blog/nfts) - [What is a Smart contract and how does it work](https://hexens.io/blog/contract) - [NFT Wallets to Make Sure your Assets are Safe](https://hexens.io/blog/nft) - [Blockchain Security: Popular Attacks and Risks to Avoid or Prevent](https://hexens.io/blog/blockchain-popular-attacks) - [What is DeFi? A beginner’s guide to decentralized finance](https://hexens.io/blog/defi) - [The Importance of Smart Contract Audit in Cybersecurity](https://hexens.io/blog/audit) - [How Cryptocurrencies Are Seized A Guide To Police Tactics](https://hexens.io/blog/crypto-seizure) - [Top 7 Cybersecurity Tips and Practices for Your Business](https://hexens.io/blog/tips) - [Ultimate Guide to What is Penetration Testing](https://hexens.io/blog/pentest) --- ## Audit Reports A full catalog of public security reviews is available at https://hexens.io/audit-reports. ### Full Client List Public audit reports are available for engagements with: Holdfast, AnchorVaultCoin, Trady, Flipper, Kerne, AutoFinance, IRIS, 1inch, EigenCloud, Astrolab, Azuro, ALGEBRA FINANCE, Fastex, Holonym, Slash Payments, API3, Camino, Persistence, Alien Base, Celo, Fungify, Quickswap, Socket, LayerCover, Layerswap, Risc ZERO, Mantle, Lido, Polygon, Polygon zkEVM, Logarithm, PancakeSwap, Zealous, BasisOS, Moonbound, Ufarm.Digital, Lendle, T3rn, Thesauros, Chaos Labs, DIN, Zharta, Valantis, mETH Protocol, GLIF, Usual, Fuel, OBSDN, Everclear, JuiceSwap, TrenDex.one, Shib.io, Royco, KalqiX, Elfomo Labs, Kyber Network, ANQ, Katana, Cybro, Sentio, CrossCurve, Fanpla, Yelay, Spool, Swell, StakeWise, Secured Finance, Wintermute, ZKsync, TRAIN Protocol, TON, Manifold Finance, Ducata, CoinRoutes, Defexa, Mintify, Mantissa Finance, Eywa, RociFi, 4k.com, Taker, Ava Labs, Boba Network, Deq.fi, Hashflow, LayerZero, ParaSwap, Pencils Protocol, Rush Trading. ### Audit Report Articles - [Mintify Web Infrastructure Security Review Report](https://hexens.io/audit-reports/mintify-web-infrastructure-jan-20244) - [Valigator Holdfast Solana Stake Manager Security Assessment Report](https://hexens.io/audit-reports/valigator-holdfast-solana-stake-manager-jun-2026) - [AnchorVault AnchorVaultCoin Contract Security Review Report](https://hexens.io/audit-reports/anchorvault-anchorvaultcoin-contract-jul-2026) - [UFarm Digital EVM Contracts Security Review Report](https://hexens.io/audit-reports/ufarm-digital-evm-contracts-jun-2026) - [Kerne Protocol Security Review Report](https://hexens.io/audit-reports/kerne-protocol-july-2026) - [KalqiX DEX Bridge & ZK Contracts Security Review Report](https://hexens.io/audit-reports/kalqix-dex-bridge-zk-contracts-dec-2025) - [Flipper Core Protocol Security Review Report](https://hexens.io/audit-reports/flipper-core-protocol-jun-2026) - [Royco Tranche Refactoring Security Review Report](https://hexens.io/audit-reports/royco-tranche-refactoring-jul-2026) - [Thesauros Rebalancer and Provider Adapters Security Review Report](https://hexens.io/audit-reports/thesauros-rebalancer-provider-adapters-jul-2026) - [Thesauros Automated Interest Rebalancing Protocol Security Review Report](https://hexens.io/audit-reports/thesauros-automated-interest-rebalancing-protocol-oct-2025) - [AutoFinance ExitDestinations Contract Security Review Report](https://hexens.io/audit-reports/autofinance-exitdestinations-contract-jun-2026) - [Iris Fixed-Rate Origination Layer Security Review Report](https://hexens.io/audit-reports/iris-fixed-rate-origination-layer-jul-2026) - [1inch Aggregation Router & Limit Order Protocol Update Security Review Report](https://hexens.io/audit-reports/inch-aggregation-router-limit-order-protocol-update-oct-2023) - [1inch Fusion Solana Implementation Security Review Report](https://hexens.io/audit-reports/1inch-fusion-solana-implementation-feb-2025) - [1inch Limit Order Protocol Update Security Review Report](https://hexens.io/audit-reports/1inch-limit-order-protocol-update-nov-2023) - [1inch Aggregation Router & Limit Order Protocol Security Review Report](https://hexens.io/audit-reports/1inch-aggregation-router-limit-order-protocol-mar-2023) - [1inch ERC20Pods, Limit Order Settlement & Delegation Security Review Report](https://hexens.io/audit-reports/1inch-erc20pods-limit-order-settlement-delegation-dec-2022) - [1inch ERC20Pods, Limit Order Settlement & Delegation Security Review Report](https://hexens.io/audit-reports/1inch-erc20pods-limit-order-settlement-delegation-nov-2022) - [1inch Limit Order Protocol & Settlement Security Review Report](https://hexens.io/audit-reports/1inch-limit-order-protocol-settlement-apr-2024) - [1inch Fusion+ Solana Contracts Security Review Report](https://hexens.io/audit-reports/1inch-fusion-plus-solana-contracts-jul-2025) - [1inch Fusion Atomic Swaps Security Review Report](https://hexens.io/audit-reports/1inch-fusion-atomic-swaps-aug-2025) - [1inch Fusion+ Cross-Chain Swaps Security Review Report](https://hexens.io/audit-reports/1inch-fusion-plus-cross-chain-swaps-jun-2025) - [Tokemak Autopilot Core Contracts Security Review Report](https://hexens.io/audit-reports/tokemak-autopilot-core-contracts-may-2024) - [Fuel Token Bridge Security Review Report](https://hexens.io/audit-reports/fuel-token-bridge-apr-2024) - [Lido V2 Upgrade Security Review Report](https://hexens.io/audit-reports/lido-v2-upgrade-feb-2023) - [Astrolab Cross Chain Protocol Security Review Report](https://hexens.io/audit-reports/astrolab-cross-chain-protocol-apr-2023) - [Azuro V2 Security Review Report](https://hexens.io/audit-reports/azuro-v2-nov-2022) - [Babylon Security Review Report](https://hexens.io/audit-reports/babylon-jan-2023) - [Algebra Core Contracts Security Review Report](https://hexens.io/audit-reports/algebra-core-contracts-aug-2022) - [Bahamut L1 Blockchain Security Review Report](https://hexens.io/audit-reports/bahamut-l1-blockchain-apr-2023) - [FastToken Distribution Contracts Security Review Report](https://hexens.io/audit-reports/fasttoken-distribution-contracts-oct-2022) - [Slash V2 NFT Vault Security Review Report](https://hexens.io/audit-reports/slash-v2-nft-vault-aug-2023) - [API3 DAO & Dashboard Security Review Report](https://hexens.io/audit-reports/api3-dao-dashboard-sep-2022) - [Chain4Travel Camino Node & Wallet Security Review Report](https://hexens.io/audit-reports/chain4travel-camino-node-wallet-feb-2023) - [Chain4Travel Camino Node & Wallet Security Review Report](https://hexens.io/audit-reports/chain4travel-camino-node-wallet-mar-2023) - [Holonym Silk Wallet Recovery Security Review Report](https://hexens.io/audit-reports/holonym-silk-wallet-recovery-may-2024) - [Persistence stkBNB Migration Security Review Report](https://hexens.io/audit-reports/persistence-stkbnb-migration-apr-2024) - [Persistence pStake Liquid Stake Module & Superfluid LP Security Review Report](https://hexens.io/audit-reports/persistence-pstake-liquid-stake-superfluid-lp-jan-2024) - [Alienbase Epsilon Protocol Security Review Report](https://hexens.io/audit-reports/alienbase-epsilon-protocol-apr-2026) - [Celo Staking Security Review Report](https://hexens.io/audit-reports/celo-staking-mar-2024) - [cLabs Celo Governance & Fee Handler Security Review Report](https://hexens.io/audit-reports/clabs-celo-governance-fee-handler-jun-2023) - [Fungify CERC721NoBorrow Security Review Report](https://hexens.io/audit-reports/fungify-cerc721noborrow-feb-2024) - [Fungify FungifyNFT, NFTMinter & Proxy2Step Security Review Report](https://hexens.io/audit-reports/fungify-fungifynft-nftminter-proxy2step-feb-2024) - [Fungify NFT Index Security Review Report](https://hexens.io/audit-reports/fungify-nft-index-jun-2024) - [Fungify Pools Contracts Security Review Report](https://hexens.io/audit-reports/fungify-pools-contracts-oct-2023) - [Fungify Pools Contracts Security Review Report](https://hexens.io/audit-reports/fungify-pools-contracts-nov-2023) - [QuickSwap QuickPerps Perpetual Futures Exchange Security Review Report](https://hexens.io/audit-reports/quickswap-quickperps-perpetual-futures-exchange-apr-2023) - [QuickSwap QuickPerps RewardDistributor Update Security Review Report](https://hexens.io/audit-reports/quickswap-quickperps-rewarddistributor-update-jun-2023) - [Socket Bungee Protocol Security Review Report](https://hexens.io/audit-reports/socket-bungee-protocol-dec-2024) - [Socket Super Token & Vault Security Review Report](https://hexens.io/audit-reports/socket-super-token-vault-jan-2024) - [Socket Supermodular Contracts Security Review Report](https://hexens.io/audit-reports/socket-supermodular-contracts-mar-2024) - [Socket Cross Chain Bridge Security Review Report](https://hexens.io/audit-reports/socket-cross-chain-bridge-aug-2023) - [Socket App Chain Bridgeable Tokens Security Review Report](https://hexens.io/audit-reports/socket-app-chain-bridgeable-tokens-aug-2023) - [ LayerCover Risk Tranching Yield Protocol Security Review Report](https://hexens.io/audit-reports/layercover-risk-tranching-yield-protocol-may-2026) - [Layerswap Atomic Bridge Security Review Report](https://hexens.io/audit-reports/layerswap-atomic-bridge-dec-2024) - [RISC Zero zkVM Security Review Report](https://hexens.io/audit-reports/risc-zero-zkvm-aug-2023) - [RISC Zero Boundless Proof of Verifiable Work Security Review Report](https://hexens.io/audit-reports/risc-zero-boundless-proof-of-verifiable-work-jul-2025) - [Mantle mETH Liquid Staking Protocol Security Review Report](https://hexens.io/audit-reports/mantle-meth-liquid-staking-protocol-aug-2023) - [Mantle mETH Oracle Daemon Security Review Report](https://hexens.io/audit-reports/mantle-meth-oracle-daemon-sep-2023) - [Mantle cMETH Boring Vault Security Review Report](https://hexens.io/audit-reports/mantle-cmeth-boring-vault-aug-2024) - [EigenLayer Middleware Contracts Security Review Report](https://hexens.io/audit-reports/eigenlayer-middleware-contracts-apr-2025) - [EigenLayer EigenPod Stage 2 Security Review Report](https://hexens.io/audit-reports/eigenlayer-eigenpod-stage-2-oct-2023) - [Zharta P2P Lending Protocol ERC20 Security Review Report](https://hexens.io/audit-reports/zharta-p2p-lending-protocol-erc20-oct-2025) - [Lendle Aave Fork Deployment on Mantle Security Review Report](https://hexens.io/audit-reports/lendle-aave-fork-deployment-mantle-sep-2025) - [Polygon Aave & DAI Bridge Integrations Security Review Report](https://hexens.io/audit-reports/polygon-aave-dai-bridge-integrations-aug-2023) - [Polygon zkEVM Security Review Report](https://hexens.io/audit-reports/polygon-zkevm-feb-2023) - [Logarithm Labs Metavault Security Review Report](https://hexens.io/audit-reports/logarithm-labs-metavault-jul-2025) - [PancakeSwap Infinity Core Contracts Security Review Report](https://hexens.io/audit-reports/pancakeswap-infinity-core-contracts-apr-2025) - [PancakeSwap Infinity Periphery Contracts Security Review Report](https://hexens.io/audit-reports/pancakeswap-infinity-periphery-contracts-may-2025) - [ZealousSwap Kaspa AMM DEX Security Review Report](https://hexens.io/audit-reports/zealousswap-kaspa-amm-dex-may-2025) - [Logarithm Basis Strategy System Security Review Report](https://hexens.io/audit-reports/logarithm-basis-strategy-system-nov-2024) - [MoonBound Bonding Curve Token Platform Security Review Report](https://hexens.io/audit-reports/moonbound-bonding-curve-token-platform-may-2025) - [UFarm Core Protocol Update Security Review Report](https://hexens.io/audit-reports/ufarm-core-protocol-update-may-2025) - [t3rn Universal Execution Protocol Security Review Report](https://hexens.io/audit-reports/t3rn-universal-execution-protocol-jun-2025) - [Chaos Labs & BGD Labs Edge Agents Security Review Report](https://hexens.io/audit-reports/chaos-labs-bgd-labs-edge-agents-apr-2025) - [Infura DIN AVS for EigenLayer Security Review Report](https://hexens.io/audit-reports/infura-din-avs-eigenlayer-oct-2025) - [Valantis Security Review Report](https://hexens.io/audit-reports/valantis-sep-2024) - [RISC Zero Crypto SCs Security Review Report](https://hexens.io/audit-reports/risc-zero-crypto-scs-may-2024) - [RISC Zero RiscZeroSetVerifier & Aggregation Security Review Report](https://hexens.io/audit-reports/risc-zero-risczerosetverifier-aggregation-dec-2024) - [Mantle Liquid Staking Aave Integration Security Review Report](https://hexens.io/audit-reports/mantle-liquid-staking-aave-integration-oct-2025) - [GLIF InfinityPoolV2 & AgentPoliceV2 Migration Security Review Report](https://hexens.io/audit-reports/glif-infinitypoolv2-agentpolicev2-migration-jul-2024) - [GLIF LpPlus & RWTFuture Contracts Security Review Report](https://hexens.io/audit-reports/glif-lpplus-rwtfuture-contracts-nov-2025) - [GLIF Plus NFT Security Review Report](https://hexens.io/audit-reports/glif-glif-plus-nft-aug-2025) - [Usual USD0++ Upgrade & Redemption Token Security Review Report](https://hexens.io/audit-reports/usual-usd0pp-upgrade-redemption-token-nov-2025) - [Usual USD0x Synthetic Yield Asset Security Review Report](https://hexens.io/audit-reports/usual-usd0x-synthetic-yield-asset-nov-2025) - [Usual sUSD0 Yield Bearing Vault Security Review Report](https://hexens.io/audit-reports/usual-susd0-yield-bearing-vault-oct-2025) - [Fuel Labs Fuel O2 Orderbook Security Review Report](https://hexens.io/audit-reports/fuel-labs-fuel-o2-orderbook-oct-2025) - [Obsidian OBSDN Perpetual Protocol Security Review Report](https://hexens.io/audit-reports/obsidian-obsdn-perpetual-protocol-may-2026) - [Shib SOU Contracts Security Review Report](https://hexens.io/audit-reports/shib-sou-contracts-nov-2025) - [Fuel Labs Fuel O2 Orderbook Security Review Report](https://hexens.io/audit-reports/fuel-labs-fuel-o2-orderbook-aug-2025) - [Everclear Solana Smart Contracts Security Review Report](https://hexens.io/audit-reports/everclear-solana-smart-contracts-dec-2025) - [Zharta P2P Lending Protocol ERC20 Security Review Report](https://hexens.io/audit-reports/zharta-p2p-lending-protocol-erc20-dec-2025) - [JuiceSwap JuiceDollar & Core, Periphery, Router Contracts Security Review Report](https://hexens.io/audit-reports/juiceswap-juicedollar-core-periphery-router-jan-2026) - [TrenDex.One Token Deployment Protocol Core EVM Security Review Report](https://hexens.io/audit-reports/trendex-one-token-deployment-protocol-core-evm-jan-2026) - [Kyber Network KSAggregationRouterV3 Security Review Report](https://hexens.io/audit-reports/kyber-network-ksaggregationrouterv3-nov-2025) - [Royco Perpetual Risk-Tranching Protocol Security Review Report](https://hexens.io/audit-reports/royco-perpetual-risk-tranching-protocol-jan-2026) - [Kyber Network Smart Intent Protocol Security Review Report](https://hexens.io/audit-reports/kyber-network-smart-intent-protocol-dec-2025) - [elfomoFi Vault Accounting Layer Security Review Report](https://hexens.io/audit-reports/elfomofi-vault-accounting-layer-apr-2026) - [AnQ Bridge & INR Stablecoin LayerZero OFT Security Review Report](https://hexens.io/audit-reports/anq-bridge-inr-stablecoin-layerzero-oft-jan-2026) - [Katana KAT Vault & LayerZero OFT Integration Security Review Report](https://hexens.io/audit-reports/katana-kat-vault-layerzero-oft-integration-jan-2026) - [Royco Entry Point Contract Update Security Review Report](https://hexens.io/audit-reports/royco-entry-point-contract-update-apr-2026) - [Zharta P2P Lending Protocol Security Review Report](https://hexens.io/audit-reports/zharta-p2p-lending-protocol-erc20-feb-2026) - [Royco Risk-Tranching Protocol Update Security Review Report](https://hexens.io/audit-reports/royco-risk-tranching-protocol-update-mar-2026) - [Layerswap Depository Security Review Report](https://hexens.io/audit-reports/layerswap-depository-mar-2026) - [Cybro V3, V4 & Automation Security Review Report](https://hexens.io/audit-reports/cybro-v3-v4-automation-mar-2026) - [Sentio Token Security Review Report](https://hexens.io/audit-reports/sentio-token-mar-2026) - [EYWA CrossCurve OFT Protocol Security Review Report](https://hexens.io/audit-reports/eywa-crosscurve-oft-protocol-mar-2026) --- ## Client Testimonials > Hexens is a hidden gem. Their attention to detail is unmatched. We started working with them for a single project to test them out but loved them so much that we gave them two more projects before the first engagement even got completed. They actually care about security and customer experience. Mudit Gupta, CTO, Polygon > Hexens’ deep knowledge of software security and ZK attack surface gave the critical outside perspective to reach production readiness for our zero knowledge virtual machine and launch 1.0 Kevin Nassery, Head of Security, RISC Zero > The Lido DAO first approached Hexens when picking audit service providers for the Lido v2 upgrade – the most significant and complex yet. We were impressed with how the Hexens team provided a thorough code audit with meaningful findings while consistently meeting the ETAs. Many thanks to the team! Gregory, Lido > Our experience with Hexens has been quite positive. One time, they went above and beyond the scope and found a clever out-of-scope remote code execution vulnerability. I highly recommend working with Hexens. Nanak Nihal, Founder, Holonym and Silk > I'd like to express my gratitude to the Hexens team for keeping the strict timelines, the quality of work, and the support provided throughout the remediation process. Many thanks once again! Nikolaos Frestis, Senior Project Manager, cLabs > Thank you, Hexens.io, for being professional, responsive, and delivering a high-quality audit. Burak Benligiray, Core Technical Team Lead, API3 > Hexens is a security consulting company, providing a myriad of DeFi projects with the best services by introducing a whole new approach to cybersecurity solutions. Adam Adamov, CBDO, Algebra.Finance > The Hexens team is extremely technically competent, high integrity, and exceptional at what they do. We couldn't have asked for a better security partner for Royco. Shiv Kapoor, Head of Engineering, Royco > Everything Hexens ships is built around the same idea: crypto should be safer, clearer, and easier to use. The team has been at it through two bull runs and three bear winters, and that kind of track record is exactly what we wanted behind our Token Risks API, the first release in GetBlock's new Wallet Audit stack. With Hexens' technology under the hood, we can now offer fast, reliable, and detailed risk audits through both API and interface. Here's to many more years and many more releases together. Vasily Rudomanov, CEO, GetBlock --- ## Frequently Asked Questions ### What is Hexens? Hexens is the go-to security firm for projects that cannot afford a single mistake. Our security and R&D team consists of CTF champions, bug bounty leaderboard veterans, and world-class vulnerability researchers — the people other firms benchmark against. We build the security technology the industry uses: Glider, Remedy, Token Risks API. We publish the vulnerability research the industry cites. And we run the audits that protect it — two independent teams per engagement, the full security engineering toolchain, a zero-exploit track record across 300+ engagements and $120B+ in protected assets. ### What makes Hexens different from other blockchain security firms? The result. Zero post-review incidents. While this can be just luck for the first year, after 5 years and hundreds of engagements with the most targeted code in the industry, this is consistency. The results are backed by the people. Our security and R&D team is comprised of CTF champions, bug bounty leaderboard veterans, and hackers with track records of breaking systems that were considered unbreakable. Combined with the methodology, every engagement gets two independent security teams working on the scope. Exclusive focus augmented by the full security engineering toolchain (including professional AI-augmentation). ### What is a smart contract audit? A smart contract audit is a systematic security review of blockchain-based code — designed to surface vulnerabilities, logic errors, access control flaws, and exploitable edge cases before deployment. At Hexens, this means rigorous line-by-line manual review by senior engineers, supported by proprietary tooling and our dual-team methodology. The goal: code that cannot be broken. ### What services does Hexens offer? The full blockchain and general security surface. Smart contract audits across every language and chain. L1/L2 and cross-chain protocol reviews. Zero-knowledge circuit and FHE security audits. Centralized exchange and wallet assessments. Full-stack penetration testing. DevSecOps consulting. Social engineering simulations. AI/ML security reviews. Plus proprietary security products: Glider for on-chain intelligence, Remedy for bug bounties, and Token Risks for real-time risk analysis. If it touches value or processes trust, we secure it. ### We already have an auditor. Why would we need Hexens? Every audit is performed by humans, and no single team — no matter how skilled — catches everything. A second review with a fundamentally different methodology reduces that margin of error. Two different teams, two different approaches, two different sets of assumptions being challenged. 90% of our reports surface critical or high-severity findings — and some of those codebases had already passed a previous audit. A second opinion from a team with a zero-exploit track record isn't redundant. It's how serious engineering teams manage risk. ### What is a ZK audit? A ZK audit is a specialized security review of zero-knowledge circuits, proving systems, and associated cryptographic implementations. ZK circuits are structurally more prone to critical bugs than standard smart contracts — industry data shows ZK audits are approximately twice as likely to uncover critical-severity findings. Hexens audits ZK implementations across Circom, Halo2, Plonky2/3, and other proving frameworks, with particular focus on underconstrained circuits, cryptographic primitive validation, and proof soundness. ### What is Web3 penetration testing? Web3 penetration testing is offensive security assessment designed for decentralized applications and blockchain infrastructure. It covers smart contract interactions, wallet integrations, API surfaces, on-chain/off-chain communication layers, and blockchain-specific attack vectors that traditional pentesting frameworks don't address. Hexens performs comprehensive penetration tests across DeFi platforms, centralized exchanges, DAOs, and other blockchain applications. ### How long does a smart contract audit take? Timelines depend on scope and complexity. A focused Solidity smart contract audit typically takes 2–4 weeks. L1/L2 protocol reviews, ZK circuit audits, and comprehensive exchange assessments take longer. Hexens provides a clear timeline during scoping — and we don't run parallel engagements that dilute focus or delay delivery. ### How can I secure my Web3 application from cyber threats? Effective security is layered: smart contract audits before deployment, full-stack penetration testing, DevSecOps integration, team training against social engineering, a live bug bounty program, and continuous monitoring. Most projects do one or two of these. The ones that survive long-term do all of them. Hexens covers the full lifecycle — audits, advisory, Remedy bug bounties, and Glider-powered on-chain intelligence. ### What are the top blockchain security frameworks? The primary security frameworks applicable to blockchain include the NIST Cybersecurity Framework, OWASP Smart Contract Top 10, ISO/IEC 27001, MITRE ATT&CK (adapted for blockchain threat modeling), and CIS Controls. Hexens integrates these frameworks into our audit methodology and security advisory, ensuring assessments meet and exceed industry compliance standards. ### Does Hexens offer ongoing security support? Yes. Most of our clients work with Hexens continuously — across multiple codebases, protocol upgrades, and new product launches. Our 91% retention rate reflects the compounding value of a long-term security partner over one-off audits. Ongoing engagements include recurring audits, continuous advisory, Remedy bug bounty management, and Glider-powered monitoring. --- ## Company ### Team The Hexens team consists of senior security researchers, CTF champions, and bug bounty leaderboard veterans. Team page: https://hexens.io/team ### Careers Open positions and application information: https://hexens.io/careers ### Contact Email: info@hexens.io Office: 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom ### Social and Code - GitHub: https://github.com/Hexens (public audit report archive, Glider documentation, public Glider queries repository, awesome-fhe-attacks list, PIL static analysis framework for zkEVM) - X / Twitter: https://x.com/hexens - LinkedIn: https://www.linkedin.com/company/hexens