BACKEND SECURITY

Security for the off-chain systems behind your protocol

We’ve worked with a wide range of projects, from qualified custodians to exchanges to mobile firmware. We’ve discovered bugs across these systems and published the research.

$1.00B+ Vulnerabilities patched120+ Projects audited$36.82B+ On-chain TVL secured

OUR AUDITING PROCESS

How we start an engagement

  1. 01

    Info gathering

    We send an MNDA and look at repositories within scope to understand the details of your project and requests.

  2. 02

    Quote

    We deliver a quote based on our expected duration, potential vulnerabilities, and the overall complexity of your project.

  3. 03

    Kickoff

    We begin the audit, share findings as they emerge, and ask questions as needed.

CLIENT PROOF

On our JavaScript work

“Their website says protecting Blockchain ideas, but their command of JavaScript is impressive. If you've got something that you think would be "too hard for pentesters to understand" - these folks will surprise you. They're not your average pentester.”
Zbigniew TenerowiczMetaMask

OUR RESEARCH

Published research on off-chain attack surfaces

Notes on exploits, audits, reverse engineering, tutorials, and security patterns we’re seeing in the field.

Wallet WebViews

Our research found 20+ major wallets where a malicious dApp could access core permissions without authorization.

OAuth misconfigurations

Our research covers real cases where differences between desktop and mobile environments left SDKs, exchanges, and wallets vulnerable.

Supply-chain attacks

Our research covers the NPM supply-chain attack and practical defenses, along with LavaMoat bypasses.

Mobile browsers

Our research shows how Samsung Internet on the Galaxy S25 shipped a six-month-old version of V8, opening the door to renderer RCE and universal XSS.

GET SECURED NOW

Bring your backend to OtterSec

Tell us what you are building and when you need coverage. We will route the request to the right security team.

Get an audit