PHENOVATIVE
Portfolio

Software security

Penetration testing, smart-contract audit and security research — on client systems and on our own.

01

Security research

Ongoing

Security research · public bug-bounty and audit platforms

Vulnerability research on live systems, run through the public programmes that pay only for findings that hold up.

Web and API targets, EVM and Solana contracts, Cosmos and Substrate chains, and AI agent tooling — assessed the way an attacker would and written up as reports the vendor can act on. The published summaries are open to read.

  • 96 bug-bounty and audit programmes engaged
  • 18 platforms — HackerOne, Bugcrowd, Immunefi, Cantina, Sherlock, CertIK
  • 19 public research summaries
worrachatrph.web.app
02

FixIt — platform security

Ongoing

Platform security · our own product

FixIt — platform security

The security work behind FixIt — the case study we can publish in full, because the client is us.

Identity and police-record verification before a partner may take a job, database rules tested against an emulator rather than assumed, admin decisions written to immutable audit records, and payment and booking flows reviewed for abuse before launch.

  • Identity and police-record checks before a first job
  • Database rules tested against an emulator, not assumed
  • Immutable audit records for every admin decision
fixitth.com

Published audits

Every engagement whose summary we have published, newest first. Each row opens the report itself.

TargetPlatformDateOutcome
Redbelly NetworkL1 · EVM · identity/KYC dAppHashlockJun–Jul 2026Paid2 valid · 1,000 USDC paidReport
Blockchain.comWebSocket · REST · KYC tiersBugcrowdMay–Jun 2026CriticalCritical · confirmed, duplicateReport
Memento (DFM)DeFi web app · 85 endpointsYesWeHackMay–Jun 2026CriticalCritical + High · duplicate / RTFSReport
BitGoSolidity · multisig walletsCantinaJun 2026CriticalCritical · duplicateReport
LaunchDarklyREST API · 242 endpointsBugcrowdJun 2026HighHigh · known issueReport
RapydSAML SSO · payments API · 203 endpointsBugcrowdJun 2026HighAuth bypass · duplicateReport
Morpho MidnightSolidity · fixed-rate P2P lendingCantina · competitionJun 2026Medium4 × Medium · duplicateReport
CircleMalachite BFT · Stellar CCTP · Remote SignerHackerOneMay–Jun 2026Medium7 reports · 6 duplicate, 1 informativeReport
Crypto.comREST + WS exchange · GraphQL · KYCHackerOneJun 2026MediumMedium · duplicateReport
Google NotebookLMLLM · search groundingGoogle VRPJun 2026MediumKnown issueReport
OSL ExchangeTrading API · 183 endpointsBugcrowdJun 2026MediumMedium · patched by vendorReport
WhitechainBridge / withdrawal flowHackenProofJun 2026Medium2 findings · duplicateReport
Kiln V1Solidity · staking infrastructureCantinaJun 2026Medium1 finding · duplicateReport
Lightspark (Spark)Go · gRPC · Bitcoin L2 tokensHackerOneMay–Jul 2026Low2 findings · duplicate / informativeReport
StripePayments API · MCP OAuth 2.1 · ConnectHackerOneJul 2026CoverageCoverage report · cleanReport
FirelightSolidity · ERC-4626 cover vault · FlareImmunefi · audit competitionAug 2026CoverageCoverage report · 15 surfaces cleanReport
Quantus NetworkSubstrate · ML-DSA · Plonky2 ZKImmunefi · audit competitionAug 2026CoverageCoverage report · 10 surfaces cleanReport
Telcoin Peg Stability VaultSolana · Anchor · Token-2022HackenProof · DualDefenseJul 2026CoverageCoverage report · 100% readReport
Zynk ProtocolSolana · Anchor · cross-border liquidityHackenProofJul 2026CoverageCoverage report · cleanReport

All reports are published on worrachatrph.web.app

How we work

The same four steps whether we are building something for you or testing something you already run.

  1. 01

    Scope

    We agree exactly what is being built or tested, what it costs and when it lands — before any work starts.

  2. 02

    Build or test

    Development in short, visible increments. Security work manual and hypothesis-driven, every finding proven.

  3. 03

    Hand over

    Working software with its source and its deployment, or a report an engineer can act on without a meeting.

  4. 04

    Stay

    Support after launch, and a free retest after you have fixed what we found.