SecurityBoat

Solutions / Use Cases

In Web3, a shipped bug and a drained treasury can be the same event

Smart contracts don't get a patch Tuesday. Once deployed, a logic flaw in a contract handling funds is a live, exploitable, often irreversible liability the moment it's found — by whoever finds it first. And the attack surface isn't only the code: phishing clones of wallet-connect flows, fake token airdrop sites, and impersonated project accounts target your users directly, outside anything your own infrastructure controls.

Where this actually breaks

  • Contract-logic review needs white-box depth before deployment — there's no “patch it in production” fallback once funds are at risk.

  • A single internal review team, however good, has fewer eyes than a broad researcher pool testing continuously against live incentives.

  • Phishing clones of a project's site or wallet-connect flow can be pixel-identical and live for days before anyone notices, draining users who trust the brand.

  • Flat bounties that don't scale with severity don't attract the researcher attention a critical contract bug deserves.

How TriNetra covers it

PTaaS

PTaaS scopes source-code and thick-client engagements as white-box reviews when depth on contract logic matters more than external discovery — the same 12-state lifecycle, CVSS v4.0-scored findings with steps-to-reproduce, and enforced retest loop apply, so a fix to contract logic gets independently reverified before it's called closed.

Bug Bounty

Bug Bounty puts the same code in front of a continuous researcher pool instead of a point-in-time review, run through the real program structure: 12 tabs per program — Overview, Scope, Rewards, Findings, Team, Payouts, Activity, Leaderboard, Collaborators, Updates, Chat, Integrations — with severity-scaled rewards (P1 Critical $5,000 · P2 High $2,500 · P3 Medium $1,000 · P4 Low $400 · P5 Info $100). Disclosure follows a governed two-stage approval (Pending TPM Review → Pending Client → Published) before anything reaches Hacktivity.

Findings

116 total12 critical26 high85 open31 resolved
Insecure deserialization in job queueLOW 1.0ResolvedPTaaS
SQL injection in legacy reporting exportLOW 1.9Accepted riskPTaaS
Outdated TLS configuration (TLS 1.0/1.1)MEDIUM 4.5Fix in progressPTaaS
Verbose error messages leak stack tracesMEDIUM 5.6Fix in progressPTaaS
Race condition in wallet balance updateMEDIUM 6.5VerifiedPTaaS
Missing rate limiting on OTP verificationHIGH 7.7ResolvedPTaaS
Privilege escalation through mass assignmentMEDIUM 5.5Ready for retestPTaaS

Digital Risk Protection

DRP covers the Web3 risk that lives outside your own contracts: phishing clones of your site (favicon-hash matching and HTML-similarity scoring against the real page), typosquat domains, and fake apps impersonating your project — routed through a real Detect → Validate → Action → Confirm takedown pipeline with a full audit trail.

The workflow

  1. 1

    White-box PTaaS review of contract and application logic before deployment or a major upgrade.

  2. 2

    Launch a Bug Bounty program with severity-scaled rewards for continuous post-launch coverage.

  3. 3

    DRP watches for phishing clones and impersonation targeting your users, independent of your own code.

  4. 4

    Disclosure Requests governs what goes public, and when.

Ready when you are

Get your contracts reviewed and your users protected from what your code can't control