Skip to content

Independent · conflict-screened

Differential testing for critical systems approaching a milestone

For teams that need independent evidence before a release, hard fork, protocol upgrade, cryptographic rollout, or standardization decision.

Detailed scopes cover differential fuzzing, client and protocol implementation review, constant-time analysis, and team capability building. Each scope is tied to public evidence and states what it does not cover.

The ranges below are planning estimates for a focused scope, not availability commitments. Timing is confirmed only after an Ethereum Foundation conflict-of-interest check and an availability discussion.

Differential-testing diagnostic

Typical duration · 1–2 weeks

For teams that suspect cross-implementation or oracle risk.

You get: A divergence and threat model, a target matrix, a harness and coverage roadmap, and a prioritized-risk debrief — the same artifact structure as the public case studies.

Review the detailed scope

Critical implementation review

Typical duration · 3–6 weeks

For teams approaching a hard fork, protocol upgrade, or cryptographic rollout.

You get: Independent tests of high-consequence behavior, reproducible findings with severity analysis, and remediation verification.

Review the detailed scope

Team workshop & advisory

½–1 day session · 1–2 weeks preparation

For teams building their own fuzzing or differential-testing capability.

You get: A tailored workshop with practical exercises and reference material, followed by focused office hours.

Review the detailed scope

Specialist review track

Constant-time analysis

For cryptographic implementation paths where secret-dependent control flow, arithmetic, or timing behavior needs a bounded, independently evidenced review.

See the review boundary

Good fit

Multi-implementation systems — L1/L2 clients, cryptographic libraries, compilers, and virtual machines — approaching a release, upgrade, audit, or standardization milestone, where a reproducible divergence is worth far more than an opinion.

Poor fit

Smart-contract application audits, generic penetration testing, or anything that conflicts with my Ethereum Foundation responsibilities. I run a conflict check before any details are shared.

What happens next

  1. 01Enquiry
  2. 02EF COI check
  3. 03Availability discussion

Do not include vulnerability details, secrets, credentials, or source code in an enquiry. Use the PGP key for sensitive reports.

Independent engagements are limited, subject to conflict review, and represent my own views and work. They are not offered, endorsed, or reviewed by the Ethereum Foundation.