Skip to content

Protocol security · pre-release review

Independent implementation review before a high-consequence milestone

A bounded review for teams approaching a client release, hard fork, protocol upgrade, cryptographic rollout, or standardization decision.

When this is useful

  • A release or upgrade changes consensus-critical, parser, arithmetic, state-transition, or interoperability behavior.
  • The implementation has strong conventional tests but needs independent adversarial or cross-implementation validation.
  • A specification change must be checked against executable behavior across more than one codebase.
  • A reported issue needs severity analysis, blast-radius testing, or remediation verification.

How the work proceeds

  1. 01

    Fix the review boundary

    Agree on the milestone, high-consequence behaviors, relevant implementations, exclusions, and evidence needed for a decision.

  2. 02

    Build independent checks

    Combine differential tests, properties, targeted harnesses, specification witnesses, and manual analysis where each adds distinct signal.

  3. 03

    Reproduce and assess findings

    Minimize failures, test cross-client or cross-version impact, and distinguish local defects from protocol-level risk.

  4. 04

    Verify remediation

    Retest fixes, recommend regression coverage, and document residual assumptions and blind spots.

Public evidence

Start with work you can inspect

Protocol, compiler, cryptographic, and fuzzing work with source artifacts.

Next step

Describe the decision, not secrets

A short, non-confidential note about the system, milestone, desired evidence, timing, and possible Ethereum Foundation conflicts is enough to begin. Do not email vulnerability details, source code, credentials, or secrets.

Independent engagements are limited, subject to conflict review, and represent my own views and work. They are not offered, endorsed, or reviewed by the Ethereum Foundation.