Public examples of consensus-sensitive fixes across revm and Nethermind.
Protocol security · pre-release review
Independent implementation review before a high-consequence milestone
A bounded review for teams approaching a client release, hard fork, protocol upgrade, cryptographic rollout, or standardization decision.
When this is useful
- A release or upgrade changes consensus-critical, parser, arithmetic, state-transition, or interoperability behavior.
- The implementation has strong conventional tests but needs independent adversarial or cross-implementation validation.
- A specification change must be checked against executable behavior across more than one codebase.
- A reported issue needs severity analysis, blast-radius testing, or remediation verification.
How the work proceeds
- 01
Fix the review boundary
Agree on the milestone, high-consequence behaviors, relevant implementations, exclusions, and evidence needed for a decision.
- 02
Build independent checks
Combine differential tests, properties, targeted harnesses, specification witnesses, and manual analysis where each adds distinct signal.
- 03
Reproduce and assess findings
Minimize failures, test cross-client or cross-version impact, and distinguish local defects from protocol-level risk.
- 04
Verify remediation
Retest fixes, recommend regression coverage, and document residual assumptions and blind spots.
Public evidence
Start with work you can inspect
Upstream fixes, coordinated disclosures, and security-relevant bugs.
Protocol, compiler, cryptographic, and fuzzing work with source artifacts.
Next step
Describe the decision, not secrets
A short, non-confidential note about the system, milestone, desired evidence, timing, and possible Ethereum Foundation conflicts is enough to begin. Do not email vulnerability details, source code, credentials, or secrets.
Independent engagements are limited, subject to conflict review, and represent my own views and work. They are not offered, endorsed, or reviewed by the Ethereum Foundation.