Rolled
Close detail of a circuit board under hard light
Security assessment & implementation

Find it before someone else charges you for finding it

Custody reviews, contract and protocol assessments and the engineering to close what we find, run by people who spend the rest of their week tracing the incidents that follow the gaps nobody closed.

Levels 1 to 3 assessed and implemented
CCSS
Typical assess-to-verified window
6 wks
Findings re-tested against the attack path
100%
Reports handed over without remediation support
0
Coverage

Where the money actually gets lost

Contracts get the attention. Keys, signers and deployment pipelines get the incidents. We cover all of it because the attackers do.

Custody & key management

Key ceremonies, shard geography, quorum policy and signer lifecycle assessed against CCSS and rebuilt where the gap is structural.

  • CCSS Level 1–3 gap analysis
  • Ceremony design and witnessing
  • Signer lifecycle controls

Smart contract assessment

Manual review by engineers who have investigated the exploits, backed by fuzzing and invariant testing rather than a linter with a logo.

  • Manual review, first
  • Invariant and fuzz harnesses
  • Fix verification included

Protocol & bridge review

Economic assumptions, oracle dependencies, upgrade authority and cross-chain message validation: the places that actually fail at scale.

  • Oracle and price-feed risk
  • Upgrade authority mapping
  • Message validation logic

Infrastructure hardening

Nodes, signers, CI pipelines and deployment keys. Most on-chain incidents start with an off-chain machine that nobody was watching.

  • Deployment key custody
  • CI/CD supply chain
  • Node and RPC exposure

Standards implementation

CCSS, ISO/IEC 27001 and internal frameworks taken past the gap analysis into evidenced, audit-ready operation.

  • Control design and rollout
  • Evidence pipelines
  • Pre-audit readiness

Red team & simulation

Adversary emulation against your real controls, social engineering the signers rather than just scanning the contracts.

  • Signer-targeted phishing
  • Approval-flow abuse
  • Detection and response scoring
Engagement

Assessment that ends in a fix, not a finding

A report nobody remediates is an expensive record of what went wrong later. We stay until the attack path is closed.

  1. 01

    Scope against the threat, not the checklist

    We start from what an attacker would actually go for in your architecture. A checklist run against the wrong surface produces a clean report and an open door.

    Week 0

  2. 02

    Assess

    Manual review, control testing and where in scope, live adversary simulation. Findings are raised as they land rather than held back for a reveal at the end.

    Weeks 1–3

  3. 03

    Rank by exploitability, not severity theatre

    Every finding carries the attack path that makes it real. If we cannot describe how it gets exploited in your setup, it goes in the observations section, not the critical list.

    Week 3

  4. 04

    Remediate together

    We work alongside your engineers on the fixes rather than throwing a PDF and an invoice. Where the gap is structural, we design the replacement control.

    Weeks 3–6

  5. 05

    Verify and attest

    Every fix is re-tested against the original attack path. You get a verification statement covering what was closed, what was accepted and what remains open by choice.

    On completion

Why it lands differently

The assessment is written by the people who work the aftermath

Every quarter our investigators reconstruct exploits that started in a control someone had already reviewed and passed. Those patterns go straight back into the assessment methodology, which is the whole argument for running both practices under one roof.

  • Attack paths drawn from live matters, not a generic threat library
  • Findings ranked by how they have actually been exploited elsewhere
  • Signer and approval abuse tested, not assumed away
  • Detection gaps reported alongside prevention gaps
See how investigations run
Secure facility corridor lit in low amber light
Responsible disclosure

Found something in a system we assessed?

Tell us and we will route it to the right team under coordinated disclosure. We acknowledge inside one business day, keep you updated through triage, and credit you publicly if you want the credit.

security@rolled.xyz
PGPFingerprint on request
AcknowledgementWithin 1 business day
Safe harbourGood-faith research protected
Security FAQ

What teams ask before scoping

Audits usually stop at the report. We stay through remediation and re-test each fix against the original attack path. And because the same practice runs investigations, the review is informed by how these systems actually get broken rather than how they theoretically might be.

The CryptoCurrency Security Standard covers how keys are generated, stored, used and retired. If you hold customer assets, it is the clearest benchmark available and increasingly what counterparties and insurers ask to see. Level 2 is the practical target for most custodians.

Yes, and it is common. Live review adds constraints, not least that you cannot pause upgrades for us, so we sequence findings by what is fixable without a migration and what genuinely needs one.

Only if you ask us to. Some clients want a public summary for their community; most want the findings kept private. The choice is yours in writing, either way.

Book the review you keep deferring

A scoping call takes thirty minutes and ends with a fixed price and a start date. No discovery invoice, no procurement theatre.