Audits

I audited contracts for Kleros, CertiK, QuillHash and Nethermind. At Safe I coordinate third-party audits by Certora, Ackee, Nethermind and ack3, and commit the reports to the repositories.

Audits I performed

DateClientReport (PDF)
KlerosKleros Liquid
KlerosKleros Governor
KlerosKleros GTCR
KlerosKleros Escrow
KlerosLinguo
KlerosRealitio
KlerosArbitrable Directory
KlerosBinary Arbitrable Proxy
QuillHashGolden Goose
KlerosArbitrable Proxy
CertiKSuper Token

At Nethermind (September 2022 to June 2023) I did 15+ audits across Solidity and Cairo codebases. Nethermind's public reports from that period do not name individual auditors, so none are listed here.

Audits I coordinated as an engineer

Third-party audits of Safe contracts that I coordinated from the engineering side. I prepared the code for review, fixed the findings where the code was mine, and committed each report to its repository, linked below with the pull request that added it. In 2026 this included retroactive audits of earlier Safe contracts, among them one Nethermind engagement that covered Safe v1.3.0 and four modules.

DateFirmReport (PDF) and pull request
ack3RealityVetoModule (#22)
NethermindSafenet (#986)
CertoraPolicy Engine policies (#106)
CertoraPolicy Engine core (#106)
CertoraSafenet Guard (#895)
NethermindSafe v1.3.0, retroactive (#1120)
NethermindERC-4337 module v0.3.0 (#542)
NethermindAllowances module v1.0.0 (#541)
NethermindPasskey module v0.2.1 (#544)
NethermindRecovery module v0.1.0 (#543)
CertoraERC-4337 module v0.3.0 (#540)
CertoraRecovery module v0.1.0 (#545)
CertoraSafe v1.3.0, retroactive (#1119)
CertoraSafenet Beta staking (#164)
AckeeSafe v1.5.0 (#983)
CertoraSafe v1.5.0 (#912)
CertoraSafe v1.4.1 library contracts (#828)
CertoraPasskey module v0.2.1 (#476)
AckeeSocial Recovery Module (Candide) (#42)
AckeeSAFE token locking (#98)
CertoraSAFE token locking (#98)

Findings I fixed or documented: Safe v1.5.0 (#886 to #897) and v1.4.1 (#817), token locking (#94, #95), the ERC-4337 module (#539), the Safenet Guard (#862, #872), the Policy Engine (#100 to #104, #168, #169) and the RealityVetoModule (#21).

Email admin@remedcu.com about any report here or about a review of public code.