“Xyrix provided us with a lot of intel about securing our Mobile-API interface.”
Offensive securityfor production systems.
Practical offensive security for Web3, DeFi and blockchain infrastructure, APIs and modern web applications. We work directly with engineering teams from responsible disclosure through remediation and final validation.
Engagement.
Two ways to engage: a coordinated responsible disclosure for a specific finding, or a full offensive security engagement scoped to a production system. Both paths converge on the same engineering-led workflow.
Responsible Vulnerability Disclosure
We identify and responsibly disclose verified security vulnerabilities to affected organizations. Ideal for teams that need to validate and remediate a confirmed issue with technical guidance.
- ›Technical validation
- ›Reproduction steps
- ›Impact analysis
- ›Remediation guidance
Full Offensive Security Engagements
Comprehensive security assessments tailored to production systems. Engage Xyrix as a standalone partner or continuously alongside your engineering team.
- ›API security
- ›Application security
- ›Infrastructure reviews
- ›Architecture review
- ›Retesting
- ›Final validation
Teams we have coordinated with.
A partial list of organizations we have supported through responsible disclosure or engagement. Full engagements remain under NDA.






























Areas we actively
research.
Directions the team is currently working in. Not marketing tags. The actual list of topics that show up in engagements and internal notes.
- SectorsDeFi protocols, wallets, exchanges, marketplaces, developer platforms, fintech.
- BlockchainEVM chains, L2 rollups, cross-chain bridges, RPC and node infrastructure.
- Application layerWeb applications, REST and GraphQL APIs, mobile clients, backend services.
- InfrastructureCloud tenancy, edge and origin exposure, authentication and authorization design.
- Jul 19Remediation validation completed▊validation
- Jul 17Infrastructure review delivered▊delivery
- Jul 15Responsible disclosure completed▊disclosure
- Jul 13API research published▊research
- Jul 11Case #023 resolved▊case
- Jul 09Origin exposure remediated for FinTech client▊remediation
- Jul 06Cloudflare edge hardening completed▊hardening
- Jul 02GraphQL enumeration research draft▊research
Case studies.
Anonymized under NDA.
Composite descriptions of real engagements. Identifying information is removed. Findings are described in engineering terms.
What teams say
after the retest.
Verbatim excerpts from clients. Attribution abbreviated to preserve engagement confidentiality.
“Nolan and Ben were hired from Xyrix to audit our whole platform.”
“Their report was the first pentest deliverable our engineers read cover to cover. Every finding had a reproduction path we could run.”
“They found a signature-domain issue we had lived with for a year. Fix guidance was in a shape our contract engineers could ship the same week.”
“Coordinated the entire disclosure privately. No noise, no drama, remediation validated end to end.”
“The retest was as thorough as the initial engagement. Closure meant the fix actually held.”
“Xyrix provided us with a lot of intel about securing our Mobile-API interface.”
“Nolan and Ben were hired from Xyrix to audit our whole platform.”
“Their report was the first pentest deliverable our engineers read cover to cover. Every finding had a reproduction path we could run.”
“They found a signature-domain issue we had lived with for a year. Fix guidance was in a shape our contract engineers could ship the same week.”
“Coordinated the entire disclosure privately. No noise, no drama, remediation validated end to end.”
“The retest was as thorough as the initial engagement. Closure meant the fix actually held.”
Capabilities.
Explained technically.
Nine core services covering the full lifecycle of an offensive security engagement, from initial disclosure through final validation.
Web3 & DeFi Security
Offensive security for blockchain applications, DeFi protocols and wallet infrastructure. Integration-layer testing, smart contract interaction abuse, signature and domain-separation review, and oracle manipulation vectors.
API Security Assessment
Business logic, authentication, authorization, rate limiting, abuse vectors, and parser edge cases across REST, GraphQL, and TRPC surfaces.
Application Security Review
Session handling, input validation, deserialization, request smuggling, template injection and framework-specific misuse across the request lifecycle.
Cloudflare & Edge Hardening
Origin protection, WAF and rule design review, cache behavior and key composition, and enforcement of trust boundaries at the edge.
Origin Infrastructure Review
Reachability audit, certificate transparency exposure, historical DNS artifacts, and origin-side rate-limit and firewall design.
Architecture Review
Threat modeling of production system design: data flow, trust boundaries, tenancy isolation, and blast-radius analysis.
Why teams work with us.
Engineering-first
Reports read like internal engineering documents, not marketing collateral. Written for the developers who fix them.
Responsible disclosure experience
Direct experience coordinating findings into large production organizations. Signal, not noise.
Developer collaboration
We work in the same channels as your engineers. Reviews happen in code, not in PDFs.
Technical documentation
Every engagement ships with reproduction artifacts, mitigation guidance and a validation checklist.
Long-term remediation support
We stay engaged through retesting and final validation. Closure is a milestone, not a handoff.
Request an audit.
Disclose a finding.
Private handling. No data accessed, modified, or retained beyond what is necessary to demonstrate the issue. Most messages are acknowledged within a few hours on business days.