Xyrix Security. Offensive Security · Web3 · APIs · Infrastructure
Active since 2022 · Private engagements

Offensive securityfor production systems.

Practical offensive security for Web3, DeFi and blockchain infrastructure, APIs and modern web applications. We work directly with engineering teams from responsible disclosure through remediation and final validation.

Xyrix. Offensive Security.Scroll
01 · How We Work

Engagement.

Two ways to engage: a coordinated responsible disclosure for a specific finding, or a full offensive security engagement scoped to a production system. Both paths converge on the same engineering-led workflow.

[01]engagement model

Responsible Vulnerability Disclosure

We identify and responsibly disclose verified security vulnerabilities to affected organizations. Ideal for teams that need to validate and remediate a confirmed issue with technical guidance.

  • Technical validation
  • Reproduction steps
  • Impact analysis
  • Remediation guidance
[02]engagement model

Full Offensive Security Engagements

Comprehensive security assessments tailored to production systems. Engage Xyrix as a standalone partner or continuously alongside your engineering team.

  • API security
  • Application security
  • Infrastructure reviews
  • Architecture review
  • Retesting
  • Final validation
Engagement flow
    ▊ step 01
    Responsible Disclosure
    Or Private Offensive Engagement
    ▊ step 02
    Technical Validation
    Reproduction, impact, scope
    ▊ step 03
    Technical Report
    Sent to team via Telegram or email
    ▊ step 04
    Engineering Collaboration
    Shared channel with your developers
    ▊ step 05
    Remediation
    Fix guidance and PR review
    ▊ step 06
    Retesting
    Mitigation validation
    ▊ step 07
    Final Validation
    Closure sign-off
Worked with

Teams we have coordinated with.

A partial list of organizations we have supported through responsible disclosure or engagement. Full engagements remain under NDA.

Client A
Client B
Client C
Client D
Client E
Client A
Client B
Client C
Client D
Client E
Client A
Client B
Client C
Client D
Client E
Client A
Client B
Client C
Client D
Client E
Client A
Client B
Client C
Client D
Client E
Client A
Client B
Client C
Client D
Client E
Active Research

Areas we actively
research.

Directions the team is currently working in. Not marketing tags. The actual list of topics that show up in engagements and internal notes.

Current areas12 tracks
Web3
DeFi
Blockchain
Smart Contracts
Wallet Security
API Security
Application Security
Authentication Logic
Origin Infrastructure
Mobile Applications
API Abuse
Threat Modeling
Coverage
  • Sectors
    DeFi protocols, wallets, exchanges, marketplaces, developer platforms, fintech.
  • Blockchain
    EVM chains, L2 rollups, cross-chain bridges, RPC and node infrastructure.
  • Application layer
    Web applications, REST and GraphQL APIs, mobile clients, backend services.
  • Infrastructure
    Cloud tenancy, edge and origin exposure, authentication and authorization design.
Recent activitysorted newest first
  • Jul 19Remediation validation completed
  • Jul 17Infrastructure review delivered
  • Jul 15Responsible disclosure completed
  • Jul 13API research published
  • Jul 11Case #023 resolved
  • Jul 09Origin exposure remediated for FinTech client
  • Jul 06Cloudflare edge hardening completed
  • Jul 02GraphQL enumeration research draft
Case Studies

Case studies.
Anonymized under NDA.

Composite descriptions of real engagements. Identifying information is removed. Findings are described in engineering terms.

7 closed cases · anonymized
Feedback

What teams say
after the retest.

Verbatim excerpts from clients. Attribution abbreviated to preserve engagement confidentiality.

Client feedback

Xyrix provided us with a lot of intel about securing our Mobile-API interface.

Engineering Lead
Mobile-API audit · Web3
Client feedback

Nolan and Ben were hired from Xyrix to audit our whole platform.

CTO
Full platform audit · DeFi
Client feedback

Their report was the first pentest deliverable our engineers read cover to cover. Every finding had a reproduction path we could run.

Head of Engineering
API assessment · FinTech
Client feedback

They found a signature-domain issue we had lived with for a year. Fix guidance was in a shape our contract engineers could ship the same week.

CTO
Responsible disclosure · Web3
Client feedback

Coordinated the entire disclosure privately. No noise, no drama, remediation validated end to end.

Founder
Disclosure & remediation · Marketplace
Client feedback

The retest was as thorough as the initial engagement. Closure meant the fix actually held.

Security Engineer
Infrastructure review · SaaS
Client feedback

Xyrix provided us with a lot of intel about securing our Mobile-API interface.

Engineering Lead
Mobile-API audit · Web3
Client feedback

Nolan and Ben were hired from Xyrix to audit our whole platform.

CTO
Full platform audit · DeFi
Client feedback

Their report was the first pentest deliverable our engineers read cover to cover. Every finding had a reproduction path we could run.

Head of Engineering
API assessment · FinTech
Client feedback

They found a signature-domain issue we had lived with for a year. Fix guidance was in a shape our contract engineers could ship the same week.

CTO
Responsible disclosure · Web3
Client feedback

Coordinated the entire disclosure privately. No noise, no drama, remediation validated end to end.

Founder
Disclosure & remediation · Marketplace
Client feedback

The retest was as thorough as the initial engagement. Closure meant the fix actually held.

Security Engineer
Infrastructure review · SaaS
Services

Capabilities.
Explained technically.

Nine core services covering the full lifecycle of an offensive security engagement, from initial disclosure through final validation.

[01]service

Web3 & DeFi Security

Offensive security for blockchain applications, DeFi protocols and wallet infrastructure. Integration-layer testing, smart contract interaction abuse, signature and domain-separation review, and oracle manipulation vectors.

[02]service

API Security Assessment

Business logic, authentication, authorization, rate limiting, abuse vectors, and parser edge cases across REST, GraphQL, and TRPC surfaces.

[03]service

Application Security Review

Session handling, input validation, deserialization, request smuggling, template injection and framework-specific misuse across the request lifecycle.

[04]service

Cloudflare & Edge Hardening

Origin protection, WAF and rule design review, cache behavior and key composition, and enforcement of trust boundaries at the edge.

[05]service

Origin Infrastructure Review

Reachability audit, certificate transparency exposure, historical DNS artifacts, and origin-side rate-limit and firewall design.

[06]service

Architecture Review

Threat modeling of production system design: data flow, trust boundaries, tenancy isolation, and blast-radius analysis.

Why Xyrix

Why teams work with us.

Engineering-first

Reports read like internal engineering documents, not marketing collateral. Written for the developers who fix them.

Responsible disclosure experience

Direct experience coordinating findings into large production organizations. Signal, not noise.

Developer collaboration

We work in the same channels as your engineers. Reviews happen in code, not in PDFs.

Technical documentation

Every engagement ships with reproduction artifacts, mitigation guidance and a validation checklist.

Long-term remediation support

We stay engaged through retesting and final validation. Closure is a milestone, not a handoff.

Establish Secure Comms

Request an audit.
Disclose a finding.

Private handling. No data accessed, modified, or retained beyond what is necessary to demonstrate the issue. Most messages are acknowledged within a few hours on business days.

Cookies

We use a minimal set of cookies to keep this site functional. Analytics cookies only with your consent. Cookie Policy.