Project Understanding
We begin by reviewing the repositories in scope to understand the codebase, its architecture, and the underlying protocol design
Scoping & Proposal
We prepare a detailed proposal based on audit complexity, expected duration, and scope. This includes a quote and timeline
Kickoff & Setup
Once the proposal is accepted, we begin the audit and establish a direct communication channel to keep collaboration smooth
SECURITY REVIEW in Progress
Our researchers examine the code thoroughly, identifying vulnerabilities and weaknesses as they go
Real-Time Communication
We keep you informed throughout the audit, sharing critical findings early and asking clarifying questions when needed
Final Report Delivery
At the end of the review, we deliver a comprehensive report detailing all findings along with recommendations for improving security

OUR TEAM

Nick

General Manager
  • General manager and team coordinator
  • Client management
  • MSc in Data Sciences, BSc in Computer Science, MA in Psychology
  • Primary point of contact -nick@clarityalliance.org
  • Renowned blockchain security expert and bounty hunter, credited with protecting millions in Total Value Locked (TVL) through critical vulnerability disclosures.
  • Extensive experience securing codebases for a diverse range of projects, with a specialization in Stacks ecosystem auditing.
  • Trusted partner to many top Stacks projects, providing rigorous code reviews and proactive security solutions.
  • One of the first to claim critical bounties in Stacks projects - Immunefi

Kristian Apostolov

Lead Security Researcher

ABA

Security Researcher
  • Bootstrapped by a cyber security career for over 8 years, ABA pivoted to securing both EVM (Ethereum Virtual Machine) compatible blockchain projects and Bitcoin L2, particularly Stacks, projects.
  • Being very detail oriented with a clear focus on quality, ABA has conducted a significant number of solo and collaborative smart contract security reviews with remarkable results.
  • Code4rena
  • Sherlock
  • As a security researcher, Stormy has a strong track record in smart contract security, demonstrated by winning both the eBTC contest on Code4rena and the eBTC bug bounty on Immunefi.
  • His expertise lies in diving deep into the protocol at a core level and identifying vulnerabilities until nothing is left unchecked.
  • Code4rena
  • Immunefi

Stormy

Security Researcher

Arabadzhiev

Security Researcher
  • Independent security researcher with a proven track record of top placements in competitive audits across some of the biggest contest platforms like Code4rena and Sherlock, including, but not limited to: 2x 1st place, 1x 2nd place, 2x 3rd place, 2x Top 5.
  • Apart from audit contests, Arabadzhiev has also worked privately on various protocols across different ecosystems, some of which that successfully accumulated 8+ digit TVLs.
  • Code4rena
  • Sherlock
Clarity Alliance was formed in Q2 of 2024 following a series of attacks and exploits that occurred on various Stacks DeFi protocol. All these protocol had been previously audited, highlighting the lack of security expertise available in the ecosystem.

Our team of security researchers is comprised of whitehats with experience in hacking and securing DeFi not only on EVM, but on Stacks specifically. The Clarity VM is significantly different from EVM, with its own nuances that are important to consider, and whitehats with Stacks DeFi experience are still hard to come by. Before coming together as a group, our whitehats had a proven track record of collecting critical bounties on bug bounty platforms from DeFi on Stacks.

Now our security researchers have collected the most valuable experience in reviewing Stacks DeFi, reviewing and securing contracts related to each fundamental type of product in the Stacks ecosystem so far: DEXs, yield farming products, liquid staking, multisig wallets, bridges and more (see our reports section).

The Clarity Alliance team also helped secure the Nakamoto upgrade and sBTC, working together with the Stacks Foundation and Stacks core engineers.