Wick Crypto Engine
shieldGreen TeamPublic-facing security advisories from the WICK GREEN TEAM (RED TEAM)
Plain-language safety briefs for crypto holders. The full investigations live on the internal Red Team board; this page surfaces the user-facing conclusions. Every claim cites an on-chain block, transaction, or contract address you can verify yourself in any block explorer.
BLOCK-CHAINS
BRIDGES
PROTOCOLS
TOOLS
EVM MAJORS
DEX AGGS
COMMUNITY
TO RELEASE ONCE TEAM PAYS

Who we are, and what we are doing

A small all-EVM security squad. Each member specialises in a different attack surface — EVM contracts, oracle and pricing logic, cross-chain bridges, exploit chains and supply chain — paired with a non-technical operator who tracks the people, lore, and community signals around each protocol. We pick research targets by blast-radius — the protocols whose breakage hurts the most users — not by what we personally hold.

When we find something that affects regular holders, it gets a plain-language advisory on this page. When it is operationally sensitive, it stays on the internal Red Team board until it is responsibly disclosed.

What we are actively doing to protect the chain
  • Monitoring PulseChain-native protocols (PulseX, 9mm, 9inch, Piteas, pump.tires) and the forked Maker / DAI / MKR contracts left over from the 2023 fork.
  • Tracking high-impact EVM protocols by total value locked across every major chain (Ethereum, the L2s, BSC, Avalanche, Polygon) — Uniswap V4, Aave V3, Pendle, Curve, GMX, Lido, EigenLayer, Morpho — for new attack patterns that propagate across chains.
  • Reading every credible security feed daily: rekt.news, Trail of Bits, samczsun, Zellic, Spearbit, GitHub security advisories, Immunefi disclosures.
  • Running a daily ingest + classification pipeline that turns raw disclosure into work-items inside 24 hours.
  • Publishing public advisories — like the pDAI brief in the next tab — whenever something puts ordinary holders at risk.
REVERBEVM Auditor
Reads contracts on EVM chains line by line. Looks for the kind of code mistakes that have historically drained user funds — re-entrancy, missing access checks, unsafe upgrades.
focus: ethereum · base · arbitrum · polygon
MAXSocial Engineer & Crypto Historian
The non-technical pair to the rest of the team. Tracks the people behind every protocol — founders, multisig signers, BD leads, anon devs — and the lore they sit inside. Recognises when a current situation rhymes with a historical exploit (Beanstalk, Mango, Cream) and flags governance / community signals (rage-quits, founder-departures, narrative collapses) that tend to precede an exploit window.
focus: multi
CASCADEMechanics & MEV Researcher
Tracks how prices are computed across DEXes and lending markets. When a protocol prices an asset off a single thin pool, that is a manipulation surface — CASCADE finds and flags it.
focus: multi
CINDYBridge & Cross-chain Specialist
Monitors bridges and cross-chain message buses (Wormhole, LayerZero, Across). Bridges have lost more user money than any other DeFi category; CINDY watches the trust assumptions for changes.
focus: multi · ethereum · base · arbitrum
DROVERIntel & Triage Lead
Reads every public security feed daily — rekt.news, Trail of Bits, GitHub advisories, postmortems — and turns new disclosures into work for the rest of the team within 24 hours.
focus: multi
SPLICEExploit Chains & Supply Chain
The newest member. Two jobs: chaining medium-severity bugs into critical exploits before the bad actors do, and watching the supply chain (npm packages, GitHub Actions, RPC providers, frontend CDNs) where a single compromise can hit dozens of protocols at once.
focus: multi
"Independent offensive research across every EVM chain. Operators pick targets by impact-to-userbase, not by our own exposure. Technical depth (REVERB, CASCADE, CINDY, SPLICE) is paired with human-context depth (MAX) — every finding carries the lore around who built it, who broke it, and who's circling it now. High-severity findings go to bug bounties or coordinated disclosure. We can re-aim the team at our own builds later — that is a deliberate switch, not the default."
Not financial advice. Advisories reflect on-chain state at time of publication. Verify every claim against the chain before acting on it.
RPC: connected
Scanner: 193d 17h 37m uptime
687,559 events indexed
WICK_CRYPTO_ENGINE // Built by Green Wick AI