Kauz Security Services

Deutsch

Hi there! I'm Dominik Muhs, an independent security consultant based in Germany. Since 2020, I've reviewed smart contracts and applications for teams of all sizes, from early-stage startups to established protocols like EigenLayer, Arbitrum, and Rocket Pool. I enjoy the detective work that comes with security research: digging into code, understanding how systems behave, and finding where they might break.

Services

Most of my work involves manual code reviews of smart contracts written in Solidity. My background in backend development helps when the scope extends to Python, JavaScript, TypeScript, or Golang code sitting alongside the contracts.

I also do penetration testing, usually when teams want a holistic look at both their on-chain contracts and the off-chain systems around them. Often, the most interesting vulnerabilities live in the seams between these layers.

Beyond reviews and pentests, I help teams think through security architecture and threat models, particularly useful during the design phase, before code is written. I've also advised individuals and organizations on operational security: key management, security practices, and risk reduction for high-value targets.

Contact

Whether you have a concrete project in mind or just a security question you're mulling over, I'm always happy to talk. Reach me at hello@kauz.gmbh.

-----BEGIN PGP PUBLIC KEY BLOCK-----

xjMEZWd0JRYJKwYBBAHaRw8BAQdAFgKHo5g2+W+9F4LvGJTqF0sJPTE0EljD
HMMp8SJpiNDNIWhlbGxvQGthdXouZ21iaCA8aGVsbG9Aa2F1ei5nbWJoPsKM
BBAWCgA+BYJlZ3QlBAsJBwgJkMl06xkuDPvzAxUICgQWAAIBAhkBApsDAh4B
FiEEAC8frkSMoJYV8YfjyXTrGS4M+/MAAMWXAP927LMkpfiumuYNgjn1c7d3
toSrNu3lUEJypTNTCoszZgEAx3pMz1Oj5baDlpNvrnty17PfmrG4copB8dJF
+waAYgnOOARlZ3QlEgorBgEEAZdVAQUBAQdAk3/TBhf0DWYl7a/MIdaYAaby
ZnZaZRI2s8Z26OX4SicDAQgHwngEGBYIACoFgmVndCUJkMl06xkuDPvzApsM
FiEEAC8frkSMoJYV8YfjyXTrGS4M+/MAAGMUAQCYGpLud63r8R3ZIdlL3WMm
uMVOiZh90FcH8JsL+j0U3QD/R7muek+4F6pZiaYiuMafTUOkOScFqy2W3RrB
it2q5AA=
=UnIA
-----END PGP PUBLIC KEY BLOCK-----

Work

Below is a selection of recent engagements. Public reports are linked where available; NDA-covered clients are listed as undisclosed.

Portfolio
Name Type Date
undisclosed Incident Response
zkLighter Penetration Test
World Capital Markets Code Review
Ern Mitigations Code Review
Ern Code Review
Everclear Swaps Code Review
Everclear Hub Upgrade Code Review
Ern f.k.a. BitYield Code Review
Lagoon Risk Assessment
Quake Cash Code Review
Web3Auth Code Review
Web3Auth Code Review
undisclosed Penetration Test
Everclear Arbitrum Tokenomics Code Review
Everclear v1.1 (Diablo) Code Review
LucidLabs Spot Check
Everclear Tokenomics Code Review
Across Protocol Code Review
Puffer UniFi Code Review
RAA Sachsen e.V. Threat Modeling
Everclear v1.0 (Chimera) Code Review
Request Finance Code Review
undisclosed Code Review
TAFEL Dresden e.V. Penetration Test
undisclosed Code Review
Hyperlane xERC20 Code Review
Puffer xERC20/VT Pricer Code Review
BakerFi Code Review
Puffer Code Review
Connext Vesting Wallet Code Review
Bitsi Feasibility Analysis
BakerFi Code Review
Moonwell MIP-M23 Code Review
xERC20 Standard Code Review
Stadt.Land.Netz MyVIA Penetration Test
Rocket Pool (Houston) Code Review
undisclosed Code Review
Protocol Labs FilSnap Code Review
undisclosed Code Review
undisclosed Code Review
EigenLayer Code Review
undisclosed Code Review
Rocket Pool (Atlas) Code Review
undisclosed Code Review
undisclosed Code Review
undisclosed Code Review
undisclosed Code Review
Rocket Pool v1.1 Code Review
Arbitrum Nitro Code Review
Fuji Finance Code Review
undisclosed Code Review
undisclosed Code Review
undisclosed Code Review
undisclosed Code Review
Arbitrum Code Review
Gluwacoin Code Review
1inch Protocol v2 Code Review
undisclosed Code Review
undisclosed Code Review
undisclosed Code Review
undisclosed Code Review
GrowthDeFi WHEAT Code Review
undisclosed Code Review
undisclosed Code Review
undisclosed Penetration Test
Rocket Pool Code Review
undisclosed Penetration Test
undisclosed Penetration Test
undisclosed Penetration Test
undisclosed Code Review
undisclosed Penetration Test
undisclosed Penetration Test