Cryptography audits,
from design to code.

Understand what happens when a server is compromised, a key is reused, or a protocol step fails. We examine the design assumptions and the code that depends on them.

300+ engagements. Every engagement is led by a senior cryptographer.

Selected clients

When to bring us in

Start with the decision you need to make.

You are designing or changing a protocol.

Review the architecture while you can still change its trust assumptions, key management, and failure handling.

Threat modeling, protocol design, primitive selection, and formal analysis where useful.

Key management in 1Password B5

You are preparing a product for release.

Check whether the implementation preserves the protocol's security properties, including when state is reused or a step fails.

Cryptographic code, session state, and error handling in Go, Rust, TypeScript, Swift, Java, .NET, C, and Solidity.

Nonce reuse in dWallet's signing implementation

You are planning a post-quantum migration.

Review primitive and library choices, hybrid constructions, interoperability, and the rollout plan before committing to an architecture.

KEM and signature choices, composition, conformance, and migration planning.

Our Post-Quantum Migration Playbook

You need to assess a verification claim.

Establish what a model or proof actually covers, which assumptions it makes, and how it connects to the code you will ship.

Protocol models in Verifpal, ProVerif, or Tamarin, and review of verification coverage and toolchain boundaries.

Our analysis of libcrux and Cryspen's hax

The scope can focus on one component or connect protocol design to implementation.

Discuss your scope

What you receive

A report your engineers can act on.

Scope, schedule, and fee agreed in writing before work begins.

Read a sample report (PDF)
  1. Scope and assumptions

    The system reviewed, attacker capabilities, security goals, and the limits of the analysis.

  2. Findings with evidence

    What can go wrong, the conditions that make it possible, its severity, and the evidence behind the finding.

  3. Remediation and follow-up

    Recommendations your engineers can work from, discussion of the findings, and retesting where agreed in the scope.

CE Labs libcrux 2026

Review of CE Labs' libcrux

We published five findings in libcrux and analyzed gaps between the code, Cryspen's hax verification pipeline, and the claims made for the library. The work is documented in two papers and an OSTIF talk.

  • Five public implementation and verification findings
  • Analysis of Cryspen's hax extraction and proof boundaries
  • ML-DSA conformance issues reproduced by Crucible
  • Separate documentation of code defects and verification coverage
libcrux Implementation and verification review Symbolic Software · 2026
  1. F-01runtimeML-KEM decompression: 1664 where pow2 (d−1) belongs
  2. F-02proofSerialization proof claims bound 1; code allows 12
  3. F-03fipsML-DSA verifier norm check missing (FIPS 204)
  4. F-04fipsHint deserialization accepts malformed hints
  5. F-05proofAVX2 axiom models x·x where hardware does x·y
Verification Theatre · eprint 2026/192 Verification Facade · eprint 2026/670
Telegram MTProto 2026

MTProto review under a network-attacker model

A technical review of Telegram's MTProto protocol under a network-attacker threat model, commissioned in 2025 by Global Network Solutions and made public in 2026 through a Swiss court filing. Conducted under editorial-independence terms reproduced verbatim in the report.

  • 64-bit auth_key_id exposed in cleartext on every message, on every platform tested
  • Telegram Desktop uses port 443 without TLS, verified four independent ways
  • Identifier persists across app restarts, IP changes, and network switches
  • Full editorial control retained by Symbolic Software, per Section 2.4 of the report
GNMX-01 MTProto — deanonymization potential for a network attacker Symbolic Software · commissioned 2025
  1. F-01critauth_key_id in cleartext on every message
  2. F-02highTelegram Desktop: port 443, without TLS
  3. F-03medIdentifier survives restarts, IP & network changes
  4. §2.4noteFull editorial independence, reproduced verbatim
Public via Swiss civil filing 2026
dWallet Labs 2024

Audit of the 2PC-MPC Rust implementation

With 3MI Labs, we compared dWallet Labs' Rust implementation with the 2PC-MPC protocol and reviewed the supporting crates. The report records three security findings, including critical nonce reuse in the decentralized-party presigning step.

  • Protocol-to-code comparison for the Rust implementation
  • Three security findings, including critical nonce reuse during presigning
  • Review of supporting cryptographic crates
  • Recommendations for further protocol and state-machine analysis
dw-01 2PC-MPC Rust implementation audit Symbolic Software × 3MI Labs · 2024
  1. SCOPEcodeProtocol-to-code comparison
  2. F-01critNonce reuse in decentralized-party presigning
  3. SCOPEcratesSupporting cryptographic crates
  4. NEXTworkProtocol and state-machine analysis
Public report · dw-01.pdf 2024
Native Labs 2023

Smart contract architecture audit

We reviewed the Native Labs smart contracts, including gas use, interoperability, transaction flows, liquidity models, code quality, and their effects on the user experience.

  • Operational efficiency, with emphasis on gas, scalability, and transaction speed
  • Integration with internal and third-party systems
  • Transaction handling, checked for correctness and security
  • Smart-contract effects on the user experience
nat-001 Smart-contract architecture audit Symbolic Software · 2023
  1. S-01scopeGas use, scalability, and transaction speed
  2. S-02scopeOn-chain and off-chain transaction flows
  3. S-03scopeInteroperability and external integrations
  4. S-04scopeLiquidity models and user experience
Public report · nat-001.pdf 2023
1Password Multiple engagements · in collaboration with Cure53

Review of 1Password B5

This work with Cure53 covered key rotation, vault security under server compromise, and public-key validation in 1Password B5.

  • Key-rotation and key-management review
  • Vault-security analysis under server compromise
  • Public-key validation review
  • Conducted with Cure53
b5 1Password B5 review Symbolic Software × Cure53 · multi-year
  1. S-01scopeKey rotation and key management
  2. S-02scopeVault security under server compromise
  3. S-03scopePublic-key validation
  4. TEAMwithCure53
Public report · pentest-report_1password-b5.pdf multiple engagements
Mozilla Thunderbird Enigmail 2017 · in collaboration with Cure53

Audit of Thunderbird's Enigmail integration

In our first client engagement, we worked with Cure53 on Mozilla Thunderbird's Enigmail PGP integration and identified a critical flaw in the signature path.

  • Detected a critical vulnerability in Enigmail's signature path
  • Outlined exposure of encrypted messages to attacker mutation
  • Evaluated exploitation risk when combined with social engineering
  • Identified how message confidentiality could be lost
enigmail Thunderbird Enigmail audit Symbolic Software × Cure53 · 2017
  1. F-01critCritical flaw in Enigmail’s signature path
  2. IMPACTmailEncrypted messages exposed to attacker mutation
  3. PATHsocialExploitation combined with social engineering
  4. TEAMwithCure53
Public report · pentest-report_thunderbird-enigmail.pdf 2017

Working with us.

We have been working together with Symbolic Software as auditors for cryptographic software. They are reliable, precise, honest, thorough and think outside the box.
— Mario Heiderich, Director, Cure53.
Symbolic Software is run by an accomplished researcher, with significant contributions in the area of applied cryptography. They're the right team for projects that require rigorous design and engineering.
— Jean-Philippe Aumasson, Chief Security Officer, Taurus Group.
Symbolic Software are a delight to work with. Their reports are incredibly thorough and they maintain an excellent line of communication. We are grateful we got the opportunity to collaborate with someone of such high calibre.
— Vishnu Mohandas, Founder, Ente.io.
Selected clients