Business Development & Strategic Partnerships. Web3 - Security -Enterprise @nethermind. Building Ethereum & Agentic AI projects @NethermindSec
San Francisco.
Joined August 2010
- Tweets114
- Following486
- Followers111
- Likes329
Comi Roa retweeted
We completed a security review of @1inch's Aqua and SwapVM.
Aqua is a shared liquidity layer where the same capital backs multiple strategies and tokens stay in the LP's wallet until a swap executes. SwapVM runs swap strategies as signed bytecode programs, so makers get pegged swaps and concentrated liquidity without deploying a contract.
The review covered 1,903 lines of Solidity across three repositories, with well-documented, well-tested code throughout.
Comi Roa retweeted
Stablecoins are turning into payment rails. Tokenized assets are moving out of pilots. But Ethereum's signatures still wouldn't survive a quantum computer. Privacy still isn't there. Scale Ethereum wrong and it loses what made it worth building on.
@_deanstef, our Lead Consensus Researcher, maps the three research pillars: post-quantum security, programmable privacy, and scaling.
nitter.cf/_deanstef/status/20872…
Comi Roa retweeted
If you run an AI security scanner twice, the second turn usually starts from zero. It forgets your codebase, so you get the same false positives every time.
AuditAgent remembers. Every scan builds on the last, so the noise drops and the signal sharpens with every run.
Comi Roa retweeted
We started an audit of @axol_io's PXE Bridge.
It exposes Aztec's shielded settlement to EVM intent solvers over JSON-RPC: solvers request note creation via a simple RPC call, and the bridge's embedded Aztec PXE creates the shielded note and generates the proof on their behalf, so solvers never need to run their own PXE or handle Aztec's private execution model themselves.
Comi Roa retweeted
A proof verified onchain is not useful if there is no budget to use it.
That was the problem with Noir on Stellar. Verifying one proof cost 224.8M CPU instructions, more than half the transaction budget, gone before the application did anything. No state updates, no withdrawals, barely room to emit an event.
We rebuilt the verifier around Stellar's native BN254 host functions. Field arithmetic and multi-scalar multiplication now run in the native layer instead of guest WASM. The contract keeps only orchestration.
Verification now takes 80M instructions, about 20% of the budget, consistent across all eight circuits we tested. On live Testnet, a shielded-pool proof verified for 0.01242 XLM in actual fees.
The other 80% belongs to the application.
Our engineers maintain and optimize the Noir verifier as part of Stellar's zk infrastructure.
Comi Roa retweeted
AuditAgent now scans codebases up to 20k lines in a single pass, up from 12k.
It also connects to GitLab now, not just GitHub. Wherever your code lives, you can point AuditAgent at it.
On our internal benchmark, the updated findings validation kept roughly 25% increase in recall.
An AuditAgent scan raises the baseline before an audit, so auditors spend their time on the business logic AI still misses.
Proud to see @NethermindSec supporting the new @Aptos Security Marketplace by @areta_io
Excited to help #Aptos builders ship securely with support from @Nethermind. 🛡️
#AptosEcosystem #MoveLang #Web3Security #SmartContractSecurity #BlockchainSecurity #SecurityAudits
1/ The Aptos Security Marketplace from Areta Market is now live on @Aptos!
Proven across 10 ecosystems, 2k+ quotes submitted, and up to 30% average cost savings per audit. Alongside the Aptos Foundation, we’re excited to make top-tier security accessible to Aptos builders.
→ aptos.areta.market
Comi Roa retweeted
We completed a security review of @arcxtrade, a yield-decomposition protocol on Starknet that settles across chains by bridging USDC into Wildcat markets through CCTP. The review covered the full Cairo and Solidity codebase, with close attention to the token decomposition model and the cross-chain settlement path. The higher-severity findings were fixed ahead of the beta.
Enjoy the summer break. We’ll keep the audits moving. ☀️...😎...@ethereum @arbitrum @solana @Starknet @base @Optimism and more...#SmartContractAudit #ZK #Web3Security
Your team takes the break. We take the audit.
A few slots open July 1 — August 15. Adjusted rates. AuditAgent Pro included so the codebase is ready before we start.
Smart contracts and ZK circuits.
nethermind.io/audit-slots
Comi Roa retweeted
We open-sourced a DeFi transaction builder for AI agents. No black box. No hidden API calls.
Protocols are JSON playbooks. Resolvers handle token addresses, decimals, slippage, approvals. You get deterministic unsigned tx data back.
44 actions across 12 protocols. Adding a new one is a JSON file.
defi-skills.nethermind.io/
Comi Roa retweeted
𝗕𝘂𝗶𝗹𝗱𝗲𝗿 𝘀𝗽𝗼𝘁𝗹𝗶𝗴𝗵𝘁: 𝗦𝘁𝗮𝘁𝗲𝗺𝗶𝗻𝗱
AgentArena's competitive model is producing results. In the last three competitions, Statemind's independent audit agent earned $2,000+ in bounties, one of around 10 active agents competing in parallel on each task.
Our platform doesn't just host agents. We support builders end-to-end: integration assistance, finding validation, performance feedback, and ongoing technical monitoring. Statemind has been building with us from the start.
Multiple agents. Independent strategies. Third party-based arbitration. Protocols benefit from broader coverage. Builders earn for what they find.
agentarena.nethermind.io
More security shipping from @NethermindSec
When Your ZK Proof Proves Nothing . . . read the thread 👇
#Web3Security #SmartContracts #Audits @ethereum #ZeroKnowledgeProof
Comi Roa retweeted
Gateway.fm is partnering with @NethermindSec to bring advanced audits and formal verification services directly into Gateway Apps.
Nethermind Security covers smart contracts, rollups, ZK systems, and the full off-chain stack (relayers, oracles, sequencers, provers) across EVM, Starknet/Cairo, Circom, Noir, Rust/Solana, and zk-VMs.
Through this integration, teams on Gateway Apps get:
- Smart contract & ZK audits
- Formal verification for high-assurance components
- Full-stack security from L1/L2 to off-chain services
Now available on Gateway Apps.
Comi Roa retweeted
Introducing Startale Superstars, our new incubation program to create the next iconic Mini App on Startale App, focused on consumer, gaming, and bold new concepts.
Build fast. Launch to thousands. Create your killer app with us on @soneium by @Sony Block Solutions Labs.
Selected teams will share a $250K prize pool and receive hands-on support from launch. We’ll work with you every step of the way.
Learn more about Startale Superstars below 👇🏻
Process. Transparency. Strong reviewers. That’s how you ship a secure mainnet.
Honored to back @StoryProtocol as an auditing partner.
#Web3 #CryptoSecurity #SmartContractAudit #NethermindSec
Projects don’t ship secure mainnets by accident. They do it with process, transparency, and strong reviewers.
Nethermind Security supports @StoryProtocol as an auditing partner, helping reinforce the standards set across their ecosystem.
nitter.cf/ethicraul/status/19882…
Excellent breakdown of audits + bounties + ecosystem reviews. Worth your time, especially if you’re gearing up to launch. ⛓️🛡️ @StoryProtocol @NethermindSec @Nethermind
We are starting a series of articles on the security measures taken in preparation for @StoryProtocol mainnet, and after.
I think it's a good read for young projects as well, since the first article also reads as "As a web3 project, how do I procure security audits, configure audit contests, bug bounties, etc?". It goes over dev process, and our ecosystem efforts to help key projects get their code reviewed as well.
Shout out to the great teams that have audited our mainnet launch and beyond
@fuzzland @slowmist @HalbornSecurity @trust__90 @FuzzingLabs
Contest and bug bounty providers:
@cantinaxyz
Our ecosystem auditing partners:
@BlockSecTeam @NethermindSec and @HalbornSecurity
Next week we’re heading to Buenos Aires 🇦🇷 for Devconnect! Ping me if you’ll be around 📲 I always have time for a chat about Security… or an asado with chimichurri 🥩🔥 #Devconnect #BuenosAires #BlockchainSecurity #Networking #AsadoTime
Comi Roa retweeted
🛡️ Nethermind Security Audit Complete
@NethermindSec has completed the audit of Kintsu’s liquid staking protocol for @monad — reviewing sMON’s staking logic, withdrawal mechanics, and more.
Another step toward secure and reliable liquid staking on Monad.
Big news! 🚨 @NethermindSec is now an official partner for the @arbitrum & @Optimism audit funding programs. Shipping on either stack? Your audit may be partially or fully covered. → Learn how to apply . . .👇
Comi Roa retweeted
We are excited to announce that Nethermind Security completed the review of Ventual's @ventuals liquid staking (vHYPE) ahead of their HIP-3 launch.
Big shoutout to the Ventuals team for a highly collaborative process from the initial kickoff call all the way to the fixes review.