Not a subscription. Not a recurring charge. One payment — one report.
⏱ Pay after you receive the report. If I find fewer than 3 actionable vulnerabilities — 100% refund.
What's included
On-chain review of your main addresses: suspicious approvals, dust attacks, address-poisoning markers, contact with known drainer contracts (Inferno, Pink Drainer, Angel Drainer). A concrete list of wallets to revoke today.
With your consent, I send 3 fake phishing attempts to your email / Telegram (looking like Uniswap, Binance, MetaMask alerts). I observe which one you click. The result is a real risk score — not subjective.
Where your email / username appears in leaks (HaveIBeenPwned + closed dumps), what reverse-image search shows on your profile, which social-engineering vectors are open, what a Lazarus / APT43-style attacker would see first.
A 15-page PDF: "If $X is drained tomorrow — steps 1, 2, 3 in the first 10 minutes". Concrete links to your exchanges, support contacts, last-known-good addresses, checklist for police / IRS.
Turnaround: 3–5 business days. Delivered as a 30-minute Loom video review of your setup + PDF.
AI scan vs Manual audit
AI scan (free with 500 💎)
- ✓12-question survey
- ✓Score 0-100 across 4 categories
- ✓Top-3 vulnerabilities by incident cases
- ✗Doesn't look at your real wallets
- ✗Doesn't test you on phishing
- ✗Doesn't customise to your setup
Manual audit ($49)
- ✓Everything from the AI scan
- ✓On-chain forensics of your addresses
- ✓Real phishing test
- ✓Digital footprint exposure
- ✓Custom playbook for your setup
- ✓30-minute video review
Why GuardLabs
We build production security infrastructure (NEXUS, RVV Hunter, oracle-guardian daemons, AskOracle anti-fraud). 50+ production AI agents in real operation. Crypto trading is our own domain; security for it is a by-product of our engineering practice, not a separate "consultancy".
The audit is performed by a real engineer. The AskOracle AI scan surfaces standard gaps; the manual audit finds vulnerabilities the AI can't — behavioural patterns, your specific setup, your reaction to phishing.
FAQ
What do you need from me?
A list of public addresses (never private keys!). A screenshot of any 2FA setup. Your Twitter / Telegram handles. ~30 minutes in Telegram for clarifying questions.
What if I haven't run the AI scan yet?
You can go straight to manual — I'll factor that into the report. But the AI scan takes 3 minutes and is free after earning 500 💎 of AskOracle activity: askoracle.site/audit.
Refund policy?
If the manual audit finds <3 actionable vulnerabilities — 100% refund. The goal isn't to "sell fear" but to really improve your posture.
Confidentiality?
NDA on request. All artefacts deleted 30 days after delivery. No case studies without your written consent.