flashbots / flashbots/mev-boost-relay

Offering a free security review — no strings attached

Open
#785 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
498
Forks
147
PR merge metrics
No merged PRs in 30d

Description

Hi @flashbots 👋

I'm **Aditya**, a security researcher at **Aditya Security Labs**.

I'd like to offer your project a **free, no-obligation security review**. Here's what I'll do:

- Review your authentication, authorization, and API security
- Check for common high-impact vulnerabilities (IDOR, SSRF, injection, logic flaws)
- Report *all* findings to you **privately and responsibly** — nothing public without your consent
- Provide a short written summary of what I find (even if it's "all clear")

**Why free?** I'm building my open-source portfolio and I genuinely want to contribute to the community. I've previously found and reported vulnerabilities in major platforms and would love to help your project too.

**No catch.** If you're interested, just reply here or email me. If you'd rather I not, no worries — I won't touch the codebase without permission.

Looking forward to hearing from you!

— Aditya
Aditya Security Labs
https://github.com/sivaadityacoder

> *This offer is made in good faith and in compliance with your SECURITY.md disclosure policy.*

Contributor guide

Open the contributing guide

Research direction

No files, tests, or entry points are identified. Before any work begins, confirm that the maintainers want an authorized security review and agree on its scope, reporting process, and definition of done.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
api, authentication, authorization, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
10/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.