We are humans who love to audit code. For more than 5 years and across over 200 engagements — from L1 consensus and bridges to DeFi protocols and restaking primitives — we have done this work. It is demanding, high-stakes, unforgiving of small mistakes — and we continue to love it. It keeps us learning. It puts us alongside builders working at the edge of what's possible. The issues we surface are real: across our recent engagements we have reported dozens of Critical and High findings, helping teams catch and close vulnerabilities before they reached production. And what is behind that record matters to us more than the record itself — we believe decentralized technology can make the world meaningfully better, and our role is clear: to protect and advocate for the people who give these systems life by participating in them, the people who bear the cost when something breaks.
Methodology
Every engagement begins with threat modeling — mapping what your system promises its users, where trust sits, and what an attacker would target. We produce this as an explicit artifact: a system diagram, a trust map, and an attack-surface inventory that becomes the spine of the review. From there, our team conducts a deep manual review of the code — line by line, with the discipline of reading past the obvious and questioning every assumption a contract makes about its callers, its state, and the world around it. AI is part of the workflow: we use it to extend our reach across large codebases, surface candidate patterns, and accelerate cross-referencing — but never as a substitute for human judgment. When we find an issue, we report it clearly, with runnable proof-of-concept exploits where they help you understand and act on the risk. We share findings as we discover them, not in a single dump at the end, and we re-review your fix commits to confirm the remediation actually closed the issue. And throughout, we treat our customers the way we'd want to be treated: responsive, attentive, invested in the outcome. White glove is the standard, because the work — and the people relying on you — deserve nothing less.
About This Public Summary
This is a public-facing summary of an independent security audit and penetration test of the Loop Wallet, conducted by Verified by Humans. It preserves the complete list of findings together with each finding's title, severity, and current remediation status. Nothing has been dropped. To protect users while remediation continues, this version omits implementation-level detail present in the full report shared privately with the Five North team: source file paths, line numbers, repository and commit references, code excerpts, and concrete exploit strings. For findings that remain Acknowledged or Partially Fixed, descriptions are kept deliberately high level and do not restate any remaining exploitable steps in production. Severity ratings follow the Immunefi Vulnerability Severity Classification System (v2.3). Status values are Fixed, Partially Fixed, and Acknowledged.
Contact Verified by Humans
https://verifiedbyhumans.co/
x.com/issue_critical
info@verifiedbyhumans.co
For audit enquiries, contact Verified by Humans directly.