Jacobo Avariento
Founder · Security Engineer
Certified ethical hacker and security engineer with 20+ years in cybersecurity, now focused on fintech, real-world assets, and tokenization — smart contracts, custody, and the systems around them.
Fintech · RWA · Asset Managers
Boutique cybersecurity for fintechs, tokenization companies, and asset managers — pentests, smart contract audits, and custody reviews.
Defensahacker Labs is a boutique cybersecurity consulting firm for fintechs, real-world-asset platforms, tokenization companies, and asset managers. We deliver penetration testing, smart contract audits, and custody and issuance reviews. Founded by a Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), and Certified Smart Contract Auditor (CSCA) with over two decades of hands-on experience — including published vulnerability research since 2006 — we help teams that issue, custody, or manage tokenized assets find and fix critical vulnerabilities before attackers do.
We simulate real attacks on the systems fintechs and asset managers actually run — investor portals, onboarding, APIs, admin consoles, and cloud — and show the path an attacker would take into client assets.
Assessments cover web applications, internal networks, mobile apps (Android & iOS), and the operational layer around custody, issuance, and fund administration.
Issuance, redemption, and transfer logic fails in ways a generic review misses. A flaw in minting, allowlists, or share accounting can misprice a fund or drain a reserve.
We review the contracts and the off-chain pieces attackers use — frontends, APIs, and DNS — with manual review, fuzzing, and invariant testing. The same approach covers DeFi protocols that sit under a tokenization stack.
Tokenization companies and asset managers put issuance, custody, and redemption on infrastructure attackers treat as a treasury. A weakness in the contract, the signing system, or the operators who control it can freeze a market or drain the reserve.
We audit MPC (multi-party computation) wallets and signing flows, review smart contracts with fuzzing and invariant testing, and run OpSec reviews of key handling, operator access, and the procedures around the token.
Ethical hacking is a controlled attack on the systems that hold client money: investor portals, issuance admin, APIs, and the contracts underneath. It shows whether those controls actually stop someone who wants the assets.
The background is institutional. Work as a consultant and penetration tester for top-tier banks and the European Central Bank, across several regions, is what fintechs, tokenization companies, and asset managers hire when the asset itself is on-chain.
That work sits on a public research record that starts in 2006, with the first published proof-of-concept for CVE-2006-3747, later CVEs, and contributions to Metasploit and Nikto. The same offensive background now goes into tokenized-asset audits, issuance and redemption logic, fuzzing, and invariant testing.
Get started todayWe don't run automated scanners and call it a pentest. Every engagement is led by a senior security engineer who thinks, moves, and pivots like an actual threat actor — uncovering logic flaws and chained vulnerabilities that tools miss.
Few consultants cover the app, the token, and the signing ceremony in one engagement. Pentesting, smart contract audits, and the operational security around custody and tokenization sit with one senior engineer.
Every finding includes a clear attack narrative, proof-of-concept, impact on reserves or client assets, and prioritized remediation — written for engineers, compliance, and the investment committee.
Trusted by global financial institutions and digital-asset protocols. The public record includes CVEs since 2006, Metasploit and Nikto contributions, and reports on HackenProof and Immunefi. Recent protocol work includes security at Midas and smart contract audits for Rootstock.
Exploit post-mortems and smart contract breakdowns for protocol teams, tokenization builders, and the security staff who protect reserves.
Read on MediumA daily newsletter tracking significant DeFi and tokenized-asset exploits — with root-cause analysis for builders, auditors, and asset managers.
SubscribeLive exploit alerts and on-chain forensics as incidents hit DeFi protocols and tokenized-asset platforms.
Follow on XFounder · Security Engineer
Certified ethical hacker and security engineer with 20+ years in cybersecurity, now focused on fintech, real-world assets, and tokenization — smart contracts, custody, and the systems around them.
A penetration test (pentest) is a controlled, authorized simulation of a cyberattack against your systems, applications, or network. Unlike vulnerability scanning, a pentest involves a human attacker chaining weaknesses to show they can reach client assets, issuance admin, or custody operations. Fintechs and asset managers use it to satisfy PCI-DSS, ISO 27001, and SOC 2, and to find the paths that sit outside those checklists. Most breaches exploit weaknesses that were present for months — regular testing closes that window.
Token contracts execute on-chain and are immutable once deployed — a bad mint, redemption, or share-accounting bug is a balance-sheet event, not a patch. The audit combines manual review with fuzzing, invariant testing, and automated analysis to find reentrancy, access-control flaws, allowlist bypasses, and economic manipulation before deployment. We also review frontends, APIs, and DNS. A large share of losses in tokenized markets start in those off-chain pieces, the same pattern behind most DeFi exploits.
GenAI red teaming tests LLM-powered applications against prompt injection, jailbreaking, data exfiltration, insecure tool use, and agentic privilege escalation. If a fintech or asset platform uses a model for support, onboarding, research, or operations, that model is an attack surface traditional tools miss. We assess against the OWASP LLM Top 10 and give remediation guidance the engineering team can ship.
Scope determines timeline. A focused web application pentest typically runs 3–5 days. A full internal network assessment with Active Directory attacks spans 1–2 weeks. Smart contract audits for a medium-complexity protocol take 5–10 days of review. We always provide a detailed scope document and timeline estimate before any engagement begins, and we include a retest of all critical findings at no extra charge.
Issuance, custody, and redemption are one system. We review the token contracts with fuzzing and invariant testing, the MPC or multisig signing path, and the operator procedures around keys, allowlists, and reserve movements. Asset managers get the same treatment on the platforms that hold or distribute those tokens: the investor portal, the admin roles, and the integrations that can move client assets.
Both. Engagements stay lean and senior-led, so a tokenization startup and an asset manager get the same engineer. The range runs from early token launches to institutions with the same expectations as the European Central Bank work. Every client talks to the lead security engineer, not a project manager relaying findings.
Get in touch if you issue a token, run a fintech platform, or manage tokenized assets. Penetration test, contract audit, or a custody and OpSec review — we're ready to help.