Independent smart contract audit services

Smart contract audits for protocols where one broken assumption can move every asset.

Manual, adversarial security reviews for DeFi, staking, bridge, wallet, governance, and application-layer contracts. The audit follows value, privileges, and invariants across the whole system—not only isolated functions.

  • 8+ critical findings
  • 40+ high / medium findings
  • 57 blockchain protocols protected
  • Public findings across Sherlock and HackenProof

01 / Scope

Smart contract security beyond a vulnerability checklist.

A useful audit models how the protocol is supposed to preserve value, then tries to break that model through unexpected state, hostile integrations, economic pressure, and privileged actions.

01

Protocol logic and access control

State transitions, privilege boundaries, role configuration, upgrade paths, initialization, emergency controls, and the assumptions connecting every contract in scope.

02

Accounting and economic security

Share math, solvency, rounding, fee mechanics, liquidations, incentive design, oracle dependencies, price manipulation, and value extraction under adversarial conditions.

03

Cross-contract and cross-chain risk

Message validation, bridge trust models, replay protection, asynchronous state, integration assumptions, token behavior, callbacks, and external protocol dependencies.

04

Availability and recovery

Denial-of-service paths, griefing, stuck funds, invariant recovery, pausing behavior, governance intervention, and safe operation when dependencies fail.

02 / Method

A review process designed to find exploitable assumptions.

Every audit is anchored to a specific code version and threat model. Automated tools can surface clues, but the core work is manual analysis of the relationships and assumptions that produce exploitable states.

  1. 01

    Scope and threat model

    The engagement starts with architecture, assets at risk, trusted roles, external dependencies, deployment assumptions, and the code or commit that will be reviewed.

  2. 02

    Manual adversarial review

    The review follows value flows and invariants across the system, using targeted tooling and tests to support—not replace—manual reasoning about exploitable behavior.

  3. 03

    Exploit validation and reporting

    Findings are reproduced, severity is tied to concrete impact and likelihood, and each issue includes the affected path, root cause, attack scenario, and practical remediation guidance.

  4. 04

    Remediation review

    Fixes are reviewed against the original issue and surrounding invariants so a patch does not silently move the vulnerability or create a new edge case.

03 / Deliverables

What your team receives

  • A prioritized security report with clear severity and impact
  • Reproducible attack scenarios and affected code paths
  • Root-cause analysis rather than symptom-only descriptions
  • Actionable remediation guidance for the engineering team
  • A remediation review with transparent issue status
  • Direct researcher-to-team communication throughout the engagement

Best fit

When to book a review

  • Before mainnet deployment or a major protocol launch
  • Before an upgrade, migration, or new collateral integration
  • After material changes to accounting or economic design
  • When adding bridges, oracles, hooks, relayers, or external protocols
  • When a prior audit did not cover the current production code
  • When the team needs a focused review of a high-risk subsystem

04 / Questions

Audit questions protocol teams ask

What kinds of smart contracts can be audited?

Reviews can cover DeFi lending, staking, DEX and CLOB systems, bridges, vaults, wallets, account abstraction, token systems, governance, cross-chain applications, and other value-bearing protocol logic. Scope is confirmed from the repository and architecture before work begins.

Which smart contract languages and ecosystems are supported?

Public work includes Solidity/EVM, Move-based ecosystems, Rust, Soroban, and adjacent Go or C++ components. Mixed-language systems can be scoped when security assumptions cross contract, client, relayer, or service boundaries.

How long does a smart contract audit take?

Timing depends on code size, complexity, documentation, test quality, external integrations, and whether the review covers a new protocol or a focused upgrade. A realistic schedule is provided after reviewing the repository and intended deployment scope.

Does the audit include fix verification?

Yes. Remediation review checks whether reported vulnerabilities were resolved and whether the fix preserves the relevant invariants. The final status makes clear which issues are fixed, accepted, or still open.

How is pricing determined?

Pricing is based on the confirmed code scope, architectural complexity, review depth, timeline, and remediation needs. Share the repository or a private scope summary to receive a direct quote without committing to an engagement.

Need an independent security review?

Put the protocol in front of an attacker before launch.

Share the repository, scope, deployment target, and timeline for a direct audit conversation.