Every line
questioned.
Every path
proven.
From bytecode to battle-tested — we combine static analysis, coverage-guided fuzzing, and formal verification so your protocol ships with proof, not hope.
The cost of skipping
a rigorous audit
Every exploit in this dataset was preventable. These protocols had code reviews. They had internal testing. What they lacked was systematic adversarial analysis — someone who thinks like an attacker, not a builder.
Exploit Flow: Vulnerability Class → Dollar Loss (USD Millions)
Data sourced from 180+ audits across EVM, Solana, and Move ecosystems. Q1 2022 – Q4 2024.
Rigor has layers.
Most firms stop at one.
A real DeFi vault protocol. Four phases of analysis. The reentrancy that would have drained $240M — found at layer one, confirmed at layer four.
Threat Modeling
We map every trust boundary, privilege escalation path, and economic incentive before touching code.
Starting from the protocol specification and deployment topology, we construct an adversarial threat model that identifies attack surfaces most automated tools never reach — flash loan composability, MEV extraction vectors, cross-contract state dependencies.
Static Analysis
Manual review of every opcode path, combined with custom Slither detectors tuned for this protocol's specific invariants.
Not a checkbox scan. Our engineers write protocol-specific detectors that understand your invariants — not generic vulnerability patterns. Every function signature is traced through every possible call path, including delegatecall chains and assembly blocks.
Coverage-Guided Fuzzing
72-hour Echidna campaign with custom invariant harnesses. Every branch hit. Every edge case surfaced.
We write property-based tests that encode your protocol's economic invariants as formal assertions — not just "doesn't revert." If a flash loan can temporarily violate a conservation law, our fuzzer will find it. Coverage maps are delivered with the report.
Formal Verification
Mathematical proof of critical invariants using Certora Prover. Not "probably safe" — provably safe.
For high-value contracts, we encode the most critical safety properties as formal specifications and produce machine-checked proofs. When we say a reentrancy is impossible, we mean a theorem prover has verified it across all possible execution paths — not that we didn't find one.
What "thorough audit"
actually means.
Not all audits are equal. This matrix shows what each tier of review actually covers — and what gets skipped when teams optimize for speed or cost.
"Typical firm" represents common industry practice based on publicly available audit reports from 2022–2024. Not a characterization of any specific firm.
Deploy with proof,
not hope.
The Audit Toolkit includes our pre-audit checklist, invariant testing templates, Slither configuration for DeFi protocols, and the threat modeling worksheet we use on every engagement.
Read the full threat analysis
Every major exploit from 2024 dissected — root cause, opcode trace, and what a proper audit would have caught. 84 pages. No paywalls after download.