EVM smart contract audits
Audits of Solidity and Vyper contracts on Ethereum and other EVM chains. $999 per audit. If we find no High or Critical issues, it costs $499.
Solidity, Vyper, Yul and inline assembly, Foundry and Hardhat
We already audit on
- Sherlock
- Cantina
- Immunefi
What we check in EVM code
Access control and upgrades
Initializers anyone can call, proxy storage collisions, misconfigured UUPS or transparent proxies, role escalation, missing timelocks.
Reentrancy and external calls
Single-function, cross-function, cross-contract and read-only reentrancy. Callback hooks in ERC-777, ERC-721 and ERC-1155. Low-level calls whose return value is ignored.
Math, rounding and decimals
First-depositor share inflation, rounding in the wrong direction on mint or burn, precision loss, and tokens with 0, 6, 8 or 18 decimals.
Oracles and price manipulation
Spot prices used as oracles, stale Chainlink rounds, missing L2 sequencer checks, short TWAP windows, flash-loan manipulation.
Token integration
Fee-on-transfer, rebasing, blocklisted and non-standard ERC-20s. Permit and Permit2 handling. Leftover approvals.
Economic attacks and MEV
Missing slippage or deadline checks, sandwich attacks, liquidation incentives, griefing, and loops that can grow until they run out of gas.
Questions
Do you audit Vyper?
Yes, along with Solidity and inline assembly. We check for bugs tied to specific compiler versions.
Do you write proof-of-concept tests?
Yes, for exploitable findings. They are Foundry tests you can run to reproduce the bug and confirm your fix.
How much does an audit cost?
$999 per audit. If we find no High or Critical issues, the price drops to $499. You pay a $10 deposit when you submit, and we subtract it from the invoice.
Why is it cheaper when there are no High or Critical findings?
If your code only has Medium or Low issues, the audit was less useful to you, so you pay $499, about half.
Who does the audits?
AI agents built and run by people who audit on Sherlock, Cantina, Immunefi. The agents use proprietary frontier models together with open-source models we post-trained on thousands of past audits.