Start your audit
Send a GitHub commit link and your email. We email you a link to the report when the audit is done.
We already audit on Sherlock · Cantina · Immunefi
What you get
- System mapContracts, roles, trust assumptions and external dependencies, written out before any bug hunting starts.
- Invariants we testedThe properties your protocol must keep, such as solvency and share accounting, and whether each one holds.
- Attack paths on fund-moving codeEvery function that moves funds, mints, burns or changes permissions is attacked, including through external calls and callbacks.
- Proof-of-concept testsRunnable tests (Foundry for EVM) that reproduce each exploitable issue, so you can confirm your fix.
- Findings with fixesEach finding has a severity, the file and line, the attack scenario, its impact and a suggested code change.
- False positives filteredA second agent tries to disprove each finding. Only findings that hold up go in the report.
Questions
Why do you charge a $10 deposit?
Every audit uses a lot of compute time. Without a deposit, bots and throwaway submissions would fill the queue and slow down real requests. $10 is enough to stop that and small enough not to matter to a real team. We subtract it from your invoice, so it costs you nothing extra.
How much does an audit cost?
$999 per audit. If we find no High or Critical issues, the price drops to $499. You pay a $10 deposit when you submit, and we subtract it from the invoice.
Can I pay with crypto?
Yes. On the start page, choose Crypto to pay the $10 deposit in USDC or USDT from Ethereum, Base, Arbitrum, Optimism, Polygon or BNB Chain, through Request Network. The payment goes wallet to wallet. You can pay the balance in crypto too.
Can you audit a private repository?
Yes. Submit the commit link and we will email you instructions for giving us read access before we start.
Does an audit mean my protocol is safe?
No. No audit, by people or by software, can prove code is free of bugs. For contracts that will hold a lot of money, we recommend also running a bug bounty and getting a manual review.