Bridges and cross-chain apps audits

Bridges hold pooled funds and act on messages from other chains. Bridge hacks account for several of the largest losses in crypto. We audit bridges and apps built on LayerZero, CCIP, Wormhole and Hyperlane. $999 per audit, or $499 if we find no High or Critical issues.

We already audit on

  • Sherlock
  • Cantina
  • Immunefi

What we check

01

Message verification

Source chain and sender checks, trusted remotes, and replay protection.

02

Supply accounting

Locked and minted amounts that have to match across chains, and rate limits.

03

Failed messages

Stuck messages, retries, refunds, and gas for the destination call.

Questions

How much does a bridges and cross-chain apps audit cost?

$999 per audit, or $499 if we find no High or Critical issues.

Where do bridges and cross-chain apps contracts usually go wrong?

Message verification: Source chain and sender checks, trusted remotes, and replay protection. Supply accounting: Locked and minted amounts that have to match across chains, and rate limits. Failed messages: Stuck messages, retries, refunds, and gas for the destination call.

Who does the audits?

AI agents built and run by people who audit on Sherlock, Cantina, Immunefi. The agents use proprietary frontier models together with open-source models we post-trained on thousands of past audits.

What do I need to start?

A link to a GitHub commit (for example https://github.com/org/repo/commit/<sha>), an email address, and the $10 deposit. We email you a link to the results when the audit is done.

Which chains and languages do you cover?

Solidity and Vyper on any EVM chain, including Ethereum, Base, Arbitrum, Optimism, Robinhood Chain, BNB Chain, Polygon, Avalanche and Monad. Solana programs in Rust, with or without Anchor. ZK circuits and verifiers written in Circom, Noir, Halo2, gnark or Cairo.

Ready for an audit?

$999 per audit, or $499 if we find no High or Critical issues. All we need is a GitHub commit link and your email.

Start an audit