Reg. No. 40203410806VAT LV40203410806

Theme

Book a consultationBook

1.07Security testing

Smart Contract & Web3 Security Audit

Manual Solidity and EVM review aligned to the OWASP Smart Contract Top 10 and SCSVS — economic attack modelling, static analysis, fuzzing and invariant testing for smart contracts and protocols.

Smart-contract defects can be difficult or impossible to reverse after deployment. The audit focuses on code and economic conditions that could lead to unauthorised asset movement, loss of control, denial of service or protocol insolvency.

Manual review covers Solidity and EVM behaviour, access control, reentrancy, oracle assumptions, upgradeability, proxy patterns, MEV exposure and protocol-specific business logic, structured around the OWASP Smart Contract Top 10 and the OWASP SCSVS. Automated tools support, but do not replace, manual analysis.

Static analysis with tools such as Slither and Mythril is combined with property-based fuzzing and invariant testing using Foundry or Echidna. Deliverables include confirmed findings, remediation guidance and a re-audit of the fixed version. EVM networks are the primary scope; other ecosystems can be agreed separately.

A code audit is one layer of Web3 security, not the whole of it. It does not cover the signing, multisig and key-management operational surface — compromised signer devices, malicious transaction-signing interfaces and key handling drove several of 2025's largest incidents, independent of any contract bug. Assessing that surface belongs to our Red Team & Adversary Emulation, Social Engineering Assessment and Supply Chain Security & SBOM services, which we can combine with the audit.

EVM-first
Ethereum & L2s; Solana/Rust & Move on request
MiCA + DORA
EU crypto and ICT-resilience framing

How it works

  1. 01

    Scoping & freeze

    Agree contracts, commit hash, architecture and threat model; freeze the codebase for review.

  2. 02

    Automated baseline

    Run and triage Slither and Mythril, and stand up the Foundry/Echidna harness for the codebase.

  3. 03

    Manual deep review

    Line-by-line Solidity/EVM analysis with economic and logic attack modelling against the contracts.

  4. 04

    Fuzzing & invariants

    Property-based fuzzing and invariant testing to surface edge cases and break stated guarantees.

  5. 05

    Reporting

    Severity-ranked findings with proof of impact, gas and best-practice notes, and clear remediation guidance.

  6. 06

    Remediation re-audit

    Re-review fixed code against findings and confirm closure with a final report.

Packages

Single Contract
Focused audit of one contract or a small module, with remediation re-audit.
Protocol AuditPopular
Full codebase review with fuzzing, invariant testing and re-audit.
Protocol + Threat Model
Protocol audit plus DeFi/economic threat modelling, optional formal/symbolic verification of critical invariants, and MiCA/DORA security framing.

Frequently asked questions

Which chains and languages do you audit?

Our principal coverage is Solidity and EVM-compatible networks, including Ethereum and common Layer 2 platforms such as Arbitrum, Optimism, Base and Polygon. Coverage for Solana/Rust or Move-based networks is confirmed separately. Share the repository, pinned code version and target networks during scoping so we can confirm the required expertise before work begins.

Is the audit just running Slither and Mythril, or is it manual?

Manual review is central to the audit. We analyse contract logic, privilege boundaries and economic assumptions, including re-entrancy, access control, oracle manipulation, flash-loan-facilitated attacks, arithmetic and precision-rounding errors, MEV and upgradeability risks. Tools such as Slither and Mythril and fuzz or invariant testing with Foundry or Echidna support the review and exercise edge cases; they do not replace human analysis.

Does an audit guarantee our contracts can’t be exploited?

No credible audit can guarantee that a contract is free of defects or cannot be exploited. The audit reduces risk within the agreed code version, scope, assumptions and time available by identifying and helping remediate the issues found. New code, dependencies, integrations, governance changes or market conditions can introduce additional risk after the audit.

How does MiCA affect our need for a security audit?

MiCA establishes authorisation and ongoing obligations for relevant crypto-asset issuers and service providers, but it does not make a smart-contract audit a universal approval mechanism. A documented audit can support evidence of ICT and security due diligence where the technology and risk profile make it relevant. The engagement scope and report can be structured to support applicable compliance work without implying regulatory approval.

Does DORA apply to us as a crypto-asset service provider?

DORA has applied since 17 January 2025 and covers crypto-asset service providers authorised under MiCA, adding ICT risk-management, resilience-testing and ICT third-party-risk obligations on top of MiCA. A smart-contract audit is not a DORA control in itself, but the report can be structured as evidence of security testing within your ICT risk framework. Our DORA Compliance & Resilience Testing service covers the wider programme, including threat-led testing where you are in scope.

Will an audit protect us from wallet, multisig or signer compromise?

No. A code audit assesses the on-chain contract logic, not the operational surface around it — signer devices, multisig approval workflows, transaction-signing interfaces and key management. Several of 2025's largest losses came from that surface rather than a contract bug. We assess it through our Red Team & Adversary Emulation, Social Engineering Assessment and Supply Chain Security & SBOM services, which can run alongside the audit.

Helpful tools

All services

Scope a test

Direct access to a senior specialist · Reply within 24 hours · NDA available on request