Smart Contract Audit
Independent, line-by-line security reviews by senior engineers who've shipped and broken production protocols. Every audit combines manual review, automated tooling, and invariant fuzzing — with a clear, prioritized report your team can ship from.
What we deliver
Manual code review
Two senior auditors review every line independently. We catch logic bugs, access-control flaws, and economic attacks that tools miss.
Invariant & fuzz testing
We write Foundry invariant tests and Echidna campaigns to surface edge cases over millions of randomized runs.
Static analysis
Slither, Mythril, Aderyn, and Semgrep — every signal triaged by a human, no noise dumped on you.
Economic & game-theory review
For DeFi protocols, we model MEV, oracle manipulation, flash-loan attacks, and incentive design.
Detailed report
Findings ranked Critical / High / Medium / Low / Informational, with PoC, impact, and concrete fix recommendations.
Fix verification
Free re-review of all remediations. We sign off only when every Critical and High is resolved or formally accepted.
Our process
Scope & quote
You send the repo + commit hash. We size the engagement based on SLOC, complexity, and external surface area.
Kickoff
Engineering call to walk through architecture, invariants, and threat model assumptions.
Audit
1–4 weeks of manual review + fuzzing. Daily Slack updates on critical findings — no surprises at the end.
Report delivery
PDF + Markdown report with every finding, PoC, severity, and recommendation.
Remediation review
We re-review your fixes and issue a final attestation suitable for public disclosure.
Tech stack
Frequently asked questions
How much does a smart contract audit cost?+
Audits start at $5k for a single contract (~500 SLOC). Mid-size protocols typically run $15k–$50k. Complex DeFi systems $50k–$150k+. Quote within 24h of receiving the repo.
How long does an audit take?+
1 week for small contracts, 2–3 weeks for typical protocols, 4–8 weeks for large DeFi systems. We never rush — fast audits miss bugs.
What do I get?+
A detailed report (PDF + Markdown), full Foundry invariant test suite, all PoC exploits, and a remediation re-review at no extra cost.
Will you publish the report?+
Only with your explicit written permission. Many clients publish to build trust — we'll coordinate timing with your launch.
Do you audit upgrades?+
Yes. We offer diff-audits at a discounted rate when you've already had the base contracts reviewed.
Related services
Ready to ship?
Tell us about your project. We'll reply within 24 hours with scope, timeline, and a fixed quote.
info@cryptohub.agency