Smart contract audits

A manual, line-by-line review of your Solidity, backed by static analysis, fuzzing and invariant tests, and checked against your spec and the SCSVS.

Once a contract is live, anyone can call it. We call it first, the way an attacker would.

What we test

Out of scope stays out. We ask first.

  • Access control

    Owner and role checks, initialisers, pausing and every privileged function.

  • Value flows

    Deposits, withdrawals, accounting, rounding and fee maths.

  • External calls

    Reentrancy, callbacks, unchecked returns and non-standard tokens.

  • Oracles and pricing

    Price manipulation, stale data and flash loan exposure.

  • Upgradeability

    Proxies, storage layout, initialisation and who can upgrade.

  • Specification match

    Does the code do what your docs and tests say?

How we test

  1. Scoping

    A frozen commit, the contracts and the dates. We read your docs and tests first.

  2. Static analysis

    Slither and Semgrep flag known patterns before we read a line.

  3. Manual review

    Line by line, with a model of who can call what, and what they could take.

  4. Invariant testing

    The properties that must always hold, fuzzed with Foundry, Echidna and Medusa.

  5. Proof

    A Foundry test for each confirmed issue. Watch it fail, then pass after the fix.

  6. Report and fix review

    Severity, impact and a fix for each finding, then we review your fix commits.

A report your engineers can act on

  • Severity, impact, the affected code and a fix for every finding.
  • Foundry tests that reproduce each confirmed issue.
  • The invariant and fuzzing suite we wrote, ready for your CI.
  • A review of your fix commits: each finding marked fixed, partly fixed or acknowledged.

How a finding reads

V-007ExampleSeverity: Critical

Withdrawal updates the balance after the external call

Weakness
SWC-107
Where
Vault contract, withdraw function
Impact
A contract receiving funds could call back in and withdraw more than its balance.
Fix
Update state before any external call (checks, effects, interactions) and add a reentrancy guard.
Fixed · retested

Web3: audits and rewards

Muneeb has audited these chains, bridges and protocols, and been rewarded for what he found. Your contracts get the same reading.

  • VeChainThor
  • Multipli Smart Contracts
  • Internet Computer Protocol (ICP)
  • Snowbridge On-Chain Code
  • Olas
  • Injective Peggy Bridge

Standards and tools

Findings mapped to
  • SCSVS
  • SWC registry
Tools we use
  • Foundry
  • Slither
  • Echidna
  • Medusa
  • Semgrep
Which chains and languages do you audit?

Solidity on Ethereum and EVM-compatible chains. Something else? Ask, and we’ll tell you straight if it fits.

Does an audit mean the code is safe?

No. It lowers risk. We review one frozen commit in a fixed time. Code that changes after it isn’t covered unless we review that too.

What do you need from us?

A frozen commit hash, docs or a spec, a test suite that runs, your deploy scripts, and a developer who can answer design questions.

Can you look at contracts that are already deployed?

We review source at a commit, and check that the deployed bytecode matches it, so the report describes what’s really on chain.

Send us the commit hash

Send the scope and your deadline, and we’ll set up a call.