What we solve
Irreversible transactions and asset control call for an independent review of code, architecture, and assumptions about participant behavior. The auditor should not be the team that developed the contract.
What you get
The project receives a separate report with classified vulnerabilities, reproducible examples, and recommendations. After fixes, a retest records the status of each finding.
What is included
- A fixed code version and audit scope
- Selection of an independent specialist auditor
- Transfer of documentation and a test environment
- Manual and tool-assisted analysis
- A report and retesting of fixes
How we work
- Freeze the version and documentation to be reviewed.
- Agree methods, timing, and disclosure channels.
- The auditor conducts an independent review.
- The development team fixes issues and submits changes for retesting.
Optional additions
- Review of protocol economic logic
- Analysis of roles and keys
- A public summary
- Advice on a safe upgrade process
Important considerations
An audit reduces risk but does not guarantee the absence of vulnerabilities. Scope, code version, known limitations, and disclosure format are agreed before the review starts.