OpenZeppelin | Security Audits (2024)

OpenZeppelin | Security Audits (1)

Audits performed by us

19

High & critical vulns uncovered

5

Relationship started

2020

OpenZeppelin | Security Audits (2)

OpenZeppelin | Security Audits (3)

Audits performed by us

4

High & critical vulns uncovered

3

Relationship started

2020

OpenZeppelin | Security Audits (4)

OpenZeppelin | Security Audits (5)

Audits performed by us

2

High & critical vulns uncovered

1

Relationship started

2020

OpenZeppelin | Security Audits (6)

Data collected as of December 31st, 2023

Our team secures leading decentralized exchanges and aggregators.

Read the reports

Engaging with various platforms including AMMs like Bancor V3 and Balancer, the UniswapX order settlement protocol, the Beefy swap router, and the Panoptic options trading platform, which leverages Uniswap V3 liquidity positions, demonstrating our proficiency in V3 concentrated liquidity mathematics. Furthermore, we've completed over 13 audits for 1inch, the premier DEX aggregator.

OpenZeppelin | Security Audits (8)

Audits performed by us

16

High & critical vulns uncovered

9

Relationship started

2022

OpenZeppelin | Security Audits (9)

OpenZeppelin | Security Audits (12)

Audits performed by us

10

High & critical vulns uncovered

14

Relationship started

2023

OpenZeppelin | Security Audits (13)

Data collected as of December 31st, 2023

We secure L1-L2 bridges, ZK-verifier contracts, and optimistic rollups.

Read the reports

We've identified critical vulnerabilities across a range of areas, including fraud-proof verification, cross-domain transactions, fee mismanagement, and reward system abuses.

Notably, critical issues were discovered in the Linea ZK-verifier, the Scroll message-passing bridge, among other ZK-rollups.

OpenZeppelin | Security Audits (15)

Audits performed by us

44

High & critical vulns uncovered

19

Relationship started

2019

OpenZeppelin | Security Audits (16)

OpenZeppelin | Security Audits (17)

Audits performed by us

3

High & critical vulns uncovered

Relationship started

2019

OpenZeppelin | Security Audits (18)

OpenZeppelin | Security Audits (19)

Audits performed by us

2

High & critical vulns uncovered

2

Relationship started

2023

OpenZeppelin | Security Audits (20)

Data collected as of December 31st, 2023

We are the key security partner for leading lending protocols like Compound, Radiant, Venus, and Morpho Blue.

Read the reports

Our researchers have identified several critical vulnerabilities in lending protocols with billions in TVL, including potential bad debt creation in AAVE V3 and stolen rewards in Radiant V2. Serving as Compound's main security partner, we’ve helped establish them as one of the safest platforms in the space.

OpenZeppelin | Security Audits (22)

Audits performed by us

20

High & critical vulns uncovered

17

Relationship started

2020

OpenZeppelin | Security Audits (23)

OpenZeppelin | Security Audits (24)

Audits performed by us

1

High & critical vulns uncovered

Relationship started

2022

OpenZeppelin | Security Audits (25)

Data collected as of December 31st, 2023

Our team expertise extends across the most sophisticated Oracle systems.

Read the reports

These include Chainlink and UMA Protocol, and Oracle-dependent components used by platforms like Compound and Synthetix Oracle manager, which utilize Pyth, Chainlink, and Uniswap V3 TWAP oracles. As UMA's primary security partner, we've conducted over 10 audits, revealing critical vulnerabilities in its optimistic verification system and cross-chain components. Additionally, we've identified high-severity issues in Polymarket's integration with UMA.

OpenZeppelin | Security Audits (27)

Audits performed by us

3

High & critical vulns uncovered

7

Relationship started

2022

OpenZeppelin | Security Audits (28)

OpenZeppelin | Security Audits (29)

Audits performed by us

1

High & critical vulns uncovered

Relationship started

2024

OpenZeppelin | Security Audits (30)

Data collected as of December 31st, 2023

Our first-hand experience auditing multiple Account-Abstraction implementations positions us as leaders in Account Abstraction security.

Read the reports

We worked with the Ethereum Foundation on three audits of Account Abstraction’s EIP-4337, identifying over seven high+ severity issues, enhancing Ethereum protocol’s security. Our discoveries encompassed deposit record manipulations, incorrect gas calculations, and invalid aggregated signature verifications, among others. We also audited Pimlico’s ERC20 token paymaster implementation, allowing users to pay transactions in any ERC20. During this audit, our researchers dived deep into the ERC 4337 paymaster reputation rules.

OpenZeppelin | Security Audits (32)

Audits performed by us

9

High & critical vulns uncovered

12

Relationship started

2021

OpenZeppelin | Security Audits (33)

OpenZeppelin | Security Audits (34)

Audits performed by us

2

High & critical vulns uncovered

Relationship started

2023

OpenZeppelin | Security Audits (35)

Data collected as of December 31st, 2023

We are the security partner for the leading stablecoins.

Read the reports

Back in 2018, we audited Tether, the most used stablecoin in the world. In 2019, our team found a live critical vulnerability affecting MakerDao, the issuer of DAI. Today, we are Origin’s main security partner, performing over 7 audits including the Origin dollar, a yield-bearing decentralized stablecoin. During our engagement with Origin, we added value through multiple findings, including critical findings that would have resulted in yield theft. We also secure Mountain Protocol, issuers of USDM, a yield-bearing rebasing stablecoin backed by T-Bills.

OpenZeppelin | Security Audits (37)

Audits performed by us

2

High & critical vulns uncovered

Relationship started

2022

OpenZeppelin | Security Audits (38)

Data collected as of December 31st, 2023

Financial Institutions entering the blockchain space face unique challenges regarding security, compliance, and operations.

Read the reports

We partner with leading financial institutions across North America, Latin America, Europe, and Asia as their trusted blockchain advisors. We also audited and provided operational infrastructure for the issuance of the A$DC Australian Dollar stablecoin by the ANZ Bank.

OpenZeppelin | Security Audits (40)

Audits performed by us

11

High & critical vulns uncovered

13

Relationship started

2023

OpenZeppelin | Security Audits (41)

OpenZeppelin | Security Audits (42)

Audits performed by us

4

High & critical vulns uncovered

2

Relationship started

2021

OpenZeppelin | Security Audits (43)

Data collected as of December 31st, 2023

We secure the leading Gaming and NFT protocols.
We are the authors of the world’s most widely used implementation of ERC721, used by the most popular protocols working with NFTs.

Our work in NFTs encompasses audits for some of the most widely known issuers and exchanges, including Yuga Labs, creators of BAYC, and OpenSea.

In the gaming space, we are The Sandbox’s security partner, performing over 15 audits to their protocol. Other gaming experience includes Decentraland’s MANA token as well as the PoolTogether protocol, finding critical issues that prevented loss of funds due to user duplication in their prize pools.

OpenZeppelin | Security Audits (2024)

FAQs

Is CertiK audit reliable? ›

CertiK is trusted as the recommended blockchain and smart contract auditor by top exchanges like Binance , OKEx , and Huobi. We audit all components of Web3 platforms. This includes projects built on blockchains like Ethereum , BNB Chain , and Polygon , to more than a dozen of these Layer 1 blockchains themselves.

How do I get into smart contract auditing? ›

How to become a Smart Contract Auditor
  1. Take a solidity and smart contract auditing course. Learn Solidity. ...
  2. Learn smart Contract auditing. The next step is to learn smart contract security and auditing. ...
  3. Practice smart contract auditing - Compete in contests. ...
  4. Continuously learn and grow.
Apr 23, 2024

What is a smart contract audit? ›

A smart contract audit involves a detailed analysis of the contract's code to identify security issues and incorrect and inefficient coding, and to determine ways to resolve the problems. The audit process is an important part of ensuring the security and reliability of blockchain applications.

What are the new solidity vulnerabilities? ›

What are common Solidity security vulnerabilities? Common vulnerabilities include reentrancy attacks, integer overflow and underflow, and improper access control.

How long does a CertiK audit usually take? ›

Audit Process:

Contracts are verified using mathematical methods through CertiK BSC Security Oracle. Experts manually review contracts, classify security vulnerabilities, propose solutions, and provide an audit report. The audit process typically takes 48 hours and is quite costly.

What are the odds of a crypto tax audit? ›

What are the odds of a crypto tax audit? In general, the odds of an audit are relatively low. It was estimated that 0.63% of tax returns in 2023 were selected for an audit.

What is the average cost of a smart contract audit? ›

Total Cost of Smart Contract Audit

Depending on the complexity of the code, smart contract auditing companies often charge between $5,000 to $15,000; however, in some circ*mstances, the cost may be significantly higher. To understand how contract intricacies reflect current security trends, experts also examine them.

Who are the best smart contract auditors? ›

Choosing the right auditor involves considering experience, chain support, audit depth, and cost. Top firms in 2024 include Certik, Hashlock, ConsenSys Diligence, Cyfrin, and Hacken, each with unique strengths. Regular auditing is essential in the Web3 space to prevent hacks and secure smart contracts.

Is smart contract auditing worth it? ›

It's mission-critical that smart contracts are tamper-proof, making audits a key part of any blockchain project's security process. Code audits are important for any application, but they're especially important for decentralized applications (dApps) because the blockchains they built on top of are immutable.

Can ChatGPT audit smart contracts? ›

The answer is No. GPT-4 is certainly amazing, and we've seen notable tweets [1]↗ [2]↗ demonstrating examples of ChatGPT identifying smart contract vulnerabilities. The thing is–and speaking as the author of one of the Tweets linked above–that these examples are cherry-picked.

How much do smart contract auditors make? ›

Here is an average compensation breakdown based on experience level: Entry-Level Smart Contract Auditor Salary: $70,000 per year. Mid-Level Blockchain Auditor Salary: $130,000 per year. Senior-Level Smart Contract Auditor Salary: $200,000 per year.

How much does CertiK cost? ›

CertiK Price Summaries

CertiK's price today is US$0.8571, with a 24-hour trading volume of $16.8 M. CTK is +4.51% in the last 24 hours. It is currently -26.72% from its 7-day all-time high of $1.17, and 5.23% from its 7-day all-time low of $0.8145. CTK has a circulating supply of 134.75 M CTK.

Is Solidity still relevant? ›

Dev & User Profiles: Solidity continues to be the most used language by the respondents, followed by JavaScript and TypeScript. A majority of Solidity experts (self-rating of 10) have been using the language for 2+ years, some even more than 5 years.

Is Solidity a bad language? ›

The Solidity language itself is a high-level (similar to how people talk), so it's not too complex and was specifically designed for working with blockchains.

What is the future of Solidity? ›

The goal is to transition from value types to reference types by the end of 2024. However, syntax sugar, a familiar face for Solidity developers, won't be on the agenda until later, possibly in 2025.

What are the benefits of CertiK audit? ›

This means that the project's developers are provided with actionable steps to address any vulnerabilities, enhancing the overall security of the project. The purpose of CertiK's audit services is to provide a comprehensive security rating of the project's code.

Is audit evidence reliable? ›

The reliability of audit evidence depends on the source and nature of the evidence and the circ*mstances under which it is obtained. The following are examples of factors that may affect the auditor's evaluation of the reliability of external information that the auditor plans to use as audit evidence.

Which audit is best for cryptocurrency? ›

List of the Top Crypto Audit Companies in 2024
  1. Certik. CertiK stands out in the blockchain security landscape, founded in 2018 by academics from Columbia and Yale universities. ...
  2. Trail of Bits. ...
  3. Astra Pentest. ...
  4. Hacken. ...
  5. Quantstamp.
Apr 11, 2024

Can audited financial statements be trusted? ›

When a CPA audits a financial statement, they will ensure the statement adheres to general accounting principles and auditing standards. Without this CPA verification, investors and lenders may not be confident the statement you're presenting is accurate.

Top Articles
Don’t give your ex another chance without keeping these things in mind
Can I Say I Quit If I Actually Got Fired?
Netronline Taxes
Genesis Parsippany
Cars & Trucks - By Owner near Kissimmee, FL - craigslist
CLI Book 3: Cisco Secure Firewall ASA VPN CLI Configuration Guide, 9.22 - General VPN Parameters [Cisco Secure Firewall ASA]
Air Canada bullish about its prospects as recovery gains steam
Craigslist Dog Sitter
[2024] How to watch Sound of Freedom on Hulu
Everything You Need to Know About Holly by Stephen King
Morocco Forum Tripadvisor
Flights To Frankfort Kentucky
Most McDonald's by Country 2024
Define Percosivism
Cyndaquil Gen 4 Learnset
1-833-955-4522
Missouri Highway Patrol Crash
V-Pay: Sicherheit, Kosten und Alternativen - BankingGeek
Testberichte zu E-Bikes & Fahrrädern von PROPHETE.
Chase Bank Pensacola Fl
Johnnie Walker Double Black Costco
Which Sentence is Punctuated Correctly?
Tire Plus Hunters Creek
Cardaras Funeral Homes
Craftsman Yt3000 Oil Capacity
Free Tiktok Likes Compara Smm
Donald Trump Assassination Gold Coin JD Vance USA Flag President FIGHT CIA FBI • $11.73
Wake County Court Records | NorthCarolinaCourtRecords.us
Car Crash On 5 Freeway Today
oklahoma city community "puppies" - craigslist
Tirage Rapid Georgia
Hellgirl000
Stanley Steemer Johnson City Tn
B.C. lightkeepers' jobs in jeopardy as coast guard plans to automate 2 stations
M Life Insider
Download Diablo 2 From Blizzard
Doe Infohub
Rocky Bfb Asset
Luciane Buchanan Bio, Wiki, Age, Husband, Net Worth, Actress
Satucket Lectionary
Expendables 4 Showtimes Near Malco Tupelo Commons Cinema Grill
Ssc South Carolina
Top 1,000 Girl Names for Your Baby Girl in 2024 | Pampers
20 Mr. Miyagi Inspirational Quotes For Wisdom
Fluffy Jacket Walmart
Cvs Coit And Alpha
Caesars Rewards Loyalty Program Review [Previously Total Rewards]
News & Events | Pi Recordings
Grand Park Baseball Tournaments
Tìm x , y , z :a, \(\frac{x+z+1}{x}=\frac{z+x+2}{y}=\frac{x+y-3}{z}=\)\(\frac{1}{x+y+z}\)b, 10x = 6y và \(2x^2\)\(-\) \(...
Rétrospective 2023 : une année culturelle de renaissances et de mutations
Naughty Natt Farting
Latest Posts
Article information

Author: Fredrick Kertzmann

Last Updated:

Views: 6535

Rating: 4.6 / 5 (66 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Fredrick Kertzmann

Birthday: 2000-04-29

Address: Apt. 203 613 Huels Gateway, Ralphtown, LA 40204

Phone: +2135150832870

Job: Regional Design Producer

Hobby: Nordic skating, Lacemaking, Mountain biking, Rowing, Gardening, Water sports, role-playing games

Introduction: My name is Fredrick Kertzmann, I am a gleaming, encouraging, inexpensive, thankful, tender, quaint, precious person who loves writing and wants to share my knowledge and understanding with you.