Smart contract audits, protocol security reviews, and invariant testing. We find the bugs that automated tools miss.
Smart contract audits at CODESPECT follow a four-phase, SEAL-aligned methodology: static analysis, manual review, fuzzing and invariant testing, and fix verification. Engagements typically span one to five weeks depending on codebase size. Primary coverage is EVM chains (Solidity), Solana (Rust / Anchor), and Starknet (Cairo), with additional support for Fogo (SVM), Canton/Daml and Sui. Deliverables include an executive summary, detailed severity-rated findings, protocol risk assessment, test-suite evaluation, and fix verification.
The majority of exploited vulnerabilities are business logic flaws that scanners cannot catch. Manual review is essential.
Our process aligns with the Security Alliance frameworks, the emerging industry standard for Web3 security.
For complex-math and novel protocols we harden the review with stateful fuzzing against the protocol invariants, hunting the edge cases no reviewer enumerates by hand.

SVM
Daml
Every audit follows a rigorous 4-phase process: static analysis, manual code review, fuzzing and invariant testing, and fix verification. Fuzzing and invariant testing is available as a premium add-on for complex-math and novel protocols, where the invariants are worth proving out mechanically.
A public double-check of the institutional audit. Once the four phases close, the codebase is opened to a contest capped at 50 researchers, selected by CODESPECT from the applicant pool rather than thrown open to anyone who registers. A curated field keeps the signal high and the duplicate noise low, while still putting many independent adversaries on the same code. Best for protocols that want a second, wider opinion before mainnet.
See SpecSiege →Our systematic approach ensures thorough security analysis and transparent communication throughout the entire audit process.
We start with a quick review of your code to assess audit readiness and identify any blockers before the main audit begins. We define project scope and requirements.
Initial codebase analysis to understand architecture, identify critical components, and establish priorities. We create a detailed audit plan.
Comprehensive manual code review supported by automated analysis. We test for vulnerabilities, logic errors, and security best practices.
Regular updates throughout the process. We maintain open communication channels and provide status reports to keep you informed.
After the initial report, we verify your fixes and re-test the updated code to ensure vulnerabilities have been properly addressed.
Comprehensive report including issue classifications, remediation suggestions, and verification results. Complete transparency guaranteed.
To get the most out of your audit, have these ready before kickoff
Feature-frozen smart contract code
No major changes during the audit window
Technical documentation and architecture diagrams
Protocol logic, invariants, and expected behavior
Test suite and coverage reports
Helps us understand expected behavior and coverage gaps
Deployment addresses (if applicable)
Required for on-chain analysis
Known issues or concerns
Share what keeps you up at night. We will dig in.
Codebase access (GitHub, GitLab, or zip)
Private repo access or archive
Every audit delivers a comprehensive, publication-ready security report
Executive Summary
High-level overview of findings and risk classification
Detailed Findings
All issues with severity levels (Critical, High, Medium, Low, Informational)
System Overview
Architecture analysis of the audited contracts and components
Protocol Risk Assessment
Systemic and design-level risks identified during the audit
Documentation Evaluation
Assessment of specification quality and completeness
Test Suite Evaluation
Test results, coverage analysis, and recommendations
Fix Verification Results
Re-testing results for all remediated findings
Comprehensive documentation for every engagement
High-level overview of findings for stakeholders
All vulnerabilities with severity, impact, and PoC
Re-test results confirming all remediations
Systemic and design-level risk analysis
Get a free 30-minute security assessment. We’ll review your codebase scope and flag the top 3 risk areas.
No commitment required · Typical audits start within 1–2 weeks