Service

Web3 Security

Smart contract audits, protocol security reviews, and invariant testing. We find the bugs that automated tools miss.

Smart contract audits at CODESPECT follow a four-phase, SEAL-aligned methodology: static analysis, manual review, fuzzing and invariant testing, and fix verification. Engagements typically span one to five weeks depending on codebase size. Primary coverage is EVM chains (Solidity), Solana (Rust / Anchor), and Starknet (Cairo), with additional support for Fogo (SVM), Canton/Daml and Sui. Deliverables include an executive summary, detailed severity-rated findings, protocol risk assessment, test-suite evaluation, and fix verification.

Why it matters

Why Web3 Security Matters

80% are logic flaws

The majority of exploited vulnerabilities are business logic flaws that scanners cannot catch. Manual review is essential.

SEAL-aligned methodology

Our process aligns with the Security Alliance frameworks, the emerging industry standard for Web3 security.

Invariant testing where it counts

For complex-math and novel protocols we harden the review with stateful fuzzing against the protocol invariants, hunting the edge cases no reviewer enumerates by hand.

Supported Blockchains

Ethereum

Ethereum

Solana

Solana

Fogo

Fogo

SVM

Starknet

Starknet

Canton

Canton

Daml

Sui

Sui

Our Methodology

Every audit follows a rigorous 4-phase process: static analysis, manual code review, fuzzing and invariant testing, and fix verification. Fuzzing and invariant testing is available as a premium add-on for complex-math and novel protocols, where the invariants are worth proving out mechanically.

Static Analysis
Manual Review
Fuzzing & Invariants
Fix Verification
Optional add-on

SpecSiege audit contest

A public double-check of the institutional audit. Once the four phases close, the codebase is opened to a contest capped at 50 researchers, selected by CODESPECT from the applicant pool rather than thrown open to anyone who registers. A curated field keeps the signal high and the duplicate noise low, while still putting many independent adversaries on the same code. Best for protocols that want a second, wider opinion before mainnet.

See SpecSiege →
Engagement

How we work.

Our systematic approach ensures thorough security analysis and transparent communication throughout the entire audit process.

01

Scoping & Assessment

1-2 days

We start with a quick review of your code to assess audit readiness and identify any blockers before the main audit begins. We define project scope and requirements.

02

Pre-Assessment Review

2-3 days

Initial codebase analysis to understand architecture, identify critical components, and establish priorities. We create a detailed audit plan.

03

Deep Audit Process

Depends on codebase size and complexity

Comprehensive manual code review supported by automated analysis. We test for vulnerabilities, logic errors, and security best practices.

04

Continuous Communication

Ongoing

Regular updates throughout the process. We maintain open communication channels and provide status reports to keep you informed.

05

Fixes Verification

2-3 days

After the initial report, we verify your fixes and re-test the updated code to ensure vulnerabilities have been properly addressed.

06

Final Report & Delivery

1-2 days

Comprehensive report including issue classifications, remediation suggestions, and verification results. Complete transparency guaranteed.

What you receive

  • Comprehensive security analysis
  • Detailed vulnerability report
  • Fix verification and re-testing

Our guarantee

  • 100% transparent process
  • Daily progress updates
  • Expert security team
  • Post-audit support

What You Need to Prepare

To get the most out of your audit, have these ready before kickoff

Feature-frozen smart contract code

No major changes during the audit window

Technical documentation and architecture diagrams

Protocol logic, invariants, and expected behavior

Test suite and coverage reports

Helps us understand expected behavior and coverage gaps

Deployment addresses (if applicable)

Required for on-chain analysis

Known issues or concerns

Share what keeps you up at night. We will dig in.

Codebase access (GitHub, GitLab, or zip)

Private repo access or archive

What's in Your Report

Every audit delivers a comprehensive, publication-ready security report

Report Table of Contents
1

Executive Summary

High-level overview of findings and risk classification

2

Detailed Findings

All issues with severity levels (Critical, High, Medium, Low, Informational)

3

System Overview

Architecture analysis of the audited contracts and components

4

Protocol Risk Assessment

Systemic and design-level risks identified during the audit

5

Documentation Evaluation

Assessment of specification quality and completeness

6

Test Suite Evaluation

Test results, coverage analysis, and recommendations

7

Fix Verification Results

Re-testing results for all remediated findings

What You Receive

Comprehensive documentation for every engagement

Executive Summary

High-level overview of findings for stakeholders

Detailed Findings

All vulnerabilities with severity, impact, and PoC

Fix Verification

Re-test results confirming all remediations

Risk Assessment

Systemic and design-level risk analysis

Start here

Ready to secure your project?

Get a free 30-minute security assessment. We’ll review your codebase scope and flag the top 3 risk areas.

No commitment required · Typical audits start within 1–2 weeks