A data-driven ranking of 100 smart contract auditors for DeFi in 2026, scored on verified client portfolios, in-scope incident history, and audit methodology.

In the high-stakes world of Decentralized Finance (DeFi), security is not just a feature—it's survival. With billions of dollars lost to hacks annually, choosing the right smart contract auditor is the single most critical decision for any project. But how do you distinguish between top-tier security partners and those who simply provide a "stamp of approval"?
This guide answers that question. We’ve moved beyond subjective marketing lists to build a data-driven ranking framework for smart contract auditors. By analyzing post-audit incident rates, DeFi-specific trust scores, and research contributions, we provide a clear, objective hierarchy of the industry's best defenders.
Before diving into the rankings, it's reliable to set expectations. As of 2026, the cost of a professional audit varies significantly based on complexity and scope:
Investing in a quality audit is often a fraction of the cost of a potential exploit.
Our ranking system reflects the priorities of serious DeFi teams, weighing effective security outcomes above all else.
| Category | Weight | Why It Matters |
|---|---|---|
| Post-Audit Incidents | 25% | The Reality Check. Did the code get hacked after they audited it? We count only in-scope exploits — not stolen keys, governance attacks, or bugs introduced after the review — weighted by severity and by how recently they happened, on a hack record current through 2026. Penalties are scaled against how much a firm secures, so one incident sinks a boutique faster than it dents a firm defending tens of billions. A firm that has simply never been tested does not score a perfect 100 — a clean record counts for more the more capital it was earned across. |
| Reputation & TVL | 40% | The Market Vote. Who do the biggest protocols (Uniswap, Aave, Lido) trust with real money? For each firm we take its top-10 DeFi clients by contribution — every one backed by an attributable published report, never a marketing logo — and combine them on a square-root scale, so one genuine multi-billion-dollar engagement outweighs a long tail of micro-caps. Scope credit is three-way: core (1.00) for the contracts that actually custody or route the money, module (0.50) for a bounded sub-component, general (0.25) for a design review, advisory, or competitive-contest engagement. And the TVL counted is the TVL the audited deployment held — reviewing v2 of a protocol does not bank v1's peak. |
| Audit Depth | 15% | The Process. Does the firm use formal verification? Manual review? Multi-engineer teams? Depth matters even more than speed. |
| Transparency | 10% | The Public Record. Clear, public reports and post-mortems build community trust. |
| Research Contribution | 5% | The Innovation. Firms that build tools (like Slither or MythX) and find zero-days push the whole industry forward. |
| Post-Audit Support | 5% | The Long Game. Security doesn't end at deployment. Continuous monitoring and re-audits are key. |
Methodology note (2026 revision). This edition rebuilds the dataset on a consistent, verified footing. Every firm is measured on the same shape of evidence — its top-10 DeFi clients by contribution, plus its full in-scope incident history — rather than whatever happened to be on file. The Trust score uses a square-root curve, so a single mega-protocol no longer counts the same as a tiny one and a long list of small clients cannot out-rank a focused elite firm.
This is a correction, not a refresh. Re-auditing our own scoring engine against every firm's source reports turned up five defects, each of which moved real placements. We are publishing what they were, because a ranking that cannot be audited is worth no more than the marketing lists it replaces.
balancer v2 and Balancer v2 (ComposableStablePool) — was charged twice. Fifteen such pairs existed. Separately, explicit "not chargeable" findings from our own researchers were being ignored whenever the underlying record used a different spelling, leaving a $197M hack charged against a firm we had already established never audited the protocol.Defects 4 and 5 together mean two firms demoted in the previous edition — CertiK and PeckShield — were demoted by our arithmetic rather than their record, and are restored here.
Tiers are relative, not absolute. Rather than a fixed score threshold, a firm's tier is its rank among the firms we can measure:
The board holds 100 firms, by rule rather than by selection: a firm qualifies if it has at least two verified client engagements, or is named by at least two of the protocols we rate. That excludes 59 names in our dataset that carry no measurable engagement at all — single-mention stubs, not firms with thin books.
Two honest caveats about this design. First, a relative scale means a firm's tier can move because a different firm improved, which is a property of any ranking and worth stating plainly. Second, the two cut lines are not equally clean: the Tier 1 line falls on a genuine 2.6-point gap between #10 and #11, while the Tier 2 line falls inside a dense cluster where #30 and #31 are separated by 0.2 — less than the precision of the inputs. Firms ranked in the high twenties and low thirties should be read as one group, not as two tiers.
To see the engine in action, walk through one firm end to end. Take Hashlock — a real firm with a clean in-scope record, ranked #55 on this edition's board. It is a useful example precisely because it is not near a tier line: nothing about its placement is contentious, so the arithmetic is easy to follow.
Here is Hashlock's scored top-10 and the full Trust calculation:
| DeFi client | Peak TVL | Scope credit | Weight | √(TVL) × weight |
|---|---|---|---|---|
| Rocket Pool | $3.17B | Core | 1.00 | 56,323 |
| SatLayer | $385M | Core | 1.00 | 19,627 |
| 1inch | $2.32B | General | 0.25 | 12,042 |
| Aegis (YUSD) | $44M | Core | 1.00 | 6,662 |
| KlimaDAO | $21M | Core | 1.00 | 4,570 |
| Algem | $37M | Module | 0.50 | 3,045 |
| Bucket Protocol | $129M | General | 0.25 | 2,841 |
| Steer Protocol | $59M | General | 0.25 | 1,919 |
| Exactly | $40M | General | 0.25 | 1,578 |
| dTRINITY | $3.6M | General | 0.25 | 474 |
| Weighted √-sum | 109,080 |
That weighted √-sum is then normalized against the deepest portfolio on the board — ChainSecurity, whose weighted √-sum is ≈ 1,269,563 — and scaled to 100:
Trust = 109,080 ÷ 1,269,563 × 100 ≈ 8.6
(The square root is taken on each client's exact peak TVL; the dollar figures are rounded for display, and the √-column is in unitless points — only its ratio to the top firm carries meaning.)
Three design choices do the heavy lifting. The square root is why Rocket Pool's $3.17B doesn't dwarf everything — it turns a 100× TVL gap into roughly a 10× score gap. Max-normalization pins the scale to the single deepest portfolio in the industry, so 8.6 reads as "this verified footprint is about 9% of the largest one we measured". And the three-way scope credit is why 1inch — nominally Hashlock's second-largest client by raw TVL — contributes less than SatLayer, a protocol one-sixth its size: the 1inch work is a general-scope engagement, while SatLayer is core security-of-record.
One row deserves a flag, and flagging it is the point. Rocket Pool is 52% of Hashlock's entire Trust term, and it is booked as core on a reading of the report — nine contract directories including the rETH minting path, commit pinned. But our standing rule is that the client's own audit index outranks the auditor's, and Rocket Pool's index does not name Hashlock. That leg could not be satisfied, so the row is published with the caveat attached rather than quietly counted as verified. It does not change the outcome here — Hashlock is Unranked either way — but on a firm near a tier line, a single unconfirmed row of that size would decide the tier, and we would not publish one.
Weighting all six dimensions together:
Total = 0.25 × 96.9 + 0.40 × 8.6 + 0.15 × 60 + 0.10 × 80 + 0.05 × 40 + 0.05 × 80 = 24.2 + 3.4 + 9.0 + 8.0 + 2.0 + 4.0 ≈ 50.7 → Unranked
Notice the shape of that sum: the clean incident record contributes nearly its full 25 points and the process dimensions add 23 of a possible 35 — it is the Trust dimension, 3.4 points out of an available 40, that decides the placement. For mid-sized firms this is the typical pattern: the 40%-weighted market-vote axis dominates the outcome.
The instructive part is what a TVL-driven score cannot see. Two structural effects routinely hold the Trust dimension below a firm's true footprint: private / NDA engagements never enter the public set, and non-DeFi work is excluded by design — chains, L2s, bridges, wallets and exchanges are outside this board's scope, so a firm doing serious infrastructure security can score low here while being nothing of the sort. So a capable firm with a clean record that specializes in smaller projects, or in infrastructure, will sit lower on this axis — a statement about where its disclosed work falls on the DeFi TVL curve, not about audit quality. This is exactly what the "Different Focus" and "Lack of Public Data" points in our disclaimer are meant to flag.
The chart below splits each Tier 1 score into the weighted contribution of its six dimensions. Note how much of the separation at the top comes from Trust — the 40%-weighted market-vote axis — and how little from the process dimensions, where the leading firms are closely bunched.
The board below is the full ranking — all 100 firms, with every sub-score. Ranks 1–10 are Tier 1, 11–30 Tier 2, and 31–100 Unranked. Select any row to read how that firm's score was reached; search or filter to find a specific one.
Showing 100 of 100 ranked firms. · Select any row to read how the score was reached.
| # | Auditor | Tier | Total | Incidents | Trust | Depth | Transp. | Research | Support | |
|---|---|---|---|---|---|---|---|---|---|---|
| 1 | Certora | Tier 1 | 94.9 | 94 | 91 | 100 | 100 | 100 | 100 | |
Formal-verification house whose Prover and CVL specification language run in the CI of Aave, Morpho, Compound and EigenLayer; the FV layer of record for most of the largest lending and staking protocols. Verified engagements: 10 · Protocols we rate that name it: 31 | ||||||||||
| 2 | ChainSecurity | Tier 1 | 88.9 | 83 | 100 | 80 | 80 | 80 | 80 | |
Swiss-based firm known for high-assurance audits using formal verification, trusted by Aave, MakerDAO, and Uniswap. Verified engagements: 10 · Protocols we rate that name it: 31 | ||||||||||
| 3 | Trail of Bits | Tier 1 | 88.9 | 92 | 80 | 100 | 100 | 100 | 80 | |
Renowned for high-end security research and developing tools like Slither and Echidna, with clients including Algorand and MakerDAO. Verified engagements: 10 · Protocols we rate that name it: 30 | ||||||||||
| 4 | MixBytes | Tier 1 | 83.3 | 97 | 81 | 80 | 80 | 60 | 80 | |
Deep technical experts in DeFi and cross-chain security, auditing Aave, Lido, and Yearn Finance. Verified engagements: 10 · Protocols we rate that name it: 13 | ||||||||||
| 5 | OpenZeppelin | Tier 1 | 82.9 | 97 | 66 | 80 | 100 | 100 | 100 | |
The leading security firm in the industry, famous for the OpenZeppelin Contracts library and auditing major protocols like Aave, Compound, and Coinbase. Verified engagements: 10 · Protocols we rate that name it: 25 | ||||||||||
| 6 | Sigma Prime | Tier 1 | 80.6 | 99 | 69 | 80 | 80 | 80 | 80 | |
Ethereum consensus client experts (Lighthouse team) offering high-assurance audits for the Ethereum Foundation and Chainlink. Verified engagements: 10 · Protocols we rate that name it: 16 | ||||||||||
| 7 | Consensys Diligence | Tier 1 | 78.0 | 94 | 64 | 80 | 80 | 100 | 80 | |
The security arm of Consensys, developing tools like MythX and auditing core infrastructure like ENS and 0x. Verified engagements: 14 · Protocols we rate that name it: 5 | ||||||||||
| 8 | Statemind | Tier 1 | 75.2 | 100 | 56 | 80 | 80 | 80 | 80 | |
A top-tier firm auditing major DeFi protocols like Lido, Yearn, and 1inch, known for discovering critical zero-day exploits. Verified engagements: 10 · Protocols we rate that name it: 9 | ||||||||||
| 9 | Hexens | Tier 1 | 75.1 | 100 | 56 | 80 | 80 | 80 | 80 | |
A cybersecurity boutique auditing complex ecosystems like Polygon zkEVM, Lido, and EigenLayer. Verified engagements: 15 · Protocols we rate that name it: 4 | ||||||||||
| 10 | Spearbit | Tier 1 | 74.3 | 93 | 57 | 80 | 80 | 80 | 80 | |
A decentralized network of top-tier security researchers, connecting projects like Uniswap and OpenSea with specialized experts. Verified engagements: 10 · Protocols we rate that name it: 22 | ||||||||||
| 11 | Ackee Blockchain | Tier 2 | 71.7 | 97 | 46 | 80 | 80 | 100 | 80 | |
Specializes in auditing Ethereum and Solana ecosystems, trusted by top protocols like Lido, Axelar, and Safe. Verified engagements: 10 · Protocols we rate that name it: 8 | ||||||||||
| 12 | Dedaub | Tier 2 | 70.3 | 99 | 42 | 80 | 80 | 100 | 80 | |
Known for deep expertise in static analysis and formal verification, trusted by the Ethereum Foundation, Chainlink, and Uniswap. Verified engagements: 10 · Protocols we rate that name it: 12 | ||||||||||
| 13 | Zellic | Tier 2 | 69.5 | 90 | 47 | 80 | 80 | 80 | 80 | |
Known for auditing complex crypto-native projects like LayerZero and Solana, with a strong background in CTF competitions. Verified engagements: 10 · Protocols we rate that name it: 28 | ||||||||||
| 14 | ABDK Consulting | Tier 2 | 68.7 | 96 | 49 | 60 | 80 | 80 | 80 | |
Cryptography-led Solidity and ZK-circuit auditor (2016), author of the ABDKMath64x64 libraries; 170-client public audit repo, with core-scope reviews of Aave V3 and Uniswap v3-core/v4-core. Verified engagements: 10 · Protocols we rate that name it: 6 | ||||||||||
| 15 | PeckShield | Tier 2 | 68.6 | 85 | 56 | 60 | 80 | 80 | 80 | |
Famous for discovering major vulnerabilities and providing threat intelligence, auditing Aave and EOS. Verified engagements: 10 · Protocols we rate that name it: 17 | ||||||||||
| 16 | Nethermind Security | Tier 2 | 67.7 | 92 | 37 | 100 | 80 | 60 | 80 | |
The security arm of Nethermind, auditing Starknet, Aave, and ensuring correctness of Ethereum clients. Verified engagements: 18 · Protocols we rate that name it: 11 | ||||||||||
| 17 | Quantstamp | Tier 2 | 67.6 | 92 | 54 | 60 | 60 | 80 | 80 | |
A global leader in blockchain security, having secured over $200B in assets for clients like Ethereum 2.0, Solana, and OpenSea. Verified engagements: 10 · Protocols we rate that name it: 35 | ||||||||||
| 18 | Cyfrin | Tier 2 | 66.1 | 89 | 37 | 80 | 80 | 100 | 80 | |
A leading firm focused on education and competitive audits, trusted by Chainlink, Wormhole, and ZKsync. Verified engagements: 10 · Protocols we rate that name it: 9 | ||||||||||
| 19 | Runtime Verification | Tier 2 | 65.9 | 96 | 25 | 100 | 80 | 100 | 80 | |
Formal verification pioneers auditing high-stakes projects like Ethereum 2.0 and Algorand. Verified engagements: 20 · Protocols we rate that name it: 4 | ||||||||||
| 20 | OtterSec | Tier 2 | 65.5 | 93 | 36 | 80 | 80 | 80 | 80 | |
Renowned for auditing Solana and high-performance chains, trusted by Wormhole and Solana Foundation. Verified engagements: 10 · Protocols we rate that name it: 34 | ||||||||||
| 21 | Cantina | Tier 2 | 65.1 | 91 | 49 | 60 | 80 | 40 | 80 | |
A marketplace for security researchers spawned from Spearbit, facilitating audits for Uniswap and Morpho. Verified engagements: 10 · Protocols we rate that name it: 20 | ||||||||||
| 22 | CertiK | Tier 2 | 64.9 | 87 | 46 | 60 | 80 | 80 | 80 | |
A giant in the space known for its leaderboard, formal verification, and Skynet monitoring, auditing Binance and Aave. Verified engagements: 10 · Protocols we rate that name it: 19 | ||||||||||
| 23 | BlockSec | Tier 2 | 64.3 | 99 | 26 | 80 | 80 | 80 | 100 | |
Focuses on full-stack security with real-time monitoring, trusted by 1inch, PancakeSwap, and Matrixport. Verified engagements: 10 · Protocols we rate that name it: 17 | ||||||||||
| 24 | SlowMist | Tier 2 | 63.7 | 97 | 36 | 60 | 80 | 80 | 80 | |
Established security team auditing major exchanges like Binance and OKX, and protocols like PancakeSwap. Verified engagements: 10 · Protocols we rate that name it: 19 | ||||||||||
| 25 | Pashov Audit Group | Tier 2 | 63.1 | 99 | 39 | 60 | 80 | 40 | 80 | |
Researcher-collective boutique run by Krum Pashov; ~50 contest-vetted researchers working in named 3-7 person teams, with 400+ reports published ungated at github.com/pashov/audits, each pinning review and fix commits. Verified engagements: 10 · Protocols we rate that name it: 15 | ||||||||||
| 26 | yAudit | Tier 2 | 62.9 | 93 | 29 | 80 | 80 | 80 | 80 | |
The audit arm of Yearn Finance ecosystem (yAcademy), known for rigorous reviews of DeFi protocols like Curve. Verified engagements: 10 · Protocols we rate that name it: 10 | ||||||||||
| 27 | Neodyme | Tier 2 | 61.6 | 99 | 20 | 80 | 80 | 100 | 80 | |
Security researchers deeply embedded in the Solana ecosystem, auditing widely used Solana lending and staking protocols. Verified engagements: 10 · Protocols we rate that name it: 15 | ||||||||||
| 28 | Guardian | Tier 2 | 61.2 | 96 | 21 | 100 | 80 | 60 | 60 | |
Provides audits for DeFi protocols including GMX and Synthetix, ensuring high-level security standards. Verified engagements: 15 · Protocols we rate that name it: 6 | ||||||||||
| 29 | Offside Labs | Tier 2 | 60.7 | 99 | 20 | 80 | 80 | 80 | 80 | |
Solana-focused offensive security research team (DEF CON / Paradigm CTF lineage, >$9M in bug bounties) that has become the de-facto release-gate auditor for Meteora, Jupiter, Kamino and Jito. Verified engagements: 10 · Protocols we rate that name it: 6 | ||||||||||
| 30 | Informal Systems | Tier 2 | 59.9 | 95 | 10 | 100 | 80 | 100 | 80 | |
Cosmos-native formal-methods firm (Quint, Apalache, Atomkraft) and the standing quarterly auditor of the dYdX Chain; almost all of its book is chain/infra rather than DeFi TVL. Verified engagements: 5 · Protocols we rate that name it: 3 | ||||||||||
| 31 | Recon | Unranked | 59.7 | 96 | 9 | 100 | 80 | 100 | 80 | |
Invariant-testing boutique (Echidna/Medusa/Halmos/Foundry) that ships stateful fuzz suites into client repos alongside manual review; builds the Recon Extension and Chimera framework. Verified engagements: 8 · Protocols we rate that name it: 3 | ||||||||||
| 32 | 0xMacro | Unranked | 59.5 | 99 | 27 | 60 | 80 | 60 | 80 | |
Boutique EVM audit firm behind the Macro Fellowship; ~200 ungated public reports at 0xmacro.com/library, with core-scope reviews of Maple v2, Kodiak, Mento V2, PoolTogether V5 and Level's minting engine. Verified engagements: 10 · Protocols we rate that name it: 3 | ||||||||||
| 33 | Oak Security | Unranked | 59.5 | 88 | 29 | 80 | 80 | 60 | 60 | |
Conducts blinded, independent audits with senior experts, securing major ecosystems like Cosmos and Terra. Verified engagements: 13 · Protocols we rate that name it: 6 | ||||||||||
| 34 | Sec3 | Unranked | 59.3 | 99 | 24 | 60 | 80 | 80 | 80 | |
Solana-specialist audit firm (formerly Soteria, legally Coderrect Inc.); manual review assisted by its in-house Sec3 Scanner/X-Ray, with a public GitHub report index and a post-audit fix review in every engagement. Verified engagements: 10 · Protocols we rate that name it: 17 | ||||||||||
| 35 | Coinspect | Unranked | 58.9 | 97 | 19 | 80 | 80 | 60 | 80 | |
Specializes in auditing smart contracts and zero-knowledge circuits, trusted by Zcash and RSK. Verified engagements: 9 · Protocols we rate that name it: 7 | ||||||||||
| 36 | Omniscia | Unranked | 58.6 | 99 | 17 | 80 | 80 | 60 | 80 | |
High-volume mid-market audit firm (216 clients / 466 engagements in its own public index) whose reports pin commit hashes and per-finding fix status, and which publishes incident post-mortems; DeFi book is mid-cap with a few large core scopes (Euler EVK, Olympus V2). Verified engagements: 16 · Protocols we rate that name it: 6 | ||||||||||
| 37 | Solidified | Unranked | 58.5 | 98 | 27 | 60 | 80 | 40 | 80 | |
One of the oldest Ethereum audit shops (2017), publishing every report since Jan 2018; fixed three-independent-reviewer format. Acquired by Oak Security in Feb 2022 and relaunched as a boutique brand in Nov 2025. Verified engagements: 10 · Protocols we rate that name it: 3 | ||||||||||
| 38 | Halborn | Unranked | 58.2 | 81 | 32 | 60 | 80 | 80 | 80 | |
Elite cybersecurity firm auditing Coinbase, Solana, and Bored Ape Yacht Club, known for deep manual penetration testing. Verified engagements: 10 · Protocols we rate that name it: 35 | ||||||||||
| 39 | Veridise | Unranked | 58.1 | 99 | 14 | 80 | 80 | 80 | 80 | |
Uses automated analysis and formal verification, founded by security researchers, auditing protocols like Aptos and Sui. Verified engagements: 13 · Protocols we rate that name it: 3 | ||||||||||
| 40 | Decurity | Unranked | 58.0 | 98 | 14 | 80 | 80 | 80 | 80 | |
Boutique EVM/Solana audit firm out of an application-security and pentest background, known for PoC-backed reports, the open semgrep-smart-contracts ruleset, and public exploit post-mortems. Verified engagements: 9 · Protocols we rate that name it: 4 | ||||||||||
| 41 | Code4rena | Unranked | 57.1 | 93 | 20 | 80 | 80 | 60 | 60 | |
A leading competitive audit platform (crowdsourced security) where wardens compete to find bugs for top protocols like ENS and OpenSea. Verified engagements: 10 · Protocols we rate that name it: 22 | ||||||||||
| 42 | Salus | Unranked | 56.8 | 98 | 18 | 60 | 80 | 80 | 80 | |
Singapore/China Web3 security boutique with a large public GitHub report index (~290 PDFs, 2022-2026); high-volume checklist-style reviews concentrated in BNB-chain BTCfi, stablecoin and CeDeFi protocols. Verified engagements: 10 · Protocols we rate that name it: 9 | ||||||||||
| 43 | Three Sigma | Unranked | 56.7 | 99 | 15 | 80 | 80 | 60 | 60 | |
Offers comprehensive security services including manual review and fuzzing, working with clients like Maple Finance. Verified engagements: 16 · Protocols we rate that name it: 6 | ||||||||||
| 44 | Zenith | Unranked | 56.1 | 98 | 22 | 60 | 80 | 40 | 80 | |
Private consultative-audit arm of the Code4rena/Zellic group, staffed by top competitive-audit researchers; publishes all 221 reports on GitHub with pinned commits and file-level scope. Verified engagements: 10 · Protocols we rate that name it: 10 | ||||||||||
| 45 | Fuzzland | Unranked | 55.1 | 95 | 6 | 80 | 80 | 100 | 80 | |
Fuzzing-led security firm (Palo Alto, 2022) behind the open-source ItyFuzz hybrid fuzzer; every engagement pairs manual review with Foundry invariants, ItyFuzz and Halmos, plus Blaz+ monitoring. Verified engagements: 10 · Protocols we rate that name it: 2 | ||||||||||
| 46 | Trust Security | Unranked | 55.1 | 95 | 8 | 80 | 80 | 80 | 80 | |
Boutique firm founded by the competitive-audit researcher 'Trust'; ~161 published engagements, senior-only reviewers, strongest on lending/options/staking codebases. Verified engagements: 6 · Protocols we rate that name it: 5 | ||||||||||
| 47 | Least Authority | Unranked | 54.3 | 93 | 5 | 100 | 80 | 60 | 60 | |
Privacy and security-focused firm known for auditing Zcash, Ethereum 2.0, and MetaMask. Verified engagements: 3 · Protocols we rate that name it: 2 | ||||||||||
| 48 | MoveBit | Unranked | 53.2 | 92 | 10 | 80 | 60 | 80 | 80 | |
Specialists in the Move ecosystem (Aptos/Sui), auditing protocols like Thala and integrated by the Move language team. Verified engagements: 10 · Protocols we rate that name it: 4 | ||||||||||
| 49 | Paladin | Unranked | 52.4 | 97 | 15 | 60 | 80 | 40 | 60 | |
High-volume EVM/Move audit shop (269 published engagements, mostly mid-cap AMM, farm and emissions contracts) whose per-project pages list every audited contract by deployed address with a resolution matrix. Verified engagements: 10 · Protocols we rate that name it: 5 | ||||||||||
| 50 | Accretion | Unranked | 52.3 | 98 | 7 | 60 | 80 | 80 | 80 | |
Solana-only audit boutique (Singapore, 2025). All 36 reports public, with pinned fix commits and on-chain build verification; sole auditor of Hylo's live v2 core; original IDL and verified-builds research. Verified engagements: 10 · Protocols we rate that name it: 3 | ||||||||||
| 51 | Composable Security | Unranked | 52.3 | 93 | 10 | 80 | 80 | 40 | 60 | |
DeFi security experts offering tailored audits, working with protocols to secure complex composability interactions. Verified engagements: 5 · Protocols we rate that name it: 0 | ||||||||||
| 52 | WatchPug | Unranked | 52.2 | 97 | 20 | 60 | 60 | 20 | 80 | |
A respected security team conducting meticulous reviews for DeFi projects to enhance privacy and safety. Verified engagements: 10 · Protocols we rate that name it: 8 | ||||||||||
| 53 | Sherlock | Unranked | 52.0 | 86 | 14 | 60 | 100 | 40 | 80 | |
A smart contract audit coverage platform combining audits with bug bounties, trusted by Optimism and Arbitrum. Verified engagements: 10 · Protocols we rate that name it: 27 | ||||||||||
| 54 | CoinFabrik | Unranked | 51.3 | 87 | 9 | 60 | 80 | 100 | 80 | |
Veteran firm since 2014, auditing stacks like RSK and reputable projects in the Bitcoin and Ethereum space. Verified engagements: 9 · Protocols we rate that name it: 4 | ||||||||||
| 55 | Hashlock | Unranked | 50.7 | 97 | 9 | 60 | 80 | 40 | 80 | |
An Australian smart-contract audit firm with a clean (no-major-exploit) record, focused on small- and mid-cap DeFi, RWA, and emerging-chain projects. Verified engagements: 10 · Protocols we rate that name it: 3 | ||||||||||
| 56 | Beosin | Unranked | 50.6 | 97 | 3 | 80 | 60 | 80 | 60 | |
Provides a 'one-stop' blockchain security solution with formal verification, auditing over 3000 smart contracts including PancakeSwap. Verified engagements: 7 · Protocols we rate that name it: 1 | ||||||||||
| 57 | Supremacy | Unranked | 50.2 | 96 | 8 | 60 | 80 | 40 | 80 | |
Small research-driven audit boutique (supremacy.team, @SupremacyHQ) publishing 17 reports for 14 mostly BTCFi / BNB-Chain / Magpie-ecosystem clients; one core engagement, the rest bounded or auditor-indexed. Verified engagements: 9 · Protocols we rate that name it: 1 | ||||||||||
| 58 | Adevar Labs | Unranked | 50.0 | 97 | 7 | 60 | 80 | 40 | 80 | |
Real boutique Solana/Rust-first security firm (not a solo researcher) with its own public report index at github.com/AdevarLabs/audit-reports — 27 dated reports since mid-2025, almost all bounded periphery, adapter and one-chain-deployment scopes. Verified engagements: 12 · Protocols we rate that name it: 2 | ||||||||||
| 59 | SECBIT Labs | Unranked | 48.9 | 95 | 5 | 60 | 60 | 80 | 80 | |
Chinese security and zero-knowledge research lab (batchOverflow / proxyOverflow CVE disclosures, 2018) that has been the standing release-gate auditor of the AladdinDAO family — Concentrator, CLever and f(x) Protocol — since 2022. Verified engagements: 5 · Protocols we rate that name it: 4 | ||||||||||
| 60 | HashEx | Unranked | 48.0 | 90 | 14 | 60 | 60 | 40 | 60 | |
Experienced firm since 2017, securing over $4B in assets for projects like SafeMoon and Trader Joe. Verified engagements: 10 · Protocols we rate that name it: 0 | ||||||||||
| 61 | Verilog Solutions | Unranked | 47.7 | 99 | 7 | 60 | 60 | 40 | 60 | |
Full-stack Web3 security firm working with WOOFi, Gnosis, and BendDAO, focusing on continuous security. Verified engagements: 10 · Protocols we rate that name it: 0 | ||||||||||
| 62 | Hacken | Unranked | 46.8 | 73 | 9 | 60 | 80 | 80 | 80 | |
A major cybersecurity auditor with a broad portfolio including 1inch and Gate.io, offering a wide range of security services. Verified engagements: 6 · Protocols we rate that name it: 9 | ||||||||||
| 63 | Kudelski | Unranked | 46.5 | 86 | 3 | 60 | 80 | 80 | 60 | |
Global security leader providing blockchain audits for Binance, Solana, and Ledger. Verified engagements: 8 · Protocols we rate that name it: 12 | ||||||||||
| 64 | Zokyo | Unranked | 46.3 | 83 | 12 | 40 | 80 | 60 | 80 | |
Venture-backed security firm auditing IOTA and offering comprehensive security and crypto-economics reviews. Verified engagements: 12 · Protocols we rate that name it: 4 | ||||||||||
| 65 | KALOS | Unranked | 46.1 | 76 | 8 | 80 | 60 | 60 | 60 | |
Formerly Haechi Audit's service, having secured over $60B in assets for clients like 1inch and Klaytn. Verified engagements: 9 · Protocols we rate that name it: 0 | ||||||||||
| 66 | Team Omega | Unranked | 45.4 | 91 | 7 | 60 | 60 | 40 | 60 | |
Focuses on hands-on solidity audits for various DAOs and DeFi protocols. Verified engagements: 8 · Protocols we rate that name it: 0 | ||||||||||
| 67 | SmartState | Unranked | 45.2 | 95 | 4 | 60 | 60 | 40 | 60 | |
Provides thorough manual and automated audits, securing projects like DAO Maker and Safle. Verified engagements: 6 · Protocols we rate that name it: 1 | ||||||||||
| 68 | Blaize.Security | Unranked | 45.0 | 95 | 3 | 60 | 60 | 40 | 60 | |
Offers comprehensive blockchain security and development services, auditing projects like LiquidAccess. Verified engagements: 6 · Protocols we rate that name it: 1 | ||||||||||
| 69 | Resonance Security | Unranked | 44.9 | 96 | 2 | 60 | 60 | 40 | 60 | |
Offers full-spectrum cybersecurity including audits and offensive security, working with various EVM and Cosmos chains. Verified engagements: 7 · Protocols we rate that name it: 2 | ||||||||||
| 70 | BlockApex | Unranked | 44.6 | 97 | 1 | 60 | 60 | 40 | 60 | |
Specializes in EVM and Rust audits, employing static analysis and manual review for clients in DeFi and NFT sectors. Verified engagements: 8 · Protocols we rate that name it: 1 | ||||||||||
| 71 | Hats Finance | Unranked | 44.0 | 97 | 5 | 40 | 80 | 40 | 40 | |
A decentralized bug bounty and audit protocol, allowing projects like Hopr to crowdsource security. Verified engagements: 12 · Protocols we rate that name it: 3 | ||||||||||
| 72 | ScaleBit | Unranked | 44.0 | 82 | 6 | 60 | 60 | 60 | 60 | |
Sub-brand of BitsLab focusing on ZK and blockchain security, exploring emerging ecosystems. Verified engagements: 10 · Protocols we rate that name it: 7 | ||||||||||
| 73 | Immunefi | Unranked | 43.9 | 92 | 5 | 40 | 80 | 60 | 40 | |
Bug-bounty and audit-competition marketplace, not an audit firm: it brokers and judges crowdsourced competitions between independent researchers and performs no review of its own. Verified engagements: 10 · Protocols we rate that name it: 3 | ||||||||||
| 74 | Bramah Systems | Unranked | 43.1 | 82 | 11 | 60 | 60 | 20 | 40 | |
Specialized security firm known for high-quality reviews of complex DeFi protocols. Verified engagements: 8 · Protocols we rate that name it: 1 | ||||||||||
| 75 | Chaos Labs | Unranked | 43.1 | 90 | 12 | 40 | 40 | 60 | 60 | |
Economic-risk and risk-parameter firm — agent-based simulation, DAO parameter mandates, risk dashboards and its own price/risk oracles; it performs no source-level code audits, so every engagement is General under §2. Verified engagements: 7 · Protocols we rate that name it: 4 | ||||||||||
| 76 | Secure3 | Unranked | 42.2 | 86 | 2 | 60 | 60 | 40 | 60 | |
Audit-CONTEST marketplace — sponsors post a reward pool and certified independent auditors compete on findings; confirmed by reading a report whose every finding is credited to a named competing warden. Verified engagements: 5 · Protocols we rate that name it: 4 | ||||||||||
| 77 | 0xGuard | Unranked | 42.1 | 95 | 1 | 40 | 80 | 20 | 60 | |
Provides manual and automated audits, securing various DeFi and NFT projects with a focus on comprehensive reporting. Verified engagements: 6 · Protocols we rate that name it: 0 | ||||||||||
| 78 | Verichains | Unranked | 42.1 | 66 | 4 | 80 | 60 | 60 | 60 | |
APAC-leading security firm auditing Axie Infinity and BNB Chain, known for discovering key vulnerabilities. Verified engagements: 6 · Protocols we rate that name it: 0 | ||||||||||
| 79 | Pessimistic | Unranked | 42.0 | 80 | 0 | 60 | 60 | 80 | 60 | |
Named by 2 of the protocols we rate, but no engagement of its own has been verified yet, so its Trust term is unscored. It sits on the board to keep the denominator honest, not as a judgement of quality. Verified engagements: 0 · Protocols we rate that name it: 2 | ||||||||||
| 80 | Monethic | Unranked | 41.2 | 84 | 0 | 60 | 60 | 40 | 60 | |
Provides cybersecurity services including smart contract audits and penetration testing for DeFi and Web3. Verified engagements: 2 · Protocols we rate that name it: 0 | ||||||||||
| 81 | ShellBoxes | Unranked | 39.3 | 95 | 1 | 40 | 60 | 20 | 40 | |
Offers audits for Solidity, Rust, and Go contracts, securing projects on BSC and other chains. Verified engagements: 6 · Protocols we rate that name it: 0 | ||||||||||
| 82 | Sub7 Security | Unranked | 39.2 | 85 | 0 | 60 | 60 | 20 | 40 | |
Luxembourg-based firm checking smart contracts and dApps for vulnerabilities using advanced tools. Verified engagements: 2 · Protocols we rate that name it: 0 | ||||||||||
| 83 | Arcadia Group | Unranked | 38.0 | 81 | 4 | 60 | 40 | 20 | 40 | |
Blockchain software and security consultancy auditing projects like Charged Particles. Verified engagements: 6 · Protocols we rate that name it: 0 | ||||||||||
| 84 | Kupia Security | Unranked | 37.6 | 83 | 10 | 40 | 40 | 20 | 40 | |
Audited Ethena and other DeFi protocols, focusing on preventing sophisticated exploits. Verified engagements: 10 · Protocols we rate that name it: 0 | ||||||||||
| 85 | Solidity Finance | Unranked | 37.3 | 49 | 3 | 60 | 100 | 40 | 60 | |
High-volume auditor for community projects, having secured over $10B for 1000+ projects. Verified engagements: 3 · Protocols we rate that name it: 0 | ||||||||||
| 86 | Armors | Unranked | 36.3 | 81 | 3 | 40 | 60 | 20 | 40 | |
Blockchain security provider auditing over 1000 projects, partnering with major exchanges for ecosystem security. Verified engagements: 4 · Protocols we rate that name it: 0 | ||||||||||
| 87 | Obelisk | Unranked | 33.9 | 82 | 1 | 40 | 40 | 20 | 40 | |
Conducted audits for projects like Gravity Finance, ensuring protocol integrity. Verified engagements: 4 · Protocols we rate that name it: 0 | ||||||||||
| 88 | Egis Security | Unranked | 32.7 | 77 | 2 | 40 | 40 | 20 | 40 | |
Security firm auditing projects like Sablier and providing library assessments. Verified engagements: 5 · Protocols we rate that name it: 0 | ||||||||||
| 89 | Electi | Unranked | 31.6 | 81 | 28 | 0 | 0 | 0 | 0 | |
Technology and innovation firm offering blockchain audits and consulting services. Verified engagements: 10 · Protocols we rate that name it: 0 | ||||||||||
| 90 | Techrate | Unranked | 31.4 | 61 | 1 | 40 | 60 | 20 | 60 | |
Known for providing accessible audit services and quick turnaround for a vast number of tokens and DeFi projects. Verified engagements: 2 · Protocols we rate that name it: 0 | ||||||||||
| 91 | Haechi | Unranked | 30.8 | 91 | 20 | 0 | 0 | 0 | 0 | |
Top Korean audit firm (now KALOS), having audited 1inch, Klaytn, and Badger DAO. Verified engagements: 10 · Protocols we rate that name it: 0 | ||||||||||
| 92 | Asymptotic | Unranked | 20.0 | 80 | 0 | 0 | 0 | 0 | 0 | |
Named by 2 of the protocols we rate, but no engagement of its own has been verified yet, so its Trust term is unscored. It sits on the board to keep the denominator honest, not as a judgement of quality. Verified engagements: 0 · Protocols we rate that name it: 2 | ||||||||||
| 93 | Bailsec | Unranked | 20.0 | 80 | 0 | 0 | 0 | 0 | 0 | |
Named by 2 of the protocols we rate, but no engagement of its own has been verified yet, so its Trust term is unscored. It sits on the board to keep the denominator honest, not as a judgement of quality. Verified engagements: 0 · Protocols we rate that name it: 2 | ||||||||||
| 94 | CodeHawks | Unranked | 20.0 | 80 | 0 | 0 | 0 | 0 | 0 | |
Named by 2 of the protocols we rate, but no engagement of its own has been verified yet, so its Trust term is unscored. It sits on the board to keep the denominator honest, not as a judgement of quality. Verified engagements: 0 · Protocols we rate that name it: 2 | ||||||||||
| 95 | FYEO | Unranked | 20.0 | 80 | 0 | 0 | 0 | 0 | 0 | |
Named by 2 of the protocols we rate, but no engagement of its own has been verified yet, so its Trust term is unscored. It sits on the board to keep the denominator honest, not as a judgement of quality. Verified engagements: 0 · Protocols we rate that name it: 2 | ||||||||||
| 96 | iosiro | Unranked | 20.0 | 80 | 0 | 0 | 0 | 0 | 0 | |
Named by 2 of the protocols we rate, but no engagement of its own has been verified yet, so its Trust term is unscored. It sits on the board to keep the denominator honest, not as a judgement of quality. Verified engagements: 0 · Protocols we rate that name it: 2 | ||||||||||
| 97 | NCC Group | Unranked | 20.0 | 80 | 0 | 0 | 0 | 0 | 0 | |
Named by 2 of the protocols we rate, but no engagement of its own has been verified yet, so its Trust term is unscored. It sits on the board to keep the denominator honest, not as a judgement of quality. Verified engagements: 0 · Protocols we rate that name it: 2 | ||||||||||
| 98 | Obsidian | Unranked | 20.0 | 80 | 0 | 0 | 0 | 0 | 0 | |
Named by 2 of the protocols we rate, but no engagement of its own has been verified yet, so its Trust term is unscored. It sits on the board to keep the denominator honest, not as a judgement of quality. Verified engagements: 0 · Protocols we rate that name it: 2 | ||||||||||
| 99 | Offbeat Security | Unranked | 20.0 | 80 | 0 | 0 | 0 | 0 | 0 | |
Named by 2 of the protocols we rate, but no engagement of its own has been verified yet, so its Trust term is unscored. It sits on the board to keep the denominator honest, not as a judgement of quality. Verified engagements: 0 · Protocols we rate that name it: 2 | ||||||||||
| 100 | Zach Obront | Unranked | 20.0 | 80 | 0 | 0 | 0 | 0 | 0 | |
Named by 2 of the protocols we rate, but no engagement of its own has been verified yet, so its Trust term is unscored. It sits on the board to keep the denominator honest, not as a judgement of quality. Verified engagements: 0 · Protocols we rate that name it: 2 | ||||||||||
Formal-verification house whose Prover and CVL specification language run in the CI of Aave, Morpho, Compound and EigenLayer; the FV layer of record for most of the largest lending and staking protocols.
Verified engagements: 10 · Protocols we rate that name it: 31
Swiss-based firm known for high-assurance audits using formal verification, trusted by Aave, MakerDAO, and Uniswap.
Verified engagements: 10 · Protocols we rate that name it: 31
Renowned for high-end security research and developing tools like Slither and Echidna, with clients including Algorand and MakerDAO.
Verified engagements: 10 · Protocols we rate that name it: 30
Deep technical experts in DeFi and cross-chain security, auditing Aave, Lido, and Yearn Finance.
Verified engagements: 10 · Protocols we rate that name it: 13
The leading security firm in the industry, famous for the OpenZeppelin Contracts library and auditing major protocols like Aave, Compound, and Coinbase.
Verified engagements: 10 · Protocols we rate that name it: 25
Ethereum consensus client experts (Lighthouse team) offering high-assurance audits for the Ethereum Foundation and Chainlink.
Verified engagements: 10 · Protocols we rate that name it: 16
The security arm of Consensys, developing tools like MythX and auditing core infrastructure like ENS and 0x.
Verified engagements: 14 · Protocols we rate that name it: 5
A top-tier firm auditing major DeFi protocols like Lido, Yearn, and 1inch, known for discovering critical zero-day exploits.
Verified engagements: 10 · Protocols we rate that name it: 9
A cybersecurity boutique auditing complex ecosystems like Polygon zkEVM, Lido, and EigenLayer.
Verified engagements: 15 · Protocols we rate that name it: 4
A decentralized network of top-tier security researchers, connecting projects like Uniswap and OpenSea with specialized experts.
Verified engagements: 10 · Protocols we rate that name it: 22
Specializes in auditing Ethereum and Solana ecosystems, trusted by top protocols like Lido, Axelar, and Safe.
Verified engagements: 10 · Protocols we rate that name it: 8
Known for deep expertise in static analysis and formal verification, trusted by the Ethereum Foundation, Chainlink, and Uniswap.
Verified engagements: 10 · Protocols we rate that name it: 12
Known for auditing complex crypto-native projects like LayerZero and Solana, with a strong background in CTF competitions.
Verified engagements: 10 · Protocols we rate that name it: 28
Cryptography-led Solidity and ZK-circuit auditor (2016), author of the ABDKMath64x64 libraries; 170-client public audit repo, with core-scope reviews of Aave V3 and Uniswap v3-core/v4-core.
Verified engagements: 10 · Protocols we rate that name it: 6
Famous for discovering major vulnerabilities and providing threat intelligence, auditing Aave and EOS.
Verified engagements: 10 · Protocols we rate that name it: 17
The security arm of Nethermind, auditing Starknet, Aave, and ensuring correctness of Ethereum clients.
Verified engagements: 18 · Protocols we rate that name it: 11
A global leader in blockchain security, having secured over $200B in assets for clients like Ethereum 2.0, Solana, and OpenSea.
Verified engagements: 10 · Protocols we rate that name it: 35
A leading firm focused on education and competitive audits, trusted by Chainlink, Wormhole, and ZKsync.
Verified engagements: 10 · Protocols we rate that name it: 9
Formal verification pioneers auditing high-stakes projects like Ethereum 2.0 and Algorand.
Verified engagements: 20 · Protocols we rate that name it: 4
Renowned for auditing Solana and high-performance chains, trusted by Wormhole and Solana Foundation.
Verified engagements: 10 · Protocols we rate that name it: 34
A marketplace for security researchers spawned from Spearbit, facilitating audits for Uniswap and Morpho.
Verified engagements: 10 · Protocols we rate that name it: 20
A giant in the space known for its leaderboard, formal verification, and Skynet monitoring, auditing Binance and Aave.
Verified engagements: 10 · Protocols we rate that name it: 19
Focuses on full-stack security with real-time monitoring, trusted by 1inch, PancakeSwap, and Matrixport.
Verified engagements: 10 · Protocols we rate that name it: 17
Established security team auditing major exchanges like Binance and OKX, and protocols like PancakeSwap.
Verified engagements: 10 · Protocols we rate that name it: 19
Researcher-collective boutique run by Krum Pashov; ~50 contest-vetted researchers working in named 3-7 person teams, with 400+ reports published ungated at github.com/pashov/audits, each pinning review and fix commits.
Verified engagements: 10 · Protocols we rate that name it: 15
The audit arm of Yearn Finance ecosystem (yAcademy), known for rigorous reviews of DeFi protocols like Curve.
Verified engagements: 10 · Protocols we rate that name it: 10
Security researchers deeply embedded in the Solana ecosystem, auditing widely used Solana lending and staking protocols.
Verified engagements: 10 · Protocols we rate that name it: 15
Provides audits for DeFi protocols including GMX and Synthetix, ensuring high-level security standards.
Verified engagements: 15 · Protocols we rate that name it: 6
Solana-focused offensive security research team (DEF CON / Paradigm CTF lineage, >$9M in bug bounties) that has become the de-facto release-gate auditor for Meteora, Jupiter, Kamino and Jito.
Verified engagements: 10 · Protocols we rate that name it: 6
Cosmos-native formal-methods firm (Quint, Apalache, Atomkraft) and the standing quarterly auditor of the dYdX Chain; almost all of its book is chain/infra rather than DeFi TVL.
Verified engagements: 5 · Protocols we rate that name it: 3
Invariant-testing boutique (Echidna/Medusa/Halmos/Foundry) that ships stateful fuzz suites into client repos alongside manual review; builds the Recon Extension and Chimera framework.
Verified engagements: 8 · Protocols we rate that name it: 3
Boutique EVM audit firm behind the Macro Fellowship; ~200 ungated public reports at 0xmacro.com/library, with core-scope reviews of Maple v2, Kodiak, Mento V2, PoolTogether V5 and Level's minting engine.
Verified engagements: 10 · Protocols we rate that name it: 3
Conducts blinded, independent audits with senior experts, securing major ecosystems like Cosmos and Terra.
Verified engagements: 13 · Protocols we rate that name it: 6
Solana-specialist audit firm (formerly Soteria, legally Coderrect Inc.); manual review assisted by its in-house Sec3 Scanner/X-Ray, with a public GitHub report index and a post-audit fix review in every engagement.
Verified engagements: 10 · Protocols we rate that name it: 17
Specializes in auditing smart contracts and zero-knowledge circuits, trusted by Zcash and RSK.
Verified engagements: 9 · Protocols we rate that name it: 7
High-volume mid-market audit firm (216 clients / 466 engagements in its own public index) whose reports pin commit hashes and per-finding fix status, and which publishes incident post-mortems; DeFi book is mid-cap with a few large core scopes (Euler EVK, Olympus V2).
Verified engagements: 16 · Protocols we rate that name it: 6
One of the oldest Ethereum audit shops (2017), publishing every report since Jan 2018; fixed three-independent-reviewer format. Acquired by Oak Security in Feb 2022 and relaunched as a boutique brand in Nov 2025.
Verified engagements: 10 · Protocols we rate that name it: 3
Elite cybersecurity firm auditing Coinbase, Solana, and Bored Ape Yacht Club, known for deep manual penetration testing.
Verified engagements: 10 · Protocols we rate that name it: 35
Uses automated analysis and formal verification, founded by security researchers, auditing protocols like Aptos and Sui.
Verified engagements: 13 · Protocols we rate that name it: 3
Boutique EVM/Solana audit firm out of an application-security and pentest background, known for PoC-backed reports, the open semgrep-smart-contracts ruleset, and public exploit post-mortems.
Verified engagements: 9 · Protocols we rate that name it: 4
A leading competitive audit platform (crowdsourced security) where wardens compete to find bugs for top protocols like ENS and OpenSea.
Verified engagements: 10 · Protocols we rate that name it: 22
Singapore/China Web3 security boutique with a large public GitHub report index (~290 PDFs, 2022-2026); high-volume checklist-style reviews concentrated in BNB-chain BTCfi, stablecoin and CeDeFi protocols.
Verified engagements: 10 · Protocols we rate that name it: 9
Offers comprehensive security services including manual review and fuzzing, working with clients like Maple Finance.
Verified engagements: 16 · Protocols we rate that name it: 6
Private consultative-audit arm of the Code4rena/Zellic group, staffed by top competitive-audit researchers; publishes all 221 reports on GitHub with pinned commits and file-level scope.
Verified engagements: 10 · Protocols we rate that name it: 10
Fuzzing-led security firm (Palo Alto, 2022) behind the open-source ItyFuzz hybrid fuzzer; every engagement pairs manual review with Foundry invariants, ItyFuzz and Halmos, plus Blaz+ monitoring.
Verified engagements: 10 · Protocols we rate that name it: 2
Boutique firm founded by the competitive-audit researcher 'Trust'; ~161 published engagements, senior-only reviewers, strongest on lending/options/staking codebases.
Verified engagements: 6 · Protocols we rate that name it: 5
Privacy and security-focused firm known for auditing Zcash, Ethereum 2.0, and MetaMask.
Verified engagements: 3 · Protocols we rate that name it: 2
Specialists in the Move ecosystem (Aptos/Sui), auditing protocols like Thala and integrated by the Move language team.
Verified engagements: 10 · Protocols we rate that name it: 4
High-volume EVM/Move audit shop (269 published engagements, mostly mid-cap AMM, farm and emissions contracts) whose per-project pages list every audited contract by deployed address with a resolution matrix.
Verified engagements: 10 · Protocols we rate that name it: 5
Solana-only audit boutique (Singapore, 2025). All 36 reports public, with pinned fix commits and on-chain build verification; sole auditor of Hylo's live v2 core; original IDL and verified-builds research.
Verified engagements: 10 · Protocols we rate that name it: 3
DeFi security experts offering tailored audits, working with protocols to secure complex composability interactions.
Verified engagements: 5 · Protocols we rate that name it: 0
A respected security team conducting meticulous reviews for DeFi projects to enhance privacy and safety.
Verified engagements: 10 · Protocols we rate that name it: 8
A smart contract audit coverage platform combining audits with bug bounties, trusted by Optimism and Arbitrum.
Verified engagements: 10 · Protocols we rate that name it: 27
Veteran firm since 2014, auditing stacks like RSK and reputable projects in the Bitcoin and Ethereum space.
Verified engagements: 9 · Protocols we rate that name it: 4
An Australian smart-contract audit firm with a clean (no-major-exploit) record, focused on small- and mid-cap DeFi, RWA, and emerging-chain projects.
Verified engagements: 10 · Protocols we rate that name it: 3
Provides a 'one-stop' blockchain security solution with formal verification, auditing over 3000 smart contracts including PancakeSwap.
Verified engagements: 7 · Protocols we rate that name it: 1
Small research-driven audit boutique (supremacy.team, @SupremacyHQ) publishing 17 reports for 14 mostly BTCFi / BNB-Chain / Magpie-ecosystem clients; one core engagement, the rest bounded or auditor-indexed.
Verified engagements: 9 · Protocols we rate that name it: 1
Real boutique Solana/Rust-first security firm (not a solo researcher) with its own public report index at github.com/AdevarLabs/audit-reports — 27 dated reports since mid-2025, almost all bounded periphery, adapter and one-chain-deployment scopes.
Verified engagements: 12 · Protocols we rate that name it: 2
Chinese security and zero-knowledge research lab (batchOverflow / proxyOverflow CVE disclosures, 2018) that has been the standing release-gate auditor of the AladdinDAO family — Concentrator, CLever and f(x) Protocol — since 2022.
Verified engagements: 5 · Protocols we rate that name it: 4
Experienced firm since 2017, securing over $4B in assets for projects like SafeMoon and Trader Joe.
Verified engagements: 10 · Protocols we rate that name it: 0
Full-stack Web3 security firm working with WOOFi, Gnosis, and BendDAO, focusing on continuous security.
Verified engagements: 10 · Protocols we rate that name it: 0
A major cybersecurity auditor with a broad portfolio including 1inch and Gate.io, offering a wide range of security services.
Verified engagements: 6 · Protocols we rate that name it: 9
Global security leader providing blockchain audits for Binance, Solana, and Ledger.
Verified engagements: 8 · Protocols we rate that name it: 12
Venture-backed security firm auditing IOTA and offering comprehensive security and crypto-economics reviews.
Verified engagements: 12 · Protocols we rate that name it: 4
Formerly Haechi Audit's service, having secured over $60B in assets for clients like 1inch and Klaytn.
Verified engagements: 9 · Protocols we rate that name it: 0
Focuses on hands-on solidity audits for various DAOs and DeFi protocols.
Verified engagements: 8 · Protocols we rate that name it: 0
Provides thorough manual and automated audits, securing projects like DAO Maker and Safle.
Verified engagements: 6 · Protocols we rate that name it: 1
Offers comprehensive blockchain security and development services, auditing projects like LiquidAccess.
Verified engagements: 6 · Protocols we rate that name it: 1
Offers full-spectrum cybersecurity including audits and offensive security, working with various EVM and Cosmos chains.
Verified engagements: 7 · Protocols we rate that name it: 2
Specializes in EVM and Rust audits, employing static analysis and manual review for clients in DeFi and NFT sectors.
Verified engagements: 8 · Protocols we rate that name it: 1
A decentralized bug bounty and audit protocol, allowing projects like Hopr to crowdsource security.
Verified engagements: 12 · Protocols we rate that name it: 3
Sub-brand of BitsLab focusing on ZK and blockchain security, exploring emerging ecosystems.
Verified engagements: 10 · Protocols we rate that name it: 7
Bug-bounty and audit-competition marketplace, not an audit firm: it brokers and judges crowdsourced competitions between independent researchers and performs no review of its own.
Verified engagements: 10 · Protocols we rate that name it: 3
Specialized security firm known for high-quality reviews of complex DeFi protocols.
Verified engagements: 8 · Protocols we rate that name it: 1
Economic-risk and risk-parameter firm — agent-based simulation, DAO parameter mandates, risk dashboards and its own price/risk oracles; it performs no source-level code audits, so every engagement is General under §2.
Verified engagements: 7 · Protocols we rate that name it: 4
Audit-CONTEST marketplace — sponsors post a reward pool and certified independent auditors compete on findings; confirmed by reading a report whose every finding is credited to a named competing warden.
Verified engagements: 5 · Protocols we rate that name it: 4
Provides manual and automated audits, securing various DeFi and NFT projects with a focus on comprehensive reporting.
Verified engagements: 6 · Protocols we rate that name it: 0
APAC-leading security firm auditing Axie Infinity and BNB Chain, known for discovering key vulnerabilities.
Verified engagements: 6 · Protocols we rate that name it: 0
Named by 2 of the protocols we rate, but no engagement of its own has been verified yet, so its Trust term is unscored. It sits on the board to keep the denominator honest, not as a judgement of quality.
Verified engagements: 0 · Protocols we rate that name it: 2
Provides cybersecurity services including smart contract audits and penetration testing for DeFi and Web3.
Verified engagements: 2 · Protocols we rate that name it: 0
Offers audits for Solidity, Rust, and Go contracts, securing projects on BSC and other chains.
Verified engagements: 6 · Protocols we rate that name it: 0
Luxembourg-based firm checking smart contracts and dApps for vulnerabilities using advanced tools.
Verified engagements: 2 · Protocols we rate that name it: 0
Blockchain software and security consultancy auditing projects like Charged Particles.
Verified engagements: 6 · Protocols we rate that name it: 0
Audited Ethena and other DeFi protocols, focusing on preventing sophisticated exploits.
Verified engagements: 10 · Protocols we rate that name it: 0
High-volume auditor for community projects, having secured over $10B for 1000+ projects.
Verified engagements: 3 · Protocols we rate that name it: 0
Blockchain security provider auditing over 1000 projects, partnering with major exchanges for ecosystem security.
Verified engagements: 4 · Protocols we rate that name it: 0
Conducted audits for projects like Gravity Finance, ensuring protocol integrity.
Verified engagements: 4 · Protocols we rate that name it: 0
Security firm auditing projects like Sablier and providing library assessments.
Verified engagements: 5 · Protocols we rate that name it: 0
Technology and innovation firm offering blockchain audits and consulting services.
Verified engagements: 10 · Protocols we rate that name it: 0
Known for providing accessible audit services and quick turnaround for a vast number of tokens and DeFi projects.
Verified engagements: 2 · Protocols we rate that name it: 0
Top Korean audit firm (now KALOS), having audited 1inch, Klaytn, and Badger DAO.
Verified engagements: 10 · Protocols we rate that name it: 0
Named by 2 of the protocols we rate, but no engagement of its own has been verified yet, so its Trust term is unscored. It sits on the board to keep the denominator honest, not as a judgement of quality.
Verified engagements: 0 · Protocols we rate that name it: 2
Named by 2 of the protocols we rate, but no engagement of its own has been verified yet, so its Trust term is unscored. It sits on the board to keep the denominator honest, not as a judgement of quality.
Verified engagements: 0 · Protocols we rate that name it: 2
Named by 2 of the protocols we rate, but no engagement of its own has been verified yet, so its Trust term is unscored. It sits on the board to keep the denominator honest, not as a judgement of quality.
Verified engagements: 0 · Protocols we rate that name it: 2
Named by 2 of the protocols we rate, but no engagement of its own has been verified yet, so its Trust term is unscored. It sits on the board to keep the denominator honest, not as a judgement of quality.
Verified engagements: 0 · Protocols we rate that name it: 2
Named by 2 of the protocols we rate, but no engagement of its own has been verified yet, so its Trust term is unscored. It sits on the board to keep the denominator honest, not as a judgement of quality.
Verified engagements: 0 · Protocols we rate that name it: 2
Named by 2 of the protocols we rate, but no engagement of its own has been verified yet, so its Trust term is unscored. It sits on the board to keep the denominator honest, not as a judgement of quality.
Verified engagements: 0 · Protocols we rate that name it: 2
Named by 2 of the protocols we rate, but no engagement of its own has been verified yet, so its Trust term is unscored. It sits on the board to keep the denominator honest, not as a judgement of quality.
Verified engagements: 0 · Protocols we rate that name it: 2
Named by 2 of the protocols we rate, but no engagement of its own has been verified yet, so its Trust term is unscored. It sits on the board to keep the denominator honest, not as a judgement of quality.
Verified engagements: 0 · Protocols we rate that name it: 2
Named by 2 of the protocols we rate, but no engagement of its own has been verified yet, so its Trust term is unscored. It sits on the board to keep the denominator honest, not as a judgement of quality.
Verified engagements: 0 · Protocols we rate that name it: 2
Tier 1 — the top 10% of the 100 firms we can measure: Certora, ChainSecurity, Trail of Bits, MixBytes, OpenZeppelin, Sigma Prime, ConsenSys Diligence, Statemind, Hexens and Spearbit. These are the firms that pair clean or well-contained incident records with deep portfolios of large, independently verified core engagements.
Certora tops the table on a distinctive profile: it is the only firm scoring full marks on all four process dimensions, and its footprint comes from being embedded in protocols rather than visiting them — its formal-verification specs live inside the repositories of Aave, EigenLayer, Morpho and Compound and run in their CI, and Lido's own audit index carries seven Certora reports.
The most useful thing in this edition may be the firms that moved for reasons that were our fault, not theirs. CertiK and PeckShield were demoted in the previous edition on incident scores that double-counted hacks and decayed them on the wrong axis; corrected, both return to Tier 2, and both hold that position even under the harshest assumption we tested — every incident charged at full weight, forever, with no decay at all. Their hack histories are still what keeps them out of Tier 1, but the size of that penalty was overstated.
Moving the other way, three firms that would have entered Tier 2 on last edition's arithmetic did not survive the attributable-TVL rule: a firm that audited a protocol's StarkNet deployment cannot bank its Ethereum peak, a firm that reviewed v2 cannot bank v1's, and a protocol reporting staked governance token rather than secured capital does not contribute that figure at all. In each case the firm's own researcher had flagged the row and asked for the ruling. Being able to name the rows that decided a tier — and to publish the ones that went against the firm — is the point of the exercise.
Below the top tier sit many genuine specialists whose placement reflects where their disclosed work falls on the DeFi TVL curve, not their quality: BlockSec for real-time monitoring, OtterSec and Offside Labs for Solana, Informal Systems for Cosmos formal methods, Nethermind and Veridise for zero-knowledge systems, and a long tail of boutiques with narrow but solid books. Several of them do high-stakes chain and L2 work that this DeFi-weighted board excludes by construction. Read the tier as an answer to one specific question — who has repeatedly been trusted with large amounts of DeFi TVL and not lost it? — and nothing more.
This ranking is for informational purposes only and is specifically tailored to Decentralized Finance (DeFi) smart contract audits.
DeFi Sentinel's September 2026 ranking scores 100 audit firms and places ten in Tier 1 — the top 10%: Certora, ChainSecurity, Trail of Bits, MixBytes, OpenZeppelin, Sigma Prime, ConsenSys Diligence, Statemind, Hexens and Spearbit. Each combines a deep portfolio of verified core-scope engagements at large DeFi protocols with a clean or well-contained record of in-scope post-audit exploits.
Six weighted dimensions: reputation and TVL (40% — the verified top-10 DeFi clients by contribution, on a square-root scale, with three-way scope credit for core, module or general work), post-audit incidents (25% — in-scope exploits only, weighted by severity and by how recently they happened), audit depth (15%), transparency (10%), research contribution (5%) and post-audit support (5%). Tiers are relative, not absolute: Tier 1 is the top 10% of the 100 firms on the board and Tier 2 the next 20%.
No. An audit is a point-in-time review of a specific commit. Code routinely changes after the audit, and even the best firms have a non-zero post-audit incident rate. A clean audit from a top-tier firm reduces risk significantly but never eliminates it — treat it as one strong signal among many, not as proof of safety.
Three structural reasons: tight engagement windows that limit deep economic-model analysis; novel vulnerabilities that don't match any known pattern; and protocol code that depends on external systems — oracles, bridges, other protocols — whose interactions are out of scope. The hardest exploits in 2024-2026 have lived in the integration layer, not in the audited contract itself.
A private audit is a fixed-team engagement, typically 2-4 weeks, with one or two firms reading the code in depth. A contest audit (Code4rena, Cantina, Sherlock) opens the code to dozens of researchers competing for bug-bounty payouts. Contests broaden the search surface; private audits typically go deeper into business logic. Top protocols use both in sequence.

Specializing in DeFi security and data-driven audits.