Smart Contract Audits

Senior-led audits.
Every line reviewed.
No shortcuts.

320+ audits · 162 public reports · $70B in assets protected

A dedicated team of senior researchers reviews 100% of your code and then challenges each other to break it—backed by the Dedaub Security Suite, which leverages 100+ static analysis techniques, fuzzing, and LLMs.
Audit Methodology

How We Audit

Dedaub's Security Audit teams comprise at least two senior security researchers, as well as any support they may need (e.g., cryptography expertise, financial modeling, testing) from the rest of our team. We carefully match the team's expertise to your project's specific nature and requirements. Our auditors conduct a meticulous, line-by-line review of every contract within the audit scope, ensuring that each researcher examines 100% of the code.

Two-Phase Review
During phase A, the auditors understand the code in terms of functionality, i.e., in terms of legitimate use. During phase B, the auditors assume the role of attackers and attempt to subvert the system's assumptions by abusing its flexibility.
Constant Challenging
The two auditors will continuously challenge each other, trying to identify dark spots. An auditor who claims to have covered and to understand part of the code is often challenged to explain difficult elements to the other auditor.
Thinking at Multiple Levels
Beyond thinking of adversarial scenarios in self-contained parts of the protocol, the auditors explicitly attempt to devise complex combinations of different parts that may result in unexpected behavior.
Use of Advanced Tools
Every project is uploaded to the Dedaub Security Suite for analysis by over 100 static analysis algorithms, AI, and automated fuzzing. The auditors often also write and run manual tests on possible leads for issues.

Dedaub's auditors also identify gas inefficiencies in your smart contracts and offer cost optimization recommendations. We thoroughly audit integrations with external protocols and dependencies, such as AMMs, lending platforms, and Oracle services, to ensure they align with their specifications.

Audit Track Record

Deep Expertise Across Every Web3 Vertical

From DeFi and stablecoins to L1/L2 infrastructure, bridges, and oracles — our researchers have secured over $70B in assets across the most critical sectors of web3.

Staking

We have audited multiple Lido staking implementations, EigenLayer modules and Staking for Zircuit. In particular EigenLayer's middleware and AVS such as EigenDA was audited by our team. Collectively, these projects handle over $40B. A number of High severity issues in these projects were identified as part of our audits.
Staking

Decentralized Exchanges

Whether it's a novel constant-function market maker or a fork of an existing protocol, our team is fully prepared. For example, we've recently identified a high severity CVE in live Uniswap smart contracts (CVE-2022-48216), which led to redeployments on all affected chains. Our team has also worked with Maverick, where we found a critical vulnerability allowing infinite minting for pool shares. We can also help secure Dex integrations, such as Uniswap V3 position managers. In an audit for Maple Finance we found 3 distinct critical and high-severity vulnerabilities related to AMM integrations.
Decentralized Exchanges

DeFi

The Dedaub team has made several security contributions for DeFi, directly auditing some of the best known protocols. Examples include multiple audits for Lido. Findings include a critical issue that allows price manipulation between the base and staked token, that can result in a theft of funds. The team has also audited Pendle smart contracts. The team discovered a high-severity CVE in a live version of Uniswap's UniversalRouter. More recently, the team also performed audits for GMX V2, Liquity V2, as well as EigenLayer, finding high-severity issues for all 3 teams. Finally, many modern DeFi protocols are underpinned by Chainlink Oracles, stablecoins such as USDC, and the evolution of the EVM. Our team has also been involved in securing these too.
DeFi

L1s - L2s

The Dedaub team has been particularly impactful for L1s. For the Ethereum Foundation we have audited and performed impact studies for a variety of EIPs over the years, including EIP-1884, EIP-3074, EIP-4788, EIP-6780, Verkle Trees and others. With our help the Ethereum community was able to derisk network upgrades, and preemptively find issues or tweak EIPs to minimize impact. Through our distinctive tech we can also pinpoint projects that would be adversely affected by network upgrades. For instance, for EIP-3074 we identified Sushiswap and older versions of Compound. Our team can also conduct audits of sequencers, node implementations in GoLang, consensus protocols and evaluate compatibility of EVM-based chains.
L1s - L2s

NFTs

Our work in NFTs includes audits for the world's largest decentralized NFT exchange, Blur. Notably our team has found access control issues allowing anyone to be able to execute arbitrary transactions on a user's proxy, together with high severity denial of attack issues.
NFTs

Oracles

As a long-term security partner of Chainlink, our team has conducted over 30 private audits targeting most components of the Chainlink stack. DeFi protocols incessantly rely on fair and accurate price and cross-chain data connectivity. Our team has also audited Oracle integrations, that in addition to Chainlink utilize Pyth, Uniswap TWAP oracles.
Oracles

Stablecoins

Our team has audited implementations of the USDC and TUSD stablecoins, developed by Coinbase and Archblock respectively.
Stablecoins

Bridges

Unfortunately, the world's largest hacks (by financial value) involve bridges. In 2022, our team proactively detected a vulnerability in a large decentralized bridge and demonstrated via a PoC how all the funds moved to the Fantom chain could be stolen in a single transaction, yielding over $1B in profit. Our team was subsequently awarded a $2M bounty for this find. Dedaub also successfully audited Chainlink CCIP, which, in our view, is one of the most secure bridges to date.
Bridges

Why Dedaub?

Dedaub is a leading blockchain security technology and auditing firm that combines deep security research, academic rigor, and practical hacker expertise.

$3M

IN BUG BOUNTIES IN 11 SUCCESSFUL CLAIMS FOR IDENTIFYING CRITICAL ISSUES

$Billions

IN TVL SECURED VIA PROACTIVE WHITE-HAT HACKING and SEAL 911 WAR ROOMS

200+

SMART CONTRACT SECURITY AUDITS FOR LEADING DEFI PROTOCOLS

Expertise

Expertise

Leverage years of smart contract security expertise and cutting-edge static analysis technology.

Knowledge

Knowledge

Access comprehensive threat intelligence and security insights from industry-leading blockchain security researchers.

Trusted

Trusted by security teams at leading DeFi protocols and Web3 companies globally for reliable token risk assessment.

Designed by World-Leading Security Experts

Dedaub has improved safety in the Web3 space by addressing vulnerabilities and collaborating with the Ethereum Foundation on EIPs and various upgrades.
Chainlink CHAINLINK BUILD PROGRAM PARTNERSHIP
Arbitrum ARBITRUM DAO SECURITY ADVISOR
Oasis Protocol OASIS PROTOCOL SAPPHIRE'S SECURITY PARTNER
Seal 911 FOUNDING COLLABORATOR OF THE SEAL 911
Uniswap UNISWAP FOUNDATION SECURITY PROVIDER
zkSync MEMBER OF ZKSYNC SECURITY COUNCIL

Secure your smart contract...

Launch your next Web3 project free of critical vulnerabilities...