DeFi Security Alliance

DeFi Security Alliance directory

Find Smart Contract Security Auditors, Reports and Tools

Compare 23 auditor profiles, open locally hosted audit reports and explore practical security resources.

All top tier companies gathered in one place with simple navigation.
Guaranteed quality

Search through the DeFi Security Alliance database, using convenient filters according to your demands.

DSA offers services from different tier auditors. Whether you're searching an affordable quality audit or development you can find answers here.
Choose an auditor according to your demands using the filters.
Easy search
Choose an auditor according to your demands using the filters.
Ask experts a question
Auditors ranked by specialty and reputation. Types of contracts, languages, networks.
Rankings
Everything from helpful articles to the latest news from auditors.
Latest News
Most relevant information about recent security breaches and attacks.
Security alerts

For smart contract security companies

How DSA Reviews Membership Applications

Membership decisions are based on public, checkable evidence of smart contract security work.

  1. Prepare the evidence

    Include published audit reports, public technical work such as GitHub activity and the company's audit specializations.

  2. Submit the application

    Keep report links and repositories accessible. Keep the organization and contact details current. Reviewers may compare the evidence with current member standards and request clarification.

  3. Plan for the review window

    The published review window is at least . After a rejection, a company may reapply in with updated evidence and a clear account of what changed.

Apply to join the alliance Read the directory methodology

Blog

  • Crypto Due Diligence Checklist: A Live Lido Protocol Walkthrough

    Personas and market

    Crypto Due Diligence Checklist: A Live Lido Protocol Walkthrough

    A crypto due diligence checklist should end in an evidence chain, not a row of green badges. We apply that standard to Lido on Ethereum by tracing two live proxies into verified implementations, matching the deployed scope to an audit commit and mapping privileged functions to their current control path. Our separate survey of 30 top total value locked records shows why the extra work matters: only 16 supplied an audit link, and a link alone says nothing about scope.

    12 min read

  • Honeypot Token Detection: How Checkers Work and the Four Contract Patterns That Beat Them

    Token risk

    Honeypot Token Detection: How Checkers Work and the Four Contract Patterns That Beat Them

    Every honeypot token detection service answers with a simulated trade, not with a statement about the token. A checker buys and sells against one live pair at one block, then reports what happened to that trade. This guide takes the method apart, names the four contract patterns that survive it, and reports our own run of 150 tokens through two public checkers on September 4, 2026.

    16 min read

  • Oracle Manipulation Attack: Spot, TWAP, Chainlink and Pull Oracles Compared

    Attack classes

    Oracle Manipulation Attack: Spot, TWAP, Chainlink and Pull Oracles Compared

    An oracle manipulation attack rarely breaks the oracle. It moves the venue the oracle reports, or reads a price the protocol should never have trusted, then borrows against the result. This comparison sizes spot reads, Uniswap TWAPs, Chainlink push feeds and pull oracles by what an attacker has to control, and carries our own survey of every Chainlink feed parameter published on four networks.

    16 min read

  • Signature Replay Attack Variants in Smart Contracts and the Check That Catches Each

    Attack classes

    Signature Replay Attack Variants in Smart Contracts and the Check That Catches Each

    A signature replay attack costs nothing to run: the attacker resubmits bytes the real owner already signed, and every check inside the contract passes. Six fields decide whether that works, and published audit reports name the category far more often than they file a finding against it. This guide maps each variant to the auditor check that catches it, then measures what 155 member firm reports actually say.

    16 min read

  • Smart Contract Audit Contest vs Private Audit: A Vendor-Neutral Decision Guide

    Audit alternatives

    Smart Contract Audit Contest vs Private Audit: A Vendor-Neutral Decision Guide

    Code4rena, the platform that made the smart contract audit contest famous, is closing its doors, which changes the answer for every team choosing between a contest, a private firm and a bug bounty. This guide prices contests and private review from platform data read on September 4 2026, across 40 finished contests on two platforms, and describes the bounty layer rather than pricing it. It ends with a routing rule that survives the disappearance of any single venue.

    16 min read

  • Smart Contract Monitoring After Defender: What to Watch, Thresholds and the Alert-to-Pause Path

    Operations

    Smart Contract Monitoring After Defender: What to Watch, Thresholds and the Alert-to-Pause Path

    The job called smart contract monitoring starts once the audit is over: watching a live contract's events and storage slots for the changes that matter, then getting a person or a script to act on them. This guide names the events with their exact signatures, gives a procedure for deriving alert thresholds rather than copying someone else's, and walks the escalation path from a firing rule to a pause transaction. It also dates the end of OpenZeppelin Defender and measures how many alliance member firms publish a monitoring service at all.

    16 min read

  • Audit Report Explained: Scope, Severity and Status Fields

    Audit deliverables

    Audit Report Explained: Scope, Severity and Status Fields

    An audit report explained properly starts at the scope statement and the dates, not at the findings table. Everything below those pages is conditional on them: which files were read, in what window and under which severity rule the firm writes its labels. This guide walks a real published report end to end, and measures the severity and status vocabulary that member firm reports actually use.

    17 min read

  • How to Tell a Fake Audit Report From a Real One

    Audit deliverables

    How to Tell a Fake Audit Report From a Real One

    A fake audit report is a document that claims a security review which never happened, or a real report that no longer describes the code you are about to use. Both are caught the same way, by checking the report against the two things it should name: the commit that was audited and the deployed address it maps to. This guide gives the procedure, and a measurement of how often published reports carry those anchors at all.

    13 min read

  • How to Publish a Security Disclosure Policy a Whitehat Will Actually Use

    Disclosure and bounties

    How to Publish a Security Disclosure Policy a Whitehat Will Actually Use

    A security disclosure policy is the published set of rules that tells a researcher where to send a vulnerability report, what they may test and what happens next. On September 2, 2026, only 3 of the 30 largest DeFi protocols by TVL served a security.txt file, and one of those three met RFC 9116. This guide gives protocol teams the policy wording, the file, the SEAL Safe Harbor steps and the response deadlines, each tied to a published source or to the terms real adopters set.

    16 min read

  • Smart Contract Fuzzing: Echidna, Medusa or Foundry for Which Situation

    Tooling

    Smart Contract Fuzzing: Echidna, Medusa or Foundry for Which Situation

    Fuzzing generates inputs and call sequences against compiled contracts and checks that stated properties hold. Echidna, Medusa and Foundry all do smart contract fuzzing, with different default budgets, coverage guidance, shrinking and setup cost, so the right pick depends on whether the bug you fear needs one input or a sequence of calls. This guide gives the decision path, a settings matrix from each tool's current documentation, and a scan of what the 30 largest DeFi protocols actually keep in their repositories.

    19 min read

About Us
By bringing together the most well-reputed auditing companies, DSA is aiming to guarantee that the decentralized market functions according to the top standards of security.
DeFi Security Alliance (DSA) is a security-driven organization that dedicates its efforts to improving standards of safe services throughout the decentralized market.

DSA unites the most trusted security auditors under one brand.
DSA holds security companies to a high standard. Before joining the Alliance, a company must confirm that it has good credentials, and is thorough in fulfilling its responsibilities. By becoming a part of DSA a company can secure its place among the top companies in the market and gain easy access to customers from all around the world.

A DSA member can share their news, updates, and most notable achievements while getting a unique opportunity to exchange knowledge and experience with their peers.
Our Standards
Our Values
DSA stands for the implementation of the best security practices and making sure that users of the DeFi apps can safely trade and exchange cryptocurrency, purchase and sell products, create new marketplaces and build financial relationships.

DSA helps users find the most reputable auditors and developers for crypto projects. We collect the most relevant security news and information.

DeFi Security Alliance

Founder

Dan Daniloff, founder of DeFi Security Alliance
Dan Daniloff, founder of DeFi Security Alliance.

DeFi Security Alliance guidance

Smart Contract Audit and DSA Membership FAQ

Answers for teams commissioning an audit and security companies considering DSA membership.

Reviewed

What is a smart contract audit, and what does it review?

A smart contract audit is a scoped review of a specific code version. Reviewers examine access control and state or accounting logic. They also assess external calls and integrations as well as upgrade paths and chain-specific assumptions. A useful report identifies the reviewed scope and commit. It records each finding with its severity and affected code. The report also states the remediation status. See the smart contract audit reports collected by DSA.

Does a smart contract audit guarantee that a DeFi protocol is secure?

No. An audit reduces risk within the agreed scope, but it is not a security guarantee. Code outside the scope, later changes, a deployed version that differs from the reviewed commit, privileged key handling and economic or oracle assumptions may remain outside the review. Before launch, confirm that the deployed code matches the audited version and that reported fixes were retested.

When should a project schedule a smart contract audit?

Schedule an audit after the intended release is feature complete and its build instructions, tests and documentation are ready, but before production deployment. Leave enough time to fix findings and complete a remediation review. Significant code changes after the audit may require additional review.

How do I choose a smart contract auditing company?

Match the auditor's evidence to your technology and risk profile. Review public reports for experience with your chain and language as well as your protocol type. Look for explicit scopes and commit identifiers. Check the severity definitions and remediation results. Confirm who will review the code and what is excluded. Ask about the schedule and retest terms. Start with the DSA auditor directory.

What should I send when requesting an audit quote?

Send a bounded and reproducible scope. Include the repository and the branch or commit. Identify the contracts in scope as well as the languages and chains. Provide architecture notes and threat assumptions. Include the build or test commands. Describe privileged roles and the deployment plan. Add the preferred review window and any earlier reports. These details help an auditor estimate effort and explain exclusions. You can begin with the audit request form.

How much does a smart contract audit cost?

There is no reliable flat price for every smart contract audit. Cost depends on scope size and complexity, language and chain, integrations, code maturity, schedule, reviewer count and whether remediation review is included. Compare written proposals by scope, exclusions, deliverables and retest terms instead of headline price alone.

Who can apply to join DeFi Security Alliance?

Smart contract security and auditing companies with a verifiable public track record can apply. An application should identify the organization and its technical specializations. It should also link to public audit reports and other relevant security work. Submit the current evidence through the membership application.

How often is DSA membership reviewed?

Membership status is reviewed annually. DSA can reconsider whether a member's activity and public evidence continue to meet alliance standards. The membership badge identifies the relevant membership year.

Is DSA membership free?

DSA does not publish a fixed public membership fee. Request the current terms through the membership application or contact form before relying on any cost assumption.

What does DSA membership provide?

A member can receive an alliance directory profile and membership badge. Members can share relevant security work and participate in the alliance's knowledge exchange. Available programs and tools can change. Review the current Audit Builder information and contact DSA for the terms that apply to a new member.