DeFi Security AllianceRequest an audit
Menu

DeFi Security Alliance directory

Find Smart Contract Security Auditors, Reports and Tools

Compare 24 auditor profiles, review public evidence and prepare an audit request. Explore security tools and EU regulation guides for your project.

Choose by security task

Web3 security tools

Choose tools for the work in front of you. Each guide explains where an approach fits and what its results cannot establish.

Tools
156
Categories
21

Country guides & regulatory topics

EU DeFi regulation

Find the relevant national procedures and security evidence for your activity. A smart contract audit and regulatory authorization address different questions.

EU countries
27
Topics
8

Award history & future selection

DSA awards and selection criteria

Trace past awards to their sources and read the evidence requirements for a future technical recommendation.

A new competition has not been announced.

2022 award archive

SlowMist
Outstanding Achievements in DeFi Security
ShellBoxes
Outstanding Quality
HashEx
Community Choice

Requirements for future selection

  • Published evidence
  • Two independent reviews
  • Conflict-of-interest checks

Original research · initial source snapshot

17 of 23 profiles had a readable public page in the initial check

On , we fetched official pages for 23 providers. 17 had at least one successful response with 500 or more extracted text characters.

This measures access to public evidence. A failed fetch or JavaScript shell does not establish a lack of security expertise. Later profile research does not change this frozen sample.

Latest articles

  • ERC2771 Forwarder Security: Trusted Context and Request Evidence

    EVM patterns

    ERC2771 Forwarder Security: Trusted Context and Request Evidence

    A recipient reads an appended sender only through a trusted forwarder with sufficient calldata. ERC2771 forwarder security requires authentic request verification, correct context consumption and application authorization on every relevant route.

    12 min read

  • Solidity Transient Storage Security: Lifetime, Ownership and Cleanup

    EVM patterns

    Solidity Transient Storage Security: Lifetime, Ownership and Cleanup

    Temporary state resets at transaction end and can still be shared by calls within that transaction. Transient storage security requires explicit owner mapping, successful-call cleanup and rollback tests for the actual execution graph.

    12 min read

  • ERC3156 Flash Loan Security: Callback Authority and Repayment

    EVM patterns

    ERC3156 Flash Loan Security: Callback Authority and Repayment

    Repayment protects the lender's financing boundary, while the receiver must authorize the work performed during the loan. ERC3156 flash loan security requires lender and initiator checks plus the application's own request and allowance policy.

    12 min read

  • Governance Timelock Security: Readiness, Roles and Execution

    EVM patterns

    Governance Timelock Security: Readiness, Roles and Execution

    An elapsed delay makes an operation eligible for further checks, while authority and dependencies still govern execution. Governance timelock security requires closing target bypasses and testing roles, predecessors and recovery paths.

    11 min read

  • ERC4337 Paymaster Security: Sponsorship, Prefund and Settlement

    EVM patterns

    ERC4337 Paymaster Security: Sponsorship, Prefund and Settlement

    A paymaster sponsors gas under its own acceptance policy and can still pay when the user action fails. ERC4337 paymaster security requires operation binding, complete prefund accounting and tested settlement behavior for the deployed EntryPoint version.

    12 min read

  • L2 Sequencer Security: Recovery Gates and Oracle Boundary Tests

    Chains

    L2 Sequencer Security: Recovery Gates and Oracle Boundary Tests

    A sequencer returning to service does not establish that every oracle-dependent operation is ready. L2 sequencer security requires separate checks for reported uptime, elapsed recovery time and the price observation used by the application.

    11 min read

For security companies

Apply with public reports and a clear account of your specializations. The application page explains the evidence packet and published review terms.

Apply to join the alliance Directory methodology

DeFi Security Alliance guidance

Questions about commissioning an audit

Scope, timing and evidence for a review of your release.

Reviewed

What is a smart contract audit, and what does it review?

A smart contract audit is a scoped review of a specific code version. Reviewers examine access control and state or accounting logic. They also assess external calls and integrations as well as upgrade paths and chain-specific assumptions. A useful report identifies the reviewed scope and commit. It records each finding with its severity and affected code. The report also states the remediation status. See the smart contract audit reports collected by DSA.

Does a smart contract audit guarantee that a DeFi protocol is secure?

No. An audit reduces risk within the agreed scope, but it is not a security guarantee. Code outside the scope, later changes, a deployed version that differs from the reviewed commit, privileged key handling and economic or oracle assumptions may remain outside the review. Before launch, confirm that the deployed code matches the audited version and that reported fixes were retested.

When should a project schedule a smart contract audit?

Schedule an audit after the intended release is feature complete and its build instructions, tests and documentation are ready, but before production deployment. Leave enough time to fix findings and complete a remediation review. Significant code changes after the audit may require additional review.

How do I choose a smart contract auditing company?

Match the auditor's evidence to your technology and risk profile. Review public reports for experience with your chain and language as well as your protocol type. Look for explicit scopes and commit identifiers. Check the severity definitions and remediation results. Confirm who will review the code and what is excluded. Ask about the schedule and retest terms. Start with the DSA auditor directory.

What should I send when requesting an audit quote?

Start with a bounded and reproducible scope:

  • Repository, branch or commit and contracts in scope
  • Languages, chains and architecture notes
  • Build/test commands and earlier reports
  • Privileged roles, threat assumptions and deployment plan
  • Preferred review window and retest needs

Begin with the audit request form.

How much does a smart contract audit cost?

There is no reliable flat price for every smart contract audit. Cost depends on scope size and complexity, language and chain, integrations, code maturity, schedule, reviewer count and whether remediation review is included. Compare written proposals by scope, exclusions, deliverables and retest terms instead of headline price alone.

DeFi Security Alliance guidance

Questions about joining DSA

Public application terms for security companies.

Reviewed

Who can apply to join DeFi Security Alliance?

Smart contract security and auditing companies with a verifiable public track record can apply. An application should identify the organization and its technical specializations. It should also link to public audit reports and other relevant security work. Submit the current evidence through the membership application.

How often is DSA membership reviewed?

The published membership policy calls for annual review. A dated badge does not by itself establish that a technical reassessment occurred. See the badge information and request the current membership terms.

Is DSA membership free?

DSA does not publish a fixed public membership fee. Request the current terms through the membership application or contact form before relying on any cost assumption.

What does DSA membership provide?

A member can receive an alliance directory profile and membership badge. Members can share relevant security work and participate in the alliance's knowledge exchange. Available programs and tools can change. Review the current Audit Builder information and contact DSA for the terms that apply to a new member.