Audit Company

DeFiMoon

DeFiMoon is an auditing company with a small list of audited projects. Despite being new in the market, it’s making a name for itself through media, its tools and developments, and its work.
DSA presents a unique series of reports on the smart contract and blockchain app auditor market. This report is published for the first time and is not affiliated with any specific vendor. The DSA expert team has performed an in-depth analysis of the blockchain security providers in the market. For that, a methodology was developed, and specific criteria were selected. The data provided in the report are actual for May 2023.
Contents
The main criteria for auditor review
1
Trustworthiness
At this point, we analyze the team, key players, as well as the experience of the company in the field.
2
Media Presence
In this paragraph, we analyze the social networks of the project, the engagement rate, and media publications.
3
Speed and service
In this paragraph, we analyze the speed of the audit as well as the speed of the team's response to the request.
4
Expertise
At this point, we analyze the company's experience with different networks, technological advancements, as well as additional services.
5
Price
In this paragraph, we analyze prices and additional services (We send the same sample contract to every auditor), sales, promo offers, bonuses, discounts, and legal transparency.
6
Quality
In this paragraph, we analyze audit quality, report analysis, and user experience.
Categories and sub-categories
6 categories are present in the review and each may be divided into sub-categories. Each category is evaluated to receive from 1 to 10 points. The same rule applies to each sub-category and the arithmetic mean value of the sub-categories will become a result of the main category. The main result will be calculated in the same manner.
Trustworthiness
  • Team members' separate experiences in the field
  • Current team’s experience in the field
  • Company experience (years of service, date of the first audit)
Media Presence
  • Social media (engagement rate, further – ER)
  • Media publications
Speed
  • Audit speed
  • First response speed (from a real person)
  • Follow-up response speed
Expertise
  • What blockchains does the company audit (rare chains and language get an additional point)
  • Technological advancements (developments, tools, automated tools)
  • Services (KYC, Incident research, marketing)
Price
  • Prices and additional services (We send the same sample contract to every auditor)
  • Sales, promo offers, bonuses, discounts
  • Legal transparency
Quality
  • Audit quality, report analysis
  • User experience

Detailed analysis

6 categories are present in the review and each may be divided into sub-categories. Each category is evaluated to receive from 1 to 10 points. Same rule applies to each sub-category and the arithmetic mean value of the sub-categories will become a result of the main category. The main result will be calculated in the same manner.

Trustworthiness

Average score 5/10

1

Team members' separate experiences in the field

The leadership team consists of 2 members
Cyrill Minyaev - CEO
Artur Makhnach - CTO

Each one possesses over 3 years of experience in their respective fields.
2
Current team’s experience in the field
Aside from the key team members, the company’s LinkedIn page lists 2 more employees. The mentioned team members are business development and design specialists.
The team participated in well-known events such as CryptoExpoEu. However, other than CTO, the team members don’t appear to have any prior experience in smart contract auditing.
3
Company experience (years of service, date of the first audit)
According to the disclaimer on the company’s website, DeFiMoon has been providing security services since 2020. According to GitHub, however, the first audit report was released on Feb 24, 2022. Since then, 38 projects were audited. The company’s repository on GitHub proves this number as it contains audited projects. It’s regularly updated.

Media presence

Average score 5,1/10

1

Social Media

Twitter has a low number of subscribers but a high engagement rating, compared to similar projects. New posts are regularly added and contain audit, KYC, or partnership announcements as well as informative posts and news on both team developments and security news.
The company also has a dedicated Twitter account for its project KYC.systems, as well as Medium and LinkedIn pages. Because of low activity, the engagement rating for them isn’t relevant.
2
Media publications
The company has publications in Blockster, GlobeNewswire, and other media.

Speed

Average score 8,5/10

1

Audit Speed

An audit takes approximately 7-11 days, which is an average result for similar companies.
2
First response speed
After being contacted via Telegram, the manager responded within 4 hours.
3
Follow-up response speed
After being provided with additional information, the manager responded with a quote within 4 hours.

Expertise

Average score 6,33/10

1

What blockchains does the company audit

Supported blockchains: Etherium, BSC, , Avalanche, Phantom, Solana, Astar, Polygon.

The list is impressive and makes it obvious that the company works with both EVM and non-EVM blockchains.
Aside from Solidity, the company takes Rust projects on Solana. In terms of stack technologies, the company has no shortcomings.
2
Technological advancements
The company offers several additional tools and projects:

KYC.systems - an automated on-chain KYC platform for user and business verification with a built-in Machine Learning core
Algem.io - a DeFi dApp built on Astar Network that allows you to stay liquid while staking your ASTR.
3
Services
Aside from audit services, the company offers KYC, DApp and smart contract development on various blockchains. The company also has its own BugBounty platform.

Prices and additional services

Average score 5,66/10

1

Audit prices, affordability

The price for the test audit is $2700. This is an average price that is available for the majority of projects.
2
Sales, promo offers, bonuses, discounts
During our communication with the manager, no discounts were offered.
In addition to the report, clients receive:
1. One free reaudit: if problems are discovered, they can be fixed and the code can be submitted for a free audit again.
2. The information about the projects is published on the company’s socials and its dashboard on the website.
3
Legal transparency
The company is officially registered in the USA but works only with cryptocurrency.

Quality

Average score 6,6/10

1

Audit quality, report analysis

  • Issue description (thoroughness, code examples): YES

  • Project description and contracts (what do they do): YES

  • Conclusions (automatically generated vs written by specialists): NO

  • Recommendations: YES

  • Manual audits (a large number of automatically generated audits is a disadvantage): YES/NO
Each report has issues that were discovered manually. However, some reports contain issue descriptions copied directly from an automated tool.

2
User Experience
Quotes can be requested through a form on the website or directly from a manager via Telegram. The latter option is a convenient one for potential clients who want to ask questions.

Final Score

Considering the results presented in every category, the following points have been assigned:
  • 5/10 Trustworthiness
  • 5,1/10 Media presence
  • 8,5/10 Speed
  • 6,33/10 Expertise
  • 5,66/10 Prices and additional services
  • 6,6/10 Quality
The Final Score:
6,19/10
This is the analytic report in a series of reports on the smart contract and blockchain apps auditor market. Presented to you by DSA, it’s guaranteed impartial and factual information on the most well-known, new, and obscure players.
Follow us on Twitter and be the first to know about new reports
Haсken Analysis Report
Hacken Defi Security company was founded in 2017 in Kyiv, Ukraine by security specialists and hackers to deliver cybersecurity solutions to companies and individuals, making histories of success.
RugFreeCoins Analysis Report
A company that conducts smart contract security audits and provides token listing and other related services.