# DeFi Security Alliance > Compare 23 smart contract audit provider profiles, review 33 security reports and analyses, and request an audit through DeFi Security Alliance. Canonical domain: https://defisec.info/ Language: English Primary topics: smart contract audits, DeFi security, blockchain security companies, auditor analysis, audit methodology and security tooling. ## Start here - [Compare 23 Smart Contract Audit Providers | DeFiSec](https://defisec.info/) - [23 Smart Contract Audit Provider Profiles | DeFiSec](https://defisec.info/members) - [156 Web3 Security Tools: Compare & Filter | DeFiSec](https://defisec.info/tools) - [Blockchain Security Articles | DeFi Security Alliance](https://defisec.info/blog) - [27 Smart Contract Security Reports & Analyses | DeFiSec](https://defisec.info/reports) - [Auditor Selection and Security Review Methodology | DeFiSec](https://defisec.info/methodology) - [Analysis of Audit Companies](https://defisec.info/analysis_of_audit_companies) - [DSA Audit Builder Plans and Report Workflow | DeFiSec](https://defisec.info/audit_builder) - [A Comprehensive Guide to Smart Contract Auditing](https://defisec.info/guide_to_smart-contract-auditing) - [The Comprehensive Smart Contract Audit Checklist](https://defisec.info/smart_contract_audit_checklist) - [Request a Smart Contract Audit | DeFiSec](https://defisec.info/request-audit) - [7 Site Data and Accessibility Updates | DeFiSec](https://defisec.info/updates) ## Blog articles - [ERC4626 Vault Security 400000 Scenarios | DeFiSec](https://defisec.info/blog/erc4626-vault-security): 90,100 of 100,000 deposits minted zero shares at virtual offset 0 in our bounded model. Separate rounding loss from attacker profit and oracle risk. - [Airdrop Contract Security 26 Archived Tests | DeFiSec](https://defisec.info/blog/airdrop-contract-security): 5 archived cases test replay or exactly once behavior; a narrow keyword scan finds only 1. Review claim data, signatures and post-expiry authority. - [Auditing AI Generated Smart Contracts 15 Tasks | DeFiSec](https://defisec.info/blog/auditing-ai-generated-smart-contracts): 62 test declarations are visible inside 15 generation prompts. Our corpus census shows why independent requirements, test oracles and run status matter. - [Bridge Integration Checklist 12 Core Only Chains | DeFiSec](https://defisec.info/blog/bridge-integration-checklist): 41 core entries and 29 token bridge entries differ in our SDK census. Check source identity, receiver policy, limits and recovery before choosing a route. - [Crypto Security Score 28 Weights No Coefficients | DeFiSec](https://defisec.info/blog/crypto-security-score): 6 categories combine code, governance and other signals. Our methodology census separates disclosed indicators from missing coefficients and project evidence. - [DeFi Insurance for Protocols 215 Retired Entries | DeFiSec](https://defisec.info/blog/defi-insurance-for-protocols): 259 Nexus product records are not marked deprecated, but that does not establish purchase capacity. Compare wording, exclusions and claims evidence. - [Emergency Pause Circuit Breakers 4 Library Files | DeFiSec](https://defisec.info/blog/emergency-pause-circuit-breakers): 3 token extensions guard updates, but 0 public pause functions appear in the four-file library census. Review authority, containment and recovery paths. - [Smart Contract Security Glossary 67 Labels Matched | DeFiSec](https://defisec.info/blog/smart-contract-security-glossary): 199 Ethereum glossary labels were checked against 44 existing articles. Definitions connect permissions, proofs and review methods to their evidence limits. - [Smart Contract Security Standards 35 Control Docs | DeFiSec](https://defisec.info/blog/smart-contract-security-standards): 11 control families need different evidence. Our OWASP file census shows how to bind requirements to audit scope, deployment assumptions and review results. - [Token Listing Audit Requirements 3 Custody Risks | DeFiSec](https://defisec.info/blog/token-listing-audit-requirements): All 3 Coinbase custody examples name an issuer mitigation; only 1 also names the exchange. Separate audits, identity checks, locks and listing decisions. - [Regulated Crypto Developers 19 MiCA Inputs | DeFiSec](https://defisec.info/blog/top-regulated-crypto-developers): 6 application items depend on the service offered. Compare 10 developers for MiCA, crypto trading, custody and regulated DeFi software. - [Transaction Simulation Security 92 Test Fixtures | DeFiSec](https://defisec.info/blog/transaction-simulation-security): 12 validation and 14 override filename signals appear in our fixture census. Read state assumptions, signature authority and unknown results before signing. - [Web3 Cybersecurity 3 Pharos Security Pages | DeFiSec](https://defisec.info/blog/web3-cybersecurity-pharos-production): 66 service pages checked: map Pharos Production security work across contracts, applications and cloud, with scope boundaries and evidence to request. - [Smart Contract Audit Report Examples 10 PDFs | DeFiSec](https://defisec.info/blog/smart-contract-audit-report-examples): 3 of 10 sampled PDFs were standalone fix reviews. Compare scope, findings, limitations and fix logs without treating keyword matches as assurance scores. - [Fake Audit Report: 6 of 50 Name Commit and Address | DeFiSec](https://defisec.info/blog/fake-audit-report): Verify a smart contract audit PDF: find it on the firm's own domain, match the commit, then match the deployed address and the proxy implementation. - [Cross chain bridge security 88 Catalog Entries | DeFiSec](https://defisec.info/blog/cross-chain-bridge-security): 37 bridge-flagged records use a bridge-specific failure label. Compare verification models and historical audit evidence without inventing risk rankings. - [Solana Smart Contract Audit: 28 Extension Types | DeFiSec](https://defisec.info/blog/solana-smart-contract-audit): 19 mint types and 9 account types appear in our pinned registry scan. Scope signer checks, PDA relationships and the token configurations a program accepts. - [Smart Contract Fuzzing: 12 of 22 Repos Run It | DeFiSec](https://defisec.info/blog/smart-contract-fuzzing): Echidna 2.3.3, Medusa 1.5.1 and Foundry 1.8.1 compared on budgets, shrinking, coverage and Slither, plus which top-30 DeFi repos keep a stateful fuzz suite. - [Smart contract audit timeline 3 of 23 Firms | DeFiSec](https://defisec.info/blog/smart-contract-audit-timeline): 55 public pages were checked for duration evidence. Separate start availability, review effort, remediation and release verification before promising launch. - [Smart contract threat modeling 50 Reports Checked | DeFiSec](https://defisec.info/blog/smart-contract-threat-modeling): 1 actual threat-model document in the matched sample covers a non-DeFi system. Build a DeFi workbook with explicit goals, trust assumptions and scope. - [White Hat Hacker Web3 6 Contact Fields | DeFiSec](https://defisec.info/blog/white-hat-hacker-web3): 20 protocol records yielded 6 security contact fields at the tested route. Check authorization, local proof and payout terms before reporting a defect. - [DeFi hacks by auditor 913 Rows Without Audit Data | DeFiSec](https://defisec.info/blog/defi-hacks-by-auditor): 1,253 catalog records expose no explicit audit-provenance keys. Cross-check Beanstalk, Nomad and Ronin with report dates and unresolved scope matches. - [Top 10 Cybersecurity Companies: 1 Lists Prices | DeFiSec](https://defisec.info/blog/top-cybersecurity-companies): Ten security firms ranked for on-chain and off-chain work, with three public report archives counted, a stale one named and the one firm that publishes prices. - [Protocol Invariants 12 Views 4 Vault Actions | DeFiSec](https://defisec.info/blog/protocol-invariants): 16 IERC4626 functions expose accounting, limits and previews around 4 state changes. Specify AMM, lending and vault properties with explicit boundaries. - [Crypto Incident Response: 84 Public Log Entries | DeFiSec](https://defisec.info/blog/crypto-incident-response): 10 takeover labels appear in our public-log census. Prepare pause decisions, verified responder contacts and evidence packets before a protocol incident. - [Perpetual DEX Security: 34/177 Markets Tiered | DeFiSec](https://defisec.info/blog/perpetual-dex-security): 56 delisted entries were excluded from our margin survey. Scope liquidation math, funding settlement and the loss rules that can close profitable positions. - [RWA Token Security: 14 Direct Role Gates | DeFiSec](https://defisec.info/blog/rwa-token-security): 6 batch wrappers call guarded methods in our T-REX reference scan. Review forced transfers, reserve evidence and the documents defining a holder claim. - [Security Disclosure Policy: 1 in 30 Meets RFC 9116 | DeFiSec](https://defisec.info/blog/security-disclosure-policy): VDP clauses to copy, a security.txt template, SEAL Safe Harbor steps and CISA response windows, plus the KYC tiers and funded caps that bounty platforms skip. - [ERC20 Token Audit 20 Compatibility Fixtures | DeFiSec](https://defisec.info/blog/erc20-token-audit): 12 of 20 unusual token fixtures declare approve directly. Build a listing packet that covers allowance behavior, supply controls and integration limits. - [Rug Pull Scanner Limits 2 Unknown Pool Results | DeFiSec](https://defisec.info/blog/rug-pull-scanner-limits): 10 WETH pool requests returned 8 negative honeypot results and 2 HTTP 404 responses. Preserve unknowns and inspect controls that a snapshot cannot predict. - [Smart Contract Backdoors 14 Modules Examined | DeFiSec](https://defisec.info/blog/smart-contract-backdoors): 3 of 14 OpenZeppelin token extension modules directly override the balance update hook. Trace admin powers beyond names, badges and scanner labels. - [Smart Contract Audit Contest: $38,750 Median Pool | DeFiSec](https://defisec.info/blog/smart-contract-audit-contest): Code4rena is winding down. Across 20 finished contests each, the median pool was $38,750 at Code4rena and $152,608 at Sherlock. - [Formal Verification Smart Contracts 42 Checks | DeFiSec](https://defisec.info/blog/formal-verification-smart-contracts): 18 of 21 Halmos example test files carry local execution options. Read proof assumptions and historical engagement costs before funding verification. - [Signature Replay Attack: 3 Findings in 155 Audits | DeFiSec](https://defisec.info/blog/signature-replay-attack): Six fields a signed message must bind, and the replay each one blocks. Of 155 member firm reports 31 mention replay and only 3 file it as a finding. - [Vyper contract audit 18 Compiler Review Entries | DeFiSec](https://defisec.info/blog/vyper-contract-audit): 10 compiler-index filenames identify limited reviews. Scope Vyper builds, nonreentrancy behavior and tool support against the actual deployed artifact. - [Reentrancy attack 6 Reports With Findings | DeFiSec](https://defisec.info/blog/reentrancy-attack): 36 of 50 public reports mention reentrancy. A reviewed subset separates named findings from checklists and maps callback variants to testable properties. - [Smart Contract Audit RFP 9 Separate Fix Reports | DeFiSec](https://defisec.info/blog/smart-contract-audit-rfp): 277 of 286 review paths lack an exact separate fix-file pair. Define remediation evidence in the RFP instead of treating archive filenames as coverage. - [Crypto Team KYC Verification 842 Archive Folders | DeFiSec](https://defisec.info/blog/crypto-team-kyc-verification): 750 of 842 KYC archive folders contain multiple files. Compare identity scope, privacy terms and public prices without mistaking badges for guarantees. - [Honeypot Token Detection: 55% of Clean Had Switch | DeFiSec](https://defisec.info/blog/honeypot-token-detection): Of 89 tokens that honeypot.is and GoPlus both called clean in our September 2026 run, 49 still gave the owner a switch that can stop selling. - [MiCA Security Obligations 2 DORA Linked Articles | DeFiSec](https://defisec.info/blog/mica-security-obligations): 149 MiCA articles contain 6 explicit DORA references across Articles 34 and 68. Map entity scope, resilience controls and current authorization evidence. - [DeFi Hack Post Mortem 191 Recovery Values Unknown | DeFiSec](https://defisec.info/blog/defi-hack-post-mortem): 197 incident records from 2023 had no source URL in the fetched archive. Build a post mortem from primary evidence and a reconciled recovery ledger. - [Solidity Static Analysis 100 Detectors | DeFiSec](https://defisec.info/blog/solidity-static-analysis): 14 of 29 High impact Slither detectors carry Medium confidence. Separate tool labels, confirmed behavior and suppressions before handing off an audit. - [Oracle Manipulation Attack: 89% of Feeds Lag 24h | DeFiSec](https://defisec.info/blog/oracle-manipulation-attack): On Ethereum mainnet 220 of 247 Chainlink feeds may sit a full day between updates. Survey figures, feed tables and an auditor checklist. - [Upgradeable contract audit 36 Report Mentions | DeFiSec](https://defisec.info/blog/upgradeable-contract-audit): 16 sampled archives contain upgrade-related wording. Accept a release through storage compatibility, initializer checks and verified upgrade authority. - [Tokenomics Audit: 1/16 Sites Named a Service | DeFiSec](https://defisec.info/blog/tokenomics-audit): 7 of 23 member sites were unreadable in our scan. Compare report scope, simulation evidence and provider offers before commissioning a review. - [Web3 Security Engineer 4 Roles 3 Currencies | DeFiSec](https://defisec.info/blog/web3-security-engineer): 192 public job entries yielded 4 security titles with disclosed base pay. Compare role scope, geography and ownership before budgeting a hire or retainer. - [Smart Contract Dependency Risk 14 Imported Files | DeFiSec](https://defisec.info/blog/smart-contract-dependency-risk): 4 direct imports expand to 15 source files in a fixed ERC4626 build input. Scope library overrides, live integrations and dependency update evidence. - [DAO security audit 15 of 50 Reports | DeFiSec](https://defisec.info/blog/dao-security-audit): 10 sampled archives contain governance wording, which does not prove execution coverage. Trace proposal payloads, delegation, timelocks and treasury roles. - [Smart Contract Monitoring: 8 of 20 Audit Firms | DeFiSec](https://defisec.info/blog/smart-contract-monitoring): Defender shuts down on July 1 2026. Watch admin roles, upgrades and large withdrawals, then derive thresholds from 30 days of your own events. - [Flash loan attack 4 Labels in 1253 Records | DeFiSec](https://defisec.info/blog/flash-loan-attack): 155 catalog rows use an oracle-manipulation label without proving their financing path. Trace prices, shares and voting power to the lasting claim. - [Audit Report Explained: 12 Words for One Column | DeFiSec](https://defisec.info/blog/audit-report-explained): Only 26 of 80 published reports say how a severity was reached. Read the scope and dates first, then the severity rule, then who wrote each label. - [Crypto Due Diligence Checklist: 16/30 Had Links | DeFiSec](https://defisec.info/blog/crypto-due-diligence-checklist): Only 4 of 30 top TVL records named a GitHub organization, and 2 of 19 audit URLs failed retrieval. Follow our live Lido evidence chain. - [Crypto Bug Bounty Program 8 Vaults Below Caps | DeFiSec](https://defisec.info/blog/crypto-bug-bounty-program): 10 program pages showed 8 vault balances below advertised maxima. Compare displayed funding, payout conditions, KYC and the work needed to run a bounty. - [Admin key management 43 Reports Mention Privilege | DeFiSec](https://defisec.info/blog/admin-key-management): 16 sampled archives mention privileged roles. Separate signing, upgrades and containment, then verify revocation across wallet modules and controllers. - [Lending Protocol Audit: 28 Configs Compared | DeFiSec](https://defisec.info/blog/lending-protocol-audit): 92 collateral rows had a positive borrowing-to-liquidation factor gap in our repository scan. Check accounting, oracle evidence and XRPL credit scope. - [Solana Audit Companies 14 Token2022 Files | DeFiSec](https://defisec.info/blog/top-solana-audit-companies): Seven Token2022 files appear beyond the dated documentation list. Compare 10 firms using opened reports, scope limits and the evidence needed for a recheck. ## Discovery - [XML sitemap](https://defisec.info/sitemap.xml) - [Site update feed](https://defisec.info/updates.xml) - [Full AI content index](https://defisec.info/llms-full.txt) - [Robots policy](https://defisec.info/robots.txt) - [Privacy policy](https://defisec.info/privacy)