Provider profile · Technical review not assessed
ImmuneBytes
ImmuneBytes lists smart contract auditing and penetration testing. This profile connects its current service information with a named public report and the earlier DeFiSec company analysis.
Sources checked .
What the provider lists
The current audit page describes review of access controls, asset accounting, external calls, upgrades and oracle dependencies. It includes manual review, adversarial tests and a report with retesting. These are provider statements; confirm which methods and deliverables apply to your proposed engagement.
Read the archived ImmuneBytes company analysis for the earlier DeFiSec record. For new work, use the dated sources below rather than treating the old analysis as a current assessment.
How to request a comparable quote
The engagement page lists fixed-price, retainer and pay-per-vulnerability models. It does not publish a numeric fee. For a vulnerability-based agreement, request the base fee, severity definitions, payout cap and treatment of duplicate findings before signing.
Send a repository, frozen commit, in-scope contracts and test instructions. Compare the proposed review effort and retest allowance using the smart contract audit pricing guide.
Source-based directory record
ImmuneBytes: evidence and scope
Provider statements identify services to discuss. Technical quality requires report-level assessment under the security review methodology.
- Audit networks
- PolygonConfirmed in cited evidence · Checked 2026-10-04. The named MaticX report concerns Polygon liquid staking. It does not establish coverage of every network. Source for audit networks
- Audit languages
- SolidityConfirmed in cited evidence · Checked 2026-10-04. The report names Solidity contracts and TypeScript unit tests; TypeScript is not classified as an audit contract language. Source for audit languages
- Services and methods
- Smart contract audit, Penetration testingProvider statement · Checked 2026-10-04. Services listed by the provider. The smart contract service describes manual review, adversarial testing and retesting. Source for services and methods
- Protocol types in reviewed reports
- Liquid stakingConfirmed in cited evidence · Checked 2026-10-04. Observed only in the named 2022 MaticX report. Source for protocol types in reviewed reports
- Current pricing
- Scoped fixed-price quote, retainer or pay per vulnerabilityProvider statement · Checked 2026-10-04. The engagement-models page names these models but gives no numeric price. Confirm the base fee, severity payouts and cap in writing. Source for current pricing
- Availability
- Confirm assigned team and start date directlyInsufficient evidence · Checked 2026-10-04. No current capacity or booking date was verified.
- Committee review
- Not assessed. No technical score or expert endorsement has been issued.
- DSA original research
- Read the source evidence review
Public report examples
Observed facts apply to the named scope and revision. Read each source before using it in an audit decision.
Stader Labs MaticX
Final report date: · Source checked
- Protocol type
- Liquid staking
- Scope
- MaticX.sol and ValidatorRegistry.sol; Solidity contracts with TypeScript unit tests.
- Code revision
- 8f914608ae40fdb35cfae281ff6c1dda9943b632
- Follow-up evidence
- The document records different initial and final audit revisions. Finding-level closure was not independently assessed in this profile.
- Limit
- The historical report does not cover the current deployment, later code changes or a new engagement.
Public sources checked October 4, 2026. Provider service statements and a named historical report establish what was observed, not an assessment of audit quality or a committee endorsement. Confirm current scope, pricing and availability directly.