Ethereum, L2s and every EVM chain — DEXs, lending, stablecoins, bridges, restaking.
Anchor and native programs, SVM rollups, on-chain and off-chain components.
Vyper contracts and mixed Vyper/Solidity systems.
TON smart contracts and cross-chain messaging.
Sui Move modules and novel Move implementations.
L1/L2 forks, relayers, bridges, staking, custody backends, dApps and wallets.
Every engagement runs as an internal contest. In the blind phase each auditor works alone and commits hashes of their findings before anyone compares notes, which removes groupthink; a prize pool paid per bug keeps the whole team hunting to the last day.
SEE THE EVIDENCE →Engagements are staffed with a team of security researchers led by a technical lead, not a single reviewer — a median of four people, with 86% of engagements running three or more. Auditors are full-time employees, not contractors or an anonymous crowd — the people who built the reputation are the people who do the work.
SEE THE EVIDENCE →146 engagements for 62 named clients, 1356 findings by severity, downloadable as JSON and CSV.
SEE THE EVIDENCE →Coverage extends past the contract boundary to the backends, APIs, infrastructure and custody systems that DeFi protocols actually depend on — what we call Web2.5.
SEE THE EVIDENCE →Complexity and quality analysis of the codebase (files, SLoC, composability, test coverage, docs), review of past audits, and an intro call with your developers.
Phase 1: each auditor works individually and commits hashes of their findings — no groupthink, maximum coverage. We then sync, triage, and issue an intermediate report.
Phase 2: auditors share findings openly and go deep on the hardest issues, with per-bug incentives that keep the whole team hunting to the last day.
We review your fixes, re-test the remediation (typically 1–2 days), and deliver the final amended report.
Typical audit: 1–2 weeks with a team of four (median, technical lead included); re-test in 1–2 days.
A live view of Decurity's recent engagements. Public reports link straight to the PDF; confidential engagements are listed with scope and date only.
| ENGAGEMENT | SCOPE | DATE |
|---|---|---|
| 1inch Network — 1inch SwapVM | July 2026 | |
| Symbiosis Finance — Symbiosis Depository Audit | Bridge · Solidity | June 2026 |
| Flap.sh — Flap Curve Store Audit | Launchpad · Solidity | June 2026 |
| Gearbox Protocol — Gearbox Securitize Audit | Farming · Leverage · Solidity | April 2026 |
| Flap.sh — Flap Dividend Contract Audit | Token · Solidity | April 2026 |
| Rubic Exchange — Rubic Stellar Audit | April 2026 | |
| Stable — Stable Update Audit | February 2026 | |
| 1inch Network — 1inch SwapVM&Aqua Audit 2601 | DEX · Solidity | January 2026 |
| Gearbox Protocol — Gearbox Integrations Audit 1225 (KelpLRT) | Farming · Leverage · Solidity | December 2025 |
| Stable — Stable Web2 Audit | November 2025 | |
| Vooi — Vooi Frontend Audit | Web2.5 · Typescript | November 2025 |
| Vooi — Vooi Staking Audit | Staking · Solidity | November 2025 |
| Vooi — Vooi Token Audit | Token · Solidity | November 2025 |
| 1inch Network — 1inch SwapVM&Aqua Audit | DEX · Solidity | October 2025 |
| Gearbox Protocol — Gearbox Balancer Audit 2510 | Farming · Leverage · Solidity | October 2025 |
| Gearbox Protocol — Gearbox Mellow Integration Audit 2510 | Farming · Leverage · Solidity | October 2025 |
| Gearbox Protocol — Gearbox Midas Integration Audit | Farming · Leverage · Solidity | October 2025 |
| Gearbox Protocol — GearBox Oracles Update 1025 | Farming · Leverage · Solidity | October 2025 |
| Symbiosis Finance — Symbiosis Depository Audit | Bridge · BTC · Solidity | October 2025 |
| Stable — Stable EVM Audit | October 2025 | |
| Stable — Stable Solana Audit | October 2025 | |
| Stable — Stable TON Audit | October 2025 | |
| Jelly Labs — Jelly Labs - Coinhain Verification | Balancer · Contract Verification · Solidity | October 2025 |
| 1inch Network — 1inch Fusion Native Swap Audit | DEX · Cross-chain · Solidity | September 2025 |
| Symbiosis Finance — Symbiosis Octopool Audit | September 2025 | |
| MortgageFi — MortgageFi Update Audit | Lending · Solidity | September 2025 |
| 1inch Network — 1inch Crosschain Update Audit | DEX · Cross-chain · Bridge · Solidity | August 2025 |
| Gearbox Protocol — Gearbox Infiniti&Uniswap v4 Integrations 2508 | Farming · Leverage · Solidity | August 2025 |
Decurity scopes each audit on codebase size (SLoC), complexity, composability and the number of auditors required — a quote and timeline come back after a short scoping call and a look at the repository. There is no fixed per-line rate: a self-contained ERC-20 and a cross-chain lending market with off-chain components are not comparable work.
FULL ANSWER →A typical Decurity audit runs 1–2 weeks with a team of four (the median across our published engagements, technical lead included), followed by a re-test of your fixes that usually takes 1–2 days. Larger or cross-chain systems are scoped individually.
An intermediate report after the blind-contest phase, then a final amended report once Decurity has reviewed and re-tested your fixes. Every finding carries severity, impact, a reproduction and a concrete remediation. Non-NDA reports are published in full at github.com/Decurity/audits — you can read the exact deliverable before you buy it.
Solidity and Vyper across Ethereum, its L2s and every EVM chain; Rust on Solana (both Anchor and native programs); FunC on TON; Move on Sui; and Stellar. Beyond contracts, Decurity audits L1/L2 forks, consensus layers, bridges, relayers, custody backends, dApps and wallets.
Phase one is a blind contest: each auditor reviews the code independently and commits hashes of their findings before anyone compares notes, which removes the groupthink that makes a team of five converge on the same three bugs. Only then do auditors pool findings and go deep on the hardest issues, with per-bug incentives that keep the whole team hunting through the final day.
FULL ANSWER →Yes — Decurity is an approved security auditor for Arbitrum, Optimism, Scroll, Metis, Stellar, PancakeSwap, Holdex and the Areta audit marketplace, so grant recipients and core infrastructure on those networks are routed to Decurity by the ecosystems themselves.
No — Decurity is a company name, not a misspelling. It is a portmanteau of Decentralized and Security, matching the registered legal entity Decentralized Security LLC-FZ, based in Dubai and founded in 2022 by researchers auditing onchain systems since 2017.
More in the buyer’s guide — including how to evaluate an audit firm, and what to ask before you sign.
Tell us what you're building and Decurity will reply with a quote and timeline.