SERVICE / SMART CONTRACT AUDIT

Smart Contract Audits by Decurity

Decurity is a smart contract audit firm trusted by 1inch, Compound, Yearn, Gearbox and ether.fi, breaking and defending onchain systems since 2017. Deep manual security review across EVM, Solana, TON, Stellar and Sui — delivered by a team, not a single reviewer.

REQUEST AN AUDITTHE FULL RECORD146 published engagements · 62 named clients · 1356 findings
WHAT WE AUDIT

Solidity / EVM

Ethereum, L2s and every EVM chain — DEXs, lending, stablecoins, bridges, restaking.

Solana / Rust

Anchor and native programs, SVM rollups, on-chain and off-chain components.

Vyper

Vyper contracts and mixed Vyper/Solidity systems.

FunC / TON

TON smart contracts and cross-chain messaging.

Move / Sui

Sui Move modules and novel Move implementations.

Consensus & off-chain

L1/L2 forks, relayers, bridges, staking, custody backends, dApps and wallets.

AUDIT METHODOLOGY
01

Pre-audit

Complexity and quality analysis of the codebase (files, SLoC, composability, test coverage, docs), review of past audits, and an intro call with your developers.

02

Blind contest

Phase 1: each auditor works individually and commits hashes of their findings — no groupthink, maximum coverage. We then sync, triage, and issue an intermediate report.

03

Collaborative audit

Phase 2: auditors share findings openly and go deep on the hardest issues, with per-bug incentives that keep the whole team hunting to the last day.

04

Re-test & final report

We review your fixes, re-test the remediation (typically 1–2 days), and deliver the final amended report.

TOOLING
  • +Manual review first — every auditor fully understands the protocol
  • +Our own tooling: a blockchain integration testing toolkit, and a fake-deposit scanner for exchanges and custodians
  • +A powerful agentic pipeline run at kickoff that clears most routine issues, so auditor time goes to the non-trivial ones
  • +Foundry, Echidna and ityFuzz for fuzzing & invariant testing; Slither and our semgrep-smart-contracts rulepack as a floor

Typical audit: 1–2 weeks with a team of four (median, technical lead included); re-test in 1–2 days.

RECENT AUDITS

A live view of Decurity's recent engagements. Public reports link straight to the PDF; confidential engagements are listed with scope and date only.

ENGAGEMENTSCOPEDATE
1inch Network1inch SwapVMJuly 2026
Symbiosis FinanceSymbiosis Depository AuditBridge · SolidityJune 2026
Flap.shFlap Curve Store AuditLaunchpad · SolidityJune 2026
Gearbox ProtocolGearbox Securitize AuditFarming · Leverage · SolidityApril 2026
Flap.shFlap Dividend Contract AuditToken · SolidityApril 2026
Rubic ExchangeRubic Stellar AuditApril 2026
StableStable Update AuditFebruary 2026
1inch Network1inch SwapVM&Aqua Audit 2601DEX · SolidityJanuary 2026
Gearbox ProtocolGearbox Integrations Audit 1225 (KelpLRT)Farming · Leverage · SolidityDecember 2025
StableStable Web2 AuditNovember 2025
VooiVooi Frontend AuditWeb2.5 · TypescriptNovember 2025
VooiVooi Staking AuditStaking · SolidityNovember 2025
VooiVooi Token AuditToken · SolidityNovember 2025
1inch Network1inch SwapVM&Aqua AuditDEX · SolidityOctober 2025
Gearbox ProtocolGearbox Balancer Audit 2510Farming · Leverage · SolidityOctober 2025
Gearbox ProtocolGearbox Mellow Integration Audit 2510Farming · Leverage · SolidityOctober 2025
Gearbox ProtocolGearbox Midas Integration AuditFarming · Leverage · SolidityOctober 2025
Gearbox ProtocolGearBox Oracles Update 1025Farming · Leverage · SolidityOctober 2025
Symbiosis FinanceSymbiosis Depository AuditBridge · BTC · SolidityOctober 2025
StableStable EVM AuditOctober 2025
StableStable Solana AuditOctober 2025
StableStable TON AuditOctober 2025
Jelly LabsJelly Labs - Coinhain VerificationBalancer · Contract Verification · SolidityOctober 2025
1inch Network1inch Fusion Native Swap AuditDEX · Cross-chain · SoliditySeptember 2025
Symbiosis FinanceSymbiosis Octopool AuditSeptember 2025
MortgageFiMortgageFi Update AuditLending · SoliditySeptember 2025
1inch Network1inch Crosschain Update AuditDEX · Cross-chain · Bridge · SolidityAugust 2025
Gearbox ProtocolGearbox Infiniti&Uniswap v4 Integrations 2508Farming · Leverage · SolidityAugust 2025
ALL PUBLIC REPORTS ON GITHUB
SMART CONTRACT AUDIT FAQ

What does a smart contract audit cost?

Decurity scopes each audit on codebase size (SLoC), complexity, composability and the number of auditors required — a quote and timeline come back after a short scoping call and a look at the repository. There is no fixed per-line rate: a self-contained ERC-20 and a cross-chain lending market with off-chain components are not comparable work.

FULL ANSWER →

How long does a smart contract audit take?

A typical Decurity audit runs 1–2 weeks with a team of four (the median across our published engagements, technical lead included), followed by a re-test of your fixes that usually takes 1–2 days. Larger or cross-chain systems are scoped individually.

What do you get at the end?

An intermediate report after the blind-contest phase, then a final amended report once Decurity has reviewed and re-tested your fixes. Every finding carries severity, impact, a reproduction and a concrete remediation. Non-NDA reports are published in full at github.com/Decurity/audits — you can read the exact deliverable before you buy it.

Which blockchains and languages does Decurity audit?

Solidity and Vyper across Ethereum, its L2s and every EVM chain; Rust on Solana (both Anchor and native programs); FunC on TON; Move on Sui; and Stellar. Beyond contracts, Decurity audits L1/L2 forks, consensus layers, bridges, relayers, custody backends, dApps and wallets.

What makes Decurity's audit methodology different?

Phase one is a blind contest: each auditor reviews the code independently and commits hashes of their findings before anyone compares notes, which removes the groupthink that makes a team of five converge on the same three bugs. Only then do auditors pool findings and go deep on the hardest issues, with per-bug incentives that keep the whole team hunting through the final day.

FULL ANSWER →

Is Decurity an approved auditor for any ecosystems?

Yes — Decurity is an approved security auditor for Arbitrum, Optimism, Scroll, Metis, Stellar, PancakeSwap, Holdex and the Areta audit marketplace, so grant recipients and core infrastructure on those networks are routed to Decurity by the ecosystems themselves.

Is "Decurity" the same as "security"?

No — Decurity is a company name, not a misspelling. It is a portmanteau of Decentralized and Security, matching the registered legal entity Decentralized Security LLC-FZ, based in Dubai and founded in 2022 by researchers auditing onchain systems since 2017.

More in the buyer’s guide — including how to evaluate an audit firm, and what to ask before you sign.

Ready for a smart contract audit?

Tell us what you're building and Decurity will reply with a quote and timeline.

REQUEST FORM