EVM smart contract security audits | Veridise

EVM audits

Comprehensive security analysis of your EVM smart contract to identify vulnerabilities and craft guidance on how to fix them.

EVM auditing involves trained professionals manually examining your smart contract code and utilizing our suite of in-house blockchain security tools to facilitate both automated and manual vulnerability discovery. The end result is a thorough smart contract audit that our team assists you to implement.

  TRUSTED BY:

  TRUSTED BY:

EVM audits

EVM audits are a core part of what we do at Veridise. If you’re building EVM smart contracts, we help teams understand their real attack surface early, before deployment.

The Ethereum Virtual Machine (EVM) became the dominant execution environment for on-chain applications, and Solidity became the primary language for expressing contract logic. Solidity compiles to EVM bytecode, which is what actually executes on-chain—meaning security depends on the execution model, not just “clean” high-level code.

Auditing EVM smart contracts requires a wide skill set. It takes hands-on experience with common vulnerability classes, familiarity with widely used DeFi frameworks and patterns (Uniswap/Aave-style design choices), and active engagement with the security community to stay current as best practices evolve.

Before we dive into code, we align on the threat model: MEV searchers, oracle manipulators, privileged roles, governance attackers, and the trust assumptions your system makes, since this is often where teams are unintentionally overconfident.

That last point, understanding what the protocol is trying to do, is where audits are won or lost. In our audit work, a large share of high-severity findings come from protocol-specific logic errors: edge cases where the code is internally consistent but violates the system’s intended behavior. These are always unique to your protocol.

Security is rarely isolated to a single contract. We review integrations, privilege boundaries, and external dependencies, because systems often fail at the seams, not just inside functions.

Building safe code is a discipline that starts at design and continues through deployment and beyond an audit. That’s why we focus on the core invariants of each protocol, making them explicit, checking them during manual review, and turning them into properties we can validate with fuzzing. This helps teams remediate faster and ship with confidence.

What sets Veridise apart in EVM audits?

The Veridise edge: Why us?

Seasoned professionals

Veridise is composed of a team of seasoned security professionals, blending the latest research insights from academia with extensive industry expertise.

AuditHub tools

In addition to rigorous human auditing, our industry-leading tools detect bugs that the human eye has a difficult time finding. This enhances the quality and effectiveness of our audits.

Confidentiality and ownership

Upon request, we uphold the confidentiality of the report, although many of our clients find value in publishing it. Additionally, our reports become fully yours upon completion of the audit, unlike with some other providers.

AuditHub access included.
No extra setup

Access detection tool results instantly, collaborate directly with our auditors, and ensure your fixes are valid.

Veridise’s edge: AuditHub tools

Veridise combines professionals who manually review code with our industry-leading tools.

AuditHub tools enable Veridise to detect hard-to-find bugs that are difficult for the human eye to identify, leading to comprehensive audit reports. With Veridise, your codebase is in the hands of industry-leading detection methods.

Vanguard

Smart contract tool

Static analysis tool for smart contracts

Picus

ZK tool

Formal verification tool for ZK circuit determinism

OrCa

Smart contract tool

Specification-guided fuzzer

ZK Vanguard

ZK tool

Static analysis tool for zero-knowledge circuits

Veridise audit or traditional audit?
See the difference

Veridise audit with
AuditHub

Traditional
audit

Our experience auditing EVM

Auditing EVM code requires a wide skill set, including experience with common vulnerabilities, deep knowledge of common frameworks like Uniswap/AAVE, active engagement with the security community to stay up to date, and an ability to analyze new protocols at a high level to understand the intended behavior.

This last point is especially important. When reviewing EVM smart contracts, we have found that around half of the high and critical vulnerabilities come from logic errors specific to the project application.

Building safe code is a practice that starts from the very first design and continues up to and after an audit. This is why our teams work to understand the core invariants of each protocol, creating formally specifying these properties to integrate into both manual review and fuzzing efforts.

Our EVM audit process

1. Assessment

Our experts assess the scope of the audit: We check the source repository and set key requirements to be verified.

2. Review

At the next step, our team formalizes key properties of your project and utilizes our proprietary analysis tools to check for common vulnerabilities and deeper logical bugs.

3. Report

At the end of the audit, we deliver a detailed Solidity audit report summarizing our findings and recommendations. Our reports include any uncovered vulnerabilities, their potential impact, and mitigation strategies.

4. Fixes & Fixes Review

Our clients’ teams fix discovered bugs and vulnerabilities. The Veridise team then verifies the new code to ensure it is secure.

5. Final Report

Once all bug fixes are verified, we issue a final audit report and it is up to our clients whether to make the final report public or not.

EVM resources

These blockchain security resources may help you learn the fundamental methods of blockchain auditing.

Academic work on auditing smart contracts

SmartPulse: Automated Checking of Temporal Properties in Smart Contracts

IEEE Symposium
on Security and Privacy (Oakland)

Synthesis-Powered Optimization of Smart Contracts via Data Type Refactoring

Object-oriented Programming, Systems, Languages and Applications (OOPSLA)

SolType: Refinement Types for Arithmetic Overflow in Solidity

Principles
of Programming Languages (POPL)

Formal Verification of Workflow Policies for Smart Contracts in Azure Blockchain

Verified Software:
Theories, Tools, Experiments (VSTTE)

Explore our EVM audit reports

Review our publicly available EVM audit reports below.

ProtocolResource
Start Date
CompanyLanguage(s)Tag(s)
ThetaNuts: Accreta MarketsReportFeb 2026ThetaNutsSoliditySmart Contracts, Solidity
Boundless: KailuaReportFeb 2026BoundlessSoliditySmart Contracts, zkVM Application, Solidity, OP-Stack Dispute Game, risc0
GumBall Labs: STICKRReportSep 2025GumBall LabsSoliditySmart Contracts, Solidity, Social, AMM, Launchpad, OpenZeppelin
Wormhole: Boundless TransceiverReportSep 2025WormholeSolidity, RustSmart Contracts, zkVM Application, Solidity, Risc0, Rust, OpenZeppelin, wormhole
Boundless: Fulfilment DataReportSep 2025BoundlessRust, SoliditySmart Contracts, zkVM Application, Risc0, Solidity, Rust, Auction
Aztec: GovernanceReportAug 2025AztecSoliditySmart Contracts, Solidity, OpenZeppelin
RISC Zero: ZKC StakingReportAug 2025RISC ZeroSoliditySmart Contracts, Solidity, Staking, ERC721, Token / ERC20
Wormhole: Boundless ReceiverReportAug 2025WormholeSolidity, RustSmart Contracts, Solidity, Risc0, Rust, OpenZeppelin, wormhole
3Jane: Morpho BlueReportAug 20253JaneSoliditySmart Contracts, Solidity, Lending, ERC4626
Succinct: SP1 Call ContractReportJun 2025SuccinctSolidity, RustSP1, Solidity, zkVM Application
RISC Zero: Kailua ProtocolReportMay 2025Risc ZeroRust, SoliditySmart Contracts, zkVM Application, Solidity, Risc0, Rust, OP-Stack Dispute Game, Optimism, Alloy, risc0
AlephZero: Common Yield AggregatorReportMay 2025Cardinal CryptographySoliditySmart Contracts, Solidity, Vault, OpenZeppelin
Fluent: Bridge ContractsReportMay 2025Fluent LabsSoliditySmart Contracts, Solidity, Blockchain, ZK Rollup, OpenZeppelin, SP1
Sygma Labs: Sprinter Liquidity PoolReportMar 2025Sygma LabsSoliditySmart Contracts, Solidity, Cross-Chain, Vault
RiscZero: BoundlessReportMar 2025Risc ZeroSolidity, RustSmart Contracts, zkVM Applications, Risc0, Solidity, Rust, Library/Infrastructure
Sygma Labs: Sprinter Liquidity MiningReportFeb 2025Sygma LabsSoliditySmart Contracts, Solidity, Staking
Inception: InceptionLRTReportFeb 2025InceptionLRTSoliditySmart Contracts, Solidity, Restaking, Vault
vlayerReportFeb 2025vlayerSolidity, RustSmart Contracts, Solidity, ZK Circuits, zkVM Application
Malda: zk-coprocessorReportJan 2025MaldaRustSmart Contracts, Solidity, ZK Circuits, zkVM Application
Malda: LendingReportJan 2025MaldaSoliditySmart Contracts, Solidity, ZK Circuits, zkVM Application
Catalyst: Bitcoin Prism & Cross CatsReport1, Report2Oct 2024Cata LabsSoliditySmart Contracts, Solidity, AMM, Cross-Chain, Light Client
Panther: Panther ProtocolReportSep 2024Panther ProtocolCircom, SolidityZK Circuits, Smart Contracts, Circom, Solidity, Shielded Pools, circomlib
DeFi84Sep 2024Sygma LabsSoliditySmart Contracts, Solidity, Substrate, Bridge, Cross-Chain
DeFi #83Aug 2024Sygma LabsSoliditySmart Contracts, Solidity
DeFi #83Aug 2024SoliditySmart Contracts, Solidity, Staking, Token / ERC20
Smoo.th: Smooth Crypto LibraryReportJul 2024Smoo.thSoliditySmart Contracts, Solidity, Library/Infrastructure
Arianee Full Privacy ExtensionReport1, Report2Jul 2024ArianeeCircom,SoliditySmart Contracts, ZK Circuits, Circom, Solidity, Identity, NFT Marketplace
DeFi #80Jul 2024SoliditySmart Contracts, Gnark, Solidity, zkVM
DeFi #79Jul 2024Good EntrySoliditySmart Contracts, Solidity, Auction, Vault
DeFi #78Jun 2024SoliditySmart Contracts, Solidity, Vault
Lombard: LBTC ReportJun 2024Lombard FinanceSoliditySmart Contracts, Solidity, Bridge, Cross-Chain, Liquid Staking
DeFi #76Jun 2024Generative LabsSoliditySmart Contracts, Solidity, AMM
DeFi #75Jun 2024Manta NetworkSoliditySmart Contracts, Solidity, Vault
DeFi #73May 2024SoliditySmart Contracts, Solidity, NFT Marketplace
Arbitrum Constructor ContractReportMay 2024onthisSoliditySmart Contracts, Solidity, Rewards / Distribution, Token / ERC20
DeFi #72May 2024Manta NetworkSoliditySmart Contracts, Solidity, Cross-Chain
DeFi #71May 2024Manta NetworkSoliditySmart Contracts, Solidity, Cross-Chain, Staking
3Jane: AmplolReportMay 20243JaneSoliditySmart Contracts, Solidity, Vault
DeFi #68May 2024SoliditySmart Contracts, Solidity, Cross-Chain, Liquid Staking, Rewards / Distribution
DeFi #67May 2024SoliditySmart Contracts, Solidity
GingerJoy: FundoraReportApr 2024Ginger Joy GamesSoliditySmart Contracts, Solidity, Games, Rewards / Distribution
3Jane: 3JANE-EETH-X-CReportApr 20243JaneSoliditySmart Contracts, Solidity, Vault
Ankr: BNB Liquid StakingReportApr 2024AnkrSoliditySmart Contracts, Solidity, Liquid Staking
Inception: bridgeReportApr 2024InceptionLRTSoliditySmart Contracts, Solidity, Bridge, Cross-Chain
DeFi #54Mar 2024SoliditySmart Contracts, Solidity, Rewards / Distribution, Staking
Edgeless Network ContractsReportMar 2024Satori FinanceSoliditySmart Contracts, Solidity, Cross-Chain, Liquid Staking, Staking
Range Protocol: Vault Updates and Vertex VaultReport1, Report2Mar 2024Range ProtocolSoliditySmart Contracts, Solidity, Liquid Staking, Vault
Cata Labs: Generalised Incentives TimeoutReportMar 2024Cata LabsSoliditySmart Contracts, Solidity, Cross-Chain
DeFi #50Feb 2024AnkrSoliditySmart Contracts, Solidity, Payments
Native: AquaReportFeb 2024NativeSoliditySmart Contracts, Solidity, Request for Quote (RFQ), Vault
Venture23: Ethereum-Aleo BridgeReportFeb 2024Venture23Leo,Solidity,TypescriptRelayer/Off-Chain Backend Service, Smart Contracts, ZK Circuits, Leo, Solidity, mongoose, Bridge, Cross-Chain
ZK #9Feb 2024Panther ProtocolSoliditySmart Contracts, ZK Circuits, Circom, Solidity, KYC, Shielded Pools
DeFi #55Feb 2024RustRelayer/Off-Chain Backend Service, Smart Contracts, AWS, Solidity, Soroban, ethers, Bridge, Cross-Chain
DeFi #47Jan 2024SoliditySmart Contracts, Solidity, NFT Marketplace
TIE Finance: WBTC Lending StrategyReportJan 2024TIE FinanceSoliditySmart Contracts, Solidity, Lending
ZK #5Jan 2024Sygma LabsRust,SoliditySmart Contracts, ZK Circuits, Halo2, Solidity, Light Client
DeFi #45Jan 2024SoliditySmart Contracts, Solidity
DeFi #49Jan 2024Manta NetworkSoliditySmart Contracts, Solidity, Rewards / Distribution
Ribbon: Aevo GovernanceReportJan 2024Ribbon FinanceSoliditySmart Contracts, Solidity, Staking, Token / ERC20
Cata Labs: Generalised Incentives and UnderwritingReport1, Report2Jan 2024Cata LabsSoliditySmart Contracts, Solidity, AMM, Cross-Chain
DeFi #41Jan 2024Manta NetworkSoliditySmart Contracts, Solidity, Token / ERC20
DeFi #48Jan 2024SuccinctSoliditySmart Contracts, Solidity, Transaction Execution
Source Code Verification #2Dec 2023SoliditySmart Contracts, Solidity, AMM
Genesis Liquid RestakingReportDec 2023GenesisLRTSoliditySmart Contracts, Solidity, Restaking
AsMatch: AsMatch Token and wUSDMReport1, Report2Dec 2023AsMatchSoliditySmart Contracts, Solidity, Token / ERC20
DeFi #36Dec 2023SoliditySmart Contracts, Solidity, Vault
DeFi #38Dec 2023SoliditySmart Contracts, Solidity, Rewards / Distribution
StakeStoneReportDec 2023StakeStoneSoliditySmart Contracts, Solidity, Vault
Meow ProtocolReportNov 2023Meow Protocol SoliditySmart Contracts, Solidity, Lending
DeFi #40ReportNov 2023Mesosphere LtdSoliditySmart Contracts, Solidity
DeFi #29Nov 2023DappLabsSoliditySmart Contracts, Solidity, Transaction Execution
Tie Finance: Eth Leverage On AAVEReportNov 2023TIE FinanceSoliditySmart Contracts, Solidity, Vault
Daimo WebauthnReportNov 2023Daimo PaySoliditySmart Contracts, Solidity, Account Abstraction / ERC 4337
GoodEntry geV2ReportOct 2023Good EntrySoliditySmart Contracts, Solidity, Options, Vault
Atem NetworkReportOct 2023Atem NetworkSoliditySmart Contracts, Solidity, Vesting
Tomo V2ReportOct 2023Mesosphere LtdSoliditySmart Contracts, Solidity, Rewards / Distribution
Ribbon: Aevo Hybrid sDAIReportOct 2023Ribbon FinanceSoliditySmart Contracts, Solidity, Options, Vault
Aperture FinanceReportSep 2023Aperture FinanceSoliditySmart Contracts, Solidity
Ribbon: Aevo ExchangeReportSep 2023Ribbon FinanceSoliditySmart Contracts, Solidity, Options
Daimo P256VerifierReport1, Report2Sep 2023Daimo PaySoliditySmart Contracts, Solidity, Account Abstraction / ERC 4337
Range Vault Manager Contracts Range GHO VaultReport1, Report2Sep 2023Range ProtocolSoliditySmart Contracts, Solidity, Vault
DeFi #16Aug 2023SoliditySmart Contracts, Solidity
DeFi #22Aug 2023SoliditySmart Contracts, Solidity, Games
Gamma Protocol | UnwindingReportJul 2023Ribbon FinanceSoliditySmart Contracts, Solidity, Yields
DeFi #18ReportJul 2023VersaSoliditySmart Contracts, Solidity, Account Abstraction / ERC 4337
Webb Tools: EVM BridgeReportJul 2023Webb ToolsSolidityZK Circuits, Circom, Solidity, Bridge, Cross-Chain
DeFi #23Jul 2023SoliditySmart Contracts, Solidity, NFT Marketplace
Puffer: RAVeReportJul 2023Puffer FinanceSoliditySmart Contracts, Solidity, Library/Infrastructure
L-TokenReportJun 2023Mesosphere LtdSoliditySmart Contracts, Solidity, Token / ERC20
DeFi #24Jun 2023SoliditySmart Contracts, Solidity, Bridge, Token / ERC20
VersaJun 2023SoliditySmart Contracts, Solidity
Davos #2ReportMay 2023Sikka TechnologySoliditySmart Contracts, Solidity
AlloyX #3May 2023AlloyXSoliditySmart Contracts, Solidity
Shib Original Vision LockerReportMay 2023Mesosphere LtdSoliditySmart Contracts, Solidity
Prime Protocol #3ReportMay 2023Prime ProtocolSoliditySmart Contracts, Solidity, Cross-Chain, Stablecoin
DeFi #25May 2023SoliditySmart Contracts, Solidity, NFT Marketplace
DeFi #19May 2023Manta NetworkRustSmart Contracts, Solidity, NFT Marketplace
Rate Limiting NullifierReportMay 2023Ethereum PSECircom,SoliditySmart Contracts, ZK Circuits, Circom, Solidity
DeFi #15Apr 2023SoliditySmart Contracts, Solidity, AMM
Satori: DwBizReportApr 2023Satori FinanceSoliditySmart Contracts, Solidity
DeFi #13Apr 2023SoliditySmart Contracts, Solidity, Staking
Shib Original VisionReportApr 2023Mesosphere LtdSoliditySmart Contracts, Solidity, Token / ERC20
UnirepReportApr 2023Ethereum PSESoliditySmart Contracts, ZK Circuits, Circom, Solidity, Reputation
Sismo CommitmentMapperReportMar 2023SismoSolidityZK Circuits, Solidity, Reputation
Sismo HydraS2ReportMar 2023SismoSolidityZK Circuits, Circom, Solidity
Gamma ProtocolReportMar 2023Ribbon FinanceSoliditySmart Contracts, Solidity, Options
Prime Protocol #2ReportMar 2023Prime ProtocolSoliditySmart Contracts, Solidity, Cross-Chain, Stablecoin, Staking
Cata Labs CatalystReportFeb 2023Cata LabsSoliditySmart Contracts, Solidity, AMM, Cross-Chain
PoolsharkReportFeb 2023PoolsharkSoliditySmart Contracts, Solidity, AMM
ANKR Token StakingReportFeb 2023AnkrSoliditySmart Contracts, Solidity, Staking
ANKR BNB Token StakingReportJan 2023AnkrSoliditySmart Contracts, Solidity, Staking
AlloyX #2Jan 2023AlloyXSoliditySmart Contracts, Solidity, Staking, Yields
Scroll ZkEVMJan 2023ScrollRustBlockchain Implementation, ZK Circuits, Solidity, Blockchain
DeFi #4Dec 2022Circom,SoliditySmart Contracts, ZK Circuits, Circom, Solidity
Parallel #2ReportDec 2022Para ChainSoliditySmart Contracts, Solidity, Lending
SemaphoreReportDec 2022SemaphoreSoliditySmart Contracts, ZK Circuits, Circom, Solidity, Identity
DeFi #2Nov 2022SoliditySmart Contracts, Solidity, NFT Marketplace
Dogechain #3Oct 2022DogechainSoliditySmart Contracts, Solidity, Library/Infrastructure
Prime Protocol #1ReportAug 2022Prime ProtocolSoliditySmart Contracts, Solidity, Cross-Chain, Lending
Dogechain #2Aug 2022DogechainSolidityBlockchain Implementation, Solidity
Davos #1Aug 2022Sikka TechnologySoliditySmart Contracts, Solidity, Rewards / Distribution, Stablecoin
Ribbon EarnReportJul 2022Ribbon FinanceSoliditySmart Contracts, Solidity, Staking
AlloyXReportJul 2022AlloyXSoliditySmart Contracts, Solidity, Staking, Yields
Infrastructure #1Jul 2022SoliditySmart Contracts, Solidity, Library/Infrastructure
DeFi #1Jun 2022SoliditySmart Contracts, Solidity, Orderbook
HelioReportMay 2022HelioSoliditySmart Contracts, Solidity, Rewards / Distribution, Stablecoin
Parallel #1ReportMay 2022Para ChainSoliditySmart Contracts, Solidity
Dogechain #1ReportMay 2022DogechainGo,SolidityBlockchain Implementation, Smart Contracts, Solidity

FAQs

Frequently asked questions

What is an EVM audit?

An EVM audit is a structured security review of your smart contracts to find vulnerabilities, logic errors, and risky design assumptions before deployment. It combines manual expert review with AuditHub tooling, ending in a written report with severity ratings and concrete fixes.

EVM audit covers areas such as contract logic, access control, upgradeability patterns, external call flows, and dependency risks (libraries, oracles, bridges, etc.). It also checks for common vulnerability classes like reentrancy, price manipulation, and signature misuses plus alignment with your threat model.

Most audits take ~1–4 weeks, end-to-end, depending on code size, complexity, and how quickly the team can answer questions. Time also includes report writing and a fix review phase.

Pricing is driven by engineering effort (person-days) based on scope: number of contracts/lines and protocol complexity. Veridise audits always include senior security analyst and include thorough code review—not just automated scanning.

Have a clear scope, solid tests, and docs that explain invariants and privileged roles, plus any known risks you’re accepting. The fastest audits happen when engineers are available to answer any questions that arise.

Veridise is the choice of industry-leaders

We have audited some of the most critical protocols in the blockchain space, with billions of dollars in Total Value Locked.

Considering EVM audit?

Don’t leave your project’s security to chance.
Get verified by Veridise and secure your smart contract.

Contact us for a security audit quote

Secure an earlier audit slot by reaching out early.

 

Contact us for a security audit quote

Secure an earlier audit slot by reaching out early.