Smart contract security

Smart Contract Audit

Find exploitable contract behavior before launch. Get a scoped manual review, actionable findings, and a clear path through remediation, with public reports you can inspect before choosing CTDSEC.

Inspect the work before choosing an auditor

Three examples from the wider public report archive, with reviewed scope and remediation status.

DEXTools Token Creator

Review the DEXTools Token Creator audit for repository scope, token-factory findings, and the development team's responses. The report records one medium, one low, and one informational finding as acknowledged, with no high-severity findings listed.

Read Audit Report

URMCDP

The URMCDP report examines collateralized borrowing, interest accrual, liquidation, oracle behavior, and configuration changes. Its final table records three high-severity findings (one acknowledged and two resolved) and five medium-severity findings marked resolved.

Read Audit Report

PWRAuctionCrossChain

The PWRAuctionCrossChain audit follows bidding, buyer identity, token claims, vesting, and administrative escrow controls across contract boundaries. The final table records four high and two medium findings as resolved, with one low and one informational finding acknowledged.

Read Audit Report

These are examples, not the entire portfolio. Explore all public audit reports.

A clear scope before a quote

Start with what your protocol does and when you expect to launch. To prepare a meaningful proposal, we clarify the repository and target revision, contracts in scope, assets at risk, dependencies, documentation, tests, and any exclusions.

Price and turnaround depend on that scope and the remediation work requested. A token factory and a lending system with external oracles need different review plans. Compare proposals on coverage, deliverables, and fix verification, not a headline price alone.

What affects audit cost? Review our auditor selection guide before requesting proposals.

Know what happens after findings

The report should connect each finding to affected code, impact, and remediation guidance. When fix verification is included, provide a new revision and change summary so the review can distinguish resolved findings from accepted risks.

An acknowledged finding is not a verified fix. A report covers its documented code and assumptions; it is not insurance against every vulnerability or automatic coverage for later upgrades.

Read the scope and remediation workflow.

A smart contract audit should find exploitable behavior before attackers, market conditions, or governance edge cases do. CTDSEC reviews contract logic, threat models, privileged roles, deployment assumptions, upgrade paths, tests, and protocol economics with the mindset of an adversary.

The audit process is built for teams that need practical findings, clear severity classification, remediation guidance, and a final report that can be shared with users, investors, exchanges, partners, or governance communities.

What CTDSEC reviews

The review is tailored to the target chain and codebase, but the audit always starts with assets at risk, trust boundaries, and the concrete ways the protocol can fail.

Audit focus

Smart Contract Audit with manual review, tool-assisted coverage, and remediation support.

Manual reviewTool-assistedRemediation support

Audit Coverage

  • Business-logic invariants and economic assumptions
  • Access control, ownership, role management, and timelocks
  • Reentrancy, external calls, callback behavior, and state ordering
  • Oracle, pricing, liquidity, and MEV-sensitive logic
  • Upgradeability, initialization, proxy storage, and admin operations
  • Test quality, deployment scripts, dependencies, and verification steps

Risk Areas

  • Loss of funds through missing validation or incorrect accounting
  • Governance or owner-key abuse paths
  • Token supply, fee, reward, or liquidation calculation errors
  • Cross-contract assumptions that fail under adversarial ordering
  • Deployment or upgrade mistakes that create permanent risk

Deliverables

  • Audit scope and commit reference
  • Severity-classified findings with impact and remediation notes
  • Manual review notes and tool-assisted testing results
  • Client remediation support and fix verification when requested
  • Final public or private report based on the agreed disclosure model

Smart Contract Audit FAQ

Short answers for teams preparing an audit scope.

What does a smart contract audit include?

It includes scope confirmation, manual code review, tool-assisted analysis where useful, severity-ranked findings, remediation guidance, and a final report for the agreed disclosure model.

Can CTDSEC review fixes after the audit?

Yes. Fix verification can be included after the team remediates reported findings, using a new commit and a clear change summary.

How is a smart contract audit priced?

The quote depends on the agreed code scope, complexity, dependencies, and remediation review. Start with a project description; we can clarify repository access and timeline by email.

Get a smart contract audit quote

Tell us what you are building and when you plan to launch. Start with a short description; repository access and technical scope can follow.

Get an Audit Quote