OpenZeppelin | Security Audits (2024)

OpenZeppelin | Security Audits (1)

Audits performed by us


High & critical vulns uncovered


Relationship started


OpenZeppelin | Security Audits (2)

OpenZeppelin | Security Audits (3)

Audits performed by us


High & critical vulns uncovered


Relationship started


OpenZeppelin | Security Audits (4)

OpenZeppelin | Security Audits (5)

Audits performed by us


High & critical vulns uncovered


Relationship started


OpenZeppelin | Security Audits (6)

Data collected as of December 31st, 2023

Our team secures leading decentralized exchanges and aggregators.

Read the reports

Engaging with various platforms including AMMs like Bancor V3 and Balancer, the UniswapX order settlement protocol, the Beefy swap router, and the Panoptic options trading platform, which leverages Uniswap V3 liquidity positions, demonstrating our proficiency in V3 concentrated liquidity mathematics. Furthermore, we've completed over 13 audits for 1inch, the premier DEX aggregator.

OpenZeppelin | Security Audits (8)

Audits performed by us


High & critical vulns uncovered


Relationship started


OpenZeppelin | Security Audits (9)

OpenZeppelin | Security Audits (12)

Audits performed by us


High & critical vulns uncovered


Relationship started


OpenZeppelin | Security Audits (13)

Data collected as of December 31st, 2023

We secure L1-L2 bridges, ZK-verifier contracts, and optimistic rollups.

Read the reports

We've identified critical vulnerabilities across a range of areas, including fraud-proof verification, cross-domain transactions, fee mismanagement, and reward system abuses.

Notably, critical issues were discovered in the Linea ZK-verifier, the Scroll message-passing bridge, among other ZK-rollups.

OpenZeppelin | Security Audits (15)

Audits performed by us


High & critical vulns uncovered


Relationship started


OpenZeppelin | Security Audits (16)

OpenZeppelin | Security Audits (17)

Audits performed by us


High & critical vulns uncovered

Relationship started


OpenZeppelin | Security Audits (18)

OpenZeppelin | Security Audits (19)

Audits performed by us


High & critical vulns uncovered


Relationship started


OpenZeppelin | Security Audits (20)

Data collected as of December 31st, 2023

We are the key security partner for leading lending protocols like Compound, Radiant, Venus, and Morpho Blue.

Read the reports

Our researchers have identified several critical vulnerabilities in lending protocols with billions in TVL, including potential bad debt creation in AAVE V3 and stolen rewards in Radiant V2. Serving as Compound's main security partner, we’ve helped establish them as one of the safest platforms in the space.

OpenZeppelin | Security Audits (22)

Audits performed by us


High & critical vulns uncovered


Relationship started


OpenZeppelin | Security Audits (23)

OpenZeppelin | Security Audits (24)

Audits performed by us


High & critical vulns uncovered

Relationship started


OpenZeppelin | Security Audits (25)

Data collected as of December 31st, 2023

Our team expertise extends across the most sophisticated Oracle systems.

Read the reports

These include Chainlink and UMA Protocol, and Oracle-dependent components used by platforms like Compound and Synthetix Oracle manager, which utilize Pyth, Chainlink, and Uniswap V3 TWAP oracles. As UMA's primary security partner, we've conducted over 10 audits, revealing critical vulnerabilities in its optimistic verification system and cross-chain components. Additionally, we've identified high-severity issues in Polymarket's integration with UMA.

OpenZeppelin | Security Audits (27)

Audits performed by us


High & critical vulns uncovered


Relationship started


OpenZeppelin | Security Audits (28)

OpenZeppelin | Security Audits (29)

Audits performed by us


High & critical vulns uncovered

Relationship started


OpenZeppelin | Security Audits (30)

Data collected as of December 31st, 2023

Our first-hand experience auditing multiple Account-Abstraction implementations positions us as leaders in Account Abstraction security.

Read the reports

We worked with the Ethereum Foundation on three audits of Account Abstraction’s EIP-4337, identifying over seven high+ severity issues, enhancing Ethereum protocol’s security. Our discoveries encompassed deposit record manipulations, incorrect gas calculations, and invalid aggregated signature verifications, among others. We also audited Pimlico’s ERC20 token paymaster implementation, allowing users to pay transactions in any ERC20. During this audit, our researchers dived deep into the ERC 4337 paymaster reputation rules.

OpenZeppelin | Security Audits (32)

Audits performed by us


High & critical vulns uncovered


Relationship started


OpenZeppelin | Security Audits (33)

OpenZeppelin | Security Audits (34)

Audits performed by us


High & critical vulns uncovered

Relationship started


OpenZeppelin | Security Audits (35)

Data collected as of December 31st, 2023

We are the security partner for the leading stablecoins.

Read the reports

Back in 2018, we audited Tether, the most used stablecoin in the world. In 2019, our team found a live critical vulnerability affecting MakerDao, the issuer of DAI. Today, we are Origin’s main security partner, performing over 7 audits including the Origin dollar, a yield-bearing decentralized stablecoin. During our engagement with Origin, we added value through multiple findings, including critical findings that would have resulted in yield theft. We also secure Mountain Protocol, issuers of USDM, a yield-bearing rebasing stablecoin backed by T-Bills.

OpenZeppelin | Security Audits (37)

Audits performed by us


High & critical vulns uncovered

Relationship started


OpenZeppelin | Security Audits (38)

Data collected as of December 31st, 2023

Financial Institutions entering the blockchain space face unique challenges regarding security, compliance, and operations.

Read the reports

We partner with leading financial institutions across North America, Latin America, Europe, and Asia as their trusted blockchain advisors. We also audited and provided operational infrastructure for the issuance of the A$DC Australian Dollar stablecoin by the ANZ Bank.

OpenZeppelin | Security Audits (40)

Audits performed by us


High & critical vulns uncovered


Relationship started


OpenZeppelin | Security Audits (41)

OpenZeppelin | Security Audits (42)

Audits performed by us


High & critical vulns uncovered


Relationship started


OpenZeppelin | Security Audits (43)

Data collected as of December 31st, 2023

We secure the leading Gaming and NFT protocols.
We are the authors of the world’s most widely used implementation of ERC721, used by the most popular protocols working with NFTs.

Our work in NFTs encompasses audits for some of the most widely known issuers and exchanges, including Yuga Labs, creators of BAYC, and OpenSea.

In the gaming space, we are The Sandbox’s security partner, performing over 15 audits to their protocol. Other gaming experience includes Decentraland’s MANA token as well as the PoolTogether protocol, finding critical issues that prevented loss of funds due to user duplication in their prize pools.

OpenZeppelin | Security Audits (2024)
Top Articles
Latest Posts
Article information

Author: Fredrick Kertzmann

Last Updated:

Views: 6535

Rating: 4.6 / 5 (66 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Fredrick Kertzmann

Birthday: 2000-04-29

Address: Apt. 203 613 Huels Gateway, Ralphtown, LA 40204

Phone: +2135150832870

Job: Regional Design Producer

Hobby: Nordic skating, Lacemaking, Mountain biking, Rowing, Gardening, Water sports, role-playing games

Introduction: My name is Fredrick Kertzmann, I am a gleaming, encouraging, inexpensive, thankful, tender, quaint, precious person who loves writing and wants to share my knowledge and understanding with you.