Smart contractaudits
Manual, line by line security reviews for BNB Chain and EVM contracts. Every finding quotes the offending code. Every report ends with a straight answer to the only question that matters: can funds leave?
We do not audit code we wrote. If we built any part of a system, it is stated on the front page of the report.
- ERC20 / BEP20 tokens
- Staking and vesting
- AMMs and liquidity pools
- NFT collections and marketplaces
- Upgradeable proxies (UUPS, Transparent)
- Multisigs and treasury contracts
- Bridges, case by case
- BNB Chain
- Ethereum
- Base
- Polygon
- Arbitrum
- Any EVM chain
- Solidity
Request
You send the repository or the deployed addresses, the commit you want reviewed, and your deadline. You get an acknowledgement the same day.
Scoping
We read the code, count the lines in scope, and flag anything that changes the cost: proxies, oracles, external calls, assembly. You get a scope document naming exact files and a commit hash, plus what is explicitly excluded.
Quote & agreement
A fixed quote and a delivery date, not an hourly estimate. Fifty percent upfront, or the full amount on small engagements. The code is frozen at the agreed commit.
Review
Manual line by line review first. Static analysis and fuzzing run alongside it, never instead of it. We write a threat model of who can move funds and under what conditions.
Preliminary report
Delivered privately. Every finding has a severity, the offending code quoted, the impact spelled out, and a recommended fix.
Fix review
You fix and send a new commit. We verify each fix individually. Every finding closes as Fixed, Acknowledged, or Won't fix — nothing is left ambiguous.
Final report & publish
A PDF and a permanent page here with a report ID. If the contract is deployed, we verify the on chain bytecode matches the audited commit and state that in the report. You can then submit the report URL to Etherscan or BscScan so it shows on the contract page.
- Line by line review of every file in scope
- A written threat model: who can move funds, and how
- Access control and privilege escalation paths
- Economic and incentive analysis, not just code correctness
EEA EthTrust Security Levels v3
Our review maps to levels [S], [M] and [Q]. We state which we reached.
OWASP SCSVS
Used as a coverage checklist so categories are not skipped.
Tools catch the known patterns. They do not catch broken business logic, and they cannot tell you whether an admin key is a backdoor. That is what the manual pass is for.
Fixed
Re-reviewed at a new commit and confirmed resolved.
Acknowledged
Client accepts the risk and has documented why.
Won't fix
Out of scope, or intentional. Stated plainly in the report.
Scope
Exact file list, the commit hash reviewed, deployed addresses if any, and what was explicitly excluded.
Executive summary
What the system does, what we reviewed, and the headline result in plain language.
Findings
Each with an ID, severity, the offending code quoted, impact, a reproduction where one applies, and a recommended fix.
Admin and owner powers
Every privileged function, who holds the key, and what they could do with it. Including the things that are not bugs.
Can funds leave?
A direct answer to the only question most holders actually care about, with the paths traced.
Bytecode match
For deployed contracts, confirmation that the on chain bytecode corresponds to the audited commit.
Fix review
Each finding re-checked at the fix commit, and closed as Fixed, Acknowledged, or Won't fix.
Disclaimer
What this audit does and does not cover. Stated plainly, not buried.
No published reports yet
Reports appear here once a client agrees to publish. We will not pad this list with audits that did not happen, and we will not name a client who asked us not to. When the first report is public it will sit here with its full findings, its scope commit and its report ID.
Price follows lines of code in scope and how much of it is non standard. Proxies, oracles, external calls and assembly cost more to review than a plain token. We quote a number and a date, and we hold both.
Under 300 lines
3–5 days
A token, a vesting contract, a simple staking pool.
300–1,000 lines
1–2 weeks
A protocol with several interacting contracts.
Over 1,000 lines
Quoted individually
Multi contract systems, bridges, anything upgradeable.
Do you audit code you wrote yourselves?
No. We do not audit code we built. If DevsBazaar wrote any part of a system, that is stated on the front page of the report and we recommend a second opinion from an unrelated firm. An audit is only worth something if the auditor can afford to fail the client.
Is the report confidential?
Yes, until you choose otherwise. The preliminary and final reports are delivered privately. Nothing is published to this site, and no client is named anywhere, without your written go ahead.
How does it show on BscScan or Etherscan?
Once the report is public at a permanent URL, the report link is submitted through the explorer's Security Audit Report form, along with the contract address, the provider name and the audit date. Approved submissions appear in a Contract Security Audit section on the contract page. The explorer reviews submissions manually and we cannot guarantee their decision or their timeline.
What does a re-audit cost?
Fix verification on the findings we raised is included. A re-audit after new features or a significant refactor is scoped and quoted as fresh work, usually at a reduced rate since we already know the codebase.
What does an audit not guarantee?
It is not a guarantee that the code is safe. We review a specific commit, in a defined scope, for a defined period. It cannot cover code changed afterwards, the deployment configuration, key management, off chain infrastructure, or the honesty of the team holding admin keys. An audit reduces risk. It does not remove it.
What do you need from us to start?
A repository link with the commit you want reviewed, or the deployed addresses. Documentation or a spec if you have one, since a bug is only a bug against intended behaviour. Access to a developer who can answer questions during the review.
Send us the commit.
We will send a quote.
Repository or deployed addresses, the commit you want reviewed, and your deadline. Scope and a fixed quote back within 48 hours.
An audit reduces risk. It is not a guarantee of security.
