Security Reviews

Smart contractaudits

Manual, line by line security reviews for BNB Chain and EVM contracts. Every finding quotes the offending code. Every report ends with a straight answer to the only question that matters: can funds leave?

View Reports

We do not audit code we wrote. If we built any part of a system, it is stated on the front page of the report.

01What we audit
Scope
Contract types
  • ERC20 / BEP20 tokens
  • Staking and vesting
  • AMMs and liquidity pools
  • NFT collections and marketplaces
  • Upgradeable proxies (UUPS, Transparent)
  • Multisigs and treasury contracts
  • Bridges, case by case
Chains
  • BNB Chain
  • Ethereum
  • Base
  • Polygon
  • Arbitrum
  • Any EVM chain
Languages
  • Solidity
02How it works
7 steps
01Same day

Request

You send the repository or the deployed addresses, the commit you want reviewed, and your deadline. You get an acknowledgement the same day.

021–2 days

Scoping

We read the code, count the lines in scope, and flag anything that changes the cost: proxies, oracles, external calls, assembly. You get a scope document naming exact files and a commit hash, plus what is explicitly excluded.

0324–48h

Quote & agreement

A fixed quote and a delivery date, not an hourly estimate. Fifty percent upfront, or the full amount on small engagements. The code is frozen at the agreed commit.

043 days – 3 weeks

Review

Manual line by line review first. Static analysis and fuzzing run alongside it, never instead of it. We write a threat model of who can move funds and under what conditions.

05On completion

Preliminary report

Delivered privately. Every finding has a severity, the offending code quoted, the impact spelled out, and a recommended fix.

062–5 days

Fix review

You fix and send a new commit. We verify each fix individually. Every finding closes as Fixed, Acknowledged, or Won't fix — nothing is left ambiguous.

071–2 days

Final report & publish

A PDF and a permanent page here with a report ID. If the contract is deployed, we verify the on chain bytecode matches the audited commit and state that in the report. You can then submit the report URL to Etherscan or BscScan so it shows on the contract page.

03Method
Manual first
Manual review
  • Line by line review of every file in scope
  • A written threat model: who can move funds, and how
  • Access control and privilege escalation paths
  • Economic and incentive analysis, not just code correctness
Standards we map to

EEA EthTrust Security Levels v3

Our review maps to levels [S], [M] and [Q]. We state which we reached.

OWASP SCSVS

Used as a coverage checklist so categories are not skipped.

Tooling, alongside the manual pass
SlitherStatic analysis across the full call graph
AderynRust based static analysis, second opinion on Slither
FoundryFuzz tests and invariant tests against stated properties
HardhatUnit and integration tests, forked mainnet scenarios

Tools catch the known patterns. They do not catch broken business logic, and they cannot tell you whether an admin key is a backdoor. That is what the manual pass is for.

04Severity
How we rate findings
CriticalFunds can be stolen, frozen, or permanently lost.
HighSerious loss or broken core logic under realistic conditions.
MediumLoss or misbehaviour under specific, reachable conditions.
LowMinor issue, or a deviation from established best practice.
InformationalCode quality, gas efficiency, documentation, naming.
Every finding closes as

Fixed

Re-reviewed at a new commit and confirmed resolved.

Acknowledged

Client accepts the risk and has documented why.

Won't fix

Out of scope, or intentional. Stated plainly in the report.

05In the report
Every time

Scope

Exact file list, the commit hash reviewed, deployed addresses if any, and what was explicitly excluded.

Executive summary

What the system does, what we reviewed, and the headline result in plain language.

Findings

Each with an ID, severity, the offending code quoted, impact, a reproduction where one applies, and a recommended fix.

Admin and owner powers

Every privileged function, who holds the key, and what they could do with it. Including the things that are not bugs.

Can funds leave?

A direct answer to the only question most holders actually care about, with the paths traced.

Bytecode match

For deployed contracts, confirmation that the on chain bytecode corresponds to the audited commit.

Fix review

Each finding re-checked at the fix commit, and closed as Fixed, Acknowledged, or Won't fix.

Disclaimer

What this audit does and does not cover. Stated plainly, not buried.

06Published reports
Public record

No published reports yet

Reports appear here once a client agrees to publish. We will not pad this list with audits that did not happen, and we will not name a client who asked us not to. When the first report is public it will sit here with its full findings, its scope commit and its report ID.

07Timeline & pricing
Fixed quote within 24–48h of scoping

Price follows lines of code in scope and how much of it is non standard. Proxies, oracles, external calls and assembly cost more to review than a plain token. We quote a number and a date, and we hold both.

Under 300 lines

3–5 days

A token, a vesting contract, a simple staking pool.

300–1,000 lines

1–2 weeks

A protocol with several interacting contracts.

Over 1,000 lines

Quoted individually

Multi contract systems, bridges, anything upgradeable.

08Questions
Straight answers

Do you audit code you wrote yourselves?

No. We do not audit code we built. If DevsBazaar wrote any part of a system, that is stated on the front page of the report and we recommend a second opinion from an unrelated firm. An audit is only worth something if the auditor can afford to fail the client.

Is the report confidential?

Yes, until you choose otherwise. The preliminary and final reports are delivered privately. Nothing is published to this site, and no client is named anywhere, without your written go ahead.

How does it show on BscScan or Etherscan?

Once the report is public at a permanent URL, the report link is submitted through the explorer's Security Audit Report form, along with the contract address, the provider name and the audit date. Approved submissions appear in a Contract Security Audit section on the contract page. The explorer reviews submissions manually and we cannot guarantee their decision or their timeline.

What does a re-audit cost?

Fix verification on the findings we raised is included. A re-audit after new features or a significant refactor is scoped and quoted as fresh work, usually at a reduced rate since we already know the codebase.

What does an audit not guarantee?

It is not a guarantee that the code is safe. We review a specific commit, in a defined scope, for a defined period. It cannot cover code changed afterwards, the deployment configuration, key management, off chain infrastructure, or the honesty of the team holding admin keys. An audit reduces risk. It does not remove it.

What do you need from us to start?

A repository link with the commit you want reviewed, or the deployed addresses. Documentation or a spec if you have one, since a bug is only a bug against intended behaviour. Access to a developer who can answer questions during the review.

Send us the commit.
We will send a quote.

Repository or deployed addresses, the commit you want reviewed, and your deadline. Scope and a fixed quote back within 48 hours.

An audit reduces risk. It is not a guarantee of security.