Need Help Choosing an Audit Firm?
Get expert guidance on selecting the right auditor for your smart contracts.
Curated List
Quick Take
Top smart contract auditors include Tier 1 firms (Trail of Bits, OpenZeppelin, Certik, Halborn, Spearbit, Cyfrin — $20,000–$150,000+), Tier 2 boutiques ($12,000–$35,000), and competitive audit platforms (Code4rena, Sherlock — $10,000–$50,000 pools). Key selection criteria: Published report database, Relevant category experience, Methodology transparency, and Audit team quality. For critical protocols: use both a traditional firm and a competitive audit.
What Makes an Audit Firm Credible
Published report database. Every reputable audit firm publishes their completed audit reports publicly (with client permission). Check: does this firm have a public report database? Do the reports look like comprehensive, finding-documented reviews — or like templated checklists?
Relevant category experience. An audit firm that has reviewed 50 DeFi lending protocols understands the economic attack vectors specific to lending. Count their DeFi, NFT, or gaming audits in your specific category — not just total audits.
Methodology transparency. Ask the firm to share their audit methodology document. A credible firm has a defined process: what vulnerability categories they check, how they classify severity, what their re-audit process covers. Firms that decline to share methodology are opaque for a reason.
Audit team quality. Who specifically will review your code? Not 'our team' — specific engineers with their public credentials and past audit experience. The quality of an audit is the quality of the individual reviewers.
Audit Firm Categories
Tier 1 — Recognized name, institutional trust: Trail of Bits, OpenZeppelin, Certik, Halborn, Spearbit, Cyfrin. These firms' reports carry weight with institutional LPs, VCs, and protocol users. Their methodology is public and their past findings are verifiable.
Tier 2 — Specialized boutiques: Smaller firms with deep category expertise. Often staffed by engineers from Tier 1 firms. Can provide equivalent quality at lower cost for specific protocol types. Require more due diligence — verify their report history specifically.
Competitive audit platforms: Code4rena, Sherlock. Crowdsourced audits by a pool of independent researchers. Can surface vulnerabilities that structured audits miss. Not a substitute for a structured firm audit — a complement to it. The coverage is non-deterministic (no researcher is guaranteed to review any specific vulnerability category).
What to Ask Any Audit Firm
Before engagement: How many engineers will review my code, and what is each reviewer's specific DeFi/protocol experience? Can I see your most recent 3 audit reports in my protocol category? What is your re-audit process for remediated findings?
During engagement: Who is the lead auditor and when can we schedule a technical call to discuss the architecture before they begin? What is your SLA for preliminary report delivery?
After report: For each Critical and High finding — can you walk through the exact attack scenario that produces the exploit?
Audit Cost Reference
| Firm Tier | Scope | Typical Cost |
|---|---|---|
| Tier 1 firm | 1,000–2,000 LoC | $20,000–$50,000 |
| Tier 1 firm | 2,000–5,000 LoC | $45,000–$90,000 |
| Tier 1 firm | Large protocol with econ modeling | $80,000–$150,000+ |
| Tier 2 boutique | 1,000–2,000 LoC | $12,000–$35,000 |
| Code4rena competitive | Variable | $10,000–$50,000 pool |