Smart contract audit
Manual line by line review with proof of concept exploits, a public report and a free fix review round.
Manual smart contract review by engineers who have written protocols, not just read them. Every finding comes with a proof of concept exploit and a fix we will review for free.
Audit pricing is quoted from the code, not from a rate card, after a free scoping call.
Manual line by line review with proof of concept exploits, a public report and a free fix review round.
Five business day focused review of a limited diff or a single contract before a deadline.
We write and test the contracts, with full Foundry test suites and invariant fuzzing delivered.
Alerting on anomalous transfers, admin key use, oracle deviation and pause conditions, routed to your on call.
Guaranteed engineer on a call within one hour, any hour, with a pre agreed triage playbook.
Machine checked proofs of critical invariants for contracts where a manual review is not sufficient assurance.
Ledgerline was founded in 2018 by three engineers who had shipped and maintained lending and AMM contracts and had watched competent teams lose funds to bugs a careful reader would have caught. We publish our reports by default, including the ones where we found serious issues, because a report nobody can read is marketing.
“They found a rounding issue in our share accounting that three prior reviews missed, and handed us a test that drained the vault. We shipped the fix before launch.”
Ana T., Lead engineer, lending protocol
“The report was readable by our non technical board, which sounds trivial and absolutely is not.”
Marcus L., COO, enterprise chain project
“We had an oracle deviation at three in the morning. Their monitoring caught it and an engineer was on the call in under twenty minutes.”
Jae P., Protocol operations
By the code, specifically the lines of Solidity in scope, the complexity of the economic design and how much external protocol interaction there is. We do a free scoping call, look at the repository, and give a fixed price and a start date. Most protocol audits land between 28,000 and 120,000 dollars.
No, and any firm that tells you otherwise is selling something. An audit is a time boxed expert review that dramatically reduces risk, it is not a proof of correctness. That is why we push monitoring, a bug bounty and formal verification for the highest value invariants as layers on top, and why our reports state exactly what was and was not in scope.
Typical protocol audits run two to four weeks of review followed by a week for the report and your fixes. Rapid pre launch reviews are five business days for a limited scope. We are usually booking three to six weeks out, so start the scoping conversation earlier than feels necessary.
By default yes, and we think you want that, because a public report from a firm that publishes its failures is worth more to your users than a private PDF. You control the publication date, typically after fixes are deployed. If a finding cannot be safely disclosed we coordinate timing with you rather than publishing on a schedule.
Send a repository link and your target launch date. The scoping call is free and takes about thirty minutes.