Security audits · EVM & Solana

We try to drain it before anyone else can.

Hashward audits smart contracts for teams about to ship. Two reviewers read the code. If a bug can move funds, the report includes a transaction that does it — and we rerun that transaction after you patch.

HW-2026-014 Confidential

Vault.sol

withdraw() · marked by reviewer B

  1. function withdraw(uint256 amt) external {
  2. require(bal[msg.sender] >= amt);
  3. (bool ok,) = msg.sender.call{value: amt}("");
  4. require(ok);
  5. bal[msg.sender] -= amt;
  6. }

re-enters
before the write

Critical

A receiver re-enters withdraw before the balance write and empties the vault. PoC in the appendix. Fix: checks-effects-interactions, then nonReentrant.

2 reviewers 11 days retest open
01Solidity, Vyper, Anchor, Move
02Two reviewers, separate notes
03Retest included in the fee

Most reports list smells. Ours includes the transaction that takes the funds.

What you hire us for

Four kinds of work. Same standard on each.

  1. 01

    Contract review

    Every function in scope, read by hand. Reentrancy, access control, accounting, proxies, upgrade paths. If it can move funds the wrong way, you get a runnable proof of concept, not a suggestion.

  2. 02

    Economic review

    Oracles, liquidation, MEV, and the incentive that breaks once real volume shows up. These sit between functions. A linter will not find them.

  3. 03

    Fuzzing and proofs

    Foundry and Echidna against the invariants you claim. Halmos where a property has to hold for every input.

  4. 04

    Fix retest

    You patch. We rerun the original proof of concept against the diff. The report stays private unless you ask us to publish it.

Method

Three passes. Then we argue.

One reviewer misses things the other one is stubborn about. We keep the notes separate until both passes are done, then reconcile them. Tooling runs in parallel so a broken invariant shows up even if both of us read past it.

Read
Intent, composition, and the attack the tools cannot imagine.
Fuzz
Generated inputs against the invariants you wrote down.
Prove
The few properties that have to hold for every input.
vault.solsuite full

$ hashward run --suite full ./src

okslither38 detectorsclean
okfoundry fuzz2,400,000 runs0 breaks
!!echidnainvarianttotalSupply
okhalmossymbolic3 proven

1 critical2 high3 medium5 low

98.7% lines · 96.1% branches

An engagement

One to three weeks. Price fixed before we start.

  1. Scope

    We read the docs and the threat model, name the contracts in scope, and send a flat quote. Nothing is billed before you accept it.

  2. Review

    Two people, independent notes, then a pass where we try to kill each other's findings.

  3. Report

    Severity, a runnable proof of concept, and the change we want. A document you can hand to the engineer who will fix it.

  4. Retest

    Included. We rerun the original proofs against your diff and say whether the hole is actually closed.

Next

Send the repo.

Scope, a timeline, and a flat quote. One business day. NDA if you want one.

FAQ

The practical questions.

How much does an audit cost?

It scales with the contracts, not a per-line rate. A focused DeFi audit usually lands between $8k and $40k. You get a flat number before we start.

How long does it take?

One to three weeks from kickoff to the report. Tell us the date if you have one.

What do we actually receive?

A report. Each exploitable finding has a proof of concept and a fix. After you patch, we rerun those proofs.

Which chains?

EVM — Solidity and Vyper. Solana — Rust and Anchor. Move, if that's what you shipped.

Do you publish the report?

Only if you ask. Otherwise it stays between us.