Language-specific risks
Storage layout collisions in proxies, unchecked blocks reintroducing overflow, ABI encoding collisions with abi.encodePacked, and the differences between call, send and transfer.
Ethereum, Base, Arbitrum, Optimism, Polygon and every other EVM chain. Solidity is the bulk of what we review, and the vulnerability classes are well understood, which is exactly why they keep reaching production.
Storage layout collisions in proxies, unchecked blocks reintroducing overflow, ABI encoding collisions with abi.encodePacked, and the differences between call, send and transfer.
Tokens that take a fee on transfer, tokens that return nothing instead of a boolean, tokens that rebase. Any vault that assumes ERC-20 compliance is one integration away from a shortfall.
Foundry for invariant and fuzz testing, Slither and Aderyn for the automated pass, and forge test --gas-report to catch the gas-griefing paths.
Same tiers as everything else. Rust and Move carry a small premium over Solidity because the reviewer pool is smaller and the codebases are usually denser.
| Tier | Scope | Price |
|---|---|---|
Snapshot Real findings on one contract, in 72 hours |
1 contract · ≤200 LoC | Free72 hours |
Single contract Full manual review of one contract, all severities |
≤500 LoC | $400–7003–5 days |
Project audit Whole codebase, PoC exploits for high and above, re-review |
≤1,500 LoC | $1,500–2,5007–10 days |
Protocol audit Multi-contract, architecture, oracle and governance review |
1,500+ LoC | $4,000–6,0002–3 weeks |
Continuous Review on every commit, for teams shipping weekly |
Rolling scope | From $800/moRetainer |
Up to 200 lines, manually reviewed, findings within 72 hours. The fastest way to judge whether we know this stack.