Tier List

Web3 Audit Firm Tiers

A heuristic ranking based on published audit reports, incident history, depth of tooling, and industry reputation. Within each tier, firms are grouped by their primary focus area.

General Smart ContractFormal VerificationCryptography & ZK
S

S Tier

Industry top tier. The standard for major protocols. High cost and long queues.

8 firms
A+

A+ Tier

Near-S reputation. Frequently chosen by major protocols.

12 firms

General Smart Contract

8
A

A Tier

Proven capability. Trusted by major DeFi and L1/L2 projects.

23 firms

General Smart Contract

22

Code4rena

Audit Contest

Public audit contest format. Strength is many independent eyes.

Clients ENS, Connext, Olympus

Sherlock

Audit ContestCoverage

Hybrid of audit contest and on-chain coverage.

Clients LayerZero, Perennial, Symmetric

Macro

Smart ContractBoutique

Boutique founded by ex-Coinbase engineers.

Clients Optimism, Reserve, Worldcoin

Dedaub

Smart ContractStatic AnalysisEVM

Static analysis strength behind the Watchdog decompiler.

Clients Lido, Yearn, Chainlink

Pashov Audit Group

Smart ContractBoutique

Boutique led by Krum Pashov. Fast turnaround and high signal-to-noise.

Clients Ethena, Karak, Sofamon

Electisec

Smart ContractDeFiZK

Rebrand of yAudit and yAcademy. Boutique audits backed by an independent fellowship pool.

Clients Yearn, Cap, Cove

Recon

Invariant TestingFuzzingSmart Contract

Invariant-testing specialist using Echidna, Medusa, and Halmos. Strong on accounting and economic bugs that manual review misses.

Clients Liquity, Centrifuge, Badger, Balancer

Cyfrin

Smart ContractEducationTooling

Led by Patrick Collins. Maintainer of the Aderyn static analyzer.

Clients Beanstalk, Eigen Foundation

Three Sigma

Smart ContractQuantDeFi

Audit work combined with quantitative analysis. Strong on financial modeling verification.

Clients Maple Finance, GMX

Statemind

Smart ContractDeFi

Standout in DeFi and LSD work. Frequently demonstrates concrete exploits.

Clients 1inch, Lido, Curve

Oak Security

CosmosCosmWasmSmart Contract

De facto standard firm in the Cosmos and CosmWasm ecosystems.

Clients Osmosis, Mars Protocol

BlockSec

Smart ContractPhalconMonitoring

Security group best known for the Phalcon monitoring platform.

Clients Compound, Trader Joe

Ackee Blockchain

Smart ContractSolanaTooling

Maintainer of the Wake toolkit. Covers EVM and Solana.

Clients Lido, Trezor

Renascence Labs

Smart ContractBoutique

DeFi mechanic-analysis boutique. Small but strong reputation.

Clients Bunni, Ekubo

Trust Security

Smart ContractBoutiqueEVM

Boutique that grew out of Trust1995's (Anatomist) solo audit reputation.

Clients Various DeFi, Solo audits

Guardian Audits

Smart ContractDeFi

DeFi-focused boutique. Active in the Arbitrum ecosystem.

Clients GMX, Arbitrum ecosystem

Paladin

Smart ContractDeFiBoutique

DeFi-focused boutique using a freelance researcher network model.

Clients LayerZero, Trader Joe, Avalanche

Pessimistic

Smart Contract

Long-running Russia-based firm. Solid output.

Clients 1inch, Curve, Pickle

MixBytes

Smart ContractDeFi

Veteran EU/CIS firm. Broad DeFi coverage.

Clients Lido, 1inch, Yearn

Coinspect

Smart ContractWalletPentest

Veteran boutique specialized in wallet and mobile security.

Clients MetaMask, Argent

Decurity

Smart ContractDeFi

Deep DeFi-mechanic expertise. Small precision boutique.

Clients Convex, Frax

TonBit

TONFunC

BitsLab-affiliated specialist for the TON ecosystem.

Clients TON ecosystem

B

B Tier

Mid-tier firms competing on price, formerly active firms with declining output, or firms whose reputation has eroded from frequent client incidents.

18 firms

General Smart Contract

18

Halborn

Smart ContractInfraPentest

Combined smart contract audits and infrastructure penetration testing.

Clients Solana, Avalanche, THORChain

Quantstamp

Smart ContractDeFi

Early DeFi audit firm. Broad portfolio.

Clients Maker, Solana, BNB Chain

Sec3

SolanaAudit-as-a-Service

Solana-focused, combining audits with the X-ray automated analysis tool.

Clients Drift, Mango, MarginFi

PeckShield

Smart ContractThreat Intel

Famous for on-chain threat-intelligence posts.

Clients BNB Chain ecosystem

SlowMist

Threat IntelWallet

Strong in Asia-region incident tracing and response.

Clients Binance, OKX, Huobi

Hacken

Smart ContractCEX

Broad service offering. Most active in exchange and wallet security.

Clients Polygon, Huobi, VeChain

QuillAudits

Smart ContractL2

Fast-turnaround mid-tier. India-based, large-scale operation.

Clients Polygon, 0x

Salus

Smart ContractZK

Active in ZK. Many researchers from Silicon Valley backgrounds.

Clients Linea, Manta

Iosiro

Smart ContractDeFi

Deep Synthetix-ecosystem expertise. Based in South Africa.

Clients Synthetix, Kwenta

Composable Security

Smart ContractDeFi

EU-based boutique. Narrow but deep specialty.

Clients Beefy, Mean Finance

Solidified

Smart ContractMarketplace

Active in the early DeFi era. Marketplace model.

Clients TheGraph, BarnBridge

Coinfabrik

Smart ContractSubstrate

Latin America-based veteran. Strong in RSK and Polkadot.

Clients RIF, Polkadot ecosystem

Hashlock

Smart ContractDeFi

Australia-based mid-tier firm. Reasonable pricing.

Clients Pendle, Various

Zokyo

Smart ContractDeFi

North America-based mid-tier. Broad security service offering.

Clients Various DeFi

ScaleBit

L2ScalingSmart Contract

BlockSec-affiliated firm specialized in scaling and L2 work.

Clients Various L2

SharkTeam

Smart ContractThreat Intel

Asia-region threat intelligence combined with audits.

Clients Asian ecosystem

Security Research Labs

PentestSmart ContractInfra

Germany's SRLabs. Long-running general security firm now expanding into Web3.

Clients Various

CertiK

Smart ContractSkynetWeb2

Smart contract audits draw quality-variance criticism, but the Web2 audit team (Skynet) has been showing meaningful recent activity.

Clients Wide BSC and altcoin coverage

C

C Tier

Low-cost mass-production auditors, or firms with thin track records and no major project audits.

46 firms

General Smart Contract

45

BAIL Security

Smart ContractDeFi

Newer boutique. High volume of small DeFi engagements.

Clients Various mid-cap DeFi

Resonance Security

Smart ContractInfraPentest

Formerly Cyber Unit. Combined infrastructure and contract security.

Clients Various

Sayfer

Smart ContractPentest

Israel-based. Many CTF-trained researchers.

Clients Various

Omniscia

Smart ContractDeFi

General DeFi-focused mid-tier firm.

Clients Various DeFi

Bunzz Audit

Smart ContractHybrid

Japan-based. Hybrid of automated analysis and manual review.

Clients Japanese Web3 ecosystem

WatchPug

Smart ContractDeFi

Long-running mid-tier boutique.

Clients Various

Oxorio

Smart ContractDeFi

EU-based mid-tier firm.

Clients Various EU DeFi

BlockApex

Smart Contract

Pakistan-based mid-tier. Reasonable pricing.

Clients Various

Blaize.security

Smart ContractDeFi

Ukraine-based mid-tier with broad DeFi coverage.

Clients Various

MetaTrust Labs

Smart ContractAI Tooling

Singapore-based. Emphasizes AI-assisted analysis.

Clients Various

Softstack

Smart Contract

EU-based mid-tier firm.

Clients Various

Beosin

Smart ContractCompliance

Active with Asia-region small and mid-cap projects. Broad portfolio.

Clients Aptos ecosystem, Bytetrade

Solidity Finance

Smart Contract

Low-cost fast-turnaround model. Narrow scope.

Clients Mid-cap DeFi

SmartState

Smart Contract

Mostly works with smaller projects. Low entry pricing.

Clients Various small-cap

BlockSafu

Smart ContractBSC

Low-cost option focused on BSC tokens.

Clients Various BSC tokens

Audit One

Smart Contract

Security service attached to a staking operator. Low-cost option.

Clients Smaller protocols

DeFiSafety

Process ReviewRating

Process-maturity scoring service rather than a security audit.

Clients DeFi protocols (process audits)

Red4Sec

Smart ContractPentest

Spain-based general security firm. Also covers Web3 work.

Clients Various

Armors

Smart ContractAI

Newer firm emphasizing AI-assisted analysis.

Clients Various

Team Omega

Smart Contract

Newer mass-market firm.

Clients Various

DeFiMoon

Smart ContractDeFi

Newer DeFi-focused mass-market firm.

Clients Various small DeFi

0xGuard

Smart ContractToken

Mass-market firm focused on token issuers.

Clients Various tokens

Rugdog

Token Screening

Token screening service focused on rug detection.

Clients Various tokens

Securr

Smart Contract

Newer mass-market firm.

Clients Various

Audita

Smart Contract

Newer mass-market firm.

Clients Various

Monethic

Smart Contract

Newer mass-market firm.

Clients Various

Advix

Smart ContractAI

Newer firm emphasizing AI.

Clients Various

Mosaia

Smart Contract

Newer mass-market firm.

Clients Various

Hakflow

Smart Contract

Newer mass-market firm.

Clients Various

SCV Security

Smart Contract

Newer mass-market firm.

Clients Various

0xTeam

Smart Contract

Newer mass-market firm.

Clients Various

BugBlow

Smart Contract

Newer mass-market firm.

Clients Various

SecureDApp

Smart Contract

India-based mass-market firm.

Clients Various

Safe Edges

Smart Contract

Newer mass-market firm.

Clients Various

Perimeter

Smart Contract

Newer boutique.

Clients Various

Null Return

Smart Contract

Newer mass-market firm.

Clients Various

ChainAudits

Smart Contract

Newer mass-market firm.

Clients Various

Adevar Labs

Smart Contract

Newer mass-market firm.

Clients Various

Sub 7 Security

Smart Contract

Newer mass-market firm.

Clients Various

TechRate

Smart ContractBSC

Low-cost mass-market focused on BSC and SCAN tokens.

Clients BSC and altcoin tokens

Cyberscope

Smart ContractKYC

Combined KYC and audit service for token issuers.

Clients Various tokens

Solidproof

Smart Contract

Germany-based low-cost firm. Fast turnaround with standardized reports.

Clients Various tokens

Hashex

Smart Contract

CIS-based low-cost option. Broad token coverage.

Clients Various

InterFi Network

Smart ContractBSC

BSC mass-market. Issuer-friendly report style.

Clients BSC tokens

Shellboxes

Smart Contract

Morocco-based low-cost firm. Fast-turnaround offering.

Clients Various