UniswapV4

They have trusted us

Dean Rubin, CTO of Othentic Labs, partnered with Composable Security to conduct a thorough security review of the Rewards V2 smart contract module. The project aimed to verify the robustness of a new rewards distribution mechanism integrated with EigenLayer and ensure secure cross-chain operations across multiple Layer 2 networks.

Amadeo Brands, CEO of YieldNest, partnered with us to evaluate the security of their Max Vault integration with the Kernel protocol on BNB Chain. The goal was to ensure safe yield generation and optimize protocol robustness before launch.

Nick Velloff came to us for a security review of Braintrust, a decentralized talent network. The primary objective was to ensure the secure expansion of the Braintrust platform onto the Base network, validate integrations with third-party services such as Coinbase Onramp, and secure the wallet infrastructure used by its users.

How Does a Security Consultation Work?

Every security consultation begins with understanding your needs. We then craft a customized plan with a clear consultation goal. Our experts carry out research to give you the best possible advice on the presented problem.

Security consultations not only elevate your security posture but also ensure more informed decisions, ensuring you can adapt as your project evolves.

What’s in a Security Consultation Report?

Our report compiles answers to the questions asked and the results of the analysis. The structure may vary depending on the subject of the consultation.

Tailored security solutions to meet the unique needs of your blockchain projects

Secure your project

Learn more

Take part in a workshops

Learn more

Take advantage of expert advice

Learn more

A structured approach to asses and secure DApps.

1. Initial Contact

You reach out to us via our website (or any preferred channel). We’ll respond within 24 hours to discuss your project’s scope.

2. Customized Proposal +

We analyze your requirements and prepare a tailored offer that addresses your specific needs.

3. Contract & Initial Payment +

We finalize the contract details, and once both parties have signed, you pay 50% of the agreed fee.

4. Audit Execution +

Our team conducts a thorough audit of your smart contract, identifying potential vulnerabilities and compliance issues.

5. Audit Report & Final Payment +

We share a detailed report of our findings. You then pay the remaining 50%.

6. Corrections & Retest +

After you make recommended corrections, we conduct a retest to ensure all issues have been resolved.

7. Peace of Mind +

With our final sign-off, you can confidently deploy your smart contract, knowing it has been rigorously tested.

We conduct thorough audits of Actively Validated Services (AVSs), use of libraries such as Othentic, proper validator coordination, and robust integration with restaking protocols like EigenLayer or Symbiotic.

Learn more

We provide in-depth audits for restaking protocols, focusing on security, reliability, and correct integrations with protocols like EigenLayer or Symbiotic.

Learn more

We specialize in Solidity and perform comprehensive audits across EVM-based smart contracts. Tokens, DeFi, Cross-chain, Liquid Staking, GameFI and many more. We identify vulnerabilities, verify logic correctness, and ensure alignment with best practices across various chains and frameworks.

Learn more
high
Uncleared claims
Learn more
medium
Permanent revert on rewards submission
Learn more
medium
Invalid EigenLayer reward submission
Learn more
high
Enabling stETH deposits causes miscalculations and permanent losses for users as rebase tokens are not supported
Learn more
medium
FULL_RESTRICTED stakers can bypass restriction through approvals
Learn more
high
OFT can be impersonated through _lzCompose with multiple compose messages
Learn more

Can’t find an answer? Contact us or follow us on Twitter.

Managing Partner & Smart Contract Security Auditor

Managing Partner & Smart Contract Security Auditor

What is Composable Security? +

We are a small, elite team of smart contract auditors specializing in (re)staking, AVS, and hooks. We tailor our solutions to each client’s unique needs. We reject one-size-fits-all strategies in favor of a personalized, continually evolving service that delivers the highest level of security.

What is smart contract audit? +

A smart contract audit is a comprehensive examination of the code underlying a blockchain-based smart contract. This process involves expert auditors looking for security vulnerabilities, design issues, and efficiency problems. The goal is to ensure the smart contract operates as intended, without any flaws that could lead to security breaches, rug pulls, or hacks.

Smart contract audit is crucial in the blockchain ecosystem to maintain trust and reliability in projects building decentralized applications.

How long do audits take? +

It depends on the complexity of the smart contract. However, on average it takes approximately two weeks.

To learn about how we perform smart contract audits head to this artice.

How much does a security review cost? +

Smart contract audits done by professionals typically cost ~$10000-$30000 for an average project. The price of the audit depends on many factors, but the following have a key impact on the price:

  • number of lines of solidity code (nSLOC),
  • the complexity of the code,
  • documentation quality and code clarity,
  • whether the auditors know your protocol and the components you use,
  • whether you are using standard implementations or implementing something from scratch,
  • the deadline for the audit.

Smart contract audit cost can be slightly minimized if before the audit you use a checklist prepared by us.

What kind of post-audit support do you provide? +

After introducing the changes to the smart contract, we perform a one-time verification to make sure that the recommendations have been introduced in the right way and that the found vulnerabilities do not exist anymore. Afterward, we are always open to assisting our clients in answering all of their questions and helping in solving issues related to security.

To learn about how we perform smart audits head to this article.

Why do smart contracts need to be audited? +

Smart contracts need to be audited to ensure their security and effectiveness. As they are self-executing contracts with the terms directly written into code, any flaws can lead to significant financial losses.

Smart contract audits help identify vulnerabilities before deployment, safeguarding against potential hacks and ensuring the contract functions as intended.