2026-04-05
OlderComprehensive Web3 Security Ecosystem Research
Trail of Bits, OpenZeppelin, Cyfrin, Spearbit, ConsenSys Diligence, Halborn, Quantstamp, CertiK, Sherlock, Code4rena, Sigma Prime, Runtime Verification, Zellic, Ackee Blockchain, Hexens, Dedaub, Pessi…
Comprehensive Web3 Security Ecosystem Research
Date: 2026-04-05 Scope: All significant audit firms, tools, and platforms in the web3 security space Method: Extensive web research, cross-referenced across multiple sources
PART 1: AUDIT FIRMS
Currently in Dataset (16 firms)
Trail of Bits, OpenZeppelin, Cyfrin, Spearbit, ConsenSys Diligence, Halborn, Quantstamp, CertiK, Sherlock, Code4rena, Sigma Prime, Runtime Verification, Zellic, Ackee Blockchain, Hexens, Dedaub, Pessimistic
Missing Firms to Add
1. OtterSec
{
"slug": "ottersec",
"name": "OtterSec",
"logo": "/images/auditors/ottersec.svg",
"description": "Leading Solana-native security firm that has secured over $36.8B in TVL. Known for rapid incident response and deep expertise in Rust-based blockchain systems. If you're building on Solana, OtterSec is one of the top choices — they've audited Wormhole, Jito Labs, and the Solana Foundation itself.",
"founded": 2021,
"specialties": ["smart-contracts", "solana", "bridges", "defi", "nft", "move"],
"chains": ["solana", "ethereum", "aptos", "sui", "polygon", "arbitrum"],
"auditTypes": ["smart-contract", "protocol", "infrastructure"],
"priceTier": 3,
"rating": 4.7,
"notableAudits": ["Solana Foundation", "Wormhole", "Jito Labs", "LayerZero", "Sui"],
"publicReports": true,
"turnaround": "4-8 weeks",
"teamSize": "40+",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/osaborec_xyz",
"github": "https://github.com/otter-sec",
"website": "https://osec.io"
},
"lastUpdated": "2026-04-05",
"featured": true
}
2. NCC Group
{
"slug": "ncc-group",
"name": "NCC Group",
"logo": "/images/auditors/ncc-group.svg",
"description": "Global cybersecurity consultancy with a specialized cryptography services division that handles blockchain and smart contract audits. Brings decades of traditional security expertise to web3. Best for projects that need a firm with recognized enterprise credibility and deep cryptographic knowledge.",
"founded": 1999,
"specialties": ["cryptography", "smart-contracts", "protocol-design", "penetration-testing", "infrastructure"],
"chains": ["ethereum", "polygon", "arbitrum", "solana"],
"auditTypes": ["smart-contract", "protocol", "cryptography", "penetration-test", "infrastructure"],
"priceTier": 3,
"rating": 4.5,
"notableAudits": ["Zcash", "Ethereum Foundation", "Protocol Labs", "Tezos"],
"publicReports": true,
"turnaround": "6-12 weeks",
"teamSize": "2000+ (security division)",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/NCCGroupplc",
"github": "https://github.com/nccgroup",
"website": "https://www.nccgroup.com"
},
"lastUpdated": "2026-04-05",
"featured": false
}
3. Kudelski Security
{
"slug": "kudelski-security",
"name": "Kudelski Security",
"logo": "/images/auditors/kudelski-security.svg",
"description": "Enterprise security arm of the Kudelski Group with a dedicated blockchain security practice of 25+ specialists. Strong cryptographic heritage from decades in digital media security. Particularly good for projects needing cryptographic protocol review alongside smart contract audits.",
"founded": 2012,
"specialties": ["cryptography", "smart-contracts", "protocol-design", "blockchain-architecture", "key-management"],
"chains": ["ethereum", "polygon", "arbitrum", "solana", "cosmos", "polkadot"],
"auditTypes": ["smart-contract", "protocol", "cryptography", "infrastructure", "architecture-review"],
"priceTier": 3,
"rating": 4.4,
"notableAudits": ["Solana Stake Pool", "Lido", "Cosmos SDK", "Near Protocol"],
"publicReports": true,
"turnaround": "6-10 weeks",
"teamSize": "25+ (blockchain division)",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/KudelskiSec",
"github": "https://github.com/AuditSecurity",
"website": "https://kudelskisecurity.com"
},
"lastUpdated": "2026-04-05",
"featured": false
}
4. Sec3 (formerly Soteria)
{
"slug": "sec3",
"name": "Sec3",
"logo": "/images/auditors/sec3.svg",
"description": "Solana-native security firm born from the ecosystem with deep protocol alignment. Developed the Soteria static analyzer and offers runtime monitoring for post-deployment protection. A strategic choice for teams building long-term Solana infrastructure who want continuous security coverage.",
"founded": 2021,
"specialties": ["solana", "smart-contracts", "runtime-monitoring", "static-analysis", "defi"],
"chains": ["solana"],
"auditTypes": ["smart-contract", "protocol", "runtime-monitoring"],
"priceTier": 2,
"rating": 4.3,
"notableAudits": ["Marinade Finance", "Raydium", "Mango Markets"],
"publicReports": true,
"turnaround": "3-6 weeks",
"teamSize": "20+",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/sec3dev",
"github": "https://github.com/sec3-service",
"website": "https://www.sec3.dev"
},
"lastUpdated": "2026-04-05",
"featured": false
}
5. Neodyme
{
"slug": "neodyme",
"name": "Neodyme",
"logo": "/images/auditors/neodyme.svg",
"description": "German security research firm with deep Solana expertise. Known for publishing educational content about Solana vulnerabilities and building CTF challenges. Small, research-focused team that brings academic rigor to Rust-based smart contract auditing.",
"founded": 2021,
"specialties": ["solana", "smart-contracts", "rust", "cryptography", "education"],
"chains": ["solana", "ethereum"],
"auditTypes": ["smart-contract", "protocol", "cryptography"],
"priceTier": 2,
"rating": 4.4,
"notableAudits": ["Solana Stake Pool", "Marinade Finance", "Wormhole"],
"publicReports": true,
"turnaround": "4-8 weeks",
"teamSize": "15+",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/neaborodyme",
"github": "https://github.com/neodyme-labs",
"website": "https://neodyme.io"
},
"lastUpdated": "2026-04-05",
"featured": false
}
6. Pashov Audit Group
{
"slug": "pashov-audit-group",
"name": "Pashov Audit Group",
"logo": "/images/auditors/pashov-audit-group.svg",
"description": "Founded by one of the most respected independent security researchers in DeFi. 50+ researchers, all security contest champions. 400+ audits and 4,000+ vulnerabilities discovered. Trusted by Aave, Uniswap, Ethena, LayerZero, and Pendle. Every audit has a dedicated team of 4 senior researchers.",
"founded": 2023,
"specialties": ["smart-contracts", "defi", "protocol-design", "cross-chain", "staking"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "bnb-chain", "avalanche"],
"auditTypes": ["smart-contract", "protocol", "peer-review"],
"priceTier": 2,
"rating": 4.7,
"notableAudits": ["Aave", "Uniswap", "Ethena", "LayerZero", "Pendle", "EtherFi", "Usual", "Beefy"],
"publicReports": true,
"turnaround": "2-4 weeks",
"teamSize": "50+",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/PashovAuditGrp",
"github": "https://github.com/pashov/audits",
"website": "https://www.pashov.com"
},
"lastUpdated": "2026-04-05",
"featured": true
}
7. Guardian Audits
{
"slug": "guardian-audits",
"name": "Guardian Audits",
"logo": "/images/auditors/guardian-audits.svg",
"description": "Boutique audit firm known for their stateful fuzzing-first approach. Every engagement includes construction of a comprehensive fuzzing suite that continues providing security coverage post-audit. A strong choice for DeFi protocols wanting long-term automated testing infrastructure.",
"founded": 2022,
"specialties": ["smart-contracts", "defi", "fuzzing", "protocol-design", "staking"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "avalanche"],
"auditTypes": ["smart-contract", "protocol", "fuzzing-suite"],
"priceTier": 2,
"rating": 4.5,
"notableAudits": ["GMX", "Level Finance", "GainsNetwork"],
"publicReports": true,
"turnaround": "3-6 weeks",
"teamSize": "15+",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/GuardianAudits",
"github": "https://github.com/GuardianAudits",
"website": "https://guardianaudits.com"
},
"lastUpdated": "2026-04-05",
"featured": false
}
8. Cantina (Spearbit's marketplace)
{
"slug": "cantina",
"name": "Cantina",
"logo": "/images/auditors/cantina.svg",
"description": "AI-native security platform combining competitive audits, managed reviews, and guild-based engagements. Built by Spearbit, Cantina is an open marketplace connecting protocols with vetted researchers and specialist guilds. Offers flexible engagement models from contests to full managed audits.",
"founded": 2023,
"specialties": ["smart-contracts", "defi", "competitive-auditing", "incident-response", "protocol-design"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "solana", "cosmos"],
"auditTypes": ["competitive-audit", "smart-contract", "protocol", "managed-review", "incident-response"],
"priceTier": 2,
"rating": 4.6,
"notableAudits": ["Ethereum Foundation (Pectra)", "Aave", "Morpho", "Scroll"],
"publicReports": true,
"turnaround": "2-8 weeks",
"teamSize": "200+ researchers",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/cantaborina_xyz",
"github": "https://github.com/cantina-forks",
"website": "https://cantina.xyz"
},
"lastUpdated": "2026-04-05",
"featured": true
}
9. Hats Finance
{
"slug": "hats-finance",
"name": "Hats Finance",
"logo": "/images/auditors/hats-finance.svg",
"description": "Decentralized audit competition and bug bounty marketplace where auditors stake their own funds, creating skin-in-the-game incentives. Permissionless and scalable, anyone can provide liquidity or participate. A unique competitive model that rewards conviction and quality findings.",
"founded": 2021,
"specialties": ["smart-contracts", "defi", "competitive-auditing", "bug-bounty", "community"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "bnb-chain"],
"auditTypes": ["competitive-audit", "bug-bounty", "smart-contract"],
"priceTier": 1,
"rating": 4.0,
"notableAudits": ["Various DeFi protocols"],
"publicReports": true,
"turnaround": "1-3 weeks",
"teamSize": "Community-driven",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/HatsFinance",
"github": "https://github.com/hats-finance",
"website": "https://hats.finance"
},
"lastUpdated": "2026-04-05",
"featured": false
}
10. Hacken
{
"slug": "hacken",
"name": "Hacken",
"logo": "/images/auditors/hacken.svg",
"description": "Large-scale Web3 security firm founded in 2017 with 130+ experts across five continents. 2,300+ audits completed with $430B+ verified through Proof of Reserves. Trusted by exchanges like Binance, Bybit, OKX, and Crypto.com. One of the most prolific auditors by volume with broad service coverage including compliance.",
"founded": 2017,
"specialties": ["smart-contracts", "defi", "penetration-testing", "proof-of-reserves", "compliance", "ai-security"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "bnb-chain", "avalanche", "solana"],
"auditTypes": ["smart-contract", "protocol", "penetration-test", "proof-of-reserves", "compliance"],
"priceTier": 2,
"rating": 4.2,
"notableAudits": ["Binance", "Bybit", "OKX", "Crypto.com", "VeChain", "MetaMask", "1inch"],
"publicReports": true,
"turnaround": "2-6 weeks",
"teamSize": "130+",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/hacaborkenclub",
"github": "https://github.com/nicenomad",
"website": "https://hacken.io"
},
"lastUpdated": "2026-04-05",
"featured": false
}
11. Nethermind Security
{
"slug": "nethermind-security",
"name": "Nethermind Security",
"logo": "/images/auditors/nethermind-security.svg",
"description": "Security arm of the Nethermind research and engineering firm. 40% of team holds PhDs with 145+ published papers. Deep expertise in formal verification, ZK circuits, and Starknet. Created AuditAgent, an AI tool that detects valid issues in 62% of projects. 70% repeat client rate speaks to quality.",
"founded": 2020,
"specialties": ["smart-contracts", "formal-verification", "zk-proofs", "starknet", "defi"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "starknet", "base"],
"auditTypes": ["smart-contract", "protocol", "formal-verification", "zk-circuit"],
"priceTier": 3,
"rating": 4.6,
"notableAudits": ["World", "Starknet", "Lido", "Polygon", "zkSync", "Optimism", "EtherFi"],
"publicReports": true,
"turnaround": "4-10 weeks",
"teamSize": "50+",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/NethermindEth",
"github": "https://github.com/NethermindEth",
"website": "https://www.nethermind.io/nethermind-security"
},
"lastUpdated": "2026-04-05",
"featured": false
}
12. BlockSec
{
"slug": "blocksec",
"name": "BlockSec",
"logo": "/images/auditors/blocksec.svg",
"description": "Integrated security firm combining audits with real-time monitoring and incident response. Built the Phalcon platform for hack blocking and MetaSleuth for on-chain investigation. Have blocked 20+ critical attacks and prevented $20M+ in losses. Backed by research and battle-tested incident experience.",
"founded": 2021,
"specialties": ["smart-contracts", "defi", "monitoring", "incident-response", "on-chain-investigation"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "bnb-chain"],
"auditTypes": ["smart-contract", "protocol", "incident-response", "monitoring"],
"priceTier": 2,
"rating": 4.5,
"notableAudits": ["MetaMask", "Uniswap Foundation", "Compound", "Forta", "PancakeSwap"],
"publicReports": true,
"turnaround": "3-8 weeks",
"teamSize": "50+",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/BlockSecTeam",
"github": "https://github.com/blocksecteam",
"website": "https://blocksec.com"
},
"lastUpdated": "2026-04-05",
"featured": false
}
13. Veridise
{
"slug": "veridise",
"name": "Veridise",
"logo": "/images/auditors/veridise.svg",
"description": "Academic-founded ZK security specialists with in-house detection tools (Picus) designed specifically for zero-knowledge circuits. Team includes multiple PhDs in formal methods, software security, and blockchain. The leading choice for ZK circuit audits where mathematical correctness is paramount.",
"founded": 2021,
"specialties": ["zk-proofs", "formal-verification", "smart-contracts", "cryptography", "circuit-auditing"],
"chains": ["ethereum", "polygon", "arbitrum", "starknet", "scroll"],
"auditTypes": ["zk-circuit", "smart-contract", "formal-verification", "cryptography"],
"priceTier": 3,
"rating": 4.6,
"notableAudits": ["Risc Zero", "Succinct", "Linea", "Scroll"],
"publicReports": true,
"turnaround": "4-10 weeks",
"teamSize": "35+",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/VeridiseInc",
"github": "https://github.com/Veridise",
"website": "https://veridise.com"
},
"lastUpdated": "2026-04-05",
"featured": false
}
14. zkSecurity
{
"slug": "zksecurity",
"name": "zkSecurity",
"logo": "/images/auditors/zksecurity.svg",
"description": "Specialized firm focused exclusively on cryptographic systems including ZK proofs, MPC, FHE, and post-quantum cryptography. Developed Circomspect, an open-source tool for ZK circuit analysis. Deep niche expertise for projects operating at the frontier of applied cryptography.",
"founded": 2022,
"specialties": ["zk-proofs", "cryptography", "mpc", "fhe", "post-quantum"],
"chains": ["ethereum", "polygon", "starknet", "scroll"],
"auditTypes": ["zk-circuit", "cryptography", "protocol"],
"priceTier": 3,
"rating": 4.5,
"notableAudits": ["Various ZK protocols"],
"publicReports": true,
"turnaround": "4-10 weeks",
"teamSize": "15+",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/zaborksecurity",
"github": "https://github.com/zksecurity",
"website": "https://zksecurity.xyz"
},
"lastUpdated": "2026-04-05",
"featured": false
}
15. MixBytes
{
"slug": "mixbytes",
"name": "MixBytes",
"logo": "/images/auditors/mixbytes.svg",
"description": "300+ audits since 2017 with zero rekts — an impressive track record. Skilled in EVM-compatible and Substrate-based blockchain projects. Combines manual review with proprietary tooling. A strong mid-tier option for teams wanting proven reliability at reasonable pricing.",
"founded": 2017,
"specialties": ["smart-contracts", "defi", "substrate", "polkadot", "staking"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "polkadot", "cosmos"],
"auditTypes": ["smart-contract", "protocol", "token"],
"priceTier": 2,
"rating": 4.3,
"notableAudits": ["Lido", "Curve", "Yearn", "1inch", "SushiSwap"],
"publicReports": true,
"turnaround": "3-8 weeks",
"teamSize": "30+",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/MixBytes",
"github": "https://github.com/mixbytes",
"website": "https://mixbytes.io"
},
"lastUpdated": "2026-04-05",
"featured": false
}
16. 0xMacro
{
"slug": "0xmacro",
"name": "0xMacro",
"logo": "/images/auditors/0xmacro.svg",
"description": "Elite boutique audit firm that stays deliberately small to maintain quality. Hand-picked expert auditors focusing on recurring client relationships rather than volume. Strong technical education arm. Best for teams wanting a dedicated, long-term security partner rather than a one-off engagement.",
"founded": 2022,
"specialties": ["smart-contracts", "defi", "protocol-design", "developer-education"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base"],
"auditTypes": ["smart-contract", "protocol", "peer-review"],
"priceTier": 2,
"rating": 4.5,
"notableAudits": ["Thirdweb", "Superfluid", "Maple Finance"],
"publicReports": true,
"turnaround": "3-6 weeks",
"teamSize": "15+",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/0xMacro",
"github": "https://github.com/0xMacro",
"website": "https://0xmacro.com"
},
"lastUpdated": "2026-04-05",
"featured": false
}
17. Three Sigma
{
"slug": "three-sigma",
"name": "Three Sigma",
"logo": "/images/auditors/three-sigma.svg",
"description": "Security firm providing blockchain audits for DeFi projects, tokens, and protocols. Works alongside firms like Spearbit and Trail of Bits on major engagements. Strong in Move language auditing (Aptos/Sui) in addition to EVM and Solana coverage.",
"founded": 2022,
"specialties": ["smart-contracts", "defi", "move", "protocol-design", "bridges"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "solana", "aptos", "sui"],
"auditTypes": ["smart-contract", "protocol", "move-audit"],
"priceTier": 2,
"rating": 4.4,
"notableAudits": ["Maple Finance", "Various DeFi protocols"],
"publicReports": true,
"turnaround": "3-8 weeks",
"teamSize": "25+",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/threesigmaxyz",
"github": "https://github.com/three-sigma",
"website": "https://threesigma.xyz"
},
"lastUpdated": "2026-04-05",
"featured": false
}
18. MoveBit (BitsLab)
{
"slug": "movebit",
"name": "MoveBit (BitsLab)",
"logo": "/images/auditors/movebit.svg",
"description": "Pioneer in Move ecosystem security, covering 80%+ of Move ecosystem projects. First firm to leverage formal verification in the Move ecosystem. Built the Move Analyzer suite of VSCode plugins. The definitive specialist for Aptos and Sui smart contract security.",
"founded": 2022,
"specialties": ["move", "aptos", "sui", "formal-verification", "smart-contracts"],
"chains": ["aptos", "sui"],
"auditTypes": ["smart-contract", "protocol", "formal-verification", "move-audit"],
"priceTier": 2,
"rating": 4.3,
"notableAudits": ["Aptos Foundation", "Sui ecosystem projects", "Liquidswap"],
"publicReports": true,
"turnaround": "3-6 weeks",
"teamSize": "30+",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/MoveBit_",
"github": "https://github.com/movebit",
"website": "https://movebit.xyz"
},
"lastUpdated": "2026-04-05",
"featured": false
}
19. QuillAudits
{
"slug": "quillaudits",
"name": "QuillAudits",
"logo": "/images/auditors/quillaudits.svg",
"description": "Prolific audit firm with 1,500+ audits across 25+ blockchains, securing over $30B AUM. Built QuillShield AI for automated vulnerability detection. Affordable pricing makes them accessible for smaller teams. Broad coverage and fast turnaround, though depth may vary on complex engagements.",
"founded": 2018,
"specialties": ["smart-contracts", "defi", "nft", "l2", "wallet-security"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "bnb-chain", "avalanche", "solana", "cosmos"],
"auditTypes": ["smart-contract", "protocol", "token", "penetration-test", "dapp"],
"priceTier": 1,
"rating": 4.0,
"notableAudits": ["Taiko", "Polygon", "Manta", "Covalent", "Metis"],
"publicReports": true,
"turnaround": "2-5 weeks",
"teamSize": "38+",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/QuillAudits",
"github": "https://github.com/Quillhash",
"website": "https://www.quillaudits.com"
},
"lastUpdated": "2026-04-05",
"featured": false
}
20. Oxorio
{
"slug": "oxorio",
"name": "Oxorio",
"logo": "/images/auditors/oxorio.svg",
"description": "Boutique audit firm that deliberately limits client volume to ensure every audit receives deep attention. Focused on quality over quantity with senior-only review teams. Best for protocols wanting thorough, unhurried security analysis from experienced researchers.",
"founded": 2018,
"specialties": ["smart-contracts", "defi", "protocol-design", "cross-chain"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base"],
"auditTypes": ["smart-contract", "protocol"],
"priceTier": 2,
"rating": 4.3,
"notableAudits": ["Various DeFi protocols"],
"publicReports": true,
"turnaround": "4-8 weeks",
"teamSize": "15+",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/OxorioSecurity",
"github": "https://github.com/nicenomad",
"website": "https://oxor.io"
},
"lastUpdated": "2026-04-05",
"featured": false
}
21. Hashlock
{
"slug": "hashlock",
"name": "Hashlock",
"logo": "/images/auditors/hashlock.svg",
"description": "Australian web3 security firm focused on prevention, education, and innovation. Launched a free AI audit tool for instant smart contract vulnerability analysis. Good for teams in the APAC region wanting a local firm with competitive pricing and accessible tooling.",
"founded": 2020,
"specialties": ["smart-contracts", "defi", "nft", "ai-auditing"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "bnb-chain"],
"auditTypes": ["smart-contract", "protocol", "token"],
"priceTier": 1,
"rating": 4.1,
"notableAudits": ["Various APAC blockchain projects"],
"publicReports": true,
"turnaround": "2-6 weeks",
"teamSize": "20+",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/HashLockAudit",
"github": "https://github.com/nicenomad",
"website": "https://hashlock.com"
},
"lastUpdated": "2026-04-05",
"featured": false
}
22. SigIntZero
{
"slug": "sigintzero",
"name": "SigIntZero",
"logo": "/images/auditors/sigintzero.svg",
"description": "Australia-based firm specializing in DeFi security, L1 infrastructure, and web3 protocol assurance. Backed by Sentinel, an internal AI engine for automated scanning. Strong technical depth on complex protocol designs. A rising firm with growing reputation for quality.",
"founded": 2022,
"specialties": ["smart-contracts", "defi", "l1-l2", "infrastructure", "ai-auditing"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base"],
"auditTypes": ["smart-contract", "protocol", "infrastructure"],
"priceTier": 2,
"rating": 4.3,
"notableAudits": ["Various DeFi and L1 protocols"],
"publicReports": true,
"turnaround": "3-8 weeks",
"teamSize": "20+",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/SigIntZero",
"github": "https://github.com/nicenomad",
"website": "https://sigintzero.com"
},
"lastUpdated": "2026-04-05",
"featured": false
}
23. Softstack
{
"slug": "softstack",
"name": "Softstack",
"logo": "/images/auditors/softstack.svg",
"description": "German blockchain security firm since 2017. 800+ clients, 1,500+ audits, and $100B+ in TVL secured. Broad service portfolio including smart contract auditing, digital asset assessment, penetration testing, and dApp audits. Reliable European option with strong track record.",
"founded": 2017,
"specialties": ["smart-contracts", "defi", "penetration-testing", "dapp-security"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "bnb-chain", "solana"],
"auditTypes": ["smart-contract", "protocol", "penetration-test", "dapp"],
"priceTier": 2,
"rating": 4.2,
"notableAudits": ["Various European blockchain projects"],
"publicReports": true,
"turnaround": "3-6 weeks",
"teamSize": "40+",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/nicenomad",
"github": "https://github.com/nicenomad",
"website": "https://softstack.io"
},
"lastUpdated": "2026-04-05",
"featured": false
}
24. Blaize
{
"slug": "blaize",
"name": "Blaize",
"logo": "/images/auditors/blaize.svg",
"description": "Full-service blockchain security company offering comprehensive web3 security audits. Covers the full development lifecycle from architecture review to post-deployment monitoring. Competitive pricing with solid methodology.",
"founded": 2018,
"specialties": ["smart-contracts", "defi", "nft", "dapp-security", "architecture"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "bnb-chain", "avalanche"],
"auditTypes": ["smart-contract", "protocol", "dapp", "architecture-review"],
"priceTier": 1,
"rating": 4.0,
"notableAudits": ["Various DeFi protocols"],
"publicReports": true,
"turnaround": "2-6 weeks",
"teamSize": "40+",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/nicenomad",
"github": "https://github.com/nicenomad",
"website": "https://security.blaize.tech"
},
"lastUpdated": "2026-04-05",
"featured": false
}
25. Certora
{
"slug": "certora",
"name": "Certora",
"logo": "/images/auditors/certora.svg",
"description": "Formal verification-focused firm that created the Certora Prover, now free and open-source. 7+ years of development securing $100B+ in TVL across Aave, MakerDAO, Uniswap, and Lido. Unlike testing which samples execution paths, Certora mathematically proves correctness for all possible states.",
"founded": 2017,
"specialties": ["formal-verification", "smart-contracts", "defi", "protocol-design"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "solana", "stellar"],
"auditTypes": ["formal-verification", "smart-contract", "protocol"],
"priceTier": 3,
"rating": 4.7,
"notableAudits": ["Aave", "MakerDAO", "Uniswap", "Lido", "Compound"],
"publicReports": true,
"turnaround": "6-12 weeks",
"teamSize": "50+",
"referralUrl": null,
"socials": {
"twitter": "https://twitter.com/CertoraInc",
"github": "https://github.com/Certora",
"website": "https://www.certora.com"
},
"lastUpdated": "2026-04-05",
"featured": false
}
PART 2: TOOLS
Currently in Dataset (36 tools)
slither, echidna, forta, mythril, semgrep-solidity, aderyn, solhint, wake, foundry-fuzz, medusa, harvey, certora-prover, halmos, kevm, scribble, openzeppelin-defender, tenderly, hexagate, chainalysis, blocknative, fireblocks, safe-wallet, fordefi, ledger-enterprise, socket-dev, snyk, npm-audit, cargo-audit, olympix, 4naly3er, pyrometer, heimdall, dedaub-decompiler, immunefi-platform, echidna-parade, manticore
Missing Tools to Add
1. Hypernative
{
"slug": "hypernative",
"name": "Hypernative",
"description": "Real-time Web3 threat detection and prevention platform using proprietary ML models. Detects cyber, economic, governance, and community threats before they have impact.",
"longDescription": "Hypernative's pre-cog platform uses machine learning models to monitor on-chain and off-chain data sources, predicting and preventing threats before they execute. It covers security exploits, governance attacks, economic manipulation, and community threats across DeFi protocols, chains, and asset managers. Automated response capabilities can block or mitigate attacks in real-time.",
"category": ["monitoring", "threat-detection", "ai-powered"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "bnb-chain", "avalanche"],
"pricing": "enterprise",
"openSource": false,
"github": null,
"docs": "https://docs.hypernative.io",
"website": "https://www.hypernative.io",
"aiPowered": true,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["forta", "hexagate", "openzeppelin-defender"],
"alternativeTo": ["forta", "hexagate"],
"lastUpdated": "2026-04-05",
"featured": true
}
2. Blockaid
{
"slug": "blockaid",
"name": "Blockaid",
"description": "Real-time transaction screening and dApp security platform. Scans 15M+ sites daily and protects major wallets including MetaMask, Coinbase, and Safe from scams and exploits.",
"longDescription": "Blockaid is a detection platform purpose-built for web3 that monitors transactions, dApps, and tokens to detect and block threats in real-time. Integrated with Coinbase, MetaMask, World App, Safe, and Uniswap, it provides pre-transaction simulation, malicious dApp detection, and token scanning. Its Cosigner product adds policy-based validation for institutional MPC and multisig wallets.",
"category": ["threat-detection", "wallet-custody", "ai-powered"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "bnb-chain", "avalanche", "solana"],
"pricing": "enterprise",
"openSource": false,
"github": null,
"docs": "https://docs.blockaid.io",
"website": "https://www.blockaid.io",
"aiPowered": true,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["safe-wallet", "fireblocks"],
"alternativeTo": ["forta", "hypernative"],
"lastUpdated": "2026-04-05",
"featured": true
}
3. Flashbots Protect
{
"slug": "flashbots-protect",
"name": "Flashbots Protect",
"description": "Private transaction RPC that shields users from MEV extraction. Serves 2.1M+ Ethereum accounts and has protected $43B in DEX volume from frontrunning and sandwich attacks.",
"longDescription": "Flashbots Protect is a free RPC endpoint that routes transactions through a private mempool, preventing MEV searchers from frontrunning or sandwiching user trades. It refunds MEV back to users where possible (313 ETH in refunds to date). In 2025, Flashbots is migrating to TEE-based infrastructure for even stronger privacy guarantees. Simply add the RPC to your wallet to get protection.",
"category": ["threat-detection"],
"chains": ["ethereum"],
"pricing": "free",
"openSource": true,
"github": "https://github.com/flashbots",
"docs": "https://docs.flashbots.net/flashbots-protect/overview",
"website": "https://protect.flashbots.net",
"aiPowered": false,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["blocknative"],
"alternativeTo": ["blocknative"],
"lastUpdated": "2026-04-05",
"featured": true
}
4. GoPlus Security
{
"slug": "goplus-security",
"name": "GoPlus Security",
"description": "Web3 security infrastructure providing token security detection, malicious address screening, and contract risk analysis across 30+ chains.",
"longDescription": "GoPlus Security is a leading Web3 security layer that provides API-driven security services including token security detection (trading status, taxes, mint/blacklist/pause functions, ownership), NFT security, malicious address detection, and dApp security info. Covering 30+ blockchain networks and safeguarding millions of wallets, it serves as real-time security infrastructure for wallets, DEXs, and DeFi protocols.",
"category": ["vulnerability-scanner", "threat-detection"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "bnb-chain", "avalanche", "solana"],
"pricing": "freemium",
"openSource": true,
"github": "https://github.com/GoPlusSecurity",
"docs": "https://docs.gopluslabs.io",
"website": "https://gopluslabs.io",
"aiPowered": true,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["token-sniffer", "defi-scanner"],
"alternativeTo": ["token-sniffer", "defi-scanner"],
"lastUpdated": "2026-04-05",
"featured": false
}
5. Token Sniffer
{
"slug": "token-sniffer",
"name": "Token Sniffer",
"description": "Automated token contract scanner for detecting rug pulls, honeypots, and scam tokens across EVM chains. Free to use for basic analysis.",
"longDescription": "Token Sniffer scans fungible token contracts on Ethereum, Polygon, BNB Chain, and other EVM chains to identify potential risks including ownership not renounced, high dump risk, unlimited minting functions, and honeypot mechanics. It monitors millions of tokens and provides a simple risk score to help users evaluate token safety before investing.",
"category": ["vulnerability-scanner"],
"chains": ["ethereum", "polygon", "bnb-chain", "arbitrum", "base"],
"pricing": "free",
"openSource": false,
"github": null,
"docs": null,
"website": "https://tokensniffer.com",
"aiPowered": false,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["goplus-security", "defi-scanner"],
"alternativeTo": ["goplus-security", "defi-scanner"],
"lastUpdated": "2026-04-05",
"featured": false
}
6. De.Fi Scanner
{
"slug": "defi-scanner",
"name": "De.Fi Scanner",
"description": "Smart contract and token analyzer with proprietary De.Fi Score rating system. Scans for rug pull risks, permission flags, and contract vulnerabilities across EVM chains.",
"longDescription": "De.Fi Scanner automatically analyzes risks in smart contracts, tokens, and NFTs across popular EVM chains. Its proprietary De.Fi Score rates tokens based on contract complexity, developer behavior, and transaction patterns. It identifies red flags including ownership concentration, honeypot mechanics, and malicious contract patterns. Serves as both an investor protection tool and protocol security checker.",
"category": ["vulnerability-scanner"],
"chains": ["ethereum", "polygon", "bnb-chain", "arbitrum", "optimism", "base", "avalanche"],
"pricing": "free",
"openSource": false,
"github": null,
"docs": null,
"website": "https://de.fi",
"aiPowered": false,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["goplus-security", "token-sniffer"],
"alternativeTo": ["goplus-security", "token-sniffer"],
"lastUpdated": "2026-04-05",
"featured": false
}
7. Kontrol (Runtime Verification)
{
"slug": "kontrol",
"name": "Kontrol",
"description": "Formal verification tool that combines KEVM with Foundry, letting developers verify smart contracts symbolically using existing test suites without learning new languages.",
"longDescription": "Kontrol, built by Runtime Verification, symbolically executes existing Foundry tests using the K Framework's formal EVM semantics (KEVM). Unlike testing which samples inputs, Kontrol proves properties hold for all possible states. Open-source under BSD-3 license, it bridges the gap between practical testing and formal verification by reusing developers' existing Foundry tests as verification specifications.",
"category": ["formal-verification", "testing"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism"],
"pricing": "free",
"openSource": true,
"github": "https://github.com/runtimeverification/kontrol",
"docs": "https://docs.runtimeverification.com/kontrol",
"website": "https://runtimeverification.com",
"aiPowered": false,
"referralUrl": null,
"installCmd": "kup install kontrol",
"pairsWith": ["halmos", "foundry-fuzz", "certora-prover"],
"alternativeTo": ["halmos", "certora-prover"],
"lastUpdated": "2026-04-05",
"featured": false
}
8. Recon
{
"slug": "recon",
"name": "Recon",
"description": "Unified invariant testing platform that integrates Echidna, Medusa, Halmos, and Foundry into one workflow with auto-generated boilerplate and parallel fuzzing.",
"longDescription": "Recon connects to any open-source Solidity project and automatically generates the boilerplate code needed for invariant testing across Echidna, Medusa, and Foundry. It enables parallel fuzzing, reusable test setups, and live monitoring. Used by protocols like Centrifuge and Badger DAO to secure over $1B+ in TVL. Includes a VSCode extension for scaffolding, running, and debugging invariant tests.",
"category": ["fuzzer", "testing"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base"],
"pricing": "freemium",
"openSource": true,
"github": "https://github.com/Recon-Fuzz",
"docs": "https://getrecon.xyz/docs",
"website": "https://getrecon.xyz",
"aiPowered": false,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["echidna", "medusa", "halmos", "foundry-fuzz"],
"alternativeTo": [],
"lastUpdated": "2026-04-05",
"featured": false
}
9. Gambit
{
"slug": "gambit",
"name": "Gambit",
"description": "Solidity mutation testing tool by Certora. Generates AST-level mutants to validate test suite and formal verification coverage. Written in Rust for speed.",
"longDescription": "Gambit generates mutants by analyzing the Solidity AST and applying syntax transformations that simulate subtle malicious code changes. It integrates with the Certora Prover formal verification pipeline to validate that specifications catch all meaningful code changes. Written in Rust for performance, it helps auditors and developers measure how thoroughly their tests and formal specs cover the codebase.",
"category": ["testing"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism"],
"pricing": "free",
"openSource": true,
"github": "https://github.com/Certora/gambit",
"docs": "https://docs.certora.com/en/latest/docs/gambit/gambit.html",
"website": "https://www.certora.com",
"aiPowered": false,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["certora-prover", "foundry-fuzz"],
"alternativeTo": ["vertigo-rs"],
"lastUpdated": "2026-04-05",
"featured": false
}
10. Vertigo-rs
{
"slug": "vertigo-rs",
"name": "Vertigo-rs",
"description": "Mutation testing framework for Solidity smart contracts. Introduces subtle code changes (mutants) to verify your test suite catches real vulnerabilities.",
"longDescription": "Vertigo-rs (maintained fork of the original Vertigo) is a mutation testing framework for Solidity that works with Foundry, Hardhat, and Truffle. It generates mutated versions of your smart contracts and checks whether your existing tests detect the changes. If a mutant survives, it reveals a gap in your test coverage. Essential for measuring test suite quality before audits.",
"category": ["testing"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism"],
"pricing": "free",
"openSource": true,
"github": "https://github.com/RareSkills/vertigo-rs",
"docs": "https://github.com/RareSkills/vertigo-rs#readme",
"website": "https://github.com/RareSkills/vertigo-rs",
"aiPowered": false,
"referralUrl": null,
"installCmd": "pip3 install vertigo-rs",
"pairsWith": ["foundry-fuzz", "echidna"],
"alternativeTo": ["gambit"],
"lastUpdated": "2026-04-05",
"featured": false
}
11. AuditAgent (Nethermind)
{
"slug": "auditagent",
"name": "AuditAgent",
"description": "AI-driven pre-audit tool by Nethermind that detects vulnerabilities and simulates attack scenarios beyond traditional scanning capabilities.",
"longDescription": "AuditAgent uses advanced AI models to provide deeper vulnerability insights, simulating attack scenarios that traditional static analysis tools miss. Evaluated across 29 audits, it detected valid issues in 62% of projects and identified 42% of Critical and 43% of High severity findings. Best used as a complement to manual review — a pair auditor that strengthens human-led audits rather than replacing them.",
"category": ["ai-powered", "vulnerability-scanner"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "starknet"],
"pricing": "freemium",
"openSource": false,
"github": null,
"docs": "https://docs.auditagent.nethermind.io",
"website": "https://auditagent.nethermind.io",
"aiPowered": true,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["slither", "aderyn", "olympix"],
"alternativeTo": ["olympix", "quillshield"],
"lastUpdated": "2026-04-05",
"featured": true
}
12. Veritas Protocol
{
"slug": "veritas-protocol",
"name": "Veritas Protocol",
"description": "Automated smart contract audit platform using AI (Qwen2.5-Coder architecture) to find vulnerabilities faster and cheaper than manual audits.",
"longDescription": "Veritas Protocol uses an advanced AI system built on the Qwen2.5-Coder architecture to detect vulnerabilities in smart contracts. Designed to be dramatically faster and cheaper than traditional manual audits while maintaining accuracy. Provides automated analysis reports that can serve as a first pass before engaging human auditors for deeper review.",
"category": ["ai-powered", "vulnerability-scanner"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "bnb-chain"],
"pricing": "freemium",
"openSource": false,
"github": null,
"docs": null,
"website": "https://www.veritasprotocol.com",
"aiPowered": true,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["slither", "aderyn"],
"alternativeTo": ["olympix", "auditagent"],
"lastUpdated": "2026-04-05",
"featured": false
}
13. ChainGPT Smart Contract Auditor
{
"slug": "chaingpt-auditor",
"name": "ChainGPT Smart Contract Auditor",
"description": "AI-powered auditing tool trained on historical audit data, known vulnerabilities, and past exploits. Evaluates Solidity contracts for security issues at speed.",
"longDescription": "ChainGPT's Smart Contract Auditor is an AI-powered tool that evaluates Solidity smart contracts using models trained on extensive historical audit data, industry best practices, and past exploit patterns. It provides rapid initial security assessment and vulnerability detection, serving as an accessible first-pass audit tool for developers who want quick feedback before engaging human auditors.",
"category": ["ai-powered", "vulnerability-scanner"],
"chains": ["ethereum", "polygon", "bnb-chain", "arbitrum", "optimism"],
"pricing": "freemium",
"openSource": false,
"github": null,
"docs": "https://docs.chaingpt.org/ai-tools-and-applications/ai-smart-contract-auditor",
"website": "https://www.chaingpt.org",
"aiPowered": true,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["slither", "aderyn"],
"alternativeTo": ["olympix", "veritas-protocol"],
"lastUpdated": "2026-04-05",
"featured": false
}
14. QuillShield
{
"slug": "quillshield",
"name": "QuillShield",
"description": "AI-powered smart contract analyzer by QuillAudits that detects logical errors beyond common vulnerability patterns in Solidity code.",
"longDescription": "QuillShield enhances traditional static analysis by using AI to detect logical errors and business logic vulnerabilities that pattern-based scanners typically miss. It goes beyond common vulnerability databases to identify context-specific issues in how smart contract logic interacts. Designed as a pre-audit tool to catch issues early in the development lifecycle.",
"category": ["ai-powered", "vulnerability-scanner"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "bnb-chain"],
"pricing": "freemium",
"openSource": false,
"github": null,
"docs": null,
"website": "https://www.quillaudits.com",
"aiPowered": true,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["slither", "aderyn"],
"alternativeTo": ["olympix", "auditagent"],
"lastUpdated": "2026-04-05",
"featured": false
}
15. Phalcon (BlockSec)
{
"slug": "phalcon",
"name": "Phalcon",
"description": "World's first crypto hack blocking system by BlockSec. Real-time attack detection and automated response that has prevented $20M+ in losses across 20+ incidents.",
"longDescription": "Phalcon by BlockSec integrates advanced attack detection, real-time monitoring, and automated response capabilities. Its Security APP detects and prevents hacks in real time, while the Compliance APP streamlines AML/CTF compliance. Phalcon has successfully blocked 20+ critical attacks in production, preventing over $20M in losses. Provides transaction simulation, debugging, and compliance tools in one platform.",
"category": ["monitoring", "threat-detection"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "bnb-chain"],
"pricing": "enterprise",
"openSource": false,
"github": null,
"docs": "https://docs.blocksec.com/phalcon",
"website": "https://blocksec.com/phalcon",
"aiPowered": true,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["forta", "hypernative"],
"alternativeTo": ["forta", "hexagate", "hypernative"],
"lastUpdated": "2026-04-05",
"featured": false
}
16. MetaSleuth (BlockSec)
{
"slug": "metasleuth",
"name": "MetaSleuth",
"description": "On-chain fund tracking and investigation platform by BlockSec. Traces transaction flows and wallet relationships for incident response and forensic analysis.",
"longDescription": "MetaSleuth is BlockSec's investigative platform for tracking fund flows and analyzing wallet relationships on-chain. Used for incident response after exploits, forensic investigation, and compliance analysis. Provides visual transaction tracing, wallet clustering, and fund flow analysis across multiple chains.",
"category": ["monitoring"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "bnb-chain"],
"pricing": "freemium",
"openSource": false,
"github": null,
"docs": null,
"website": "https://metasleuth.io",
"aiPowered": false,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["chainalysis", "phalcon"],
"alternativeTo": ["chainalysis"],
"lastUpdated": "2026-04-05",
"featured": false
}
17. TRM Labs
{
"slug": "trm-labs",
"name": "TRM Labs",
"description": "Blockchain intelligence platform covering 77 chains with FedRAMP High authorization. Used by government agencies and financial institutions for compliance and investigation.",
"longDescription": "TRM Labs provides blockchain intelligence for compliance, investigation, and risk management. With FedRAMP High authorization (the most stringent federal security certification) and coverage of 77 blockchains, it serves government agencies, exchanges, and financial institutions. Features transparent, explainable attribution and an AI investigative assistant for accelerated analysis.",
"category": ["monitoring"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "bnb-chain", "avalanche", "solana", "bitcoin"],
"pricing": "enterprise",
"openSource": false,
"github": null,
"docs": null,
"website": "https://www.trmlabs.com",
"aiPowered": true,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["chainalysis"],
"alternativeTo": ["chainalysis", "elliptic"],
"lastUpdated": "2026-04-05",
"featured": false
}
18. Elliptic
{
"slug": "elliptic",
"name": "Elliptic",
"description": "Blockchain analytics and compliance platform processing 300M screenings per quarter with 99.99% uptime. AI copilot reduces alert management time by 50%.",
"longDescription": "Elliptic provides blockchain analytics for crypto compliance, risk management, and investigation. Processing 300 million screenings per quarter with near-perfect uptime and 1.6s API latency. Its AI copilot generates screening summaries and risk analysis, reportedly reducing alert management time by 50%. Trusted by financial institutions and exchanges for AML/KYC compliance and transaction monitoring.",
"category": ["monitoring"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "bnb-chain", "avalanche", "solana", "bitcoin"],
"pricing": "enterprise",
"openSource": false,
"github": null,
"docs": null,
"website": "https://www.elliptic.co",
"aiPowered": true,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["chainalysis"],
"alternativeTo": ["chainalysis", "trm-labs"],
"lastUpdated": "2026-04-05",
"featured": false
}
19. Arkham Intelligence
{
"slug": "arkham-intelligence",
"name": "Arkham Intelligence",
"description": "On-chain intelligence platform with entity-level wallet labeling, real-time alerts, and an intelligence marketplace. Deanonymizes blockchain activity at scale.",
"longDescription": "Arkham Intelligence provides on-chain analytics with extensive wallet labeling, linking blockchain addresses to real-world entities. Features include real-time alerts on whale movements, portfolio tracking, entity-level analysis, and an intelligence marketplace where users can buy and sell blockchain insights. Popular with traders, researchers, and investigators for understanding fund flows and market movements.",
"category": ["monitoring"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "bnb-chain", "avalanche", "solana", "bitcoin"],
"pricing": "freemium",
"openSource": false,
"github": null,
"docs": null,
"website": "https://www.arkhamintelligence.com",
"aiPowered": true,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["chainalysis", "nansen"],
"alternativeTo": ["chainalysis", "nansen"],
"lastUpdated": "2026-04-05",
"featured": false
}
20. Nansen
{
"slug": "nansen",
"name": "Nansen",
"description": "AI-driven on-chain analytics platform with 500M+ labeled wallets. Tracks smart money flows, whale movements, and DeFi activity across major chains.",
"longDescription": "Nansen combines on-chain data with off-chain labeling to identify who is behind wallet activity. With 500M+ labeled wallets including exchanges, whales, funds, and DAOs, it provides real-time dashboards for token flows, DeFi interactions, and NFT activity. Used by investors, protocols, and researchers for market intelligence, due diligence, and security monitoring.",
"category": ["monitoring"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "bnb-chain", "avalanche", "solana"],
"pricing": "paid",
"openSource": false,
"github": null,
"docs": null,
"website": "https://www.nansen.ai",
"aiPowered": true,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["chainalysis", "arkham-intelligence"],
"alternativeTo": ["arkham-intelligence"],
"lastUpdated": "2026-04-05",
"featured": false
}
21. Trugard
{
"slug": "trugard",
"name": "Trugard",
"description": "AI-driven smart contract risk intelligence engine with 20M+ contracts scored. Uses dynamic analysis to predict contract behavior beyond known vulnerability patterns.",
"longDescription": "Trugard uses AI and machine learning to assess smart contract risks, providing actionable insights to developers, enterprises, and investors. Unlike conventional scanners that check for known vulnerabilities, Trugard employs dynamic analysis to predict how contracts will behave under various scenarios. With over 20 million contracts scored, it serves as a comprehensive risk intelligence layer for the web3 ecosystem.",
"category": ["ai-powered", "vulnerability-scanner"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "bnb-chain"],
"pricing": "freemium",
"openSource": false,
"github": null,
"docs": null,
"website": "https://www.trugard.ai",
"aiPowered": true,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["goplus-security", "blockaid"],
"alternativeTo": ["goplus-security"],
"lastUpdated": "2026-04-05",
"featured": false
}
22. DeFiSafety
{
"slug": "defisafety",
"name": "DeFiSafety",
"description": "Independent DeFi protocol rating organization. Scores protocols 0-100 on process quality, smart contracts, documentation, testing, security, and admin controls.",
"longDescription": "DeFiSafety publishes Process Quality Reviews (PQRs), Contract Scores, and Chain Scores for DeFi protocols. PQRs evaluate six categories: smart contracts & team, documentation, testing, security, admin controls, and oracle assessment. A passing score is 70%. Research shows lower DeFiSafety scores correlate with increased likelihood of protocol exploits, making it a useful risk signal for investors and integrators.",
"category": ["vulnerability-scanner"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "bnb-chain", "avalanche"],
"pricing": "free",
"openSource": false,
"github": null,
"docs": null,
"website": "https://www.defisafety.com",
"aiPowered": false,
"referralUrl": null,
"installCmd": null,
"pairsWith": [],
"alternativeTo": [],
"lastUpdated": "2026-04-05",
"featured": false
}
23. Chaos Labs
{
"slug": "chaos-labs",
"name": "Chaos Labs",
"description": "DeFi economic security platform providing agent-based simulations, real-time risk monitoring, and automated parameter optimization for lending protocols.",
"longDescription": "Chaos Labs is the first automated risk management platform for crypto. It runs agent-based and scenario-based simulations on mainnet forks to stress-test protocol economics against attacks, volatility, and market manipulation. Risk Oracles monitor key indicators in real-time and adjust protocol parameters when significant deviations are detected. Trusted by Aave, Uniswap, and other major DeFi protocols for ongoing economic security.",
"category": ["monitoring", "testing"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base", "avalanche"],
"pricing": "enterprise",
"openSource": false,
"github": null,
"docs": null,
"website": "https://chaoslabs.xyz",
"aiPowered": true,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["forta", "tenderly"],
"alternativeTo": ["gauntlet"],
"lastUpdated": "2026-04-05",
"featured": false
}
24. Gauntlet
{
"slug": "gauntlet",
"name": "Gauntlet",
"description": "Simulation-based risk modeling platform for DeFi protocols. Tests economic hypotheses and optimizes risk parameters through agent-based simulations.",
"longDescription": "Gauntlet provides simulation-based risk management for DeFi protocols, modeling protocol behavior under various market conditions, attack vectors, and parameter configurations. Its customizable agents simulate market manipulators, liquidators, and other adversaries to stress-test protocol economics. Used by Aave, Maker, Compound, and Synthetix for ongoing parameter optimization and risk assessment.",
"category": ["monitoring", "testing"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism", "base"],
"pricing": "enterprise",
"openSource": false,
"github": null,
"docs": null,
"website": "https://www.gauntlet.xyz",
"aiPowered": true,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["tenderly"],
"alternativeTo": ["chaos-labs"],
"lastUpdated": "2026-04-05",
"featured": false
}
25. Surya
{
"slug": "surya",
"name": "Surya",
"description": "Smart contract visualization tool by ConsenSys. Generates call graphs, inheritance diagrams, and function interaction maps for Solidity codebases.",
"longDescription": "Surya is a utility tool for smart contract systems that provides visual outputs including call graphs, inheritance diagrams, and function interaction maps. It supports querying the function call graph and is integrated with the Solidity Visual Developer VSCode extension. Essential for auditors and developers who need to quickly understand complex contract architectures and identify potential interaction risks.",
"category": ["static-analyzer"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism"],
"pricing": "free",
"openSource": true,
"github": "https://github.com/ConsenSysDiligence/surya",
"docs": "https://github.com/ConsenSysDiligence/surya#readme",
"website": "https://github.com/ConsenSysDiligence/surya",
"aiPowered": false,
"referralUrl": null,
"installCmd": "npm install -g surya",
"pairsWith": ["slither", "solidity-visual-developer"],
"alternativeTo": [],
"lastUpdated": "2026-04-05",
"featured": false
}
26. Solidity Visual Developer
{
"slug": "solidity-visual-developer",
"name": "Solidity Visual Developer",
"description": "VSCode extension for smart contract auditors. Provides visual code analysis, flowchart generation, and security-focused code navigation for Solidity.",
"longDescription": "Solidity Visual Developer is a powerful VSCode plugin designed for smart contract auditors and developers. It provides syntax highlighting with security awareness, flowchart generation for contract logic, inheritance visualization, and integrated tools like Surya for call graph analysis. Enhances the auditing process by making complex contract interactions visually comprehensible.",
"category": ["static-analyzer"],
"chains": ["ethereum", "polygon", "arbitrum", "optimism"],
"pricing": "free",
"openSource": true,
"github": "https://github.com/ConsenSys/vscode-solidity-auditor",
"docs": null,
"website": "https://marketplace.visualstudio.com/items?itemName=tintinweb.solidity-visual-auditor",
"aiPowered": false,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["surya", "slither", "aderyn"],
"alternativeTo": [],
"lastUpdated": "2026-04-05",
"featured": false
}
27. Move Prover
{
"slug": "move-prover",
"name": "Move Prover",
"description": "Formal verification tool for Move smart contracts on Aptos and Sui. Uses Move Specification Language to mathematically prove contract correctness.",
"longDescription": "Move Prover (MVP) verifies smart contracts written in the Move language through formal verification. Users specify functional properties using the Move Specification Language (MSL), and the prover automatically checks them against all possible execution states. Supports struct invariants, per-function specifications, and global state-machine specifications. Critical for ensuring correctness in the Aptos and Sui ecosystems.",
"category": ["formal-verification"],
"chains": ["aptos", "sui"],
"pricing": "free",
"openSource": true,
"github": "https://github.com/move-language/move",
"docs": "https://aptos.dev/build/smart-contracts/prover",
"website": "https://aptos.dev",
"aiPowered": false,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["move-analyzer"],
"alternativeTo": [],
"lastUpdated": "2026-04-05",
"featured": false
}
28. Move Analyzer (MoveBit)
{
"slug": "move-analyzer",
"name": "Move Analyzer",
"description": "VSCode plugin suite by MoveBit providing syntax highlighting, code completion, diagnostics, and Move Specification Language support for Aptos and Sui development.",
"longDescription": "The Move Analyzer suite, developed by MoveBit/BitsLab, offers end-to-end development support for Move language across Aptos and Sui ecosystems. Features include syntax highlighting, intelligent code completion, navigation tools, diagnostics, framework integration, and recently added Move Specification Language (MSL) support for formal verification workflows. Available as a VSCode extension.",
"category": ["static-analyzer"],
"chains": ["aptos", "sui"],
"pricing": "free",
"openSource": true,
"github": "https://github.com/movebit/move-analyzer",
"docs": null,
"website": "https://movebit.xyz/analyzer",
"aiPowered": false,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["move-prover"],
"alternativeTo": [],
"lastUpdated": "2026-04-05",
"featured": false
}
29. Circomspect
{
"slug": "circomspect",
"name": "Circomspect",
"description": "Static analysis tool for Circom ZK circuits developed by zkSecurity. Detects common vulnerabilities in zero-knowledge proof implementations.",
"longDescription": "Circomspect is an open-source static analysis tool specifically designed for auditing Circom zero-knowledge circuits. It detects common ZK circuit vulnerabilities including under-constrained signals, unused variables, and constraint issues that could compromise proof soundness. Developed and maintained by zkSecurity, it assists both auditors and developers in building secure ZK applications.",
"category": ["static-analyzer"],
"chains": ["ethereum"],
"pricing": "free",
"openSource": true,
"github": "https://github.com/trailofbits/circomspect",
"docs": "https://github.com/trailofbits/circomspect#readme",
"website": "https://zksecurity.xyz",
"aiPowered": false,
"referralUrl": null,
"installCmd": "cargo install circomspect",
"pairsWith": [],
"alternativeTo": [],
"lastUpdated": "2026-04-05",
"featured": false
}
30. Picus (Veridise)
{
"slug": "picus",
"name": "Picus",
"description": "In-house ZK circuit vulnerability detection tool by Veridise. Specifically designed for ensuring correctness of zero-knowledge circuit implementations.",
"longDescription": "Picus is Veridise's proprietary detection tool designed specifically for zero-knowledge circuit security analysis. It identifies issues like under-constrained circuits, soundness bugs, and implementation flaws in ZK proof systems. Used internally by Veridise's audit team (which includes multiple PhDs in formal methods and cryptography) to complement manual review of ZK circuits.",
"category": ["static-analyzer"],
"chains": ["ethereum", "starknet", "scroll"],
"pricing": "enterprise",
"openSource": false,
"github": null,
"docs": null,
"website": "https://veridise.com/security/tools/zk-tool",
"aiPowered": false,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["circomspect"],
"alternativeTo": ["circomspect"],
"lastUpdated": "2026-04-05",
"featured": false
}
31. Soteria
{
"slug": "soteria",
"name": "Soteria",
"description": "Static analysis tool for Solana programs by Sec3. Analyzes Rust code for common Solana-specific vulnerabilities including missing account validation and CPI issues.",
"longDescription": "Soteria is Sec3's static analyzer designed specifically for Solana programs written in Rust and Anchor. It detects common Solana-specific vulnerabilities such as missing account validation, cross-program invocation (CPI) risks, program-derived address exploits, and missing signer checks. Provides automated first-pass vulnerability detection tailored to the unique security model of Solana.",
"category": ["static-analyzer", "vulnerability-scanner"],
"chains": ["solana"],
"pricing": "freemium",
"openSource": false,
"github": null,
"docs": null,
"website": "https://www.sec3.dev",
"aiPowered": false,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["cargo-audit"],
"alternativeTo": [],
"lastUpdated": "2026-04-05",
"featured": false
}
32. EigenPhi
{
"slug": "eigenphi",
"name": "EigenPhi",
"description": "MEV analytics and monitoring platform. Tracks sandwich attacks, arbitrage, liquidations, and other MEV activity across DeFi protocols in real-time.",
"longDescription": "EigenPhi provides detailed analytics on MEV (Maximal Extractable Value) activity including sandwich attacks, arbitrage opportunities, and liquidation events across Ethereum and other EVM chains. Used by researchers, traders, and protocols to monitor MEV extraction, verify protection effectiveness, and understand the economics of MEV on their platforms.",
"category": ["monitoring"],
"chains": ["ethereum", "polygon", "arbitrum", "bnb-chain"],
"pricing": "freemium",
"openSource": false,
"github": null,
"docs": null,
"website": "https://eigenphi.io",
"aiPowered": false,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["flashbots-protect", "blocknative"],
"alternativeTo": [],
"lastUpdated": "2026-04-05",
"featured": false
}
33. Solana Security Scanner
{
"slug": "solana-security-scanner",
"name": "Solana Security Scanner",
"description": "Official Solana toolkit security scanner for detecting common vulnerabilities in Solana programs built with Rust and Anchor.",
"longDescription": "The Solana Security Scanner is part of the official Solana development toolkit for checking programs for common security vulnerabilities. It provides automated scanning of Solana programs to detect issues like missing account validation, unsafe CPI patterns, and other Solana-specific security anti-patterns. Integrated into the Solana development workflow.",
"category": ["vulnerability-scanner"],
"chains": ["solana"],
"pricing": "free",
"openSource": true,
"github": "https://github.com/solana-labs/solana",
"docs": "https://solana.com/docs/toolkit/test-suite/security-scanner",
"website": "https://solana.com",
"aiPowered": false,
"referralUrl": null,
"installCmd": null,
"pairsWith": ["cargo-audit", "soteria"],
"alternativeTo": ["soteria"],
"lastUpdated": "2026-04-05",
"featured": false
}
PART 3: PROPOSED NEW CATEGORIES
The existing category list should be expanded. Recommended additions:
| Slug | Label |
|---|---|
forensics |
Forensics & Investigation |
mev-protection |
MEV Protection |
defi-risk |
DeFi Risk Management |
token-scanner |
Token Scanners |
zk-security |
ZK Security |
competitive-audit |
Competitive Audit Platforms |
economic-security |
Economic Security |
PART 4: COMMUNITY CONSENSUS SUMMARY
Top Firms by Community Recognition (Cross-Referenced Sources)
Tier 1 — Universally Recognized (mentioned in 5+ independent sources):
- Trail of Bits
- OpenZeppelin
- Cyfrin
- Spearbit/Cantina
- Sherlock
- CertiK (volume leader, quality debates)
- Zellic
Tier 2 — Highly Respected (mentioned in 3-4 sources):
- Pashov Audit Group
- OtterSec
- Halborn
- Quantstamp
- ConsenSys Diligence
- Nethermind Security
- Hacken
- Code4rena
- BlockSec
- Dedaub
Tier 3 — Solid Specialists (mentioned in 1-2 sources):
- Runtime Verification (formal verification specialist)
- Veridise (ZK specialist)
- zkSecurity (crypto specialist)
- Sigma Prime (Ethereum consensus)
- Ackee Blockchain (Solana/EVM)
- Guardian Audits (fuzzing-first)
- 0xMacro (boutique quality)
- Pessimistic (adversarial approach)
- MixBytes (zero rekts track record)
- MoveBit (Move ecosystem)
- Three Sigma (DeFi focus)
- NCC Group (traditional → web3)
- Kudelski Security (cryptography heritage)
Top Tools by Community Usage
Static Analysis: Slither (dominant), Aderyn (rising fast), Semgrep, Mythril Fuzzing: Echidna + Medusa (Trail of Bits ecosystem), Foundry Fuzz (most popular dev tool), Recon (unified platform) Formal Verification: Certora Prover (now open-source), Halmos (a16z), Kontrol (Runtime Verification) AI-Powered: Olympix (DevSecOps leader), AuditAgent (Nethermind), Veritas Protocol Monitoring: Forta (decentralized standard), Hypernative (ML-powered), BlockSec Phalcon (incident response), Hexagate (Chainalysis) Forensics: Chainalysis (government standard), TRM Labs (compliance), Elliptic (speed), Arkham Intelligence (entity intelligence) MEV Protection: Flashbots Protect (2.1M users), MEV Blocker, Blocknative Token Scanning: GoPlus (30+ chains), Token Sniffer, De.Fi Scanner DeFi Risk: Chaos Labs (simulation), Gauntlet (modeling), DeFiSafety (ratings) Wallet Security: Blockaid (transaction screening), Fireblocks (institutional MPC), Safe (multisig standard)
PART 5: RESEARCH SOURCES
- Sherlock: Top 10 Best Smart Contract Auditing Companies in 2026
- QuillAudits: Top 15 Smart Contract Audit Firms in 2026
- Alchemy: List of 91 Blockchain Auditing Companies
- Alchemy: List of 174 Web3 Security Tools
- CryptoJobsList: Top 8 Smart Contract Audit Companies
- BeInCrypto: Best Web3 Security Audit Companies in 2026
- Cyfrin: Best Smart Contract Auditing and Security Tools
- QuillAudits: Top 10 Smart Contract Security Tools in 2026
- Softstack: Top 5 Smart Contract Auditors for Solana
- MarkAICode: ZK Proof Auditing Tools 2025
- zkSecurity: State of Security Tools for ZKPs
- Johnny Time: Complete Audit Competitions Guide
- BlockSec: Top 5 Security Monitoring Platforms
- Allium: Top Blockchain Intelligence Platforms 2025
- Sherlock: Smart Contract Audit Pricing 2026
- Immunefi: Bug Bounty Programs
- Forta Network: Documentation
- OtterSec: Security Audits
- Pashov Audit Group
- Veridise: ZK Security
- Nethermind: AuditAgent
- Flashbots: Protect Documentation
- Certora: Prover Goes Open Source
- Runtime Verification: Kontrol
- Chaos Labs
- Blockaid
- Hypernative
- GoPlus Security
- DeFiSafety
PART 6: SUMMARY OF GAPS IN CURRENT DATASET
Auditors Missing (25 firms to add)
- OtterSec — Major Solana-focused firm (user flagged)
- NCC Group — Traditional security firm doing web3 (user flagged)
- Kudelski Security — Cryptography heritage, 25+ blockchain specialists
- Sec3 — Solana-native with Soteria analyzer
- Neodyme — German Solana security researchers
- Pashov Audit Group — 50+ researchers, 400+ audits, Tier 1 reputation
- Guardian Audits — Fuzzing-first boutique
- Cantina — Spearbit's marketplace platform
- Hats Finance — Decentralized competitive audit platform
- Hacken — 2,300+ audits, 130+ staff, exchanges specialist
- Nethermind Security — PhD-heavy team, ZK/Starknet specialist
- BlockSec — Audit + monitoring + incident response
- Veridise — ZK circuit audit specialists with Picus tool
- zkSecurity — ZK/MPC/FHE specialist
- MixBytes — 300+ audits, zero rekts
- 0xMacro — Elite boutique, long-term partnerships
- Three Sigma — Move language + DeFi auditing
- MoveBit (BitsLab) — Move ecosystem dominance
- QuillAudits — 1,500+ audits, affordable pricing
- Oxorio — Boutique quality-over-quantity firm
- Hashlock — Australian firm with free AI audit tool
- SigIntZero — Australian firm with Sentinel AI engine
- Softstack — German firm, 1,500+ audits
- Blaize — Full-service blockchain security
- Certora — Formal verification pioneer (currently listed as tool only)
Tools Missing (33 tools to add)
- Hypernative — ML-powered threat detection
- Blockaid — Transaction screening for wallets
- Flashbots Protect — MEV protection RPC
- GoPlus Security — Token security API (30+ chains)
- Token Sniffer — Rug pull detection scanner
- De.Fi Scanner — Token and contract risk analyzer
- Kontrol — Formal verification via Foundry tests
- Recon — Unified fuzzing platform
- Gambit — Mutation testing (Certora)
- Vertigo-rs — Mutation testing (RareSkills)
- AuditAgent — AI pre-audit tool (Nethermind)
- Veritas Protocol — AI automated audit platform
- ChainGPT Auditor — AI smart contract auditor
- QuillShield — AI vulnerability detection
- Phalcon — Hack blocking system (BlockSec)
- MetaSleuth — On-chain investigation (BlockSec)
- TRM Labs — Blockchain intelligence/compliance
- Elliptic — Blockchain analytics
- Arkham Intelligence — Entity-level on-chain intelligence
- Nansen — Wallet labeling and analytics
- Trugard — AI smart contract risk scoring
- DeFiSafety — Protocol risk rating
- Chaos Labs — DeFi economic security simulation
- Gauntlet — Risk parameter modeling
- Surya — Contract visualization
- Solidity Visual Developer — VSCode audit extension
- Move Prover — Move formal verification
- Move Analyzer — Move development IDE support
- Circomspect — ZK circuit static analysis
- Picus — ZK circuit vulnerability detection
- Soteria — Solana static analyzer
- EigenPhi — MEV analytics
- Solana Security Scanner — Official Solana vulnerability scanner