Authority Assurance for smart contract code. EVM (Solidity) and Solana (Rust/Anchor) protocol reviews by researchers, focused on invariants, state transitions, value-flow correctness, authorization boundaries, and proxy topology. Findings come with severity, exploit scenarios, and fixes.
In-depth · Manual review
The problem
By the time code reaches mainnet it compiles and passes tests. The failures that drain a protocol live in the assumptions, the invariant that quietly breaks, the rounding that accrues, the path no test exercised.
Scope
A full audit covers the contract logic and everything that determines whether it behaves correctly under adversarial conditions.
Methodology
A structured engagement with a fixed scope, clear checkpoints, and post-fix verification, the same process behind every Themis audit.
Deliverables
Reports can be published with your consent or kept private per the disclosure agreement. Private findings stay confidential.
Why Themis
FAQ
A code repository (or verified on-chain addresses), documentation or a spec, and a point of contact. We scope from there and return a quote within 48 hours.
It depends on scope and complexity, most engagements run one to several weeks. We agree a fixed timeline during scoping.
Yes. We review Solidity on EVM chains and Rust/Anchor on Solana, including PDA validation and CPI safety.
Your choice. Reports are delivered privately by default and published only with your written consent.
Yes, we support your team through remediation and re-verify the fixes before the final report.
Share your repository and protocol overview. We’ll scope a security audit and return a quote within 48 hours.