h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Security & Exploits

Audit Firm Reviews: Who to Trust After a $1.26B Quarter

Q3 2026 was the worst quarter on record for crypto theft, with $1.26 billion gone across 247 incidents. Most of the victims had been audited, so here is how to actually review a security firm.

On the last day of September, CertiK closed the books on the worst quarter that crypto security has ever recorded. The firm counted roughly $1.26 billion stolen across 247 incidents in the third quarter of 2026, which pushed the year-to-date total past $2.68 billion. September alone accounted for about $766 million, the single worst month of the year, and it arrived while Bitcoin was posting its best quarter since 2024.

Here is the part that should unsettle anyone who has ever paid for a security review: most of the platforms and protocols that bled out in Q3 had been audited. Several had been audited many times, by the most respected names in the business. The audit badge, that small logo in the footer of a project website, has never been more common and has arguably never meant less. So treat this as a buyer guide of a different kind. Not simply a list of who the big firms are, but a method for reviewing the reviewers, and an honest look at what a stamp of approval is worth after a $1.26 billion quarter.

The quarter that broke the audit pitch

Two events did most of the damage, and neither looked like the textbook smart-contract hack. On 24 September the exchange Bitget lost about $387.5 million after an attacker chained zero-day flaws in two third-party security products, reached a production wallet server, and ran a purpose-built tool that forged the exchange’s internal risk-control fields so that Bitget’s own signing service approved the transfers. In Halborn’s technical reconstruction, the attacker never held a private key. Bitget absorbed the loss through its protection fund, so customer balances stayed whole, but the mechanism is the story: nothing a Solidity auditor reviews would have touched the systems that actually failed.

Three weeks earlier, on 6 September, the Bitcoin sidechain Liquid Network lost around $318.7 million when a caching flaw in its range-proof verification let an attacker mint roughly 3,998 unbacked L-BTC. About 3,400 BTC were returned the following day, which is why CertiK logged an unusually large $270 million returned or frozen for the month. Liquid runs consensus-level code that has been reviewed and re-reviewed for years. It is not a DeFi smart contract, and that is exactly the point. The two largest losses of crypto’s worst month both sat outside the scope of a standard smart-contract audit.

Nicolai Sondergaard, senior research analyst at Nansen, framed the cost precisely when the quarterly numbers landed: “The reputational damage can still be larger than the losses themselves.” For firms whose entire product is trust, that sentence cuts in both directions, and it explains why the audit industry spent 2026 scrambling to change what it sells.

The headline numbers come with a caveat worth stating, because reviewing the industry means reviewing its scorekeepers too. The security firms do not agree on the totals. For the same month, Immunefi counted roughly $742 million across 33 hacked entities, while CertiK logged closer to $766 million across 99 incidents, with the gap driven by what each counts as a reportable event and how it values returned funds. The disagreement is not noise; it is a reminder that even the measurement of crypto losses is a competitive product sold by some of the same companies that sell audits. What none of them dispute is the direction. The third quarter was the worst on record, the trend line points up, and the audit stamp did little to bend it.

Nobody licenses these firms

Before reviewing any individual firm, understand the vacuum they operate in. There is no licensing board for smart-contract auditors. Nothing in the United States plays the role that the Public Company Accounting Oversight Board plays for financial auditors, and no regulator certifies that a given firm is competent to sign off on Solidity. When the Securities and Exchange Commission laid out its digital-asset agenda in the Project Crypto keynote, chair Paul Atkins talked about how tokens are classified under the Howey test, not about code-review standards. The SEC may eventually ask who audited a protocol, but it does not tell anyone how.

Europe is no different in this respect. Neither the Markets in Crypto-Assets regime nor the Digital Operational Resilience Act mandates a smart-contract code audit or accredits the firms that perform them, a gap that persists even as MiCA shifts from rulemaking to enforcement. Fully decentralized protocols fall outside MiCA entirely, which means that for a large slice of DeFi the audit and the post-mortem are the only accountability that exists. Quality, in other words, is policed by reputation alone. That is the whole reason a review of these firms is worth doing carefully: the market is the only regulator, and the market has been getting the price wrong.

There is a second-order problem that makes reviewing firms harder than it should be: the word audited is doing a great deal of unearned work. A project can commission a narrow review of one contract, leave three others untouched, and still advertise audited by a famous firm. It can act on none of the findings and publish nothing. It can show a logo for a review that ran two years and forty code changes ago. The badge in a footer tells you a firm was paid; it does not tell you what was in scope, what severity the findings carried, or whether anything was fixed. Treat an unlinked badge as marketing until you have read the report behind it, and treat a refusal to share that report as an answer in itself.

OpenZeppelin and Trail of Bits: the standard setters

Two firms set the reference points everyone else is measured against. OpenZeppelin has been around since 2015, and its real influence sits upstream of any single audit: its open-source Contracts library is the plumbing under a huge share of Ethereum, used by Aave, Uniswap and Compound among thousands of others. The company says more than $37 trillion in value has moved through those contracts, across 900-plus security engagements and 10,000-plus vulnerabilities caught before production. In September 2026 it agreed to be acquired by S&P Global, the credit-rating giant, a deal worth its own section below because of what it signals about where this industry is heading.

Trail of Bits is the other pole. Founded in 2012 by Dan Guido and Alexander Sotirov, it took no major venture money and built its name on hard problems: cryptography, zero-knowledge systems and low-level security. Its open-source toolkit, the static analyzer Slither and the fuzzers Echidna and Medusa, is in the workflow of most serious auditors, including its competitors. Guido is blunt about the philosophy behind it. “I don’t ever want to find the same bug twice,” he told Decential, which is why the firm turns each finding into a reusable tool. By 2026 it reported finding roughly 200 bugs a week on some engagements with AI assistance, up from about 15, with every result still verified by a human before it ships.

That reputation is exactly why the Balancer and Bunni cases sting. Trail of Bits had reviewed Balancer code and flagged a rounding weakness years earlier, but rated its severity undetermined because the exploit path could not be confirmed under the pool configurations of the day; the same arithmetic class resurfaced and was drained in November 2025. On Bunni the firm identified a rounding issue, the team patched it, and the patch did not cover the exact edge case later exploited. Neither is a story of incompetence. They are stories about the limits of a snapshot: threat models move, code gets added, and a finding rated low on the day can become the whole ballgame a year later. A firm honest enough to publish that retrospective is more trustworthy, not less.

CertiK and Halborn: scale and the offensive school

CertiK is the volume leader and the most argued-about name in the field. Founded in 2017 by Columbia professor Ronghui Gu and Yale professor Zhong Shao out of formal-verification research, it has grown into a machine: by its own count more than 5,000 clients, roughly 20,000 projects reviewed and over 115,000 vulnerabilities flagged, with its Skynet dashboard continuously monitoring the market value of audited projects. It has raised hundreds of millions at a reported $2 billion valuation, and Gu has said he wants it to become the first publicly listed Web3 security firm. The flip side of that scale is a thick file of controversy, from the 2024 Kraken dispute, where a CertiK researcher drained about $3 million of real funds and Kraken security chief Nick Percoco called it “not white-hat hacking, it is extortion”, to its audit of a stablecoin tied to the Huione marketplace that the US Treasury later designated a money-laundering concern.

Halborn represents a different school. Founded in Miami in 2019 by Steven Walbroehl and Rob Behnke, it raised a large Series A led by Summit Partners in 2022 and built its name on offensive security: red-teaming, incident response and the forensic Explained series that dissects other people’s hacks. It was Halborn that reconstructed the Bitget breach within days. Under chief executive Jacques Boschung, a Kudelski Security veteran, the firm has leaned hard into institutional and tokenized-asset work. If you want a team to break into your system before an attacker does, or to run the investigation after one has, Halborn is the archetype. If you want a line-by-line review of a lending contract, it is not the first name on the list.

Both firms publish research that doubles as marketing, and it rewards reading on its own terms. CertiK’s Hack3d report for the first half of 2026 tallied more than $1.3 billion lost across 344 incidents, with wallet compromise, not code bugs, the costliest category at over $444 million. Halborn built its name on a 2022 disclosure its researchers called Rab13s, a set of flaws in the Dogecoin codebase that reached more than 280 networks and put billions of dollars of assets at theoretical risk. The through-line across both bodies of work is the one the hacks keep confirming: the industry is very good at finding bugs in code and much weaker at the keys, infrastructure and people around it. A firm that only sells you the first half is selling you half a defense.

The specialists: Zellic, Certora and Spearbit

Below the generalists sit firms that win on a single axis. Zellic made its name outside the Ethereum Virtual Machine, on Solana, Rust and Move code, the fast-growing and under-served corner that a generic EVM auditor is not equipped to review; it also acquired the competitive-audit platform Code4rena in 2024. Certora sells something different again: formal verification, the practice of mathematically proving that code satisfies a written specification rather than testing it and hoping. Its Prover and the CVL specification language are the serious answer to the arithmetic-edge-case bugs that keep draining DeFi, with the important caveat that a proof is only as good as the spec it is checked against.

Spearbit, which merged its two brands under the Cantina name in 2025, runs an elite freelance collective rather than a fixed staff, matching reviewers to scope and routing work through competitions and a marketplace; it has paid tens of millions to researchers and hosted the Uniswap v4 security competition. Sherlock blends an audit contest with an on-chain coverage product, so a protocol can buy a review and a payout promise in the same package. Each of these firms is excellent inside its lane and a poor default outside it, which is the first lesson of reviewing auditors: specialization is not marketing, it is the whole game.

A side-by-side on the major firms

No table can capture a firm’s judgment, but it can orient you before you read a line of a proposal. The column that matters most is the last one. Every serious firm on this list has a protocol in its portfolio that was later drained, and a firm that pretends otherwise is the one to avoid.

FirmFoundedCore specialtySignature tooling or productKnown limitation or controversy
OpenZeppelin2015Contract libraries, EVM DeFiOZ Contracts, Defender monitoringBalancer V2 fell outside its engagement scope
Trail of Bits2012Cryptography, ZK, low-levelSlither, Echidna, MedusaUnderrated the Balancer and Bunni findings
CertiK2017High-volume audits, monitoringSkynet, AI AuditorKraken dispute, Huione stablecoin audit
Halborn2019Offensive security, incident responseRed-team, Explained post-mortemsJudged on response more than prevention
Zellic2020Solana, Rust, MoveRust and Move code reviewCleared the function later exploited on Cetus
Certora2018Formal verificationCertora Prover, CVLProofs only as strong as the specification
Spearbit / Cantina2021Elite freelance collectiveCantina marketplace, contestsCork Protocol drained after review
Sherlock2022Contests plus coverageAudit contests, on-chain coverCoverage pool shrank sharply in 2026

Audited, and hacked anyway

The uncomfortable pattern of the past two years is that audits increasingly protect the wrong risk. Ronghui Gu said it plainly in CertiK’s mid-year review: “Attackers are getting more return by going after key management, multisig governance, and operational infrastructure than by hunting for bugs in code.” The table below gathers the marquee losses, and most of them share that shape.

IncidentWhenLossRoot causeIn audit scope?
BybitFeb 2025~$1.5BMalicious JavaScript in the Safe wallet UINo, signing flow
Cetus (Sui)May 2025~$223MInteger overflow in liquidity mathYes, three audits missed it
Balancer V2Nov 2025~$128.6MRounding error in batch swapsPartly, audited 11 times
Kelp DAOApr 2026~$292MSingle cross-chain verifier configNo, integration layer
DriftApr 2026~$285MSocial-engineered pre-signed instructionsNo, operational
BitgetSep 2026~$387.5MForged withdrawals via signing serviceNo, exchange infrastructure
Liquid NetworkSep 2026~$318.7MRange-proof caching flawNo, consensus-level code

Look at the right-hand column. Cetus is the exception that proves the rule, a genuine integer-overflow bug in liquidity math that three separate firms cleared, including one audit that closed barely a month before the exploit. Balancer V2 is the subtler case, a rounding weakness in code audited eleven times; OpenZeppelin noted that the exploited contract was added to the repository after its own review had ended. The rest were not code bugs at all. Bybit was a compromised front-end, Drift was a months-long social-engineering con against the team, and Kelp DAO lost $292 million with zero bugs found, because, as OpenZeppelin put it, the contracts performed exactly as written.

This is why Suhail Kakar, a developer-relations lead at TAC, reacted to the Balancer losses by telling Cointelegraph that “audited by X means almost nothing. Code is hard, DeFi is harder.” It is also why what rescues value now is often not the auditor but the responders: a validator set that halts a chain, an Arbitrum-style security council that freezes stolen funds, or a protocol team that catches a perp-DEX exploit like Drift before the full balance leaves. The report is written before the hack; the recovery happens after it.

From one-time audit to always-on security

The deepest change of 2026 is not which firm is best. It is that the firms themselves have concluded the one-time audit is broken as a product. A classic audit is a snapshot: a specific commit, reviewed over a few weeks, by a team that then moves on. The code keeps changing, the threat model keeps shifting, and the report ages the moment it is signed. Jack Sanford, co-founder of Sherlock, summed up the pivot when he described the firm’s AI auditor: “Point-in-time audits are indispensable, but they were never meant to carry the entire burden of security.”

So the business model is migrating toward always-on coverage. CertiK runs Skynet as a continuous monitor over the market value of its audited clients. OpenZeppelin sells Defender and monitoring tooling that watches deployed contracts and admin actions in real time. Sherlock bundles an audit with an on-chain payout promise. Halborn offers retainer-based incident response so a client is not cold-starting a forensic team at the worst possible moment. The marketing word is continuous; the honest word is subscription. When you review a firm today, the point-in-time report is table stakes, and the real question is what it offers for the 51 weeks after the report lands.

The mechanics of why a snapshot decays are not mysterious. Kelp DAO is the cleanest example: its contracts performed exactly as written and the money left anyway, because the danger had migrated into a cross-chain configuration that no prior review was scoped to cover. Code ships, upgrades land, a new integration adds an external dependency, and the system running in production six months later is not the system anyone audited. Continuous coverage tries to close that gap with monitoring that watches live contracts, alerting that fires on anomalous admin actions, and a standing agreement to re-review on every material change. It costs more than a single report, and it is the only model that matches how fast the code actually moves.

Contests and bounties: the crowd as auditor

Alongside the fixed-fee firms sits a second model that treats security as a market. Competitive audits open a codebase to dozens or hundreds of independent researchers who compete for a prize pool, and bug bounties pay out when someone reports a live vulnerability. The category consolidated hard this year. Code4rena, the pioneer of competitive auditing, announced its shutdown in May 2026, and Immunefi moved to absorb its researchers and bounty clients.

That leaves Immunefi as the dominant bug-bounty venue, Cantina running competitions and a marketplace, and Sherlock pairing contests with coverage. The numbers argue the model works: Immunefi reported paying researchers about $13.45 million for 837 valid bugs in the first half of 2026 alone, crossing $140 million in lifetime payouts, with more than 92,000 registered researchers watching over $180 billion in protocol value. A bounty is cheaper than a hack by orders of magnitude, and unlike an audit it never expires. Its weakness is coverage: a bounty only pays if an honest researcher finds the bug before a dishonest one does, and the September totals show that race is being lost more often than it is won.

The AI wedge

Every firm now has an AI story, and for once the hype is partly earned. CertiK launched an AI Auditor in April 2026 that it says hit an 88.6 percent exact-match rate against 35 real 2026 incidents, positioned as triage and continuous coverage rather than a replacement for human review. Trail of Bits reports AI agents surfacing a large share of its findings, always human-verified. The same technology, though, is in the attackers’ hands: AI lets a social engineer build convincing personas at scale, and AI coding assistants ship vulnerable code faster than any human team can review it.

The sober take comes from David Schwed, chief operating officer at SVRN, who warned against treating a prompt as a program: “‘Claude, audit my smart contract, make no mistakes’ is not a security program.” His point generalizes to the whole category. A tool that finds more bugs is only useful if the person running it can evaluate what comes back; otherwise you have not bought security, you have bought a false sense of it. When a firm pitches you its AI, the question to ask is not how many bugs the model finds, but who checks them and how.

How to review an audit firm yourself

Strip away the logos and a usable scorecard emerges. These are the six things worth checking before you trust a firm, or before you trust a project’s claim that it was audited by one.

  • Specialization. Does the firm actually work in your environment? An elite EVM auditor is the wrong choice for a Solana or Move codebase, and the reverse is just as true.
  • Methodology. Manual review, fuzzing, formal verification or some blend. Ask which, and ask what their tooling is; the serious firms publish theirs.
  • Scope and level of effort. The single most important number in any report is how many engineer-weeks went into it against how much code. A clean report on a narrow scope proves very little.
  • Report transparency. Is the full report public, with severities, an adversary walkthrough and a fix-review appendix, or is there only a badge? Read the report, never the badge.
  • Continuous coverage. What happens after launch? Monitoring, re-audits on upgrades and a live bounty program matter more than a single pre-deployment pass.
  • Follow-up. Did the firm verify that findings were actually fixed, and does it track issues it rated low that could turn critical as the code changes?

Price is the seventh factor, and it is less negotiable than buyers expect. Industry reference ranges, published by Sherlock and broadly consistent across firms, look like the table below, with surcharges on top for Rust or Solana work (roughly 25 to 40 percent), Move (30 to 45 percent), zero-knowledge circuits (80 to 120 percent), formal verification and emergency turnarounds.

TierTypical rangeWhat it buys
Boutique or narrow scope$8,000 to $25,000A few engineer-days on a small contract
Mid-market$25,000 to $80,000Multi-week manual review plus fuzzing
Top-tier or enterprise$80,000 to $350,000 and upMultiple engineers, weeks, formal methods

Price buys hours, and hours are the number to interrogate. The most useful line in any report is not the list of findings but the level of effort, usually stated in engineer-weeks, measured against the size of the codebase. Two weeks on ten thousand lines is a very different assurance from two weeks on two hundred. Serious reports also separate the severity of a finding from the difficulty of exploiting it, which is why an easy medium can matter more than a hard critical, and they close with a fix-review appendix showing what was actually remediated. You do not need to be an engineer to read for these signals, and you do not need to take a project’s word for any of it: aggregators such as Solodit collect tens of thousands of public findings from across the major firms in one searchable place.

What no audit will ever catch

Even a perfect review of perfect code leaves most of the modern attack surface untouched. The Q3 losses map almost exactly onto the categories that sit outside audit scope: stolen or mismanaged keys, governance takeovers, bridge and oracle trust assumptions, operational infrastructure and plain human manipulation. An auditor reads the contract; it does not run the multisig, pick the oracle, secure the laptop of the lead developer, or sit in the room when a fake recruiter spends three months earning a team’s trust.

That is where the rest of a security program lives, and it is why the audit is one line item among many. Hardware and key hygiene matter, which is why supply-chain attacks on hardware wallets are now their own category of risk. Signing design matters, which is why the move toward smart accounts changes what a compromised key can and cannot do. A code audit is necessary and nowhere close to sufficient, and any firm that sells it as a guarantee is selling the wrong thing.

The fastest-growing line on that list is the human one. Several of the year’s largest thefts began not with a transaction but with a conversation: an operative posing as a recruiter, a contractor or a counterparty, patient enough to spend months inside a team’s trust before asking for the one signature that mattered. The Drift and Bybit losses ran through people and interfaces rather than flawed logic, and the Bitget breach turned a legitimate signing service into the attacker’s own tool. No static analyzer models a social engineer, and no fuzzer tests whether a developer will install a malicious dependency a supposed colleague recommended. This is why the better firms now sell red-teaming and phishing simulations next to code review. The contract is only one of the doors, and lately it is not the one being used.

When Wall Street starts rating code

The most telling event of the quarter was not a hack. On 17 September, S&P Global agreed to acquire OpenZeppelin. The company that assigns credit ratings to sovereign debt and corporate bonds now owns one of crypto’s foundational security firms, which will keep its name and its chief executive while reporting into S&P Global Ratings. The logic is that as capital markets move on-chain, the quality of the code becomes a form of credit risk, and someone has to rate it. CertiK, meanwhile, is openly preparing for a public listing, and the DeFi insurance market that is meant to backstop all of this is shrinking, not growing.

That last point is the quiet alarm. CertiK’s quarterly report put total on-chain insurance capacity at about $130 million, down more than 20 percent year over year, with a single mutual covering most of it. Nexus Mutual founder Hugh Karp has called the amount of real cover “a fraction of what the market needs”. Stack it together and the shape of the next few years is clear. The audit is becoming a subscription, the auditor is becoming an institution, and the stamp of approval is becoming a rating. None of that changes the rule a $1.26 billion quarter just taught again: read the report, not the badge, and never confuse being audited with being safe.

Frequently Asked Questions

Does a smart contract audit guarantee a project is safe?

No. An audit is a point-in-time review of specific code at a specific moment. It cannot cover stolen keys, governance takeovers, bridge and oracle trust assumptions or operational failures, and those categories caused most of the losses in 2026.

Who is the best crypto audit firm in 2026?

There is no single best firm; the right choice depends on your technology. OpenZeppelin and Trail of Bits lead on EVM code and tooling, Zellic specializes in Solana and Move, Certora in formal verification, CertiK competes on scale, and Halborn on offensive security and incident response.

How much does a smart contract audit cost?

Prices run from roughly $8,000 for a boutique review of a narrow scope to $350,000 or more for top-tier enterprise work, with surcharges for Rust, Solana, Move, zero-knowledge circuits, formal verification and emergency turnarounds.

Are crypto audit firms regulated?

No. No US or EU regulator licenses smart-contract auditors or requires a code audit. The SEC and MiCA address token classification and provider conduct, not code-review standards, so the quality of audit firms is policed by reputation alone.

Why did audited protocols still get hacked in 2026?

Because attackers moved to targets outside audit scope: key management, signing infrastructure, social engineering and cross-chain configuration. September’s two biggest losses, at Bitget and Liquid Network, were infrastructure and consensus failures rather than Solidity bugs.

By Anneke de Vries, security desk, HOGE Wire.

Share 𝕏 Post Telegram