PUBLIC AUDIT REPORTS

Read our work first: every public security review

Browse past audits, including findings that helped patch more than $1B in vulnerabilities across 120+ projects. Our audits page lists every public security review from the OtterSec team.

120+ Projects audited$1.00B+ Vulnerabilities patched66% Core-severity findings

FREQUENTLY ASKED QUESTIONS

About our audit reports

Where can I read OtterSec’s past audit reports?

On osec.io/audits, which lists every public security review from the OtterSec team with its date, chain, and findings by severity.

AUDITING PROCESS

How a report gets made

  1. 01

    Quote

    We deliver a quote based on our expected duration, potential vulnerabilities, and the overall complexity of your project.

  2. 02

    Kickoff

    We begin the audit, share findings as they emerge, and ask questions as needed.

  3. 03

    Report delivery

    At completion, we send you a report with our findings and suggestions for fixes.

CLIENT TESTIMONIAL

What Squads says

“Having OtterSec as a security partner has been a fantastic experience for us. They are diligent, fast, creative and very responsive. Basically everything one could ask from a security audit firm.”
Stepan SimkinSquads

WHERE TO LOOK

Deep dives, clear reports.

Our reports and our research sit side by side: vulnerability breakdowns, protocol deep dives, and the security research behind the audits.

Solana core reports

Public reports include Solana Core v1.11.3 to v1.14.10, Solana Runtime Syscalls, and Solana Account Compression.

EVM reports

Public reports include LayerZero V2, Stargate V2, Euler, and Vyper Vyperlang.

Sui and Aptos reports

Public reports include Sui Bridge, Mysten ZK Login, Aave Aptos V3, and Thala.

Research behind the audits

Our blog collects notes on exploits, audits, reverse engineering, tutorials, and security patterns we’re seeing in the field.

GET SECURED

Get an audit from the team behind these reports

Tell us what you are building, where the highest-risk parts live, and when you need coverage. We will route the request to the right security team.

Get an audit