Skip to content

Hashlock-Auditing/hashlock-audits

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

30 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Hashlock Security Audits

Public repository of smart contract security audits and Web3 penetration testing engagements conducted by Hashlock, a globally leading Web3 security firm headquartered in Australia.

Website Audits AI Audit Tool Twitter License

What Hashlock Does

Hashlock secures the Web3 ecosystem through manual smart contract audits, tokenomics reviews, penetration testing, bug bounty operations, and ongoing security advisory. We are chain agnostic with deep multi-chain expertise. We audit any blockchain and any smart contract language, and our public portfolio includes hundreds of engagements on Ethereum, Solana, Polkadot, Cosmos, Aptos, Sui, Starknet, Bitcoin, zero knowledge circuits, and many other ecosystems, including newer and emerging Layer 1s on request. Our auditors come from competitive security backgrounds with proven results in public security competitions and bug bounty programs.

Notable Clients

Chain agnostic by capability, multi-chain by experience.

🚀 Recent and recognized engagements. Names recognised across the Web3 industry:

Rocket Pool (Ethereum liquid staking) · 1inch (DeFi aggregation) · SushiSwap (multi chain DEX) · Gala (Web3 gaming) · P2P (institutional staking) · Vana (user owned AI data) · EigenLayer (restaking) · Energy Web (Polkadot infrastructure) · Manifest (Cosmos appchain) · Spicenet (Solana DeFi infrastructure)

What's in This Repository

Hundreds of security audit engagements conducted by Hashlock across Web3. We are chain agnostic with deep multi-chain expertise. Our portfolio spans smart contracts, blockchain protocols, dApps, and infrastructure across every major ecosystem we've engaged with to date, including Ethereum, Solana, Avalanche, BNB Chain, Polygon, Arbitrum, Base, Berachain, Cosmos, Polkadot, Starknet, Sui, Aptos, Near, Kadena, Stacks, Bitcoin, and many more. If your chain is not listed, we audit it too.

Each client folder contains:

  • 📄 Public engagements: full audit report PDF with findings, severity ratings, and remediation status
  • 🔒 NDA engagements: audit confirmation under client confidentiality

Legend: 🛡️ Hashlocked tier · 🐛 Active Bug Bounty Program · NDA full report confidential

Browse the Portfolio

By Ecosystem

🟦 Ethereum & EVM Audits · 🟣 Solana Audits · 🔴 Polkadot Audits · 🌌 Cosmos Audits

By Category

💰 DeFi Audits · 🎮 Gaming Audits · 🏛️ RWA Audits · 🛡️ Hashlocked Projects · 🔒 NDA Engagements

Security Documentation

📋 Methodology · ⚖️ Severity Definitions · ⏱️ Audit Process · ❓ FAQ · 🎯 How to Choose an Auditor

Machine Readable Index

📊 audits.json. Full client portfolio in JSON for developers, AI systems, and integrations.


Featured Audits

The most prominent projects featured on hashlock.com/audits, in order of recency.

📂 Browse all public audits below or jump to NDA engagements.


All Audits (Public Reports)

The following projects have published their full Hashlock audit reports. Open each folder for the detailed README and PDF.

The full alphabetical list of public audit reports is preserved below for completeness. We recommend using the category pages above for filtered browsing.


Audited by Hashlock (NDA Engagements)

The following projects have engaged Hashlock for security audits where the full report remains under client confidentiality. The engagement itself is publicly disclosed on hashlock.com/audits.


About Hashlock

Hashlock is a globally leading Web3 security firm headquartered in Australia, specializing in smart contract audits and blockchain security across the DeFi, gaming, RWA, AI, and infrastructure sectors. Our auditors come from competitive security backgrounds and have secured hundreds of protocols across the ecosystem.

Languages & Ecosystems (Selected Examples)

Hashlock is chain agnostic with deep multi-chain expertise. We audit any blockchain and any smart contract language. Selected examples from our portfolio:

  • EVM (Solidity, Vyper): Ethereum, Polygon, Arbitrum, Base, BNB Chain, Avalanche, Berachain, Optimism, and many other EVM compatible chains
  • Solana (Rust): native programs and Anchor framework
  • Polkadot, Kusama (Rust, Substrate): custom pallets, parachains, runtime modules, XCM
  • Cosmos ecosystem (Go, CosmWasm): Cosmos SDK appchains, IBC integrations
  • Aptos, Sui (Move): resource semantics, object ownership, abilities
  • Starknet (Cairo): smart contracts and ZK proof systems
  • Zero knowledge circuits: Noir, Circom, and other proving stacks
  • Bitcoin: Bitcoin Scripts, BRC 20, Ordinals, Runes
  • Other ecosystems we have audited: Near, Kadena, Stacks, Mavryk, ICP, Cardano, Algorand, Tron, Tezos, and more
  • Any other blockchain or smart contract language on request, including newer Layer 1s, emerging VMs, and novel cryptographic protocols

If your chain or language is not listed above, contact us. We adapt to any codebase.

Core Services

  • Smart Contract Audits: manual, line by line security reviews
  • Tokenomics Audits: token model and incentive design reviews
  • Penetration Testing: application and infrastructure security testing
  • Bug Bounty Program Management: run on Hashlock's own bug bounty platform
  • vCISO & Security Advisory: ongoing security leadership
  • CCSS Certification Support: Cryptocurrency Security Standard compliance
  • Free AI Audit Tool: powered by custom tuned LLMs trained on real audit data

Resources

🌐 Website: hashlock.com 📋 Audits Directory: hashlock.com/audits 🤖 Free AI Audit Tool: aiaudit.hashlock.com 📩 Request an Audit: Submit our RFI form 🐦 X / Twitter: @Hashlock_


Contact

Need a security audit, penetration test, or ongoing security advisory? Reach out to our team. We work with projects from pre launch startups to established protocols across every major blockchain ecosystem.

For questions about this repository, open an issue or contact us at info@hashlock.com.au.


All audit reports in this repository are published with client consent. Hashlock retains ownership of report content per our standard engagement terms. For full disclaimers, methodology, and severity definitions, please refer to each individual audit report PDF.

About

Public repository of smart contract audits and Web3 security engagements by Hashlock: auditing DeFi, gaming, RWA, and blockchain infrastructure across Ethereum, Solana, and 30+ chains.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors