Smart Contract Auditing Services: 23 Public Audit Reports
This is Fidesium’s public audit portfolio: 23 signed reports covering 16 protocols, most of them on EVM chains and Solana, published between 2024 and April 2026. Every report here is the document as it was delivered to the client, with its findings, its severities and its remediation record intact, and every one can be downloaded in full. If you are deciding whether to hand us a codebase, this is the evidence to read first.
Instant results
What is in the portfolio
Most of the work is EVM. Four reports cover Solana programs, and one, SafeDrop, is an application assessment rather than a contract audit: its report covers a separate backend and frontend repository, tested both whitebox and blackbox.
The protocols split across five categories. DeFi is the largest by some distance, which follows from where the money and the exploit risk sit.
wo protocols account for nine of the 23 reports. PB&J has six, one per contract, and Novel Labs has three. That is what a multi-contract engagement looks like: each component is scoped, assessed and signed off on its own terms rather than bundled into a single verdict.
Every published report
Sorted by report date, newest first. Each link opens the signed PDF exactly as it was delivered.
What is inside one of these reports
Scope:
A Fidesium report opens with the scope: the repository, the audited commit, the number of source files, the lines of code, and the assessment window. Then the findings, graded Critical, High, Medium, Low and Informational, each with its location, its mechanism and its remediation. Then the verification pass, where the fixes are re-read against the changed code and each finding is closed or left open on the record.
Assessment:
The Adrena assessment is the clearest worked example, and it is the largest report in the portfolio. It covered 33,747 lines of Rust across 168 source files and 125 public instructions, at two named commits. The assessment ran from 10 February to 18 March 2026. Forty-two findings were raised: 1 Critical, 3 High, 8 Medium, 12 Low and 18 Informational. A second pass reviewed the remediation work between 31 March and 8 April, and the report was delivered on 11 April 2026. The protocol’s risk score moved from 43 out of 100 at first delivery to 11 out of 100 at the close of the review.
Engagement:
That engagement applied nine methods: manual source code review, system design analysis, fuzzing, on-chain analysis, red-team exploit simulation, economic modelling, formal verification, supply chain and dependency audit, and compound attack chain analysis. The methodology behind it is written up in full in the Fidesium and Adrena case study. The Sumvin engagement, a soulbound identity protocol on Sei, is written up the same way.
Why the reports are public
The hardest question a smaller audit firm gets asked is why anyone should trust a cheaper audit. Publishing the work is the only honest answer to that, so the reports go out whole rather than as a badge or a summary. You can read what was found, how severe it was, what was changed, and what was still open when the report was signed.
Three things sit behind them.
The people who built the tooling do the audit. You get the core team, not a third party running a scan on your behalf.
The analysis is deterministic. It runs on AST analytics and static analysis. The same code produces the same findings, which is what makes a second pass against changed code meaningful.
Each audit is minted as an on-chain NFT, so the record is machine readable, verifiable and permanent. A report that lives only on a website can be edited later. One that is minted cannot.
An audit describes a codebase on one day
A report is a snapshot of specific code at a specific commit. It is not a guarantee, and no audit firm can honestly offer one. The moment the code changes, the report describes something that no longer exists, which is why the audits above name their commits and why several of these protocols came back for a second pass.
That is the whole argument behind Fidesium’s security services: continuous scanning on every commit, pull request and deployment, plus post-deployment monitoring tuned to the protocol’s own logic rather than generic threshold alerts. Security is a process, and an annual report is not one.
What an engagement costs, and how long it takes
Manual smart contract audits start at $5,000, priced on the codebase after a review of it. That includes line-by-line human review, logic and economic risk analysis, two rounds of fix verification, a public report, the badge and the NFT, and a month of continuous scanning alongside it. Chain agnostic, with an EVM specialism.
On timelines, the reports above are a better answer than a range. Adrena took five weeks of assessment for 33,747 lines of Rust and 125 public instructions, then a delivery, then a separate remediation review the following month once the team had made its changes. A smaller codebase takes less. Scope is what drives it, so the honest answer arrives with the scope, and that is the first thing we work out with you.
If you want the continuous scanning without the manual engagement, that is the platform pricing, from $399 a month.
Frequently asked questions
What is in a Fidesium audit report?
Four things, in this order: the scope, which names the repository, the audited commit, the file and line counts and the dates the assessment ran; the findings, each one graded and located, with its mechanism and its fix; the verification pass against the changed code; and the closing state of every finding, open or closed. Nothing is summarised away. What you download is what the client received.
What do the severity levels mean?
A finding’s grade reflects what it can do and how easily it can be reached. Critical and High cover paths that can move or lock funds, mint without authority, or break a guarantee the protocol is built on. Medium and Low cover issues that are bounded in impact or depend on conditions unlikely to line up. Informational covers code quality, documentation and hardening that carry no direct risk. Every grade arrives with its location and its remediation, so you can weigh it yourself.
How do I verify one of these reports is genuine?
Start with this page. Every report published here is served from fidesium.com at a fixed address, so check any document you are sent against the copy above. Not every engagement is published, so a report missing from this list is not automatically false. Each audit is also minted as an on-chain NFT, a machine-readable record that cannot be edited after the fact, so ask the team who sent it for the mint.
Why are the reports public rather than a badge or a summary?
A badge asks you to take a firm’s word for it. A full report asks you for nothing: the findings, their severities, the fixes and whatever was still outstanding at signing are all in the document, so you can judge the work instead of the marketing. That is the only real answer to the question this market actually asks: why should anyone trust an audit that costs less than the top tier charges?
Does a clean report mean the protocol is safe?
No. An audit is a description, not a guarantee, and no firm can honestly sell it as one. The report covers the commit it names, on the date it names. Code moves, and the report does not move with it. That is why each report states its commit, and why what we actually sell is continuous scanning on every commit, pull request and deployment.
How current are these reports?
The portfolio runs from 2024 to April 2026 and was last reviewed in August 2026. Every report carries its own date and the commit it covers, so its age is stated on the document rather than implied by the page it sits on. An older report is not a worse one. It describes an older codebase, which is the whole argument for scanning continuously instead of auditing once a year.
What chains do you audit?
EVM is the specialism and 18 of the 23 reports above are EVM work. Four cover Solana programs: Adrena, Banana Zone, Beanz and BlockAsset. The remaining report, SafeDrop, is an application assessment covering a separate backend and frontend repository rather than on-chain contracts. Manual audits are chain agnostic, so if you are shipping somewhere not represented here, send the repository and we will tell you plainly whether it is work we should take.
Can I see a report before I hire you?
You are looking at 23 of them. Every one downloads in full, with no form and no email address to hand over first, and they are the same documents an engagement with us would produce. If you want one to start with, read Adrena. It is the largest in the portfolio, and the Fidesium and Adrena case study walks through how that assessment was run.
Request a quote
Tell us what you are shipping, roughly how large the codebase is, and when you need to be live. We come back with a scope and a price rather than a discovery call, and manual audits start at $5,000.
The detail of what a manual engagement covers is on the manual smart contract audits page.