The OpenZeppelin Security Audit

Providing trust and confidence for the world's leading blockchain protocols and onchain financial infrastructure.

Trusted by the world's leading financial institutions and blockchain protocols

Uniswap
aaveLogoWhite 1-1
Coinbase-1
DTCC
Ethereum Foundation-1
BitGo
ZKsync
Across
ANZ-Logo-2009 1-1
WisdomTree
Uniswap
aaveLogoWhite 1-1
Coinbase-1
DTCC
Ethereum Foundation-1
BitGo
ZKsync
Across
ANZ-Logo-2009 1-1
WisdomTree

The OpenZeppelin Advantage

More than

95%

Of our clients
hire us again

More than

$110 billion

Total Value
Locked secured

More than

1 million

Lines of Code
Reviewed

More than

700

Critical and High
vulnerabilities uncovered

Securing the most critical blockchain protocols and applications

Uniswap Labs

Audits performed by us

9

High & critical vulns uncovered

5

Relationship started

2020

1inch

Audits performed by us

19

High & critical vulns uncovered

5

Relationship started

2020

Synthetix

Audits performed by us

4

High & critical vulns uncovered

31

Relationship started

2020

Data collected as of April 2025

Read the reports

ZKsync

Audits performed by us

46

High & critical vulns uncovered

39

Relationship started

2022

Optimism

Audits performed by us

5

High & critical vulns uncovered

34

Relationship started

2022

Scroll

Audits performed by us

11

High & critical vulns uncovered

14

Relationship started

2023

Data collected as of April 2025

Read the reports

Ion Protocol

Audits performed by us

7

High & critical vulns uncovered

11

Relationship started

2023

Aave

Audits performed by us

8

High & critical vulns uncovered

5

Relationship started

2019

Morpho

Audits performed by us

5

High & critical vulns uncovered

2

Relationship started

2023

Data collected as of April 2025

Read the reports

UMA

Audits performed by us

33

High & critical vulns uncovered

22

Relationship started

2020

The Graph

Audits performed by us

43

High & critical vulns uncovered

56

Relationship started

2020

Data collected as of April 2025

Read the reports

Ethereum Foundation

Audits performed by us

3

High & critical vulns uncovered

7

Relationship started

2022

Pimlico

Audits performed by us

1

High & critical vulns uncovered

0

Relationship started

2024

Data collected as of April 2025

Read the reports

Origin

Audits performed by us

20

High & critical vulns uncovered

14

Relationship started

2021

Mountain Protocol

Audits performed by us

2

High & critical vulns uncovered

0

Relationship started

2023

Data collected as of April 2025

Read the reports

ANZ

Audits performed by us

2

High & critical vulns uncovered

0

Relationship started

2022

WisdomTree

Audits performed by us

1

High & critical vulns uncovered

0

Relationship started

2025

Fireblocks

Audits performed by us

5

High & critical vulns uncovered

2

Relationship started

2022

Data collected as of April 2025

Read the reports

The Sandbox

Audits performed by us

17

High & critical vulns uncovered

17

Relationship started

2023

Decentraland

Audits performed by us

1

High & critical vulns uncovered

0

Relationship started

2018

Data collected as of April 2025

Agora

Audits performed by us

9

High & critical vulns uncovered

7

Relationship started

2023

Lido

Audits performed by us

2

High & critical vulns uncovered

0

Relationship started

2023

Compound

Audits performed by us

74

High & critical vulns uncovered

33

Relationship started

2019

Data collected as of April 2025

Read the reports

The OpenZeppelin
client centered approach

Client Engagement
We communicate and collaborate with you in every stage to ensure both business and code objectives are achieved securely and efficiently.

Team Structure

  • 2+ Blockchain Security Researchers
  • Technical Manager
  • Project Manager

The team is supported by Cryptographers, Advanced Testing Engineer and Security Analyst based on the project requirements.

The OpenZeppelin client centered approach

Circle icon
Step 1

Pre-Audit

Run Code Inspector on your code for free
Circle icon
Step 2

Security Audit

Circle icon
Step 3

Fix Review

Circle icon
Step 4

Ongoing Support

Request a Security Audit

We protect blockchain protocols and applications.
(Language is your choice)

Solidity isotype

Solidity is the cornerstone of Ethereum smart contracts, powering the onchain applications and financial infrastructure that are reshaping global finance.

Our Solidity smart contract audits go beyond code review; they are a comprehensive safeguard for your protocol’s integrity and user trust.

Trusted by

Uniswap Logo Compound Logo Optimism Logo

With a meticulous blend of static analysis, manual inspection, and automated tools, we review every line of code to identify vulnerabilities, assess code design and system architecture, and ensure alignment with the latest Ethereum Improvement Proposals (EIPs).

Trusted by

Uniswap Logo Compound Logo Optimism Logo
Cairo Logo

Cairo—a revolutionary language for creating provably secure smart contracts—brings about a new era of blockchain possibilities, including zk-Rollups and more efficient layer 2 solutions.

Our Cairo smart contract audits are at the forefront of this innovation, offering specialized services to ensure your Cairo contracts are both powerful and impenetrable.

Trusted by

Starknet Logo Dojo Logo

Some examples of issues found include severe protocol issues for Starknet including one which incorrectly allowed anyone to invoke functions only specific users should be able to, as well as a number of other issues such as in the case of the Snapshot protocol, regarding their voting system accounting as well as many others.

Trusted by

Starknet Logo Dojo Logo
Rust Logo

Rust's promise of memory safety and concurrency without compromise makes it a formidable choice for blockchain applications seeking unparalleled security and performance.

Our Rust security audits and reviews harness Rust's strengths to secure your blockchain infrastructure, focusing on Layer 2 networks and other innovative platforms that push the boundaries of scalability and efficiency.

Trusted by

Parity Logo Arbitrum Stylus Logo

We also delve deep into the auditing of Zero-Knowledge Proofs (ZKP) and other cryptographic primitives, that leverage Rust's inherent safety features but also embody the cutting-edge of blockchain security techniques.

One of the noteworthy findings in this category is a bug which was found in the bus-mapping segment of the Scroll ZK system which could be exploited to censor transactions, impair the Sequencer's functionality, and potentially compromise the L2.

Trusted by

Parity Logo Arbitrum Stylus Logo
Go Logo

Go, with its simplicity and efficiency, powers some of the most critical infrastructure elements of blockchain networks.

Our Go audit service is designed to address the unique challenges of Go-based blockchain projects.

Trusted by

Mantle Logo Avalabs lOGO

By combining thorough code reviews and security best practices, we ensure your system stands up to the demands of operational availability, scalability and security.

Trusted by

Mantle Logo Avalabs lOGO

“Collaborating with OpenZeppelin on our security audit was a productive and positive experience.
We appreciated their thoroughness and attention to detail.”

Yoav Weiss

Security at Ethereum Foundation

DTCC

"Huge thanks to OpenZeppelin for being a great partner during the security audit — their expertise and constant support were invaluable for the entire engagement."

Zach Short

Director of Blockchain Engineering at DTCC

WisdomTree

"The OpenZeppelin team was collaborative, and deeply knowledgeable. They took the time to understand our use case and made meaningful contributions throughout the process."

Jason Guthrie

Head of Product in Digital Assets at WisdomTree