Solana Projects › Adevar Labs

Adevar Labs

Ship Safely

Programs · 24h on-chain

On-chain activity

All programs →

Adevar Web3 Security Audits

Adevar Labs provides security audits for blockchain protocols and infrastructure through manual code review, formal verification, and infrastructure assessment. The service examines on-chain smart contracts and off-chain systems including cloud configurations, CI/CD pipelines, and network architecture to identify vulnerabilities and protocol risks.

Visit
About

Adevar Labs

Adevar Labs is a Web3 security firm launched in early 2025 that offers smart contract audits, formal verification, custom fuzzing, and infrastructure security assessments, with Solana and Move protocols as its primary focus.

What Adevar Labs Does

The company's name comes from the Romanian word for "truth," and its tagline is "Ship Safely." That framing reflects its founding premise: that security reviews must be exhaustive rather than statistical. Every engagement involves manual review of every line of code — no sampling, no automated shortcutting — with each audit led by an internal Adevar engineer scoped for depth rather than speed.

Adevar Labs operates across a broad set of smart contract languages. Rust on Solana and Solidity on Ethereum form the core of their workload, but the firm also reviews Move (Aptos and Sui), Go, Vyper, Yul, C++, Clarity, and FunC. This breadth positions them to serve projects across several ecosystems, while their public-facing positioning consistently emphasizes Solana-specific expertise — particularly the account model, cross-program invocation boundaries, and the BPF runtime, which create attack surfaces that generalist EVM-focused auditors can miss.

Services

Adevar Labs structures its offerings into several distinct service types:

Whiteglove Audits are the firm's flagship engagement. These are full manual code reviews with findings categorized by severity, documented with proof-of-concept exploits where applicable, and delivered alongside clear remediation guidance. Audit timelines are described as starting within two weeks of engagement.

Formal Verification extracts properties from smart contract code and uses automated provers to check whether those properties hold under all execution paths. This adds mathematical guarantees to critical protocol components, and Adevar applies it alongside manual review rather than as a replacement for it.

Custom Continuous Fuzzing generates and runs millions of test cases against a protocol's code to surface edge-case vulnerabilities. The GLAM engagement, for example, involved over one million fuzz executions; the M0 Labs engagement exceeded three million. Fuzzing is offered as a standalone service and as a component of whiteglove audit packages.

Infrastructure Audits cover deployment environments, cloud configuration, CI/CD pipelines, and operational security. The firm's June 2026 audit of Fystack's full-stack Web3 platform backend produced 62 findings — one critical, nine high severity — illustrating that off-chain infrastructure can carry as much risk as on-chain code.

Pre-Audit Preparation is a lighter initial engagement designed to help teams identify high-risk areas before the formal audit begins. It reduces churn in the main review and helps less security-mature teams come in better prepared.

Penetration Testing and Protocol Design Consulting round out the service catalog, with the latter aimed at projects seeking security guidance before development begins rather than after code is complete.

Audit Track Record

Adevar Labs makes its completed audit reports publicly available through a GitHub repository. As of mid-2026, the public portfolio includes:

  • Loopscale (July 2025): Solana credit protocol. Whiteglove audit of the lending engine and vault isolation modules. 21 findings and 10 enhancement opportunities identified.
  • GLAM (November 2025): Programmable investment infrastructure on Solana. Combined whiteglove audit and custom fuzzing engagement. 14 findings, 28 enhancement opportunities, over one million fuzz executions.
  • DoubleZero (November 2025): Decentralized network protocol on Solana covering Telemetry, Passport, and Revenue Distribution modules. 5 findings and 7 enhancements across 3 modules.
  • M0 Labs (January 2026): Yield-bearing wrapped token extensions using the m_ext and ext_swap programs. 6 findings, over three million fuzz executions across 2 modules.
  • Bench (Preaudit, 2026): Opportunity markets protocol on Solana with confidential compute. 11 validated issues, none critical or high severity.
  • Fystack (June 2026): Infrastructure audit of a full-stack Web3 development platform backend. 62 total findings including one critical vulnerability.

The portfolio spans early-stage DeFi protocols, institutional asset management infrastructure, network layer software, and Web2-style backend systems supporting Web3 products.

Ecosystem Recognitions and Partnerships

Adevar Labs is listed as a security partner in the Circle Alliance Directory, which means projects building on USDC infrastructure can reference the firm as a vetted auditor. The company is also included on the Aptos Foundation's security roster, making it eligible to support projects through Aptos's Security Credits program.

In a 2026 ranking of Move audit firms, Adevar Labs was placed in the Move-specialist tier — notable for a firm that publicly leads with Solana positioning, and indicative of the firm's cross-chain technical footprint.

The firm participated in Cypherpunk Week in Amsterdam in August 2026, co-organizing a Security Day alongside VaultMindAI.

Team and Background

Adevar Labs was founded by Dr. Sebastian Banescu, who serves as CEO. Banescu holds a PhD from the Technical University of Munich and has accumulated over 1,200 citations on Google Scholar for research at the intersection of formal verification and real-world exploit analysis. He has more than 15 years in digital security overall, including engagements at BMW, Philips, and Deloitte, and has conducted over 100 smart contract audits since 2018. The firm's LinkedIn presence has been amplified through Superteam Balkans, suggesting community ties in that region.

The management team also includes Iulia Banescu as Head of Operations and a security engineer named Catalin N. The firm describes itself as having "near-unlimited capacity," which likely reflects an intention to scale through contract-based or affiliate engagement structures alongside a core internal team.

Research and Publishing

Beyond client work, Adevar Labs publishes technical content under its blog and positions it as educational material for the Web3 developer community. A detailed post on supply chain attacks in the Solana ecosystem analyzed the December 2024 compromise of @solana/web3.js — in which attackers phished package maintainers and injected credential-harvesting code into versions 1.95.6 and 1.95.7, draining at least $160,000 in assets. The post recommended pinning exact dependency versions, using cargo vendor to freeze dependency trees, and deploying tools like JFrog Xray to detect typosquatting and obfuscated packages.

This kind of writing serves dual purposes: demonstrating technical depth to potential clients and contributing to the broader security conversation in the Solana ecosystem.

Solana Ecosystem Fit

Smart contract security on Solana requires specialization that doesn't transfer directly from Ethereum. Solana's account model means that program logic and account state are separated in ways that introduce ownership and authorization risks not present in EVM contracts. Cross-program invocations create trust boundaries that must be explicitly validated. The BPF runtime introduces its own constraints and edge cases. Audit firms that built their reputations on Solidity often apply frameworks that miss these nuances.

Adevar Labs entered the market with Solana and Rust as explicit primary targets rather than as add-ons to an EVM practice. Its public audit portfolio is weighted toward Solana-native protocols — credit markets, investment infrastructure, network primitives — and its blog output addresses Solana-specific attack vectors. That positioning, combined with a growing public audit record and formal verification capabilities, places the firm among the specialist options available to Solana protocols seeking security coverage before launch.

Contents

Note: inclusion in Solana Compass directory does not indicate a recommendation or endorsement of this project, its token(s) or its products. Data sourced with thanks from The Grid to aid in building these pages.

Reviews

0.0
0 reviews
Please login to write a review.
Solana tokens

Solana Token Markets

Explore all tokens →