On-chain activity
CODESPECT Smart Contract Audits
CODESPECT Smart Contract Audits is a manual security review service for blockchain protocols on various blockchain networks. Auditors perform line-by-line code review of Solidity, Cairo, and Rust contracts supplemented by automated analysis and optional fuzz testing for protocols with complex financial logic. The process covers scoping, pre-assessment, deep audit, fix verification, and delivery of a detailed vulnerability report with severity classifications.
CODESPECT
[[PROJECT:2172]] is a blockchain security firm founded in May 2024 that covers the full attack surface of Web3 protocols: smart contract audits, web application and infrastructure penetration testing, AI and LLM adversarial testing, red team exercises, and operations security consulting. Its tagline, "Every Attack Surface. One Team," reflects a positioning against fragmented vendor arrangements where gaps between separate specialist firms create exposure.
Smart Contract Audit Coverage
The firm audits contracts across five ecosystems: EVM chains (Solidity), Solana (Rust and Anchor), Starknet (Cairo), Fogo (an SVM-based chain), and Sui. Solana-specific audit work forms a material part of the practice, with published findings covering PDA seed collision patterns, stale balance accounting errors, and cross-context vulnerabilities in confidential computing environments.
CODESPECT aligns its audit methodology with the Security Alliance (SEAL) framework and structures every engagement in four phases: static analysis, manual review, fuzzing and invariant testing, and fix verification. The firm states on its website that roughly 80% of exploited vulnerabilities are business-logic flaws that automated scanners cannot detect, consistent with the emphasis on manual review as the core deliverable rather than tooling output.
Engagements follow a seven-stage process: scoping, kickoff, primary review, interim findings delivery, fix period, fix verification, and final report. Timelines scale with codebase size: under 1,000 lines takes one to two weeks; 1,000 to 4,000 lines takes two to five weeks; codebases above 4,000 lines run five weeks or longer. Deliverables include an executive summary, severity-tiered findings (from Critical through Informational), system architecture analysis, documentation and test-suite evaluation, and a fix-verification section confirming that reported issues were resolved before the final report is issued.
Audit Track Record
CODESPECT's public GitHub repository holds more than 38 completed audit reports across DeFi protocols, token infrastructure, staking systems, oracle networks, and bridge contracts. Clients in the public record include Redstone (oracle infrastructure), TokenTable (multi-chain token distribution and vesting), Swell (liquid staking on Ethereum), and Hyperwave (solver infrastructure on Hyperliquid). The firm claims on its website to have protected over 4 billion dollars in total value locked across its client base, citing ETHSign, The Vault, and LST Olas among its named clients.
SpecSiege: Competitive Audit Contests
Alongside private engagements, CODESPECT offers SpecSiege, a curated public audit contest format capped at 50 selected researchers. The product is positioned as a complement to the standard private audit: protocols can access a broader set of independent reviewers before mainnet launch without opening the codebase to an unlimited public contest. Participation is by invitation rather than open registration, which CODESPECT presents as a quality filter on the researcher pool.
AI and LLM Security
AI adversarial testing is a distinct service line, not a secondary capability. The offering covers threat modeling against large language model integrations using OWASP and MITRE ATT&CK frameworks. This addresses DeFi protocols incorporating autonomous agents, a growing attack surface as on-chain agent systems have moved from experimental to production use on Solana and other chains. A blog post published in August 2026 examined why traditional smart contract audits are insufficient when the protocol layer is controlled or influenced by an AI agent's decision-making.
CODESPECT has also published canton-ai-review on GitHub, an open-source tool that applies AI-assisted analysis to Daml smart contracts on the Canton network, extending the firm's automated review research to non-EVM environments.
Educational Resources and Research Output
The firm maintains several open-source repositories alongside its commercial practice. solana-ctf-vault is a Solana capture-the-flag exercise written in Rust, designed for security practitioners learning to find vulnerabilities in on-chain code. audit-preparation-guidelines documents how protocols can structure their codebases, documentation, and test coverage before engaging an auditor. DeFi-Security-Best-Practices provides a reference for protocol teams on known vulnerability classes and defensive patterns.
The blog publishes original security research tied to real audit findings. Posts have covered PDA seed collision on Solana, stale balance accounting in yield protocols, cross-context ciphertext replay in confidential computing, Merkle tree corruption in Cairo privacy contracts, and security pitfalls in liquid staking on Hyperliquid. A workshop at CTU Prague in early 2026 introduced the firm's methodology to a European academic security audience.
Engagement
Protocols seeking an audit or penetration testing engagement can reach the team at [email protected]. The firm accepts engagements across all supported chains, with scoping, timeline, and deliverable details discussed before any commitment.
Contents
- Smart Contract Audit Coverage
- Audit Track Record
- SpecSiege: Competitive Audit Contests
- AI and LLM Security
- Educational Resources and Research Output
- Engagement
Solana Token Markets