On-chain activity
CODESPECT Smart Contract Audits
CODESPECT Smart Contract Audits is a manual security review service for blockchain protocols on various blockchain networks. Auditors perform line-by-line code review of Solidity, Cairo, and Rust contracts supplemented by automated analysis and optional fuzz testing for protocols with complex financial logic. The process covers scoping, pre-assessment, deep audit, fix verification, and delivery of a detailed vulnerability report with severity classifications.
CODESPECT
CODESPECT is a boutique blockchain security firm founded in May 2024 and based in Opava, Czech Republic. Operating under the tagline "Every Attack Surface. One Team," the firm provides end-to-end security coverage for Web3 protocols, spanning smart contract audits, penetration testing, AI agent security, red team exercises, on-chain monitoring, and operations security. Its researchers have backgrounds in competitive audit platforms such as Cantina and CodeHawks.
Problem Solved
Blockchain protocols face a broad and fragmented threat landscape. A project may secure its smart contracts while leaving its web infrastructure, key management practices, or AI-integrated components exposed. CODESPECT addresses this by consolidating multiple security disciplines under one team rather than requiring projects to coordinate across multiple specialized vendors. The firm notes that approximately 80 percent of exploited vulnerabilities in Web3 are business-logic flaws that automated scanners cannot detect — a gap that motivates its emphasis on deep manual review.
Core Services
Smart Contract Audits are CODESPECT's flagship offering and follow a four-phase, SEAL-aligned methodology: static analysis, manual review, fuzzing and invariant testing, and fix verification. Engagements typically last one to five weeks depending on protocol complexity and run through seven stages — scoping, kickoff, primary review, interim findings, a fix period, fix verification, and final report delivery. Deliverables include an executive summary, risk-categorized findings, system architecture analysis, protocol risk assessment, documentation review, test-suite evaluation, and fix-verification documentation.
The firm supports multiple smart contract languages: Solidity for EVM chains, Rust and Anchor for Solana, Cairo for Starknet, and additional coverage for Daml (Canton), Move, Sui, and Fogo (SVM).
SpecSiege is an optional post-audit add-on in which up to 50 curated independent researchers conduct a parallel review of the audited codebase before mainnet deployment. It functions as a constrained, high-signal bug bounty contest designed to catch residual issues that a primary audit team might miss, providing an additional verification layer for novel or mathematically complex protocols.
Penetration Testing covers web applications, APIs, cloud infrastructure, and CI/CD pipelines using OWASP, PTES, and SEAL standards. This extends security assurance beyond on-chain code to the full technical stack that protocols rely on.
AI Security Testing applies adversarial evaluation to AI agents and large language models integrated into Web3 applications, using frameworks including OWASP LLM Top 10, MITRE ATLAS, and Google SAIF. As AI-powered components become more common in DeFi and protocol tooling, this service addresses an emerging attack surface.
Red Team Exercises simulate realistic adversaries through social engineering, phishing campaigns, and insider threat scenarios, testing the human and operational dimensions of a protocol's security posture.
On-Chain Monitoring is delivered in partnership with Guardrail and provides continuous post-deployment surveillance of live contracts, supplemented by triage support when anomalies arise.
Operations Security addresses the governance and key management layer: multisig configurations, upgrade authority controls, protocol governance parameters, and software supply chain protections.
Solana Ecosystem Fit
CODESPECT treats Solana's Rust/Anchor environment as a primary supported stack rather than an afterthought. Its research blog documents original findings from Solana-specific audits. A 2026 post examines PDA (Program Derived Address) seed collision vulnerabilities arising from sequential counter designs in token allocation contracts, illustrating how an account isolation flaw can emerge without requiring elevated permissions. The firm also co-hosted a hackathon security workshop at CTU Prague focused on Solana development, signaling engagement with the developer community beyond paid engagements.
The Solana audit practice targets the risk classes particular to the account model — including cross-program invocation (CPI) patterns, signer validation, account ownership checks, and the interaction between Anchor macros and program logic — that do not map directly from EVM experience.
Research and Technical Findings
CODESPECT maintains an active public research blog with original technical write-ups documenting vulnerability classes discovered during engagements. Published findings as of mid-2026 include a cross-context ciphertext replay vulnerability in Arcium MXEs, showing how encrypted inputs function as bearer tokens that can be replayed across different computation contexts; a stale balance accounting bug in YieldBasis's gauge contract that went undetected by prior audits due to narrowly scoped review boundaries; a Merkle tree corruption vulnerability in a Cairo-based privacy mixer triggered by the 1,025th deposit; and an analysis of security and implementation pitfalls in liquid staking tokens deployed on Hyperliquid.
Track Record
The firm reports having protected over 4 billion dollars in total value locked across its client base. Named clients cited on the firm's website include ETHSign, The Vault, and LST Olas. Protocols citing CODESPECT as a trusted security partner include Swell, Redstone, and TokenTable. An independent account of a CODESPECT engagement describes a 14-day end-to-end process that concluded with zero critical findings and only minor and low-severity issues.
Team and Background
CODESPECT was founded in May 2024 and is headquartered in Opava, Czech Republic. Its researchers developed experience on competitive audit platforms such as Cantina and CodeHawks before forming the firm. The team does not publicly identify individual members by name on its website. Contact for audit inquiries is listed as [email protected].
Position in the Solana Ecosystem
As Solana's total value locked and protocol complexity have grown, demand for security review capable of handling Rust-native programs has increased. CODESPECT occupies the boutique segment of this market, emphasizing depth of review and breadth of attack-surface coverage over volume throughput. Its combination of Rust/Anchor smart contract auditing, web and infrastructure penetration testing, and AI security evaluation positions it to serve Solana protocols that have expanded beyond purely on-chain components into full application stacks.
Contents
- Problem Solved
- Core Services
- Solana Ecosystem Fit
- Research and Technical Findings
- Track Record
- Team and Background
- Position in the Solana Ecosystem
Solana Token Markets