Solana Projects › Hashlock

Hashlock

Secure Your Web3 Project with Hashlock

Programs · 24h on-chain

On-chain activity

All programs →

Smart Contract Auditing Services

Hashlock provides comprehensive smart contract security audits through manual analysis and automated testing across multiple blockchain protocols. The service conducts line-by-line code review, vulnerability assessment, and security recommendations for Solidity, Rust, Cairo, and Move smart contracts. Audits identify critical security flaws including reentrancy attacks, integer overflows, access control issues, and logic errors before deployment.

Visit
About

Hashlock

Hashlock is an Australian Web3 security firm specializing in smart contract auditing, blockchain penetration testing, and ongoing security advisory across more than 30 blockchain networks. Founded in 2022 and headquartered in Sydney, New South Wales, the company targets one of the most persistent risk vectors in decentralized finance: undetected vulnerabilities in on-chain code that expose user funds to irreversible loss. By providing independent, manual security review before and after deployment, Hashlock occupies the layer between protocol developers and live users where bugs, if undetected, cannot be patched retroactively.

Problem and Purpose

Smart contracts execute autonomously and immutably on-chain. A vulnerability in production code can result in exploits that drain protocol treasuries, user assets, or liquidity pools within seconds—often with no recourse. While automated scanning tools can catch known vulnerability patterns, they miss novel attack vectors, logic errors, and chain-specific runtime issues. Hashlock's core thesis is that manual expert review, grounded in deep knowledge of both the application layer and the underlying virtual machine, is required to catch the class of bugs automated tooling misses.

Audit Methodology

Hashlock uses a two-phase process. In the first phase, security researchers conduct a comprehensive code review combining manual analysis with automated tooling. Researchers begin by understanding the protocol's specification and intended behavior, then examine the codebase to identify vulnerabilities and cross-reference the implementation against similar protocols and known attack patterns from the broader audit landscape. The engagement produces a written report itemizing findings by severity, impact, and recommended remediation.

In the second phase, once the development team has addressed findings, Hashlock performs a re-audit to verify that fixes were correctly implemented and that remediations did not introduce new vulnerabilities. This two-step cycle—initial discovery followed by verification—closes the audit loop before code reaches production or is integrated by third parties.

Beyond vulnerability identification, the process includes gas optimization analysis, test suite review, and where applicable, assessment of the protocol's tokenomics design.

Services

Beyond the core smart contract audit, Hashlock offers a suite of adjacent services:

  • Web3 penetration testing: Red-team exercises targeting protocol infrastructure, front-ends, APIs, and backend systems supporting on-chain applications.
  • Tokenomics reviews: Analysis of token distribution, incentive alignment, and economic attack surfaces.
  • Bug bounty program management: Coordination and structuring of ongoing disclosure programs post-audit.
  • On-chain monitoring: Post-launch surveillance for anomalous transaction patterns.
  • Incident response: Forensic investigation and containment guidance following an exploit.
  • Blockchain security education: Training and workshops for development teams.
  • AI Audit Tool: A free, publicly accessible automated scanner available at aiaudit.hashlock.com, powered by custom-tuned large language models trained on Hashlock's library of manual audit reports. The tool flags potential vulnerabilities, provides impact summaries, and recommends fixes—intended as a preliminary triage check before a full professional engagement, rather than a replacement for manual review. Integration with open-source tools including Slither and Mythril is planned.

Supported Chains and Languages

Hashlock operates chain-agnostically across 30+ blockchains, with specialization in Ethereum and EVM-compatible networks (Polygon, Arbitrum, Base, BNB Chain, Avalanche, Berachain, Optimism), Solana, Polkadot and Kusama (Substrate, parachains, XCM), Cosmos SDK appchains and CosmWasm, and networks including Aptos, Sui, Starknet, Bitcoin Layer 2, Near, Kadena, and Stacks. The firm audits Rust-based programs—including Solana native programs and Anchor framework contracts—as well as Solidity and Haskell/Plutus.

Solana Ecosystem Fit

Hashlock maintains a dedicated Solana practice. Solana's runtime model—account-based architecture, concurrent transaction processing, and the Anchor framework's implicit trust assumptions—creates a distinct set of audit considerations that differ materially from EVM environments. Common Solana vulnerability classes include signer validation failures, missing account ownership checks, integer overflow in fixed-point arithmetic, and program-derived address (PDA) misuse; each requires auditors with working knowledge of the Rust language and Solana's execution model.

A documented Solana engagement is the 2024 audit of Balanced and ICON General Message Passing (GMP) contracts, conducted as Balanced expanded its DeFi protocol cross-chain to Solana. Spicenet, a Solana DeFi infrastructure project, also appears among Hashlock's disclosed client roster.

Track Record and Portfolio

Hashlock's public GitHub repository lists over 200 audited clients spanning DeFi, gaming, real-world assets, infrastructure, and AI categories, with more than 16 additional engagements disclosed under NDA. Named projects in the public portfolio include Rocket Pool (Ethereum liquid staking), 1inch (DeFi aggregation), SushiSwap (multi-chain DEX), EigenLayer (restaking), Gala (Web3 gaming), Vana (user-owned AI data), Energy Web (Polkadot infrastructure), Manifest (Cosmos appchain), Peaq, Redbelly Network, and Verida Network. Institutional clients have included RMIT University, UNSW, and the New South Wales state government. Through these engagements, Hashlock reports having helped secure more than $1.3 billion in on-chain assets. The firm states that no project that has received a full Hashlock audit has subsequently been successfully exploited.

Hashlock is rated 4.9/5 across 19 verified client reviews on Clutch, with perfect scores for scheduling and cost benchmarks. Clients on Clutch frequently cite timely delivery and responsiveness. Pricing is customized per engagement, with indicative rates of $100–$149 per hour and typical project costs in the $10,000–$49,999 range; the firm promises quote responses within 6–48 hours.

Team and Background

Hashlock was co-founded by Jock Haslam and Fletcher Roberts. Haslam previously worked as a cybersecurity consultant and brings substantial enterprise security experience to the firm. Roberts holds a background in technology and digital strategy. The founding team reports over 20 years of combined cybersecurity and digital forensics experience across the two co-founders. The company employs between 10 and 49 staff.

Hashlock is a member of both Blockchain Australia and FinTech Australia, and is the first fully independent-from-development auditor to be accepted by Blockchain Australia as a recognized security provider—a designation that distinguishes third-party reviewers from in-house security teams.

Contents

Note: inclusion in Solana Compass directory does not indicate a recommendation or endorsement of this project, its token(s) or its products. Data sourced with thanks from The Grid to aid in building these pages.

Reviews

0.0
0 reviews
Please login to write a review.
Solana tokens

Solana Token Markets

Explore all tokens →