On-chain activity
MixBytes Audit
MixBytes Audit delivers smart contract security reviews through dedicated three-auditor teams for EVM-compatible and Substrate-based protocols. The process covers four stages: interim code analysis using hacker-mindset and structured checklist approaches, re-audit of implemented fixes, final mainnet deployment verification, and continuous support for subsequent protocol updates. CTO-level review of all reports maintains consistent quality standards across engagements.
MixBytes
MixBytes is a blockchain security firm founded in 2017 that specializes in smart contract auditing, code reviews, and security consulting for DeFi protocols. Operating under the tagline "Safeguarding Innovation in DeFi," the firm has completed more than 300 audits across Ethereum-compatible chains, Polkadot, and Solana, and claims a zero-rekt record across its client base.
Core Services
MixBytes offers three engagement types: a full security audit delivered with a public report, a confidential code review without publication, and research and consulting for teams that need ongoing security guidance rather than a one-time assessment. Returning clients can access differential audits at discounted rates, handled by the same team that performed the original review.
Audit Methodology
Each engagement follows a four-phase process. The first phase, the interim audit, begins with independent analysis where auditors approach the code with an adversarial mindset—enumerating attack vectors, running tests, and conducting pair audits to surface overlooked issues. This is followed by a collaborative verification stage in which the team cross-checks findings against continuously updated vulnerability checklists.
The second phase is a re-audit: after the client addresses interim findings, auditors verify that fixes are correctly implemented and check whether any changes introduced new vulnerabilities. The third phase is a final audit conducted at or near deployment, confirming that mainnet contracts match the audited codebase. A fourth phase of continuous support offers returning clients discounted coverage for protocol upgrades and new modules.
Every client is assigned a dedicated team of three senior full-time auditors rather than rotating contractors. Auditors are specialists in mathematics, DeFi mechanisms, and low-level operations. The firm's CTO reviews all audit reports before delivery, providing a senior layer of quality control. Returning clients retain the same auditing team, eliminating the ramp-up time that typically comes with new engagements.
Track Record and Clients
MixBytes has audited extensively for some of the most consequential protocols in DeFi. Publicly documented work includes 27 separate engagements with Lido Finance, 21 with Yearn Finance, 11 with Aave, 9 with 1inch, and 5 with Curve Finance—the latter describing MixBytes as having "audited all of our core systems, including DEX, lending, and stablecoin infrastructure." Additional named clients include Instadapp/Fluid, Euler, Balancer, Swell, Stader, Mantle, Resolv, and OKX. The firm's public audit archive on GitHub (mixbytes/audits_public) has accumulated over 500 stars.
Ecosystem Coverage
MixBytes supports projects deployed on a broad range of chains. EVM-compatible networks covered include Ethereum, Arbitrum, Optimism, Base, BNB Chain, Polygon, Mantle, Sonic, Avalanche, and Berachain. Polkadot and Kusama (Substrate/Rust-based environments) are also covered, reflecting the firm's work building liquid staking infrastructure for those ecosystems. Solana is listed as a supported chain.
Solana Ecosystem Fit
MixBytes has developed documented expertise in Solana program security. In June 2026 the firm published research analyzing recent production exploits and mapping the vulnerability classes auditors encounter most frequently in Solana programs.
The research examined three recent incidents: a roughly 6 million dollar loss on Loopscale caused by a fake oracle supplying inflated collateral valuations, a roughly 2 million dollar loss on Texture Finance where LP tokens were minted to attacker-controlled addresses due to insufficient destination validation, and a roughly 254 thousand dollar loss on GoonFi stemming from an external price feed that dropped 30x in seconds with no sanity checks in the consuming AMM.
From this analysis MixBytes identified ten Solana-specific vulnerability classes: token and vault semantic errors including mint and authority mismatches, Token-2022 extension issues, and transfer fees; account graph integrity failures where positions belong to wrong users or markets; malformed data and panics from unchecked deserialization; PDA namespace collisions from incomplete seeds; CPI trust boundary violations where programs accept untrusted external calls; rent and lifecycle mishandling; account ownership and discriminator gaps; and signer semantic confusion between stored keys and active signers.
The firm highlights a core architectural distinction: unlike EVM contracts that fetch their own storage, Solana programs receive all accounts as inputs from the transaction builder. This means any account can be substituted by an attacker unless the program explicitly validates ownership, relationship, and identity for every account it receives—a validation burden requiring security expertise distinct from EVM auditing.
Research Output
Beyond client audits, MixBytes maintains an active security research blog covering DEX protocol mechanics (Curve, Balancer, Uniswap V4, 1inch, CoW, Fluid), lending vulnerabilities (Aave, Morpho Blue, Ajna, Euler V2), stablecoin design (Liquity V2, M^0, F(x) Protocol), zero-knowledge security, liquidation mechanisms, and ERC20 edge cases. The blog also covers developer tooling including Foundry-based exploit reproduction and mainnet fork testing strategies.
Team and Company Background
MixBytes was founded in 2017, giving it a longer operating history in blockchain security than most firms in the space. The team includes multiple senior auditors organized under dedicated team leads, with a head of audit overseeing engagements. The firm emphasizes recruitment selectivity and describes its auditors as specialists who train continuously to maintain technical edge across rapidly evolving protocol architectures.
MixBytes operates as a boutique security consultancy rather than a marketplace or crowdsourced audit platform. The firm positions itself as a long-term security partner for major protocols: consistent team assignments across engagements, a service model oriented toward sustainable protocol security, and a track record of public audit reports spanning over 300 engagements since inception.
Contents
- Core Services
- Audit Methodology
- Track Record and Clients
- Ecosystem Coverage
- Solana Ecosystem Fit
- Research Output
- Team and Company Background
Solana Token Markets