Solana Projects › Pashov Audit Group

Pashov Audit Group

World Class Smart Contract Security Audits

Programs · 24h on-chain

On-chain activity

All programs →

Security Auditing

Pashov Audit Group provides smart contract security audits that identify vulnerabilities through manual code reviews. The service examines all aspects of contract implementations including access controls, input validation, business logic, and economic models.

Visit
About

Pashov Audit Group

Pashov Audit Group is a leading boutique smart contract security firm that deploys teams of four senior researchers on every engagement, operating across EVM chains and Solana to protect some of the largest protocols in DeFi.

Origins and Founder

The firm was founded by Krum Pashov, a Bulgarian security researcher who entered the smart contract auditing space on Code4rena in June 2022 and quickly rose to become a contest champion on both Code4rena and Sherlock. Working solo, Krum generated roughly 600,000 USDC over approximately 20 months before formalizing his practice into a collective. He then built the group into a 50+ researcher network by applying the same competitive vetting standard, hiring only researchers who could demonstrate top placements in public audit competitions.

The group's public audit repository on GitHub (pashov/audits) traces this evolution through its directory structure, preserving solo-era reports alongside the team-era engagements. With over 1,300 stars and 170 forks, the repository is one of the most referenced audit archives in the space and stands as a transparency artifact that most peer firms do not replicate.

Methodology

Every Pashov Audit Group engagement is staffed by four senior researchers. The firm deliberately avoids the common boutique pattern of one senior lead supervising junior auditors. All four reviewers are senior staff, each with verified contest credentials from Code4rena, Sherlock, or Cantina. This uniform seniority is designed to reduce the variance in finding quality that plagues larger or more hierarchically organized security firms.

The audit process follows a structured workflow: codebase preparation and scoping, multi-angle independent review with continuous client communication, delivery of an initial draft report, a client remediation window, and a final fix-review pass to verify that patches do not introduce regressions. Typical timelines run three to five days for a single focused contract and two to four weeks for a complex, multi-component DeFi protocol.

All reports are published to the public GitHub repository with client consent, providing prospective clients with a direct, unmediated view of past findings rather than curated summaries.

Language and Chain Coverage

Pashov Audit Group covers a wide stack of smart contract languages and execution environments. On the EVM side, the firm handles Solidity across Ethereum, Arbitrum, Optimism, Base, Polygon, BNB Chain, and Avalanche. Beyond EVM, the group audits Solana programs written in Rust using the Anchor framework, Move-based contracts on Aptos and Sui, Vyper, and Cairo on Starknet. This cross-environment breadth is relatively uncommon among boutique-scale firms and is a direct result of the contest-champion hiring gate, which surfaces researchers who specialize in non-EVM environments.

Solana Presence

Pashov Audit Group has established a meaningful footprint in the Solana security ecosystem. The firm is one of eight independent audit organizations identified in a 2025 SSRN empirical analysis of 163 multi-auditor Solana security reviews covering 1,669 vulnerabilities, alongside Sec3, Neodyme, OtterSec, Zellic, Offside Labs, Zenith, and Accretion. This inclusion reflects the group's active participation in Solana protocol security at scale, not merely peripheral coverage.

Among specific Solana engagements, the firm conducted a security review of Jupiter's JupUSD stablecoin in December 2025, alongside Offside Labs and Guardian Audits. A four-person team reviewed the codebase over one week and identified 12 issues. Jupiter is one of Solana's highest-volume DEX aggregators and JupUSD represented a major product expansion, making this one of the higher-profile Solana audits published in 2025. Additional Solana-native clients include Meteora and Pump.fun.

Client Portfolio and Scale

Across its EVM and non-EVM work, Pashov Audit Group has compiled an audit list that spans the top tier of DeFi by TVL and volume. Notable clients include Aave, Uniswap, Ethena, LayerZero, Pendle, EtherFi, 1inch, SushiSwap, PancakeSwap, Polymarket, Gains Network, TapiocaDAO, Venus, Dinari, Radiant, and Resolv. The firm's cumulative statistics as of 2026 stand at 400+ completed audits, 4,000+ vulnerabilities discovered, and over 100 billion dollars in TVL secured across client protocols.

The GitHub repository categorizes work across DeFi verticals including DEXs, lending protocols, stablecoins, asset management platforms, real-world asset protocols, cross-chain infrastructure, fundraising and token sale contracts, and gaming applications, indicating breadth rather than narrow vertical specialization.

Team Structure

Day-to-day operations involve Krum Pashov as founder, Dan Ogurtsov as Head of Audits, and a rotating cast of 50+ senior researchers drawn from the competitive audit contest ecosystem. The firm communicates via Telegram and its website for engagement inquiries. Client-facing interactions during an audit involve direct researcher access rather than account-management intermediaries.

Reputation and Track Record

The firm's track record is broadly strong, though not without nuance. A Q3 2024 Pashov audit covered the RebalancerSpot and SwapLogic contracts of a protocol that subsequently suffered a 3.6 million dollar exploit. Post-incident analysis identified the relevant contracts as in-scope for that audit, which constitutes a legitimate miss. Two additional incidents cited in third-party reviews were characterized as out-of-scope, meaning the exploited code was not included in the engagement. The group's overall false-negative rate across 400+ audits remains low by industry standards, and the public report archive allows independent verification of prior work, a meaningful differentiator in an industry where reputation is otherwise difficult to audit.

Positioning in the Solana Ecosystem

For Solana protocols seeking security coverage, Pashov Audit Group occupies the higher end of the market alongside firms such as OtterSec, Neodyme, and Zellic. The firm's contest-champion hiring standard, fixed four-researcher staffing model, and public report archive make it a credible choice for protocols that require both Rust/Anchor expertise and EVM cross-compatibility. The Jupiter JupUSD engagement demonstrates that the group can handle Solana's flagship-tier protocols under tight timelines.

Contents

Note: inclusion in Solana Compass directory does not indicate a recommendation or endorsement of this project, its token(s) or its products. Data sourced with thanks from The Grid to aid in building these pages.

Reviews

0.0
0 reviews
Please login to write a review.
Solana tokens

Solana Token Markets

Explore all tokens →