QuillAudits
Multi-chain smart contract security auditing and Web3 security services
On-chain activity
Smart Contract Audit Services
Provides smart contract security audits through manual code review and automated testing across multiple blockchain platforms, delivering detailed vulnerability reports with remediation guidance. Services include smart contract audits, penetration testing, wallet security audits, and protocol analysis for Ethereum, Solana, Polygon, Starknet, and other major blockchain ecosystems.
QuillAudits
QuillAudits
QuillAudits is a multi-chain smart contract security firm founded in 2018 that combines manual adversarial auditing with AI-driven tooling to protect Web3 protocols across more than a dozen blockchain networks, including Solana.
Background
QuillAudits was established in 2018 by Preetam Rao and Rajat Gahlot as a security arm of QuillHash Technologies. Headquartered in Dubai, UAE, the firm grew from an Ethereum-focused smart contract auditor into one of the broader blockchain security vendors active before the 2020 DeFi boom. It is ISO 27001 certified and has been recognized as a security partner by the DeFi Security Alliance and the Uniswap Foundation. As of mid-2026 the team comprises approximately 30 full-time employees, supplemented by an independent researcher network described as Vigilant Squad, with groups of 10 to 12 researchers assigned per audit to provide adversarial coverage beyond the core review team.
What QuillAudits Does
The firm provides security assessments across the full lifecycle of a Web3 protocol, from pre-deployment design review through post-launch monitoring. Its principal service is the smart contract audit: a multi-stage process involving manual line-by-line code review by senior auditors, independent red-team analysis, automated scanning, fuzzing, and property-based testing. Separate service tracks cover penetration testing of decentralized applications, wallet security audits, operational security advisory (including a virtual CISO offering), and RWA token standard reviews.
Beyond audit delivery, QuillAudits operates a suite of proprietary security tools:
- QuillShield — AI-powered vulnerability scanner that clients can run against their contracts prior to engaging a formal audit
- QuillMonitor — on-chain monitoring that flags anomalous transactions in deployed contracts
- AEGIS — an internal security analysis layer used during audit engagements
- Multisig Inspector — tooling to assess multisig wallet configurations for governance risk
In mid-2026, QuillAudits released open-source Claude Skills under the QuillShield brand, extending AI-assisted audit capabilities to independent researchers worldwide.
Solana Coverage
QuillAudits supports Solana program auditing as part of its multi-chain offering. Its Solana methodology addresses the account-based programming model specific to the SVM, auditing for vulnerabilities that do not exist on EVM chains: signer authorization gaps, missing owner checks, PDA sharing issues, bump seed canonicalization errors, rent exemption misconfigurations, SPL token account validation failures, and sysvar address spoofing. The audit process incorporates Solana-native tooling including Soteria, cargo-audit, cargo-clippy, cargo-tarpaulin, and cargo-geiger. Public audit reports for Solana programs are published to the firm's GitHub repository under the Quillhash organization.
Track Record and Scale
Across its eight years of operation, QuillAudits reports:
- 1,500+ projects audited
- $3 billion+ in TVL protected
- 10,000+ issues identified
- More than 2,000 critical or high-severity vulnerabilities reported
- Over 80% client retention rate for multi-audit engagements
Networks served span Ethereum, Solana, Polygon, Arbitrum, Optimism, Base, Avalanche, Binance Smart Chain, Aptos, Sui, zkSync, and Starknet. Its audit reports are accepted by more than 50 exchanges and its auditor credentials are verified on Etherscan and smartcontractaudits.com. Notable launchpad and fund partners include Woodstock, Unicrypt, dxSale, and Superlauncher.
Research and Content Presence
The firm maintains an active blog publishing postmortem analyses of on-chain exploits, typically within hours of an attack. Coverage in 2025 and 2026 has included detailed breakdowns of price manipulation attacks, oracle exploits, governance takeover vectors, and logic errors across EVM and non-EVM chains. This output functions both as marketing and as an independent research record of exploit techniques. The X/Twitter account (@quillaudits_ai) mirrors this focus with real-time alert threads and security checklists. Recent posts have covered RWA token standard attack surfaces and cross-chain lending exploits.
Positioning in the Solana Ecosystem
QuillAudits is a service provider rather than a protocol or DeFi primitive. It holds no native token and does not operate on-chain infrastructure. Its relevance to the Solana ecosystem is as an external security gatekeeping layer: projects launching on Solana that require a credentialed third-party audit for exchange listings, launchpad participation, or investor due diligence can engage QuillAudits as one of the established audit vendors with published Solana-specific methodology. The firm competes in this space with other multi-chain security firms, and its differentiation rests on its 2018 founding date, published audit volume, ISO certification, and the breadth of its tooling suite including real-time monitoring.
Contents
- Background
- What QuillAudits Does
- Solana Coverage
- Track Record and Scale
- Research and Content Presence
- Positioning in the Solana Ecosystem
Solana Token Markets