Solana Projects › QuillAudits

QuillAudits

Multi-chain smart contract security auditing and Web3 security services

Programs · 24h on-chain

On-chain activity

All programs →

Smart Contract Audit Services

Provides smart contract security audits through manual code review and automated testing across multiple blockchain platforms, delivering detailed vulnerability reports with remediation guidance. Services include smart contract audits, penetration testing, wallet security audits, and protocol analysis for Ethereum, Solana, Polygon, Starknet, and other major blockchain ecosystems.

Visit
About

QuillAudits

QuillAudits

QuillAudits is a multi-chain smart contract security firm founded in 2018 that combines manual adversarial auditing with AI-driven tooling to protect Web3 protocols across more than a dozen blockchain networks, including Solana.

Background

QuillAudits was established in 2018 by Preetam Rao and Rajat Gahlot as a security arm of QuillHash Technologies. Headquartered in Dubai, UAE, the firm grew from an Ethereum-focused smart contract auditor into one of the broader blockchain security vendors active before the 2020 DeFi boom. It is ISO 27001 certified and has been recognized as a security partner by the DeFi Security Alliance and the Uniswap Foundation. As of mid-2026 the team comprises approximately 30 full-time employees, supplemented by an independent researcher network described as Vigilant Squad, with groups of 10 to 12 researchers assigned per audit to provide adversarial coverage beyond the core review team.

What QuillAudits Does

The firm provides security assessments across the full lifecycle of a Web3 protocol, from pre-deployment design review through post-launch monitoring. Its principal service is the smart contract audit: a multi-stage process involving manual line-by-line code review by senior auditors, independent red-team analysis, automated scanning, fuzzing, and property-based testing. Separate service tracks cover penetration testing of decentralized applications, wallet security audits, operational security advisory (including a virtual CISO offering), and RWA token standard reviews.

Beyond audit delivery, QuillAudits operates a suite of proprietary security tools:

  • QuillShield — AI-powered vulnerability scanner that clients can run against their contracts prior to engaging a formal audit
  • QuillMonitor — on-chain monitoring that flags anomalous transactions in deployed contracts
  • AEGIS — an internal security analysis layer used during audit engagements
  • Multisig Inspector — tooling to assess multisig wallet configurations for governance risk

In mid-2026, QuillAudits released open-source Claude Skills under the QuillShield brand, extending AI-assisted audit capabilities to independent researchers worldwide.

Solana Coverage

QuillAudits supports Solana program auditing as part of its multi-chain offering. Its Solana methodology addresses the account-based programming model specific to the SVM, auditing for vulnerabilities that do not exist on EVM chains: signer authorization gaps, missing owner checks, PDA sharing issues, bump seed canonicalization errors, rent exemption misconfigurations, SPL token account validation failures, and sysvar address spoofing. The audit process incorporates Solana-native tooling including Soteria, cargo-audit, cargo-clippy, cargo-tarpaulin, and cargo-geiger. Public audit reports for Solana programs are published to the firm's GitHub repository under the Quillhash organization.

Track Record and Scale

Across its eight years of operation, QuillAudits reports:

  • 1,500+ projects audited
  • $3 billion+ in TVL protected
  • 10,000+ issues identified
  • More than 2,000 critical or high-severity vulnerabilities reported
  • Over 80% client retention rate for multi-audit engagements

Networks served span Ethereum, Solana, Polygon, Arbitrum, Optimism, Base, Avalanche, Binance Smart Chain, Aptos, Sui, zkSync, and Starknet. Its audit reports are accepted by more than 50 exchanges and its auditor credentials are verified on Etherscan and smartcontractaudits.com. Notable launchpad and fund partners include Woodstock, Unicrypt, dxSale, and Superlauncher.

Research and Content Presence

The firm maintains an active blog publishing postmortem analyses of on-chain exploits, typically within hours of an attack. Coverage in 2025 and 2026 has included detailed breakdowns of price manipulation attacks, oracle exploits, governance takeover vectors, and logic errors across EVM and non-EVM chains. This output functions both as marketing and as an independent research record of exploit techniques. The X/Twitter account (@quillaudits_ai) mirrors this focus with real-time alert threads and security checklists. Recent posts have covered RWA token standard attack surfaces and cross-chain lending exploits.

Positioning in the Solana Ecosystem

QuillAudits is a service provider rather than a protocol or DeFi primitive. It holds no native token and does not operate on-chain infrastructure. Its relevance to the Solana ecosystem is as an external security gatekeeping layer: projects launching on Solana that require a credentialed third-party audit for exchange listings, launchpad participation, or investor due diligence can engage QuillAudits as one of the established audit vendors with published Solana-specific methodology. The firm competes in this space with other multi-chain security firms, and its differentiation rests on its 2018 founding date, published audit volume, ISO certification, and the breadth of its tooling suite including real-time monitoring.

Contents

Note: inclusion in Solana Compass directory does not indicate a recommendation or endorsement of this project, its token(s) or its products. Data sourced with thanks from The Grid to aid in building these pages.

Reviews

0.0
0 reviews
Please login to write a review.
Solana tokens

Solana Token Markets

Explore all tokens →