SlowMist
Blockchain ecosystem security — audits, threat intelligence, and crypto
On-chain activity
SlowMist Security Services
SlowMist Security Services provides professional security assessments for blockchain ecosystems through smart contract, exchange, wallet, and blockchain source code audits, alongside red team simulations, security monitoring, defense deployment, incident response, security consulting, and blockchain threat intelligence sharing. Audit methodologies combine white-box, black-box, and gray-box analysis aligned with OWASP, CVSS, and HKSFC compliance frameworks, covering EVM chains, Solana, EOS, Fabric, Move-based chains, and enterprise consortium blockchain systems.
SlowMist
SlowMist is a blockchain-focused threat intelligence and security firm that aims to make the broader blockchain ecosystem as secure as possible. Founded in January 2018 by professionals with over a decade of network security experience, the company provides security audits, anti-money-laundering (AML) tooling, and active threat monitoring to exchanges, wallets, DeFi protocols, and public chains across the industry — including Solana.
Core Services
SlowMist's service portfolio spans the full security lifecycle of a Web3 project:
- Exchange and wallet security audits: Gray-box assessments covering network attack surfaces, private key architecture, and business logic.
- Blockchain infrastructure audits: Reviews of node configuration, consensus mechanisms, and core code resilience for public chains and Layer 2 mainnets.
- Smart contract audits: White-box source code review for tokens, DApp contracts, and on-chain programs.
- Red teaming: Penetration testing and adversarial exercises.
- Incident response: Rapid engagement for active exploits, leveraging SlowMist's threat intelligence network to freeze or recover stolen funds.
- Defense deployment: Hardening recommendations for hot wallet infrastructure and deposit verification systems.
Flagship Products
MistTrack is SlowMist's AML and crypto-tracking platform. Launched in 2022, MistTrack supports fund tracing across 17 blockchains — including Solana, which was added in March 2024 — and has accumulated over 100,000 users. The platform provides address labels, in-depth transaction behavior analysis, and fund-flow visualization. It received the Gold Award in FinTech (RegTech) at the HKICT Awards 2025. SlowMist's team also built MistTrackMCP, a TypeScript integration that pipes MistTrack's blockchain transaction-tracking data directly into AI assistants including Claude.
MistEye is a Web3 threat intelligence and dynamic monitoring platform that tracks potential vulnerabilities and attack patterns across the ecosystem in real time.
SlowMist Hacked is a publicly maintained database of blockchain security incidents. As of mid-2025, the database tracks over 1,875 incidents representing $35.8 billion in cumulative losses — 305 of which originated from smart contract flaws.
Badwhale is a deposit-verification system designed to prevent fake-deposit attacks on exchanges, which SlowMist reports has protected against billions of dollars in potential losses.
The firm also holds ISO/IEC 27001:2022 Information Security Management System certification, and in 2025 received the "Cyber Security Excellence Contribution Award" from the Hong Kong Police Force Cybersecurity and Technology Crime Bureau.
Solana Ecosystem Engagement
SlowMist has developed a meaningful body of work specific to Solana. The team published and actively maintains a Solana Smart Contract Security Best Practices guide on GitHub, covering common vulnerabilities and recommended mitigations specific to Solana's account model and program execution environment.
Key Solana-specific audit areas SlowMist focuses on include:
- Account ownership and data validation: Ensuring that programs correctly verify account ownership before trusting account data.
- Program ID and signer authentication: Confirming that callers are who they claim to be.
- SPL token standard compliance: Checking that token accounts conform to expected formats.
- Program Derived Address (PDA) legitimacy: Verifying that PDAs are derived correctly and cannot be spoofed.
- Rent adequacy: Confirming that accounts hold sufficient lamports to remain rent-exempt.
The firm has documented major historical Solana attacks in detail, including the Wormhole bridge exploit — where failure to validate system accounts allowed forging of 120,000 ETH worth of fake tokens — and the Nirvana flash-loan incident, where price manipulation against an unaudited protocol netted attackers over $3 million. SlowMist's team has also presented on advanced Solana auditing strategies at industry events, covering security considerations from development through deployment.
In its 2025 mid-year blockchain security and AML report, SlowMist identified Solana as one of the ecosystems most affected by security incidents in the first half of 2025, with approximately $5.8 million in losses across the period. The firm's threat intelligence network assisted in freezing over $112 million in funds across all chains throughout 2024.
Audit Track Record and Clients
SlowMist has audited more than 1,500 smart contracts across multiple blockchains. The firm has worked with major centralized exchanges including Binance, OKX, Crypto.com, Amber Group, and HTX, as well as DeFi protocols and public chain teams. OKX has formally recognized SlowMist as a Best Security Audit Partner.
Open-Source Contributions
The SlowMist GitHub organization maintains 42 repositories across security tooling, research, and education. Widely-used public resources include:
- Knowledge-Base (4,600+ stars): Comprehensive security knowledge repository available in English and Chinese.
- SlowMist-Learning-Roadmap-for-Becoming-a-Smart-Contract-Auditor (923 stars): Education resource for the next generation of auditors.
- Crypto-Asset-Tracing-Handbook (430 stars): Reference on cryptocurrency tracing methodology.
- slowmist-agent-security (494 stars): Security review framework for AI agents operating in adversarial environments.
- Web3-Project-Security-Practice-Requirements (349 stars): Operational security guide covering development, release, and incident response.
Team and Operations
SlowMist was established in January 2018 and operates within People's Republic of China jurisdiction. The team publishes regular security reports — including annual and mid-year blockchain security and AML reports — that have become reference documents for the broader industry. The company's InMist intelligence network connects its internal research with a broader partner ecosystem for real-time threat sharing and coordinated incident response.
SlowMist's security philosophy emphasizes continuous rather than point-in-time protection: audits at launch are considered necessary but not sufficient, with ongoing monitoring, regular re-audits as code evolves, and executive-level accountability for security budgets all forming part of the firm's recommended posture for Web3 projects.
Contents
- Core Services
- Flagship Products
- Solana Ecosystem Engagement
- Audit Track Record and Clients
- Open-Source Contributions
- Team and Operations
Solana Token Markets