Skip to main content

Auditors

PAL works with a curated pool of reputable auditors in the Web3 security space. This includes both traditional auditing firms and platforms for crowdsourced audits.


The following is a list of PAL-approved auditors with their contacts:

Traditional audits

NameWorks withContact
BeosinRust, Solidityservice@beosin.com
ChaintroopersRust, Solidityinfo@chaintroopers.com
CoinFabrikRust, Solidityvaleria.caracciolo@coinfabrik.com
DedaubRust, Soliditycontact@dedaub.com
GuvenkayaRust, Web2timur@guvenkaya.co
HackenRust, Solidityb.bennett@hacken.io
OAK SecurityRust, Solidityinfo@oaksecurity.io
OpenZeppelinRust, Soliditycontact@openzeppelin.com
Pashov Audit GroupRust, Soliditypashovkrum@gmail.com
Red4SecRust, Solidityinfo@red4sec.com
Runtime VerificationRust, Soliditycontact@runtimeverification.com
SpearbitRust, Solidityhenry@spearbit.com
SRLabsRust, Solidityhello@srlabs.de
Trail of BitsRust, Soliditysales@trailofbits.com
ZellicRust, Soliditykaushik@zellic.io

Crowdsourced audits

NameWorks withContact
Code4renaRust, Soliditytrebien@code4rena.com
CantinaRust, Solidityhenry@spearbit.com
CodehawksRust, Soliditymark@cyfrin.io
HackenProofRust, Soliditye.fedotova@hackenproof.com
ImmunefiRust, Solidityteam@immunefi.com

Selecting an Auditor

When selecting an auditor for your project:

  • Consider their expertise in the specific technologies you're using (e.g., Rust, Substrate, ink!, Solidity).
  • Review their past audit reports, if available.
  • Consider their familiarity with the Polkadot ecosystem.
  • Reach out to multiple auditors to compare quotes and availability.
  • Rotate your auditors - consider picking a different supplier for your next audit.

Remember to mention that you're applying under PAL when contacting these auditors.

For any questions about selecting an auditor or if you have a preferred auditor not on this list, please contact the PAL curators.