Directory

Firms & platforms

Audit firms and security harnesses grouped by where they do their deepest work. This is a sample, not a ranking. Match the focus sectors to your scope.

Sectors Zero-knowledgeSmart contractsProtocol / consensusApplied cryptographyFormal verificationInfrastructure

Audit firms

Fixed teams that review a codebase in depth over a defined engagement.

Audit firms by focus sector.
Firm / Platform Focus sectors Size Notes
Trail of Bits
Smart contractsCryptographySoftware assuranceTooling
Smart contracts, Protocol / consensus, Applied cryptography, Infrastructure Large Large, broad security firm covering blockchain, cryptography, and traditional software assurance, with a substantial open-source tooling output.
NCC Group
CryptographyProtocol reviewEnterprise security
Applied cryptography, Protocol / consensus, Infrastructure Large Global enterprise security consultancy with a dedicated cryptography practice that reviews protocols and primitives across many industries.
Informal Systems
Consensus protocolsCosmos / TendermintModel checking
Protocol / consensus, Formal verification Mid-size Specializes in protocol correctness and formal methods, with deep roots in the Cosmos / Tendermint ecosystem and model-based testing.
Galois
Formal methodsCryptographic verificationHigh-assurance software
Applied cryptography, Formal verification Mid-size Research firm specializing in formal methods and high-assurance cryptography, with open-source tools such as Cryptol and SAW for verifying cryptographic implementations.
IOActive
Hardware securityCryptographySecurity research
Applied cryptography, Infrastructure, Protocol / consensus Large Global security consultancy known for deep hardware, firmware, and cryptography research across many industries, including blockchain and embedded systems.
Kudelski Security
Applied cryptographyBlockchain securityEnterprise security
Applied cryptography, Protocol / consensus, Infrastructure Large Cybersecurity division of the Kudelski Group, with an applied-cryptography practice and a blockchain security team serving enterprise and Web3 clients.
EY
Enterprise blockchainZero-knowledge R&DAssurance
Zero-knowledge, Protocol / consensus, Infrastructure Large Global professional-services firm whose blockchain group has invested in zero-knowledge research, including the Nightfall protocol and the Starlight ZK compiler, alongside enterprise assurance work.
Calif
AI-driven vulnerability research0-day researchOffensive security
Infrastructure, Applied cryptography Boutique Vulnerability-research firm that pairs AI models with human researchers to find and exploit bugs, with work spanning operating systems, low-level software, and cloud infrastructure.

Security harnesses

Audit-competition and bug-bounty platforms that put your code in front of many independent researchers.

Security harnesses by focus sector.
Firm / Platform Focus sectors Size Notes
Code4rena
Open audit competitionsLarge researcher crowd
Smart contracts, Protocol / consensus Large Established competitive-audit marketplace with a large crowd of wardens, strongest on smart-contract and protocol scope.
Sherlock
Audit contestsCoverage guarantees
Smart contracts, Protocol / consensus Mid-size Audit-contest platform that has experimented with coverage and payout guarantees on top of competitive review.
Cantina
CompetitionsResearcher marketplaceManaged reviews
Smart contracts, Protocol / consensus, Zero-knowledge Mid-size Marketplace combining competitions, a curated researcher network, and managed reviews under one roof.
Immunefi
Ongoing bug bountiesWhitehat network
Smart contracts, Protocol / consensus, Infrastructure Large Large continuous bug-bounty platform for live protocols, complementary to point-in-time audits and competitions.

Want to be listed, corrected, or have details updated? See our methodology for how listings work, then get in touch.