I can't tell a real audit from a rubber stamp.
We deliver a severity-graded report with a proof-of-concept for each finding and a final report confirming fix status—not a logo for your website.
Smart Contract Audit
Find the scary stuff before strangers do. Independent, line-by-line audits for tokens, DeFi protocols, and bridges—combining manual review with automated tooling, plus remediation and re-audit so fixes actually land.
Independent review · Proof-of-concept exploits · Re-audit included in scope
650+
Smart contracts audited
$5K–$150K+
Honest 2026 audit cost range
1–6 wks
Typical audit window by complexity
Zero
Critical incidents on audited launches
Select complexity, code size, chain, and audit depth for indicative 2026 pricing.
Estimated audit cost
$18K–$60K
Timeline
3–6 weeks
Plus 1–2 weeks if remediation re-review is needed.
What's included
Estimates only — final scope after discovery call. Bridges and high-TVL protocols may require multiple independent audits.
Where founders get stuck
I can't tell a real audit from a rubber stamp.
We deliver a severity-graded report with a proof-of-concept for each finding and a final report confirming fix status—not a logo for your website.
The audit wasn't in my original quote.
We never exclude the audit to make a number look smaller. Security is a transparent line item, because the most expensive audit is the one you need after an exploit.
What if fixing one bug introduces another?
That's exactly why we re-audit. After your team fixes findings, we review the changes, since edits can introduce new issues—deploying an unreviewed version defeats the purpose.
My previous vendor left issues unresolved.
We run remediation engagements: take the existing report, fix critical/high/medium findings at root cause (not patches), add tests, and prepare the code for re-audit.
I don't know how much security to budget.
A practical starting point is 5–10% of development cost for assessment; for production projects, coding plus auditing together often run 50–65% of the build. We size it honestly to your risk.
What we build
Senior auditors read every line for reentrancy, access-control failures, oracle/price manipulation, and economic exploits that tools miss.
Static and dynamic analysis (Slither, Mythril, fuzzing) to surface known vulnerability classes quickly and broaden coverage.
Threat modeling and economic analysis for AMMs, lending, staking, and vaults where the exploit is in the math, not just the code.
High-stakes review for bridges and L1/ZK systems, where formal verification is often warranted for the highest trust bar.
Root-cause fixes, added tests, and a re-review of changes with a final report confirming each finding is resolved.
Beyond contracts: front-end and wallet security, key/MPC custody design, admin-key management, monitoring, and incident response.
How we deliver
01
We map your contracts, asset flows, and trust boundaries to define audit scope and the most likely attack surfaces.
02
Static/dynamic analysis and fuzzing surface known vulnerability classes and hot spots for deeper manual review.
03
Senior auditors review line-by-line and model economic exploits, writing a proof-of-concept for each real finding.
04
You get a severity-graded report (critical/high/medium/low/informational) with clear remediation guidance for each issue.
05
We help your team fix at root cause and add tests, or run the remediation ourselves where you prefer.
06
We review the fixes and issue a final report confirming resolution status before you deploy to mainnet.
Pricing & timelines
Indicative ranges blended from current market data. Your fixed-scope quote is set after a short discovery call.
$5K–$15K
2–7 days
Audit for ERC-20/BEP-20 tokens and standard NFT contracts, with report and fix verification.
Best for: Token launches and simple NFT drops.
$15K–$50K
2–4 weeks
Staking, vesting, governance, and custom marketplace contracts with deeper manual and economic review.
Best for: Protocols with meaningful custom logic.
$50K–$150K+
4–8 weeks
AMMs, lending, and cross-chain systems with threat modeling, economic analysis, and remediation support.
Best for: High-TVL DeFi protocols.
$150K–$500K+
Custom
The highest-stakes systems, where multiple audits, formal verification, and a bug bounty are standard.
Best for: Bridges and institutional-grade infrastructure.
A re-audit of fixes typically adds 20–40% of the original fee. Formal verification adds roughly $20K–$50K. Top firms book 2–4 months ahead—schedule early.
Automated scanners miss logic and economic bugs. Our edge is senior manual review with proof-of-concept exploits.
Fixes get reviewed. We confirm resolution before deployment instead of signing off on an unreviewed version.
We grade findings by real impact and won't inflate or downplay—your investors and users can trust the report.
We don't just point at problems. We can fix them at root cause and harden the code for re-audit.
Proof
Criticals remediating before launch
Full DeFi audit with economic analysis, remediation, and re-audit before Arbitrum mainnet.
“Two critical findings our previous auditor missed. Marshall's remediation team fixed root causes, not patches.”
FAQ
Simple token/NFT contracts cost $5,000–$15,000, mid-complexity protocols (staking, vesting, governance) $15,000–$50,000, and full DeFi protocols (AMMs, lending, cross-chain) $50,000–$150,000+. Bridges and L1/ZK systems can reach $150,000–$500,000+. A re-audit of fixes adds 20–40% of the original fee.
Simple contracts take 2–7 days, standard DeFi protocols 2–4 weeks, and complex systems 4–8 weeks, plus 1–2 weeks for remediation verification. Total engagement is typically 4–10 weeks. Top firms book 2–4 months ahead, so schedule early.
An audit is a systematic security review where experts examine contract code line-by-line for vulnerabilities, logic errors, and economic exploits before deployment. Because deployed contracts are immutable and hold real funds, an audit is essential—the most expensive audit is the one you need after an exploit.
Reentrancy (an external call re-entering your contract before state updates), access-control failures (missing permission checks), oracle/price manipulation, integer issues, and unchecked external calls are the most common. Reputable audits combine automated tools (Slither, Mythril) with manual review to catch them.
Yes. After your team fixes findings, auditors must review the fixes, since changes can introduce new bugs. Most firms charge 20–40% of the original fee for re-review. Deploying a version the auditor hasn't reviewed defeats the purpose of the audit.
Formal verification mathematically proves that your contract's critical invariants can't be broken. It adds roughly $20,000–$50,000 and extra weeks. It's optional for simple tokens but effectively required for high-value bridges and institutional protocols where the bar for trust is highest.
A practical starting point is 5–10% of your development cost for security assessment. For production projects, smart-contract coding plus auditing together often account for 50–65% of the total build budget. Cutting the audit isn't a saving—it's transferring risk to your users.
Yes. Remediation engagements take an existing audit report, fix the critical/high/medium findings at root cause (not patches), add tests, and prepare the code for re-audit. This is common when a previous team or vendor left issues unresolved.
A proper audit delivers a findings report graded by severity (critical/high/medium/low/informational), a description and proof-of-concept for each issue, remediation recommendations, and a final report confirming fix status after re-review. Threat modeling and economic analysis may be separate line items.
For high-value protocols like bridges and large-TVL DeFi, multiple independent audits plus a public bug bounty are standard practice and expected by serious investors. For a simple token, one reputable audit is usually sufficient.
It's the hours spent testing versus writing code. For anything touching money, you want at least 1.5:1 to 3:1. A low ratio means under-tested code and higher exploit risk. Ask any development partner to break out code hours versus testing hours.
Solidity is the standard for Ethereum and all EVM chains (Polygon, BNB Chain, Arbitrum, Base). Solana uses Rust, and some ecosystems use Vyper, Move, or Cairo. Most projects choosing maximum tooling and liquidity build in Solidity on an EVM chain.
Web3 security also covers front-end and wallet security, private key/MPC custody design, oracle integrity, access-control and admin-key management, monitoring and alerting for live contracts, and incident response. It's a continuous lifecycle, not a one-time checklist before launch.
Last updated: June 2026
Related services
Get a transparent, fixed-scope quote with a realistic timeline, security plan, and first-year cost breakdown—no obligation, senior engineer on the first call.