Web3 & EmergingWeb3 / DeFi lendingMulti-week audit with a re-audit of fixes
Auditing a DeFi lending protocol before it held real TVL on mainnet
Seed-stage DeFi lending protocol, ~15-person core team, pre-mainnet
In DeFi a single contract bug is an irreversible loss, and no serious backer or integrator commits liquidity to unaudited code. We audited the lending protocol's contracts, economic design and oracle dependencies before mainnet, caught a fund-draining reentrancy path along with the rest of the findings, and re-audited every fix so the team launched with a publishable report — and a clean on-chain record since.
Representative engagement — the client is confidential, and the figures and the quoted comment illustrate typical outcomes for the work described.
- Findings across contracts and economic design
- 1 critical, 4 high, 7 medium
- all remediated
- Fund-draining reentrancy path caught pre-mainnet
- 1
- fixed and re-audited clean
- Critical & high findings confirmed closed
- 100%
- before publication
- Live on mainnet with no protocol-level exploit
- 14 months
- since launch
The challenge
- The protocol was heading to mainnet with immutable code that would custody real user funds, where one missed flaw is unrecoverable.
- Backers, integrators and the community would not commit liquidity without an independent audit and a publishable report.
- Risk sat not only in the contracts but in the economic design and the price oracles the protocol depended on.
What we did
- Ran a full smart-contract audit with manual review of every privileged and fund-moving path.
- Conducted a DeFi protocol audit covering economic design, liquidation logic and oracle-manipulation and flash-loan vectors.
- Added web3 penetration testing of the surrounding interfaces and integration points, not just the contracts in isolation.
- Delivered findings severity-ranked with proof-of-concept exploits so the team understood real impact, not theoretical risk.
- Re-audited every remediation and confirmed closure before signing off the report for publication.
The outcome
- A fund-draining reentrancy path was caught and fixed before mainnet, along with the remaining findings.
- Every critical and high finding was remediated and confirmed clean on re-audit.
- The protocol launched with a publishable audit report that unlocked integrations and community confidence.
- It has run on mainnet since launch with no protocol-level exploit.
“The reentrancy finding alone would have ended the protocol on day one. They didn't just flag it — they proved it, we fixed it, and they re-checked. Fourteen months live with no incident is the number I actually care about.”