Security data web3 can build on.

One open record per project: who reviewed the code, what they found, what is still open. For every wallet, explorer and team that needs it.

Looking for an audit firm? See the audit firms, A to Z

Recently audited projects

How to read a record

Audits
The audit reports we hold for the project, who wrote them, and the date of the latest.
No open critical findings
Every critical finding in those reports is marked fixed, or the reports list none.
1 open critical finding
A report lists a critical finding that it does not mark as fixed. The line names the report and its date.
2 criticals acknowledged, not fixed
The project team told the firm it knows about the finding and chose not to change the code.
Incident Mar 2024
An incident on record for the project, with its date, its source, and the audits published since. The line shows only when we hold one.
No audit on Trustblock
We hold no report for the project. It says nothing about audits published elsewhere.

Every status is the audit firm’s own word, taken from its report. A record is not a rating of the project, of a firm, or of the code as it runs today. Incidents are on record up to Sep 2026.

The same record, on contract pages

Block explorers show its first lines as a card on a contract’s page. The card links back to the project’s record here.

What do you need?

Project teams

Check your record and get a free label

What is on record for your project, how to correct it, and a label for your site that links to it. No account needed.

Find your project
Audit firms

Check your page

The projects you reviewed, with your reports, dates and statuses as we hold them. Tell us what to correct, or publish from your own account.

Find your firm
Developers, wallets, explorers

Use the record

One request by chain and address returns the project’s card. Try it first in the Playground, then create an account for a key.

Open the API docs
Trustblock: public smart contract audits, as data