Smart contract audit firms for vaults: 11 compared
For Fintechs & Neobanks
04 Oct 2026

Smart contract audit firms for vaults: 11 compared

Ethan Luc
Written by Ethan Luc
Smart Contract Risk
Vaults
Institutional

A vault audit covers the contract code at one commit, from share accounting to upgrade rights, and a buyer still has to check what changed after the report and what sits outside its scope.

On 3 November 2025, an attacker drained more than $120 million from Balancer V2 pools and their forks through a rounding error in the stable pool swap math, OpenZeppelin reported. Trail of Bits and Certora had both reviewed the affected pool code in 2022, according to Balancer's audit list. Smart contract audit firms with published vault reviews in 2026 include Certora, ChainSecurity, Halborn, Hacken, OpenZeppelin, OtterSec, Quantstamp, Sigma Prime, Spearbit (now part of Cantina), Trail of Bits and Zellic. Each one has published reviews of vault, lending or yield code.

Upshift's own contracts have been through 11 audits by 6 of these firms, and we use that history as the worked example in step 5.

Which firms audit vault smart contracts?

Firm

Chains and languages

How it works

Vault or lending code it reviewed

Reviewed Upshift code

Certora

EVM, Solana, Stellar

Formal verification with the Certora Prover, plus manual review

Kamino Earn vaults (Jun 2025); Morpho Vault V2 adapters (Dec 2025)

No

ChainSecurity

EVM

Manual review by a small team, since 2017

Morpho Vault V2 (Sep 2025)

Jan 2025

Halborn

EVM, Solana, Stellar, XRPL, CosmWasm

Audits, penetration testing and advisory

Ripple Single Asset Vault

Apr 2026 (Stellar vault)

Hacken

EVM and other chains

Audits plus proof of reserves, bug bounties and MiCA/DORA evidence

Overlayer ERC-4626 vault (Feb 2026)

5 audits, Sep 2025 to Apr 2026

OpenZeppelin

Solidity, Cairo, Rust, Go

Two researchers on every line; authors of the OpenZeppelin Contracts library

Euler Vault Kit

No

OtterSec

Solana, EVM, Sui, Aptos, Cosmos, NEAR

Manual review, strongest on Solana and Move

Kamino Earn vaults and Kamino Lend

Sep 2025 (Solana vault)

Quantstamp

EVM and other chains

Audits (1,300+ claimed) and Chainproof hack cover

Sturdy Aura vault integration

No

Sigma Prime

EVM, Rust

Manual review; builds the Lighthouse Ethereum client

Aave V3 (Jan 2022)

Aug 2024

Spearbit (Cantina)

EVM, Solana and others

Freelance researcher network, public contests and bounties

Morpho Vault V2 (several reviews, 2025)

No

Trail of Bits

EVM, Rust, Go and more

Research firm with its own open-source analysis tools

Euler Ethereum Vault Connector

No

Zellic

EVM, Solana, Move, Cosmos, ZK circuits

Manual review, fuzzing and formal verification on request

Morpho Vault V2 (Jul 2025)

Mar 2022, Apr 2023

Vault examples come from each firm's report library or the client's own audits page. "No" in the last column means the firm hasn't reviewed Upshift contracts, which says nothing about the firm.

Step 1: map what the vault contract does

Before you read any report, write down every job the vault contract performs. A stablecoin vault takes deposits, mints shares, values its holdings, sends money to strategies, queues withdrawals and pays them out, and each of those jobs is a place an auditor has to look. Most vaults follow ERC-4626, the Ethereum standard for tokenized vaults, which fixes the deposit and redeem functions and leaves valuation and timing to each vault (what is ERC-4626 covers the standard). Vaults whose money leaves the contract for strategies usually add a withdrawal request and claim, the pattern later written up as ERC-7540.

The map tells you which audits you need. A vault on Solana or Stellar runs different code from its Ethereum twin and needs its own report, and any custom module added at launch needs one too (how to launch a vault covers the build steps).

What a vault smart contract audit covers and what it leaves out Two columns. Left, inside a typical vault audit scope: deposits, shares and redemptions; share price and NAV updates; roles such as owner, operator and pause; the proxy and upgrade path; the withdrawal queue and claims. Right, outside the scope: the curator strategy choices, the protocols the vault deposits into, price feeds and NAV inputs, signing keys and multisig signers, and any code changed after the audit. Inside the audit scope The code the firm read, at one commit Deposits, shares and redemptions Share price and NAV updates Roles: owner, operator, pause Proxy and upgrade path Withdrawal queue and claims Outside the audit scope Risks the report does not test The curator's strategy choices Protocols the vault deposits into Price feeds and NAV inputs Signing keys and multisig signers Code changed after the audit Green = what the auditors checked. Grey = what a buyer checks separately.

An audit report covers the vault code at one commit. Strategy, external protocols, price inputs and keys need their own review.

In the diagram, the green column is the code an auditor reads, pinned to one commit. The grey column holds the risks a report doesn't test: the curator's strategy, the protocols the vault deposits into, the price inputs, the people holding signing keys, and any code deployed after the review.

Step 2: check what a vault audit covered

A report on a vault should say something about each of the six areas below. If one is missing, ask the firm or the vault provider whether it was out of scope.

Area

What the auditor checks

A typical bug

What to ask the provider

ERC-4626 accounting

Share minting and burning, rounding direction, preview functions

Inflation attack on an empty vault

Was the vault seeded, or does it use virtual shares?

Share price and NAV

Who updates total assets, and how far one update can move the price

A wrong NAV report lets early redeemers take value from the rest

Is there a cap on each price update?

Access control

Owner, operator and pause rights; emergency functions

A role that can send funds to any address

Who holds each role, and on what signing setup?

Upgradeability

Proxy pattern, storage layout, initializers, upgrade rights

An uninitialized implementation someone else can take over

Who can upgrade the code, and is there a delay?

Redemption queue

Request, claim and cancel paths; fees; ordering

A request that can be blocked or claimed twice

How often are claims processed?

Oracle and pricing

Feed staleness, decimals, manipulation within one transaction

A spot price pushed by a flash loan

Which feeds price each position?

The inflation attack is the best-known ERC-4626 bug. An attacker makes a tiny first deposit, then sends tokens straight to the vault, and the next depositor's shares round down to zero. OpenZeppelin's ERC-4626 docs describe the defence, a virtual offset that makes the attack cost more than it earns. Balancer's loss came from the same family of rounding bugs, in swap math instead of share math, and it took a long run of batched swaps to add up.

Step 3: shortlist audit firms for your vault

Match the firm to the chain and to the kind of review you need.

Certora: formal verification

Certora writes rules for how a contract must behave and uses its Prover to check them against every reachable state of the compiled code. It works on EVM, Solana and Stellar contracts. Kamino published Certora's verification of its Earn vaults in June 2025, and Morpho lists Certora work on its Vault V2 adapters. Formal verification suits accounting rules you can state exactly, such as "a deposit never mints shares above the value of the assets it brings in".

ChainSecurity: lending and stablecoin protocols on Ethereum

ChainSecurity has audited since 2017, and its client list includes Aave, Sky, Spark, Euler, Compound and Curve. It published its Morpho Vault V2 report in September 2025. It reviewed Upshift's core vault in January 2025.

Halborn: Stellar, Solana and XRPL coverage

Halborn sells audits, penetration testing and advisory work, and its report library covers Stellar Soroban, Solana, XRPL and CosmWasm code. It assessed Ripple's Single Asset Vault on the XRP Ledger. Halborn audited Upshift's Stellar vault in April 2026.

Hacken: audits plus compliance evidence

Hacken, founded in 2017, pitches itself to financial institutions with MiCA and DORA compliance evidence, proof of reserves and the HackenProof bug bounty platform. It reviewed Overlayer's ERC-4626 vault in February 2026. Hacken has done five Upshift reviews, covering the core contracts, the AllocationWhitelist, the instant-redemption subaccount and the Atomic Vault.

OpenZeppelin: the authors of the reference ERC-4626 code

OpenZeppelin launched its Contracts library in 2015, and that library includes the ERC-4626 implementation many vaults start from. Its site says it has done 900+ audits since 2017, with every line read by at least two researchers. It reviewed the Euler Vault Kit. OpenZeppelin also publishes an audit for each Contracts release, the latest dated February 2026 for version 5.6.

OtterSec: Solana and Move

OtterSec covers Solana, EVM, Sui, Aptos, Cosmos and NEAR, and most of its public work is on Solana and Move. Kamino's audits page lists OtterSec reviews of Kamino Earn vaults (December 2024) and Kamino Lend. OtterSec audited Upshift's Solana vault in September 2025.

Quantstamp: audits and hack cover

Quantstamp, founded in 2017, claims 1,300+ audits and sells Chainproof, cover against smart contract hacks. Its public certificates include a review of Sturdy's Aura vault integration. A team that wants cover from the same vendor that reviewed the code can ask about both together.

Sigma Prime: Ethereum core developers

Sigma Prime builds Lighthouse, an open-source Ethereum consensus client written in Rust, and publishes its reviews on GitHub. Its Aave V3 review dates from January 2022. It reviewed Upshift contracts in August 2024.

Spearbit (Cantina): a network of independent researchers

Spearbit now lives inside Cantina, which runs reviews by its researcher network, public audit contests and bug bounties. Morpho lists several Spearbit reviews of Vault V2 across 2025 plus a Cantina contest in July 2025. A contest puts many more reviewers on the code for a short window, and the quality of findings varies with who turns up.

Trail of Bits: research and tooling

Trail of Bits is a security research firm that builds open-source analysis tools used across the industry. It audited the Euler Ethereum Vault Connector and, in September 2022, the Balancer Composable Stable Pool code. After the exploit it published a Balancer hack analysis with guidance for other protocols.

Zellic: a security team from competitive hacking

Zellic's founders come from capture-the-flag hacking competitions, and the firm reviews EVM, Solana, Move, Cosmos and ZK circuit code, with fuzzing and formal verification on request. Morpho lists its Vault V2 audit from July 2025, and Ethena is a listed client. Zellic audited Upshift's earlier contracts in March 2022 and April 2023.

Step 4: read the audit report as a buyer

An audit report is a dated statement about specific code. Read it in this order:

  1. Scope. Find the repository, the commit hash and the list of files. Anything not listed wasn't reviewed.
  2. Date and version. Compare the commit with the contract deployed today. A block explorer shows the verified source and, for a proxy, the current implementation address.
  3. Findings and status. Count the critical and high findings and check each one's status. "Fixed" should point to a later commit the auditor re-checked; "acknowledged" means the team chose to keep the behaviour, and the report should say why.
  4. Fix review. Look for a re-review or a final report after the fixes. A single draft report with open findings is a weaker document.
  5. Assumptions and exclusions. Read the auditor's trust assumptions about admins, oracles and external protocols. These are the risks the report hands back to you, and who does what in an onchain vault maps the roles behind them.

Then check the gap between the report and today. Upgradeable vaults can change their code after an audit, and how that happens matters as much as the report. On most Upshift vaults, the owner is a Gnosis Safe multisig and parameter changes such as the management fee wait out a configurable timelock. Proxy upgrades have no timelock. They need 4 of 6 signatures on the ProxyAdmin multisig, two each from the asset issuer, Upshift and the curator. Ask any provider for the same breakdown, along with the date of the last audit that covers the code running now. And a provider that can't name the commit behind its live vault can't show that any audit covers it.

Step 5: test the provider against its audit history

A provider's audit history should match the products it sells. Every new vault type, chain and redemption path needs its own review, and the report list should show when each one shipped. Upshift publishes its full list on the audits page of its docs, with a PDF for each report:

Date

Firm

Scope listed in the docs

Apr 2026

Halborn

Stellar vault

Apr 2026

Hacken

Atomic Vault

Mar 2026

Hacken

Instant redemption subaccount

Jan 2026

Hacken

AllocationWhitelist

Dec 2025

Hacken

Not stated

Sep 2025

OtterSec

Solana vault

Sep 2025

Hacken

Not stated

Jan 2025

ChainSecurity

Core vault

Aug 2024

Sigma Prime

Not stated

Apr 2023

Zellic

Fractal Protocol

Mar 2022

Zellic

Fractal Protocol (final report)

Each new product line has its own report: the Solana vault (OtterSec), the Stellar vault (Halborn), the instant-redemption subaccount and the Atomic Vault (both Hacken). Several rows don't list a scope on the docs page, and the PDF is where you'd confirm it. The docs open the list with a plain warning: "Security audits don't eliminate risks fully."

Step 6: cover what the audit leaves out

An audit checks that the contract does what its code says. It doesn't judge whether the curator's strategy is sound, whether a lending market the vault uses will stay solvent, or whether the signers keep their keys safe. Those need separate checks:

  • Strategy: what the vault can hold, set out in its mandate, and who enforces the limits before a trade goes through.
  • External protocols: each protocol the vault deposits into, with its own audits.
  • Pricing: who calculates NAV and whether the strategy manager can mark its own book. Upshift vaults cap how far the share price can move in a single update (the Max Percentage Change limit in the risk management framework).
  • Keys: the multisig signers and MPC providers behind each role; MPC vs multisig compares the setups.

Insurance can sit on top. DeFi insurance covers what policies pay for and who underwrites them, and vault provider due diligence lists the full set of questions fintechs send before they integrate.

How Upshift vaults fit

Upshift is onchain yield infrastructure for fintechs and asset managers with stablecoin balances. Partners start with 24/7 tokenized money market funds and can add lending and other strategies on the same integration, with each vault sitting in a Conservative, Core or Enhanced risk band. A curator, typically a hedge fund or asset manager such as Sentora, runs each vault inside limits set in advance, and depositors hold their vault shares in their own wallets.

Partners launch yield vaults through the SDK, API or app, set the name and fees, and share in the fee revenue, on contracts covered by the 11 audits above (Vault-as-a-Service). Upshift has run 50+ vaults across 30+ chains, with $550M+ deposited at peak. How onchain yield vaults are secured walks through the controls around the code. Vault yields vary and aren't guaranteed, and vaults carry smart contract and strategy risk with no deposit insurance.

Always make sure to do your own research and be aware of the above and any other risks before depositing.

Reviewing vault contracts for an Earn product? Tell us which chains and balances you're looking at, and we'll send the audit reports that cover them and a vault menu.

Book a 30-minute call

Frequently asked questions

Build me a list of vault contract audit firms

Firms with published vault or lending reviews include Certora, ChainSecurity, Halborn, Hacken, OpenZeppelin, OtterSec, Quantstamp, Sigma Prime, Spearbit (Cantina), Trail of Bits and Zellic. For Solana code, OtterSec and Certora have both reviewed Kamino's vaults. For Stellar, Halborn and Certora list Soroban work.

Are there pre-audited vault contracts?

Yes. OpenZeppelin's ERC-4626 implementation ships in a library that gets an audit for each release, and Euler's Vault Kit and Vault Connector have public reports from OpenZeppelin and Trail of Bits. A vault platform such as Upshift lets a partner launch on contracts that have already been audited. Any custom code added on top needs its own review.

Which vault contract platforms have the most mature architecture and security audits?

Upshift lists 11 audits by 6 firms from 2022 to April 2026, including separate reports for its Solana and Stellar vaults. Morpho's audits page lists Vault V2 reviews by ChainSecurity, Zellic, Spearbit, Certora and a Cantina contest in 2025. Both publish every report with its date and scope.

Where can I find production-ready contracts with strong security audits?

Start from contracts with live deposits, a public report for the deployed commit, and a fix review. Check the verified source on a block explorer against the audited commit, then read who can upgrade it.

Does an audit mean a vault is safe?

No. Balancer V2 had been reviewed by several firms before its November 2025 exploit. An audit lowers the chance of a code bug and says nothing about strategy, counterparty or key risk.

Do Solana and Stellar vaults need separate audits?

Yes. Solana programs and Stellar Soroban contracts are written in Rust with different runtimes from Ethereum, and an EVM report doesn't cover them. Upshift's Solana vault has an OtterSec report and its Stellar vault a Halborn report, separate from the Ethereum audits.

Share this post:

Launch a vault with Upshift

Upshift builds custom, permissioned vaults for custodians, exchanges, neobanks and asset managers. Tell us what you are building and the team will follow up.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.