All posts Use cases Services Contact
Login Get started

Before you ship on-chain

The audit you skipped is cheaper than the incident you are explaining. What actually has to be true before a contract holds real value.

A contract bug is the cheapest class of engineering defect to prevent and the most expensive to fix after mainnet. There is no rollback, no patch release, and no customer support queue that makes a drained pool acceptable. The checks below are the minimum, and none of them are optional.

1. It has been read by someone who did not write it

A second pair of eyes catches the class of bug the author is structurally unable to see, because the author has the mental model that produced the mistake. This is not about seniority. It is about not being the same person.

2. Invariants are written down as prose

If nobody can state in plain language what must always be true — total supply never increases, only the owner can pause, a withdrawn position cannot be double-claimed — then nobody can check whether the code does that.

Write the invariants first. Then read the code against them. Most contracts we audit have at least one rule that lived only in the author’s head, and that rule is where the drain was waiting.

3. The tests include the attack, not just the happy path

Normal-path tests pass on almost everything. What matters is the reentrancy attempt, the flash loan, the rounding edge, the role that was meant to be pausable. Our Solidity work starts at $499 and the security audit is separate on purpose, because the person who wrote the contract is the wrong person to certify it.

4. The deployment is rehearsed

Test the deployment itself on a fork and on testnet with real value movement. Constructor arguments, proxy patterns, ownership transfer, pause and unpause — every one of these is where a correct contract fails to deploy.

5. The chain-specific integration is reviewed

Oracle assumptions, bridge trust, token decimal mismatches. A 18-decimal token treated as 6 is not a smart contract bug; it is an integration bug that reads identically. AI-on-chain work — agents that read chain state and act on it — adds a third surface: the agent must not be able to act on a state it misread.

6. Someone can actually operate it

Ownership in a multisig, not an EOA nobody has tested a recovery from. Monitoring on real events. A written runbook for the three situations that will happen. On-chain guides from $899 cover this, and it is the deliverable clients most often did not know they needed.