Audits

Five firms. Zero criticals.

Every Sudo contract is publicly audited by independent firms. Every finding — and every mitigation — is published.

5

Firms engaged

0

Critical findings

1

High finding (mitigated)

$1M

Bug bounty pool

Reports

Every audit, every finding, in public

FirmTargetDateFindings (C/H/M/L)StatusReport
Trail of BitsSudo Escrow v3Feb 12, 20260/0/2/4MitigatedPDF →
SpearbitValidator Selection (VRF + commit-reveal)Jan 28, 20260/1/3/5MitigatedPDF →
Code4renaSUDO Token + VestingDec 4, 20250/0/1/9MitigatedPDF →
OpenZeppelin.sudo Name RegistryNov 18, 20250/0/1/3MitigatedPDF →
HalbornSmart-group Indexer & Gating ContractsOct 2, 20250/0/0/6MitigatedPDF →

Continuous review

What we run between audits

Foundry & Echidna

Property-based fuzzing on every contract change in CI.

Slither + MythX

Static analysis blocks PRs that introduce known unsafe patterns.

Tenderly war room

Forked-mainnet simulations for every deployment, with on-call review.

Immunefi bounty

Always-on whitehat program with up to $250k for critical findings.

Public canary deploy

Every release runs on a low-stakes canary 7 days before mainnet rollout.

Open source first

Contracts and clients open-source on GitHub. Pull requests welcome.

Trust by verification

Don't trust. Read the reports.