Guardian Audit Package

The Guardian Standard

Guardian's comprehensive audit package is designed to bring new releases to production with assurance rated for billions in digital assets.

Synthetix
GMX
Ethena
PayPal
Jupiter
Yuga Labs
Arbitrum
USDT0
LayerZero
Protected across active clients $0 protected
Team A Guardian Team A
Sentry AI Tooling Human Judgement Directed Tokens
Team B Guardian Team B
Manual analysis Deep fuzzing Invariant Spec
Competitive incentives Performance rewarded
1 / Two-Team Model

Two independent teams, maximum security outcome.

One team pushes AI systems to their limits while another focuses on manual analysis and deep fuzzing.

Competitive incentives reward performance, and each team cross-checks the other so the final result is stronger than either workflow alone.

2 / Full Invariant Fuzzing

Exhaustive Invariant Suite.

Guardian builds an exhaustive invariant suite around the protocol's core safety properties, then uses it to continuously pressure-test every reachable state.

The suite becomes a reusable security harness for fixes, retesting, and future changes to the codebase.

Accounting Rounding Solvency Math formulas Edge states Regression guard
3 / Full Guardian Audit

World-renowned security researchers battle-test your system.

Guardian researchers attack the protocol manually and make the system as air-tight as possible before it faces the public.

Guardian Audits
Contest-proven researchers Private audit depth backed by public competitive security experience.
Contest Researcher Medal Payout
RaftMay 18, 2023
CuriousApple1st 馃$8,000.00
VMEX ProtocolJune 19, 2023
CuriousApple1st 馃$13,700.00
Chainlink Cross-ChainJuly 5, 2023
Osman2nd 馃$6,106.70
DittoSeptember 7, 2023
Cosine2nd 馃$9,197.42
WildcatFiNovember 20, 2023
0xCiphky1st 馃$13,133.89
ZeroLendJanuary 8, 2024
Osman2nd 馃$11,830.31
ZeroLendJanuary 8, 2024
Wafflemakr3rd 馃$6,462.70
JOJO ExchangeJanuary 12, 2024
Nicholas Chew3rd 馃$841.79
OpalFebruary 12, 2024
Nicholas Chew2nd 馃$5,155.61
TelcoinMarch 4, 2024
Zdravko1st 馃$3,070.99
MentoMarch 15, 2024
Kose1st 馃$3,571.42
Fairside NetworkApril 18, 2024
Nicholas Chew2nd 馃$8,333.28
Optimism Safe ExtensionsMay 6, 2024
Zdravko1st 馃$9,549.86
xKeeperMay 16, 2024
Kose1st 馃$7,172.16
SophonMay 20, 2024
Zdravko1st 馃$1,329.90
Yolo GamesMay 27, 2024
R0bert2nd 馃$3,477.28
Karak RestakingSeptember 26, 2024
0xCiphky1st 馃$3,077.89
Fuel AttackathonNovember 6, 2024
MinatoNamikazi3rd 馃$156,085.00
Silo FinanceJanuary 13, 2025
Cosine2nd 馃$15,654.32
Reserve ProtocolJanuary 13, 2025
CuriousApple1st 馃$5,688.95
RovaFebruary 14, 2025
Zdravko2nd 馃$1,178.25
Uniswap UnistakerFebruary 23, 2025
Osman3rd 馃$5,987.35
Starknet PerpetualsMarch 19, 2025
Nicholas Chew2nd 馃$26,332.70
Liquity V2March 20, 2025
Cosine1st 馃$36,712.62
4 / Public Defender Contest

Guardian stakes $100,000 in a Defender contest.

We sponsor a $100,000 public contest after the audit, putting our own funds behind the quality of the review and inviting the broader security community and all AI agents to challenge it.

$100,000
Public Defender Contest
Critical vulnerability protection Security Researchers Guardian funded Frontier AI Agents
Hosted & managed bounty
$50,000 in Critical bounty matching
5 / Bug Bounty

Hosted bounty with $50,000 in matching.

Guardian hosts and manages the bug bounty, with $50,000 in Critical bounty matching.

Bonus / Continued Review

Six months of update review for the same codebase.

Continued review of any updates the team makes to the same scope within six months after production, up to 2,500 SLOC.

Production Month 1 Month 3 Month 6
2,500 SLOC update window
Bonus / Web2 Security Credits

Half the package cost back toward offchain risk.

Get half of the package cost back in credits toward the offchain security services below. Select a service to see what the assessment covers.

01 OpSec Audit People, keys, and operational workflows Access controls Keys & secrets Developer hygiene SaaS admin security Notable incident Drift Protocol 路 $285M stolen

A systematic review of the operational controls protecting your team and production environment. We trace access, key and secret handling, developer devices, deployment workflows, internal communications, and SaaS or social admin accounts to uncover paths to unauthorized action or credential theft.

02 Infrastructure Pentest Cloud, SaaS, CI/CD, and access paths AWS GCP Azure Kubernetes Terraform Docker Notable incident Mixin Network 路 $200M stolen

Examines cloud and SaaS environments鈥攆rom AWS, GCP, and Azure to source control, CI/CD, infrastructure as code, Kubernetes, and edge platforms鈥攆or exploitable misconfigurations. We review IAM, network controls, logging, data protection, exposed assets, and insecure integrations that could lead to privilege escalation or compromise.

03 WebApp Pentest Frontend, authentication, and user flows App flow mapping Auth & sessions Roles & access Business logic Notable incident Crypto.com 路 $34M stolen

Maps the application end to end, then tests how the frontend and backend enforce authentication, roles, sessions, sensitive actions, and business logic. Manual manipulation and fuzzing target access-control bypasses, insecure inputs, workflow abuse, and client or server weaknesses.

04 API Pentest Endpoints, authorization, and data flows REST, GraphQL & gRPC Auth & authorization Input & data Endpoint logic Notable incident 3Commas 路 $22M stolen

Tests REST, GraphQL, gRPC, and other APIs across authentication, authorization, rate limits, input validation, data exposure, and endpoint logic. Real-world attack paths include token abuse, parameter tampering, mass assignment, injection, and multi-step transaction flaws.

05 Keeper/Offchain Automation Pentest Bots, relayers, signers, and scheduled jobs State transitions Key flows Failure & retries Chain interactions Notable incident THORChain 路 $10M stolen

Reviews the autonomous systems that influence onchain behavior鈥攊ncluding schedulers, bots, relayers, oracle updaters, sequencers, and risk engines. We test decision logic, data pipelines, key flows, retries, trust assumptions, race conditions, replay resistance, and unsafe state transitions.

06 Perimeter Security Audit Internet-facing assets and perimeter controls Recon & inventory Ports & exposure CVEs & exploitation WAF & TLS Notable incident CoW Swap 路 $1.2M stolen

Maps the public attack surface through reconnaissance, DNS and subdomain discovery, service enumeration, port and TLS analysis, and vulnerability scanning. Findings are manually validated through safe exploitation, with WAF and Cloudflare controls reviewed and exposed assets inventoried.

Close

Not just an audit,
a launch partner.

Before audit

Independent AI and manual tracks pressure-test the highest-risk surfaces.

During audit

Cross-checking compounds automated depth with expert judgment.

After audit

Public contest, hosted bounty, update review, and Web2 credits extend protection.

Pricing

View Audit Pricing.

Compare the Guardian Max and Guardian Basic.

View Audit Pricing