A high-level article going over penetration testing in the Web3 space, and what protocol teams need to be aware of when securing their infrastructure.
Where Rust security actually breaks in 2026: unsafe contracts, FFI boundaries, async deadlocks, and supply chain gaps. Technical audit patterns with Miri, sanitizers, and fuzzing.
Smart contract audits in 2025 range from $8K to $300K+. Learn what drives pricing, how long audits take, and what those costs actually cover.
Ethereum Foundation’s Protocol Security Team partnered with Sherlock to run a 28-day, $2M audit contest as Fusaka’s final pre-mainnet stress test, drawing 510+ researchers and surfacing four high-severity issues that were fixed and verified before launch.
Perennial was helped by Sherlock through uncover hidden systemic risk in a complex DeFi derivatives protocol through broad adversarial review ahead of mainnet deployment.
Right now the process of choosing and recommending audit firms in the blockchain space is opaque. Sticking to the values of Web3, we want to demystify the selection process and introduce quantifiable metrics for audit effectiveness, thereby enhancing trust and reliability within the blockchain ecosystem.
At Sherlock, one of the top Lead Senior Watsons, recently uncovered and helped to resolve a vulnerability related to the lack of overflow protection in Solidity's inline assembly. Read on for the details behind the vulnerability that was detected, allowing the arbitrary call of functions from a vulnerable smart contract.