We find the vulnerabilities before attackers do. Rigorous manual code review, economic attack modeling, and on-chain risk assessments for protocols across the EVM ecosystem.
Stolen in 2025
Incidents
YoY Increase
Services
From line-by-line manual code review to protocol-level risk intelligence — every layer of your security surface, covered.
In-depth manual review of your Solidity codebase. Every function traced, every attack vector mapped, every edge case tested.
Protocol-level risk assessments for projects, DAOs, and funds evaluating integrations. Research-grade reports delivered fast.
Ongoing security retainer for protocols that ship frequently. We review every update before it reaches mainnet.
Every line of unaudited code is a liability. Independent security review isn't optional — it's infrastructure.
Methodology
Every audit starts with automated tooling to catch known patterns. But the real value is a senior researcher reading every line, tracing every execution path, and thinking like an attacker.
Risk Intelligence
For projects, DAOs, and funds evaluating protocol integrations — we produce research-grade risk assessments covering the full attack surface.
Expertise
Lending, staking, vaults
Bridges, oracles, relayers
ERC-20, ERC-721, ERC-1155
DAOs, multisigs, timelocks
Proxies, diamonds, UUPS
Process
Submit your repo. We assess complexity, count nSLOC, and deliver a fixed-price quote within 24 hours.
Slither, Mythril, Echidna, and Foundry fuzz suites catch known vulnerability patterns.
A senior researcher traces every function, maps the state machine, and tests attack vectors.
Every finding classified by severity with clear explanations and recommended fixes.
After you implement fixes, we re-review every change to confirm correctness.
We accept ETH, USDC, and DAI. Crypto-native from day one.
The Landscape
Web3 exploits are accelerating. Every project deploying code needs an independent review.
Ecosystems
Security research across the EVM ecosystem and beyond.
Pricing
No hourly billing. No scope creep. Every audit is quoted upfront based on nSLOC, complexity, and external dependencies.
$3,000 – $5,000 · 2–3 days
$5,000 – $15,000 · 4–10 days
$10,000 – $20,000 · 2–3 weeks
On-chain risk intelligence reports start at $1,000–$3,000 per assessment. Get a custom quote →
About
Arx is Latin for fortress — the fortified citadel at the highest point of an ancient city, the last line of defense. We chose the name because it captures exactly what we do: we build the stronghold around your protocol's code so that when attackers probe for weakness, they find none.
Arx Inc. is a Virginia-incorporated Web3 security firm providing independent smart contract audits and on-chain risk intelligence to protocols, DAOs, and funds across the EVM ecosystem.
We were founded on a simple principle: every project that handles crypto value deserves an independent security review — not just the ones that can afford six-figure engagements.
Our researchers maintain active profiles on Code4rena and Sherlock, contribute to open-source security tooling, and publish technical research on vulnerability patterns and exploit post-mortems. Every finding in our portfolio is real. Every report is public.
All audit reports are published. Our track record is public and verifiable on competitive platforms.
We don't rush audits. Every engagement gets the time and attention required for thorough coverage.
Upfront quotes based on scope. No hourly rates, no surprise invoices, no scope creep.
We accept payment in ETH, USDC, and DAI. Built for the ecosystem we protect.
Submit your project details and we'll scope your audit within 24 hours. Fixed pricing, no commitment required.
Or reach us at audits@arxaudit.com