Protocol due diligence,
delegated.

Before you allocate, someone on your team hand-checks admin keys, multisig thresholds, and timelocks — for every protocol, on every chain. Forward that work to us. We audit the live deployment and hand you a verifiable report, with the cost carried by the protocol that wants your liquidity.

ForLPs, vault curators, risk teams, treasuries
OutputFull Live Infrastructure Audit report
Turnaround1–2 weeks, typical scope
Your costNone — the protocol sponsors it
01 / The Manual Work

You're already doing this audit — by hand.

Before every allocation

  • owner() and proxy admins on every contract
  • Multisig thresholds and signer counts
  • Timelocks — present, and actually binding

Explorer tab by explorer tab.

Across every chain

  • The same checks, redone per deployment
  • Cross-chain parity nobody guarantees
  • New deployments shipping faster than you re-verify

The work multiplies. Your team doesn't.

Again, after you allocate

  • Owners change. Signers rotate. Thresholds drop.
  • Upgrades land without announcements
  • Your diligence was true the day you ran it

Allocation-time checks expire silently.

02 / The Model

Forward it. They cover it.

Protocols come to you asking for liquidity. Independent verification of their infrastructure is part of the cost of asking — so the protocol sponsors the audit, not you. You forward the protocol; we run a full Live Infrastructure Audit of its deployment; the report is in your hands before your capital moves.

The work is human-accountable and peer-reviewed: tooling finds candidates fast, but a human engineer owns every finding, and every Critical and High is independently peer-reviewed. You get verified facts — the allocation judgment stays yours.

03 / How It Works

Four steps.

01ForwardA name and a chain is enough
02SponsorThe protocol carries the cost
03AuditRoles, signers, integrations — 1–2 weeks
04DecideFull report before you allocate
04 / Coverage

What we verify — three pillars.

Roles & Power Distribution

  • Every owner, admin, upgrader, and pauser — mapped per chain
  • EOAs vs. multisigs vs. timelocks, verified on-chain
  • Concentration risk scored per role

If one key can reach what you deposit, you'll know.

Signer Trust Analysis

  • Real thresholds vs. paper thresholds
  • Signer overlap across orgs and chains
  • Phishing, deepfake, and bribery vectors

If the multisig is softer than it looks, you'll know.

Integration Verification

  • Bridges, oracles, DeFi dependencies — checked
  • Vendor defaults vs. hardened configs
  • Upstream supply-chain exposure

If they shipped on dangerous defaults, you'll know.

05 / The Stakes

Where the losses actually land.

$3.31BStolen on-chain · last year

Not code bugs — compromised keys, weak multisigs, dangerous defaults.The losses landed on depositors and LPs.

$290MKelp DAO · LayerZero1-of-1 DVN default. One compromised verifier.3rd-party setup
$285MDrift Protocol2-of-5 multisig, no timelock. Signers phished for 6 months.Social engineering
$25MResolv LabsSingle EOA mint authority on USR. Supply-chain breach.Single point of failure
1B DOTHyperbridgeBounds check missed by audit. Bridge admin seized.Ownership posture

Every one of these had a code audit. The people who supplied the liquidity learned about the 1-of-1 verifier and the phished signers after the money was gone. We check it before you allocate.

06 / Independence

Sponsored by them. Built for you.

Findings are on-chain facts

Every finding is pinned to exact addresses and live configuration anyone can re-derive. We read the chain — we don't take the protocol's word for anything.

Fixed methodology, comparable reports

Same three pillars, same severity ladder, every engagement. Sponsorship buys the audit — it doesn't buy a softer lens. Candidates stay comparable side by side.

The report reaches you regardless

Whatever we find, the party who forwarded the protocol sees the full report. Criticals are tracked to remediation or formal acceptance — never quietly dropped.

07 / After Allocation

Configs drift. Diligence shouldn't expire.

The posture you approved is a snapshot. Owners hand over, signers rotate, thresholds drop, integrations get rewired — usually without an announcement. Re-checks against the posture you approved are part of the conversation: set a cadence, or re-verify before you top up an allocation.

08 / FAQ

Forwarded audits — common questions.

Who pays for a curator-forwarded audit?

The protocol seeking liquidity sponsors the engagement. Independent verification of its live infrastructure is part of the cost of asking for capital — so the project pays, and the party forwarding it does not. LPs, curators, and risk teams can also scope engagements with us directly.

Is the report independent if the protocol pays for it?

Yes — by construction. Findings are live on-chain facts pinned to exact addresses and configurations, reproducible by anyone with a block explorer. The methodology and severity ladder are fixed across all engagements, and the forwarding party receives the full report regardless of what we find. Sponsorship buys the audit, not the conclusions.

How long does a forwarded audit take?

Typically 1–2 weeks for a curator-driven scope, depending on the number of chains, multisigs, and third-party integrations involved. Scope is agreed up front, so the timeline is known before the engagement starts.

What does the report cover?

Three pillars, read live from chain: every privileged role mapped per chain (EOA vs. multisig vs. timelock), multisig threshold and signer-trust analysis including signer overlap and social-engineering exposure, and third-party integrations — bridges, oracles, upgrade proxies — checked against hardened baselines instead of vendor defaults. Findings are severity-ranked with remediation status, delivered as a PDF and a permanent web URL.

What if the protocol refuses to sponsor an audit?

That is diligence signal in itself: a team asking for your liquidity while declining independent verification of its own infrastructure. When it happens, talk to us — there are ways to structure the engagement directly.

Can we forward protocols on a standing basis?

Yes. A standing arrangement keeps methodology and reporting identical across everything you evaluate, so candidates stay comparable side by side. Contact us to set terms.

Protection

Find every weak link before they do.

LZCheck surfaces ownership and DVN risks on-chain. Full Stabilytics coverage maps every social engineering vector and hidden single point of failure across your entire project.