Before every allocation
- owner() and proxy admins on every contract
- Multisig thresholds and signer counts
- Timelocks — present, and actually binding
Explorer tab by explorer tab.
Before you allocate, someone on your team hand-checks admin keys, multisig thresholds, and timelocks — for every protocol, on every chain. Forward that work to us. We audit the live deployment and hand you a verifiable report, with the cost carried by the protocol that wants your liquidity.
Explorer tab by explorer tab.
The work multiplies. Your team doesn't.
Allocation-time checks expire silently.
Protocols come to you asking for liquidity. Independent verification of their infrastructure is part of the cost of asking — so the protocol sponsors the audit, not you. You forward the protocol; we run a full Live Infrastructure Audit of its deployment; the report is in your hands before your capital moves.
The work is human-accountable and peer-reviewed: tooling finds candidates fast, but a human engineer owns every finding, and every Critical and High is independently peer-reviewed. You get verified facts — the allocation judgment stays yours.
If one key can reach what you deposit, you'll know.
If the multisig is softer than it looks, you'll know.
If they shipped on dangerous defaults, you'll know.
Not code bugs — compromised keys, weak multisigs, dangerous defaults.The losses landed on depositors and LPs.
Every one of these had a code audit. The people who supplied the liquidity learned about the 1-of-1 verifier and the phished signers after the money was gone. We check it before you allocate.
Every finding is pinned to exact addresses and live configuration anyone can re-derive. We read the chain — we don't take the protocol's word for anything.
Same three pillars, same severity ladder, every engagement. Sponsorship buys the audit — it doesn't buy a softer lens. Candidates stay comparable side by side.
Whatever we find, the party who forwarded the protocol sees the full report. Criticals are tracked to remediation or formal acceptance — never quietly dropped.
The posture you approved is a snapshot. Owners hand over, signers rotate, thresholds drop, integrations get rewired — usually without an announcement. Re-checks against the posture you approved are part of the conversation: set a cadence, or re-verify before you top up an allocation.
The protocol seeking liquidity sponsors the engagement. Independent verification of its live infrastructure is part of the cost of asking for capital — so the project pays, and the party forwarding it does not. LPs, curators, and risk teams can also scope engagements with us directly.
Yes — by construction. Findings are live on-chain facts pinned to exact addresses and configurations, reproducible by anyone with a block explorer. The methodology and severity ladder are fixed across all engagements, and the forwarding party receives the full report regardless of what we find. Sponsorship buys the audit, not the conclusions.
Typically 1–2 weeks for a curator-driven scope, depending on the number of chains, multisigs, and third-party integrations involved. Scope is agreed up front, so the timeline is known before the engagement starts.
Three pillars, read live from chain: every privileged role mapped per chain (EOA vs. multisig vs. timelock), multisig threshold and signer-trust analysis including signer overlap and social-engineering exposure, and third-party integrations — bridges, oracles, upgrade proxies — checked against hardened baselines instead of vendor defaults. Findings are severity-ranked with remediation status, delivered as a PDF and a permanent web URL.
That is diligence signal in itself: a team asking for your liquidity while declining independent verification of its own infrastructure. When it happens, talk to us — there are ways to structure the engagement directly.
Yes. A standing arrangement keeps methodology and reporting identical across everything you evaluate, so candidates stay comparable side by side. Contact us to set terms.
Protection
LZCheck surfaces ownership and DVN risks on-chain. Full Stabilytics coverage maps every social engineering vector and hidden single point of failure across your entire project.