Frequently Asked Questions
What severity levels do you use?
Critical: direct fund loss or permanent contract breakage exploitable by any external actor. High: significant fund loss or protocol disruption under specific but realistic conditions. Medium: indirect fund loss, access control bypass or protocol degradation. Low: best-practice violations, gas inefficiencies or issues requiring insider access. Informational: code quality, documentation and architecture recommendations. We do not inflate findings — a report with 40 informational issues and no criticals is a good report.
How long does an audit take?
A typical DeFi protocol audit (2,000–5,000 lines of Solidity) takes 2–3 weeks for combined automated and manual review plus remediation cycle. Complex protocols with custom AMM mathematics, cross-chain components or upgradeable architecture take 4–6 weeks. Token contracts and simple staking contracts can be completed in 5–7 business days.
Do you provide a certificate or public report?
Yes to both. We deliver a full PDF audit report suitable for sharing with users, integrators and institutional partners. The report includes all findings, remediation status and a final assessment. We recommend publishing the full report — protocols that hide audit findings lose user trust when those findings are discovered independently.
What is the difference between your audit and a Code4rena contest?
Code4rena competitive audits provide broad coverage via many independent researchers but vary significantly in depth per researcher. They are effective at finding known vulnerability classes across a large codebase. PROPELOO audits provide consistent depth across all code paths, include economic model review that competitive auditors rarely do, and include a direct remediation cycle with the development team. For protocols handling significant TVL, both are complementary — not alternatives.
Can you audit Solana/Rust contracts?
Yes. Rust/Anchor program audits require a different toolchain (Trdelnik, Soteria, custom fuzzing) and different vulnerability classes — account validation errors, missing signer checks, arithmetic in checked vs unchecked contexts, and program-derived address misuse are Solana-specific. Our Solana audit process parallels our EVM process but uses the appropriate Rust security toolchain.
What should we prepare before an audit?
Final code freeze (no changes during audit), full test suite with coverage report, NatSpec documentation on all public and external functions, architecture documentation explaining the intended behaviour of each contract, list of any known issues or areas of concern, and any prior audit reports. Audits of undocumented code take significantly longer and produce more ambiguous findings.
How do you handle a critical finding?
Critical findings are communicated immediately via private channel — we do not wait for the final report. We provide a PoC that demonstrates the exploit, a specific remediation recommendation and an offer to review the fix within 24 hours of implementation. We do not publish critical findings until the fix is verified and the protocol team has had adequate time to respond.
Is one audit enough before mainnet?
One thorough audit from a reputable firm is the minimum for mainnet deployment. For protocols expecting significant TVL, two audits from different firms is the standard — different auditors have different mental models and catch different issues. For critical financial infrastructure (bridges, stablecoins, custody systems), formal verification of core invariants is recommended in addition to traditional audit.