Code security & audit · since 2016

Independent audit for code you can't afford to trust blindly.

Smart contracts and DeFi applications since 2016. Now also code generated by Copilot, Cursor and other AI tools: we find the bugs, then rebuild it into production shape.

Write in Telegram · [email protected]

Services

Smart contract & DeFi audit

Full analysis of source code and logic: all known vulnerabilities, exit-scam patterns, gas and architecture improvements. Signed PDF report you can verify on-chain.

  • Terms: From 2 days, urgent audit possible
  • Result: Signed PDF report, vulnerability rating, fix recommendations, warranty
  • For: DeFi projects, tokens, contracts with complex logic

AI code audit & reconfiguration

We review code generated by Copilot, Cursor and similar tools for security bugs and architecture flaws, then refactor it into production shape. You get a report and a fixed repository.

  • Terms: 3–5 days or more, depends on project scale
  • Result: Findings report + refactored repo with pull requests
  • For: Teams shipping AI-assisted code to production, founders validating a vibe-coded MVP

AI writes code that compiles. We make sure it is safe to run.

Generated code tends to pass tests and fail in production: hardcoded secrets, missing authorization checks, duplicated logic, dependencies nobody chose. We audit the result the same way we audit a smart contract, then fix it.

  1. Scope & access. Repo access, stack, what the code is supposed to do. Fixed quote before we start.
  2. Security review. Injection, auth and session handling, secrets, data exposure, dependency risk, rate limits.
  3. Architecture review. Structure, duplication, error handling, performance paths, what will break at 10× load.
  4. Reconfiguration. We refactor and deliver pull requests plus a report. Every change explained, nothing rewritten for its own sake.

Why audit is needed

Even a minor flaw in contract logic can freeze a lot of money. Holes can also be introduced intentionally, to commit exit-scam.

The EVM allows very complex logic, and the more complex the logic, the higher the probability of error. Solidity is easy to learn, which attracts unskilled developers. An external audit identifies errors in the code, vulnerabilities, and checks the program logic.

For creators

A third-party audit identifies errors not caught during development and testing, and eliminates asset-freezing situations on the contract.

For investors

Is it safe to invest in a project, judging from the contract code itself? Are there accidental or intentional holes to freeze investors' funds?

For exchanges & payment services

A token code audit answers whether it is safe to list this token in your product.

For teams shipping AI code

Code you did not write line by line still carries your name. We check what the model skipped and fix it before your users find it.

Every report is signed with keys from 2016. It cannot be forged.

Our Bitcoin and Ethereum addresses date back to our first year on the market. All reports carry a digital signature from these addresses, so anyone can verify a report is ours. No exceptions.

  • Warranty on every full audit
  • Fixed lead time
  • Urgent audit possible
  • Clear analysis readable by non-developers

Check a report · Check bytecode revision

Published reports

All audits →

Additional services

Community for investors

Access to a closed community where each participant can submit a project for scam analysis and get a result in a short time. Ask the managers for details.

Project audit for opinion leaders

If you are a blogger or expert receiving requests to advertise dubious projects, we analyze the project and its source code to identify scam and fraud, and deliver a full report.

Frequently asked questions

How long does a smart contract audit take?

From 2 days for a typical contract; urgent audits are possible. An AI code audit with reconfiguration usually takes 3–5 days or more, depending on project scale. We state a fixed lead time in the quote before work starts.

How much does an audit cost?

The price depends on the size and complexity of the code, so there is no flat rate. Send a repository link or contract address via Telegram or email, and we reply with a fixed quote and lead time within one working day.

What do I get as a result?

For a smart contract audit: a signed PDF report with a vulnerability rating, fix recommendations and a warranty. For an AI code audit: a findings report plus a refactored repository delivered as pull requests, with every change explained.

How can I verify a report is really yours?

Every report is signed with the same Bitcoin and Ethereum keys we have used since 2016, no exceptions. Anyone can check the signature from the last page of a report on the verification page, and confirm the deployed contract matches the audited code on the bytecode check page.

What exactly do you check in AI-generated code?

Security first: injection, authorization and session handling, hardcoded secrets, data exposure, dependency risk, rate limits. Then architecture: structure, duplicated logic, error handling and performance paths. After the review we refactor the code into production shape.

Do you audit TRON contracts, or only Ethereum?

Both: we audit Solidity contracts on Ethereum and other EVM chains as well as TRON contracts — the published portfolio includes both ecosystems.

Contact

Fastest way is Telegram. https://t.me/telescrinbot

Or by email: [email protected]. Describe the project, send a repo or contract address, and we reply with a fixed quote and lead time.