FUZZING

Security audits from a team that builds its own fuzzers

Fuzzing is one of our core disciplines. Our work includes differential compiler fuzzers for Vyper, novel differential transactional fuzzers for Solana validators, rBPF JIT fuzzers, and Move VM bytecode fuzzers.

$36.82B+ On-chain TVL secured120+ Projects audited$1.00B+ Vulnerabilities patched

OUR AUDITING PROCESS

From scoping call to final report

  • 01

    Initial discussion

    We discuss your goals, timeline, and security needs to see whether we’re a fit.

  • 02

    Kickoff

    We begin the audit, share findings as they emerge, and ask questions as needed.

  • 03

    Report delivery

    At completion, we send you a report with our findings and suggestions for fixes.

QUESTIONS

Frequently asked questions

Does OtterSec fuzz every codebase it audits?

We pick the mix that fits yours: pentesting, formal verification, and fuzzing, which is one of our core disciplines.

WHERE FUZZING FITS

One technique in the mix we pick for your system

Different systems call for different techniques. We pick the mix that fits yours, from fuzzing and formal verification to white-box and black-box pentesting.

Compiler fuzzing with Vyper

We’re partnered with Vyper to audit their compiler and develop differential fuzzing infrastructure.

Validator and VM fuzzers

Our fuzzing work spans Solana validators, the rBPF JIT, and Move VM bytecode.

Formal verification

We’ve built our own tooling, developed a novel verification framework for Solana, and worked with the Aptos core team to formally verify their standard library.

Where the tools stop

Our talk “Fuzzing, Formal Methods, and a Loss of Funds” covers why fuzzing and formal verification miss business logic exploits, and the mitigations that catch them.

GET AN AUDIT

Get an audit from the team that builds its own fuzzers

We work with leading teams across multiple blockchains. Put the same collaborative approach to work on your protocol.

Get an audit