COMPILER SECURITY

Security audits for the compilers your contracts depend on

We’ve worked with a number of different compiler targets. We’re partnered with Vyper to audit their compiler, and we reviewed the Move compiler rewrite on behalf of Aptos.

120+ Projects audited$36.82B+ On-chain TVL secured66% Core-severity findings

WHY OTTERSEC

Compiler work across ecosystems

  • Partnered with Vyper to audit their compiler and develop differential fuzzing infrastructure.
  • Reviewed the Move compiler rewrite on behalf of Aptos.
  • Discovered vulnerabilities in Solana’s LLVM backend and solc.

WHAT WE BRING

Compilers, virtual machines, and the research behind them

Fuzzing is one of our core disciplines, and compilers are one of the platforms we audit.

Differential fuzzing for Vyper

Our fuzzing work includes differential compiler fuzzers for Vyper.

rBPF JIT fuzzers

Our rBPF JIT fuzzers resulted in multiple denial of service and integrity issues.

Move VM bytecode fuzzers

Our Move VM bytecode fuzzers resulted in over half a dozen crashes.

Compiler research

Our research covers a timeline and postmortem for the Vyper compiler bug, Solidity compiler memory safety, and how a 12-year-old g++ bug took down Solidity.

OUR AUDITING PROCESS

How an engagement begins

  1. 01

    Initial discussion

    We’ll discuss your goals, timeline, and security needs to see whether we’re a fit.

  2. 02

    Info gathering

    We’ll send an MNDA and look at repositories within scope to understand the details of your project and requests.

  3. 03

    Quote

    We’ll deliver a quote based on our expected duration, potential vulnerabilities, and the overall complexity of your project.

PROOF

Feedback from the Solana Foundation

“As a blockchain, speed, scalability, and security are critical to our everyday operations. OtterSec's responsiveness, attentiveness, and talent are second-to-none when it comes to securing Solana's core code.”
Dominic TsangSolana Foundation

GET STARTED

Have your compiler reviewed by a team that loves compilers

Tell us which compiler targets matter and where the highest-risk parts live. We will route the request to the right security team.

Get an audit