How we rank smart contract auditors
Smart contract auditors work in the open: audits are published, and exploits of audited code are public events. That makes auditors one of the few verticals in crypto where outcomes can be measured — so we measure them. Auditors are ranked on two deliberately separate axes: evidence and verified peer review. Opinion never moves the evidence score; the two are shown side by side.
Axis one: evidence
The evidence axis (Audit Quality) combines two measures, equally weighted, both computed from public exploit data:
Failure Rate — of the distinct protocols an auditor has audited, the share later hit by a smart-contract exploit. The numerator counts distinct audited protocols hit by at least one incident classified as a smart-contract or protocol exploit — hacks that audits are meant to prevent; a protocol exploited twice counts once, so the rate can never exceed 100%. Exchange collapses, rug pulls, and phishing are excluded. The denominator is the count of unique protocols the auditor has audited — drawn from public audit registries and the auditor's own published portfolio, whichever is larger — so auditing the same protocol repeatedly neither helps nor hurts.
Severity — how large each exploit was relative to the value the protocol held: funds lost divided by the protocol's total value locked (for lending protocols, minus borrowed funds). Protocol value is taken from a snapshot roughly two weeks before the incident, so the measure reflects what was at risk — not the crash the exploit itself caused. A $1M loss means something different at a $2M protocol than at a $2B one; this metric says which. Where no reliable value data exists, we currently assume maximum severity rather than quietly flattering the number — conservatively against the auditor, and marked as assumed.
Axis two: verified peer review
Practicing industry professionals — the people who hire, work alongside, or build on top of these auditors — rate them on a 1–5 scale. Every reviewer's identity and relevance are verified before their review counts, almost always through their company email. Peer review is published as its own axis, next to the evidence axis, and is never blended into Audit Quality: measured outcomes and professional perception are different kinds of truth, and merging them would hide both.
How incidents get attributed to auditors
Linking an exploit to the auditor who audited that protocol is the hardest step, and we do it transparently. Attributions are made by matching the exploited protocol against public audit registries and auditors' published portfolios, and every attribution carries a recorded confidence tier — high for exact matches, lower for normalized or partial matches — plus the source of the match. Low-confidence attributions are excluded from every published rate and count; they are retained in the underlying data, flagged. Disputed attributions are flagged while under review, and corrections are applied with the change logged.
The data behind the numbers
- Exploit and incident data is aggregated from multiple public trackers, then normalized, merged, and deduplicated — with every merge and correction logged in an audit trail.
- Every score links to the incidents and audits behind it.
- Found an error? Tell us — the corrections policy applies to every number on the leaderboard.
These rankings follow the site-wide rules in our methodology: measure what can be verified, show provenance on every number, and never sell a ranking.