Tech trends · Web3 / blockchain

Smart-contract code-review

We do smart-contract code-review: we read the contract code, look for typical vulnerabilities, logic errors and dangerous patterns, and provide a report with recommendations. Honestly and bluntly upfront, this is key: this is professional code-review, NOT a formal security audit with a seal, insurance and legal liability. We find problems and reduce risk, but we CANNOT guarantee the absence of vulnerabilities — in smart-contracts a bug means irreversible loss or theft of funds, and no honest party gives an absolute guarantee in this field. For contracts with large sums at stake a separate certified audit by a specialized firm is needed. We honestly state this limit before starting.

Price
$18,000
Duration
usually 1–3 weeks (depends on contract size)

Smart-contract code-review — overview

Smart-contract code-review — price, timeline & scope

Smart-contract code-review is expert reading of the contract's source code (Solidity etc.) searching for vulnerabilities and errors: typical bug classes (reentrancy, overflows, incorrect access control, logic errors, unsafe external calls), deviations from best practices, dangerous patterns. The result is a report of found problems by severity with fix recommendations. Honestly about 'review, not a formal audit', this is critical and key: there is a fundamental difference between code-review and a formal security audit. A formal audit is a service of specialized audit firms: deep multi-stage analysis, often several auditors, formal methods, sometimes insurance coverage and a public report with the firm's seal/reputation at stake. Our code-review is a quality expert reading that catches typical and many non-trivial problems and noticeably reduces risk, but it is NOT a formal audit and does not replace one. We honestly distinguish this before starting rather than pass one off as the other. Honestly about 'no guarantee of no vulnerabilities': neither code-review nor even a formal audit gives a 100% security guarantee — hacks of audited contracts are known. We reduce the probability of problems but do not promise invulnerability. Anyone promising '100% safe' is lying. Honestly about irreversibility and the cost of error: in smart-contracts a bug is not 'we'll fix it next release': funds can be stolen or locked irreversibly, the contract is often immutable after deployment. So the cost of a missed error is extremely high, and for large sums our review may be insufficient. Honestly about the recommendation: if the contract will hold large user funds, we will honestly recommend additionally ordering a formal audit from a specialized firm — even if it means part of the work goes elsewhere. Honestly about the effect: we give professional reading, a vulnerability report and risk reduction, but not a security guarantee and not formal-audit status. Honestly about access: the contract source code is needed. An important boundary: this is code-review (not a formal audit with a seal); contract development/deployment — 1083; launchpad — 1073; NFT/DeFi — 1074/1076. The base price starts from 90,000 ₽ (depends on contract size and complexity).

Problems we solve

  • A smart-contract is written — expert reading before deployment is needed.
  • Fear of missing a vulnerability that leads to theft of funds.
  • An expectation that review = a formal audit with a guarantee (it is not).
  • The contract holds large sums — a single review may be insufficient.

What's included in the Smart-contract code-review service

  • Expert reading of the contract code (Solidity etc.)
  • Searching for typical vulnerabilities (reentrancy, access, overflows, external calls, logic)
  • A report of found problems with severity and recommendations
  • Checking for deviations from best practices
  • Honest boundaries (this is NOT a formal audit with a seal; no invulnerability guarantee; irreversibility; for large sums — a separate audit)
  • An honest recommendation to order a formal audit if sums are large
  • A report review with the team
  • Handover

What you get

  • A contract vulnerability report with severity and recommendations
  • Noticeably reduced risk of typical and many non-trivial bugs
  • An honest assessment: is a formal audit additionally needed
  • Honest boundaries (not a formal audit; not a security guarantee; the cost of error is irreversible)

How the work goes: steps

  • We receive the source code, discuss the contract's purpose and sums at stake
  • We do expert reading, record findings by severity
  • We give a report and honest boundaries; for large sums we recommend a formal audit

Why PDV Expert

  • Fixed price and timeline — no surprises on the invoice.
  • Report and recommendations in plain language — clear without a technical background.
  • In touch at every step and answering questions about the result.

FAQ

  • Is your review a security audit with a guarantee?

    No, honestly, and this is key: this is professional code-review, NOT a formal security audit with a seal, insurance and legal liability. A formal audit is a service of specialized firms (deep multi-stage analysis, sometimes insurance and a public report). Our review catches typical and many non-trivial problems and reduces risk, but does not replace a formal audit. We honestly distinguish this before starting rather than pass one off as the other.

  • After the review, is the contract definitely safe?

    It cannot be guaranteed, honestly: neither code-review nor even a formal audit gives a 100% guarantee — hacks of audited contracts are known. We reduce the probability of problems but do not promise invulnerability. In smart-contracts a bug = irreversible theft/loss of funds. Anyone promising '100% safe' is lying. We are honest about the limit: we reduce risk, we do not eliminate it entirely.

  • What if the contract will hold large user sums?

    We will honestly recommend more than our review: if the contract holds large funds, the cost of a missed error is extremely high (irreversible), and our code-review may be insufficient. We will honestly advise additionally ordering a formal audit from a specialized audit firm — even if part of the work goes elsewhere. Your users' safety matters more than our revenue.

About the provider

The «Smart-contract code-review» service is provided by PDV Expert — a team specialising in «Tech trends». We work under contract and deliver a written report with recommendations.

Prepared by PDV Expert · updated