defirisk.co
rubric v1.7.0

Audit firm tier

A code & audits factor in the v1.7.0 rubric. Measured per protocol on a s cadence.

Methodology how we score#

What this measures
This factor records the categorical tier assigned to the audit firms that have reviewed the protocol's deployed code. Tier classifications are maintained by curators on a published reputation list and are based on firm track record, auditor count, methodology rigor, and industry recognition. The categories are: Tier-1 (Trail of Bits, OpenZeppelin, Spearbit, ChainSecurity, Sigma Prime), Tier-2 (Halborn, Peckshield, Certik, Dedaub, MixBytes, others with established track records), boutique (smaller or newer firms), and unknown (no assessable reputation).

Why it matters
Audit firm quality affects the probability that a given bug survives review. KyberSwap Elastic ($48M, 2023) was reviewed by ChainSecurity (Tier-1) and Sherlock -- yet the sub-microscopic precision failure was missed by both, illustrating that tier alone does not guarantee coverage of novel vulnerability classes. Conversely, protocols audited only by unknown boutique firms or self-reported internal reviewers have a weaker baseline assurance. Audit firm tier is a soft signal that is most useful in combination with other Cat 1 factors -- particularly audit scope coverage and post-audit code change status.

Green / Yellow / Red
Green: at least one Tier-1 firm has reviewed the currently deployed code. Yellow: all audits are from Tier-2 or boutique firms with established track records but no Tier-1 involvement. Red: all audits are from unknown-reputation firms, or the only audits are self-reported internal reviews with no independent third-party verification.

Common gray cases
Curators cannot grade this factor when audit firm identity is not disclosed, or when the curator-maintained reputation list has not yet classified a newly active firm. This factor is also gray when no audit exists (in which case RD-F-004 captures the absence).

Notable historical examples
No hacks are currently linked in the database for this specific factor as a causal driver; audit firm tier is a soft input rather than a single-factor sufficient condition for exploit. The factor's value is as a quality modifier on the audit count signal.

Measurement what to look for#

Classify each auditing firm into: Tier-1 (Trail of Bits / OpenZeppelin / ConsenSys Diligence / Certora / Sigma Prime / Spearbit / Zellic) / Tier-2 (established, named firm with public track record) / boutique / unknown.

Data & output #

Data source
Curator-maintained firm-tier registry (updated monthly) + audit PDF firm letterhead
Output format
Green / Yellow / Red
Evidence artifact
Curator-maintained registry version slug + firm name → tier mapping JSON + audit PDF URL
Confidence signal
green = at least one Tier-1 audit of deployed code; yellow = Tier-2 only; red = boutique/unknown only; gray = no firm identifiable

Scored protocols 0 carry this factor#

No protocols have been scored for this factor yet.

Linked hacks no historical incidents linked#

No historical incidents are linked to this factor.
rubric_version v1.7.0factor RD-F-005category 1carried 0critical no