Having a due diligence done by a competent firm is a must have for any project, and with the expertise of QuillAudits it will be done flawlessly. The due diligence process for DeFi is based on the comprehensive approach we follow to investigate the code for security flaws and potential vulnerabilities, and the best possible ways to mitigate them.
While interacting with DeFi protocols, users' and investors' funds are likely to be stolen. Due Diligence in a DeFi project is one of the crucial steps in analysing DeFi protocols before using them.
There is a steep rise in DeFi-related scams and cryptocurrencies being stolen; having a thorough analysis of the DeFi project can help avert them. Investigating a DeFi project by considering the movement of funds between address to address can save users and investors from fraudulent activities in the DeFi ecosystem that is vulnerable and should be approached cautiously.
QuillAudits acknowledges the significant threats linked to the DeFi ecosystem, which can lead to many critical possibilities.
We identify ways the system is susceptible to be gamed or abused, what parts are exposed to centralisation risks like the point of interaction with oracles, and what governance mechanisms are in place that could be a potential threat to the investor funds.
The complex nature of DeFi protocols is not surprising that there are errors in the code that can provide malicious parties with an attack vector through which hackers can steal funds. One such attack was on DeFi protocol SushiSwap which was exploited for between $10,000 and $15,000.
The risk posed as it is trivial for a malicious party to take control of the singular source of data and manipulate the market to their profit. Oracles are a possible source of systemic risk, and their data feeding role is prone to manipulation.
DeFi protocols are based on public blockchains. These blockchains typically have a native digital asset. The price-performance of the asset of the supporting blockchain is likely to affect the value of the holdings locked in a DeFi protocol. While this may lead to profit, it is also possible that there are losses.
Unfortunately, due to a combination of factors, such as a lack of understanding and the complexities in technology, some regulators and jurisdictions are not in favour of the DeFi space. Fortunately, this issue is likely to be alleviated with time.
Risk mechanisms that are, by default, incorporated into a protocol's design are referred to as intrinsic protocol risk. Even if the protocols function as they should, they pose significant dangers to investment plans. With DeFi due diligence, risks can be mitigated from centralised counterparties to programmable mechanics in a protocol.
Attacks such as oracle manipulations, flash loan exploits or attacks exploiting contract logic bugs are extrinsic risks associated with DeFi protocols. Thorough analysis helps in identifying whether a trustworthy firm audits the protocol you are dealing with or not.
DeFi protocols depend on the blockchain infrastructure on which they are built. Compromising parameters like consensus mechanisms on a specific blockchain can lead to vulnerabilities in DeFi projects on those platforms. We check for the dependency of these protocols on the underlying blockchains.
If the asset price significantly changes from when the liquidity was delivered to the pool, investors in non-stablecoin AMM pools may experience losses. We analyse the traditional market risk elements like volatility and price manipulations that can impact investors' funds.
You should be cautious if a white paper briefly summarises a protocol without detailed information on the working of the protocol. If a project fails to explain its mechanism, it should be considered a Red Flag.
It tells how to interact with the protocol; verifying the documentation's uniqueness is one way to spot potential scams, as a good project has its documentation written by the project team.
It's often not a good sign when team members only post about and hype up the token for their project. A successful project team concentrates on the result, which is the protocol itself rather than the token.
Approaching projects with a sizable portion of the token supply allocated to insiders and project team members should be done cautiously. Tokenomics helps to understand the economic condition of protocol.
Each year, millions drain down the crypto hacks. Here are a few examples how hackers took advantage of the loopholes in the code to escape with millions:
In March 2022, $615M were stolen from Ronin Network, a platform powering the popular mobile game Axie Infinity.
In August 2021, the criminals transferred $611M-worth of Poly Network tokens to three wallets they controlled.
In September 2020, $275m worth of cryptocurrency was stolen from the Singapore-headquartered exchange KuCoin.
Caption: Values calculated according to cryptocurrency prices at the time of the theft
Source: Statista/Bloomberg, Business Insider, TechCrunch, CNBC, Ronin Network, Vice.
I can absolutely recommend working with QuillAudits, great work together, high level of advising and reviewing!
You guys rock, and I really will stick with you guys. I will even look at the opportunity to go to other services that you are providing.
The whole experience was good, from the beginning to the delivery of the final certification certificate. Undoubtedly a professional job and with a focused attention to understand the project. 100% recommended.
On top of doing our security audit, the team identified ways to decentralize further the governance and management of our smart contracts.
Our experience with QuillAudits was pretty good. They helped us improve our protocols in many spectrums, security being one of them.
While researching similar companies, I came across QuillAudits and from the moment we first contacted, we were constantly supported and the process went smoothly.
The whole experience was far better than we expected. The reports given by quill team were outstanding and we do see quill as one of the top auditing companies currently. If things evolve in the same way as until now, we predict that quill has everything it needs to be the top company for auditing.
Quillhash team was very meticulous in planning our smart contract audit and they did a very good job identifying issues with our code and also provided us with a crystal clear understanding of the potential fix as well. The Audit report is comprehensive and have a pretty smooth flow as well.
QuillAudits helped us with the auditing of our smart contract and even helped us with amazing feedback! It was a good experience with them and hope to work again with them.
It was an awesome experience with QuillAudits, for sure. Everything was fast, smooth and perfect; I can't seem to see any loophole
I enjoyed working with QuillAudits because they were very responsive and patient with us. They followed up with us professionally and overall a positive experience with everyone.
It was quite a wonderful service and the customer experience was top-notch.
QuillAudits were very professional in executing the audit and providing valuable suggestions to V2SOFT. Their quick turnaround and style of audit is really commendable.
It was really awesome experience working with QuillAudits, best thing about QuillAudits is their expert team committed to provide their best service in stipulated time. The Best
Very satisfied. You were the ones who could start the audit much earlier than others.
The complete Audit process from beginning to delivery was Smooth.
The process was made quite simple by QuillAudits. The turnaround time was less which was favorable for us.
The team was very helpful at solving problems that they identified at reviewing our smart contract.
Pretty fast process and good reporting.
The auditing process was professional and on-time.
Very Knowledgeable, professionals, very smooth experience. Thank you for your professionalism.
All great, quick response, high efficiency, high responsible team.
Everything was top-notch. Its our first experience with audit agencies. Happy so far.
Very skilled people, kind. Overall very good experience with QuillAudits.
Amazing service and attention to detail!
Our overall experience with QuillAudits was exceptionally positive. Their smart contract audit services demonstrated expertise, thoroughness, and clear, timely communication, instilling confidence in the security of our smart contract. They not only met deadlines but also delivered results promptly. We highly recommend QuillAudits as a trusted partner for smart contract security.
QuillAudits provided security enhancements for Polygon projects, earning positive feedback for their prompt and high-quality service as an auditing partner.
All great, quick response, high efficiency, high responsible team.
Got a smart contract audit for 10 contracts, spetted and helped solving multiple bugs.
The service was extremely professional on time and budget. The staff are all well trained and know their tasks. Very satisfied.
It was just fantastic. Created a safe and secure contract audit.
We had a great experience working with QuillAudits! Communication was perfect and they delivered on time! Besides working closely with our devs they also took the time to explain their findings to our management who dont have the same level of deep understanding about smart contracts.
Very responsive, fast and detailed audits by QuillAudits.
They have been very helpful and cooperative with us, we cant thank them enough for giving us this opportunity :)
We have sent 6 smart contracts for auditing and experienced the quality auditing service from QuillAudits.
QuillAudits is always as expected fast, efficient, supportive.!
QuillAudits delivered the audit Fast with professional service.
QuillAudits services are Professional, timely, and cost-effective.
It was a Great experience getting our Audit done by QuillAudits.
You are kind, smart and communicative, it was a pleasure to work with you.
Guys are really fast and are hardworking to deliver the best experience.
Fast & Clean.
The whole audit process was done within a desirable time frame. The team demonstrated a high level of professionalism in dealing with us.
It was super smooth and the whole process with QuillAudits was beyond the expectations. As a start-up we guys are looking for something genuine & QuillAudits is way ahead of our expectations.
Initially when we talked with Audit company they said they will deliver it on so and so day but it was delayed by 3-4 days. Reason behind this was complexity of our contract [5000+] which took longer for them and they did it with complete responsibility. Their recommendation also helped us a lot in later stage so I would recommend if any of my friends looking for Audit.
Fast, professional, and always a quick response.
It was really smooth. Team at QuillAudits cooperated and helped us know the vulnerabilities in our smart code and also suggested possible ways to fix. Excellent support during the process.
QuillAudits is a professional and attentive auditing firm.
It felt like the auditing team was available within a short timeframe, which was excellent. The auditing process looked thorough, and I really appreciate the fact that you took time to investigate GAS optimizations. However, some issues found were a bit far-fetched and in were not about the security.
Service from QuillAudits was Smooth as silk.
Visit our FAQs help centre to clear out any doubts or queries you may have regarding us and our services. or reach out to us directly at Telegram.Explore FAQs
DeFi & NFT Hacks, CTFs, and Blockchain Security Insights Straight to your Inbox. Explore our weekly newsletter: HashingBits. Stay updated on everything we’re publishing. Stand a step ahead.