Smiling Treasure Chest
Start Proof of Audits NowOpen audit proof flow

Know What You Are Signing Before You Sign It

Crypto losses keep showing the same trust gap: a protocol can have audits, dashboards, multisigs, or public claims, while users still cannot see whether the live contract, upgrade path, authority keys, and unresolved findings match the evidence they are relying on.

System Loading
Category
Proof-Based
Interface
Extension Signal
Deployment
Bytecode Match
Engine
Cascading Audits

The problem is not that teams never audit. The problem is that trust evidence goes stale, missing, or invisible before users sign.

Real crypto losses go far beyond direct theft. They trigger cascading downstream collateral contagion, frozen withdrawals, emergency governance, liquidity shocks, reputational ruin, and weeks of team time lost to incident-response panic.

2026 DeFi exploits$942M+

Q2 2026 became the most active exploit period on record.

By late June 2026, DeFi platforms suffered over 120 exploits totaling $942M, with attack vectors shifting from simple contract bugs to governance manipulation, oracle attacks, and social engineering.

June 2026 DeFi Security Report
Drift Key Exploit$285M

Compromised admin keys bypass static audits.

On April 1, 2026, Drift Protocol suffered a $285M loss. Attackers spent months gaining the team's social trust to compromise admin keys and manipulate prices, highlighting that stale audit PDF records fail to prove live authority safety.

Drift Exploit Investigation, April 2026
KelpDAO bridge exploit$292M

Single-point bridge flaws trigger systemic contagion.

On April 18, 2026, KelpDAO lost $292M via a single-verifier bridge logic flaw. The stolen assets were collateralized on Aave, triggering cascading liquidity crunches and panic withdrawals across the ecosystem.

KelpDAO-Aave Post-Mortem, April 2026
The Problem
$3.4B

stolen in 2025 alone — most from protocols with existing audits

Audited code ≠ deployed code. Proxy upgrades, redeployments, and implementation swaps make audit reports stale the moment code changes — and ~70% of major exploits hit protocols that already had audit reports.

AUDITED DOES NOT ALWAYS MEAN LIVE CODE MATCHED

An Audit Only Matters
If the Live Code Still Matches

A protocol can show a real audit and still run different code today. Proxy upgrades, new implementations, redeployments, and post-audit edits can separate the report from the contract users actually touch.

Proof of Audits checks the deployed bytecode, implementation address, audited commit, and upgrade history before treating the audit as current evidence.

Exact reviewed commit identified

Traces the audit to a specific commit in the repository.

Live bytecode & implementation checked

Compares deployed bytecode and implementation with the audited source.

Upgrade history verified

Reviews proxy status and upgrade events to confirm no unreviewed changes.

If the live code does not match the audited code, old audit reports may no longer be relevant.

Select protocol to verify proof:

Current-Code Match

Verify Engine v2.4

Matched

The live deployed code matches the audited commit.

This audit is currently valid for the live protocol.

Audited CommitThe exact commit that was audited
0xdc86a10
VERIFIED
Live ImplementationCurrent implementation contract
0x8787...Ca6
VERIFIED
Proxy StatusIs the protocol upgradeable?
Upgradeable (Proxy)
VERIFIED
Last UpgradeWhen the implementation was last updated
June 12, 2026 • 14:32 UTC
REVIEWED
Upgrade ReviewWere upgrade changes reviewed?
Reviewed by VeerSec
VERIFIED

You are interacting with the exact code that was audited. No unreviewed implementation changes detected.

Audited SourceCode reviewed at commit
Deployed ImplementationCode deployed on-chain
Verification EngineBytecode & logic comparison
Match ConfirmedAudit is valid for live code
$1.5B

Bybit (Feb 2025) — attackers compromised a third-party wallet interface to drain the largest single theft in crypto history

The Problem

Admin keys can override audited code at any time. Access control and key compromises account for 58–70% of all stolen crypto — more than smart contract bugs, flash loans, and rug pulls combined.

ADMIN KEYS CAN CHANGE TRUST AFTER THE AUDIT

The Audit Checks the Code.
This Checks Who Controls It.

Crypto losses keep showing the same trust gap: a protocol can have audits, dashboards, multisigs, or public claims, while users still cannot see whether the live contract, upgrade path, authority keys, and unresolved findings match the evidence they are relying on.

Live-code match answers one question: is this the reviewed code? It does not answer who can change the rules after deposits. Upgrade admins, pause guardians, oracle controllers, treasury roles, and multisig signers can still affect funds, withdrawals, pricing, and protocol behavior.

Proof of Audits maps critical control roles, verifies key-holder proof, tracks multisig thresholds, and marks stale or missing authority evidence before trust is shown. This inverses the security dynamic by verifying how much key-holders know of the key value and how to protect it.

Upgrade, pause, oracle, and treasury powers mapped

Upgrade, pause, oracle, treasury, and guardian powers identified.

Multisig thresholds and signer roles verified

Multisig threshold, signer count, and approval logic clearly shown.

Missing or stale key-holder proof clearly flagged

Missing, stale, or unverified authority evidence is clearly flagged.

If an upgrade admin, pause role, or oracle controller is unverified, stale, or controlled by a single EOA, Proof of Audits flags it before investors rely on the protocol.

Authority Control Map

Verify Engine v2.4

VERIFIED WITH WARNINGS
UPGRADE CONTROL3 / 5 Multisig
PAUSE RIGHTSGuardian Council
ORACLE ADMIN2 / 3 Multisig
TREASURY CONTROLDAO Timelock
RoleHolderControl ModelStatus
Upgrade Admin3 / 5 multisigMultisigVERIFIED
Pause GuardianGuardian CouncilMulti-sig CouncilVERIFIED
Oracle Admin2 / 3 multisigMultisigMONITORED
Treasury ControlDAO TimelockTimelockVERIFIED
Emergency RoleLimited scopeSingle WalletVERIFIED

Transparent authority mapping reduces hidden control risk.

Role DetectedCritical role identified on-chain
Protocol ConfirmedTeam confirms role & control source
Proof SubmittedKey-holder proof & evidence uploaded
Reviewer VerifiedReviewer validates and marks status here — audio or video bytes posted online
The Problem
$235MWazirX (Jul 2024) — withdrawal freeze hit users hours after the multisig exploit, locking remaining funds

Users deposit easily but cannot verify if they can exit. Lockups, cooldowns, pause controls, freeze rules, and emergency modes can trap funds after risk materializes — and users only discover this when it is too late.

CertiK Security Report 2024
THE REAL TEST: CAN USERS GET OUT?

Deposits Are Easy.
Exits Reveal the Real Risk.

A deposit button can look safe while the exit path is constrained. Lockups, cooldowns, withdrawal queues, pause controls, freeze rules, upgrade delays, and emergency modes decide whether users can leave before risk becomes loss.

Proof of Audits maps exit paths, withdrawal timing, pause/freeze behavior, upgrade notice windows, and emergency controls so users see the real exit conditions before relying on a protocol.

Withdrawal paths mapped

Cooldowns, queues, and lockups clearly shown.

Exit blockers checked

Pause, freeze, and emergency controls reviewed.

User notice visible

Upgrade delay and exit window shown before trust is given.

If users cannot exit before an upgrade, freeze, or emergency change, Proof of Audits flags the exit risk before users deposit.

Exit Rights Check

Withdrawal timing, pause rules, and upgrade notice

EXIT PATH VERIFIED
Investor Exit Scenario
Position10,000 USDC
ActionWithdraw
Withdrawal Delay
7 days
Cooldown
Required
Exit Fee
0.20%
Pause Can Block Exit
No
Upgrade Notice
48 hours
Emergency Freeze
Limited scope
DepositFunds deposited
Cooldown7 days
Request ExitWithdraw requested
QueueIn withdrawal queue
Funds ReceivedFunds in wallet

Exit Status

Withdrawals available with 7-day queue.

Exit conditions are shown before trust is displayed.
84%of hacked tokens fail to recover their price within 6 months — users cannot trace which function failed
The Problem

A badge covers the whole contract, but users interact with one function at a time. There is no way to know if deposit() was reviewed but withdraw() was not — and 84% of hacked tokens never recover their pre-hack price.

Immunefi Ecosystem Report 2025
A BADGE DOES NOT TELL YOU WHO REVIEWED WHAT

Know the Auditor
Behind the Function

A badge does not say whether the deposit, withdraw, borrow, stake, or bridge function was reviewed. Users depend on one code path at a time, and that path needs its own evidence.

Proof of Audits links major user actions to contract-level and function-level review evidence, including reviewer tier, confidence, covered surfaces, and residual risk.

Exact function reviewed

Critical user actions are mapped to the actual code surface.

Auditor and reviewer tier shown

Lead reviewer, final reviewer, and specialist roles are visible.

Confidence and residual risk disclosed

Coverage, confidence, and remaining concerns are shown before interaction.

If a function has no mapped auditor, stale review, or unresolved residual risk, Proof of Audits flags it before the user interacts.

Function Review Lens

Contract, function, auditor, confidence, and residual risk

REVIEW EVIDENCE FOUND
Selected ActionDeposit USDC
$
Contract / Function
Pool.sol ➔ supply(address asset, uint256 amount, address onBehalfOf, uint16 referralCode)
Auditor Map
ReviewerTierRoleConfidence
Alice
Alice
T3
Lead Reviewer
4/5
Bob
Bob
T2
Final Reviewer
5/5
Carol
Carol
T4
Function Specialist
4/5
Coverage StatusReviewed
Covered Surfaces
Share mintingDeposit accountingFee calculationReceiver handling
Residual Risk

Yield depends on external rate and oracle assumptions.

Follow-up

Runtime monitoring recommended

Action SelectedUser selects an action (e.g., deposit).
Function MappedAction is mapped to the exact contract function.
Auditors LinkedRelevant auditors and tiers are attached.
Confidence VisibleConfidence and residual risk are clearly shown.
The Problem

Protocols display audit logos, but the report may cover a stale commit, partial scope, or a completely different code version. A logo is not proof — and sophisticated attacks now bypass code-level audits entirely.

$50M

Radiant Capital (Oct 2024) — had multiple clean audit reports, still exploited via developer hardware wallet malware

AUDIT LOGOS ARE NOT ENOUGH WITHOUT PROOF

See Which External
Audits Still Apply

Audit names, contest badges, and security logos can hide the details that matter: reviewed scope, covered commit, finding status, fix review, and whether the report still applies to the current deployment.

Proof of Audits turns external audit history into a proof timeline that separates current evidence from partial, stale, or unresolved work.

Exact scope + commit linked
Every report is anchored to the precise code and files reviewed.
Findings + fix status shown
Severity counts, fix completion, and re-review state are visible.
Stale & partial flagged upfront
Old commits, partial scope, or unresolved items never hide behind logos.

If an external audit covered old code, partial scope, or unresolved fixes, Proof of Audits shows that clearly instead of treating the logo as current trust.

External Audit Proof Timeline

Verified history of external audits and their current relevance

EVIDENCE LINKED
SUMMARY
2 MATCHED
1 PARTIAL
1 STALE
4 total reports • 2 apply to live deployment
SherlockCONTEST
May 12, 2024 • 0xadc...910
SCOPE
Vault + Rewards
FINDINGS
2 High • 4 Medium
FIX REVIEW
Completed
RELEVANCE
Partial — scope covers only part of current contracts
This audit reviewed only the Vault + Rewards module. Later protocol modules and upgrades were not in scope.
Code4renaCONTEST
Apr 01, 2024 • 0x88f...21c
SCOPE
Core Protocol Contest
FINDINGS
1 High • 7 Medium
FIX REVIEW
Completed
RELEVANCE
Stale — predates June 2026 upgrade
Code reviewed here is no longer live. A major implementation upgrade and proxy change occurred after this contest.
CantinaPRIVATE AUDIT
Feb 18, 2024 • 0xabc...123
SCOPE
Oracle + Risk Engine
FINDINGS
0 Critical • 1 Medium
FIX REVIEW
Completed
RELEVANCE
Matched — current code matches reviewed commit
The oracle and risk contracts in production are identical to the code reviewed in this private audit.
VeerSec
VeerSec — Current AuditLIVE PROOF
Jun 01, 2024 (ongoing) • 0xabc...123
SCOPE
Current Deployment (full)
FUNCTION MAP
Available — 42 functions reviewed
CONFIDENCE
42 / 50 (T4+T3+T2 coverage)
RELEVANCE
Matched — live bytecode matches audited commit
Fix reviewed & re-verifiedBytecode match confirmed against on-chain implementation
LEGEND — WHAT EACH STATUS MEANS
MATCHED
Applies to current live code
PARTIAL MATCH
Only some of the scope still applies
STALE
No longer matches deployed code
FIX REVIEWED
Findings independently re-verified

Proof of Audits cross-checks each external report against the live bytecode, implementation address, and upgrade history before displaying any status.

The Problem
$25M

average loss per exploit — users could not verify terms before signing

Users sign transactions without seeing real terms: fees, lockups, cooldowns, exit paths, and the exact function their wallet will call. The average exploit drains $25M before anyone can react.

BEFORE USERS SIGN, SHOW THE TERMS

Show What Happens
Before the Wallet Opens

A score is not enough at signing time. Users need the exact action terms: amount, token, fees, lockup, withdrawal path, rate assumptions, and the contract function their wallet will call.

Proof of Audits turns verified protocol inputs into pre-signing calculators for deposit, withdraw, borrow, stake, swap, bridge, claim, and redeem flows.

User enters real transaction values

Amount, token, duration, slippage, and preferences added by you.

Verified protocol terms power the calculation

Fees, rates, cooldowns, lockups, and exit rules are from verified data.

Audited function and exit risk shown before signing

Function map, reviewer confidence, and exit conditions revealed.

If rates, fees, lockups, cooldowns, or exit rules are unverified or stale, Proof of Audits blocks the calculator from being shown as trusted.

Investor Action Calculator

Verified terms, audited function, and risk preview before signing

3 VERIFIED CALCULATORS
Amount
USDC $
Token
USDC
Duration
Days
Verified Protocol Terms
Estimated APY8.40%
Deposit Fee0.10%
Withdrawal Delay7 days
CooldownRequired
Pause Can Block ExitNo
Output Preview
Projected Exposure10,000.00 USDC
Estimated Gross Yield69.04 USDC
Estimated Fees10.00 USDC
Exit Path7 days withdrawal queue
Function Called
Pool.sol ➔ supply(address asset, uint256 amount, ...)
View on Explorer
Reviewed By
Alice
Alice
4/5 Confidence
Bob
Bob
5/5 Confidence
Main Risk

APY depends on external rate and oracle assumptions.

See All Risks & Mitigations
All calculations use verified protocol data and are linked to audited evidence.
Last UpdatedMay 26, 2026 • 10:42 AM UTC
Network Ethereum Mainnet
49%

of vulnerable smart contracts exploited within 30 days of deployment — by the time users check, it is already too late

The Problem

Trust signals live on marketing pages, not at signing time. Wallet warnings arrive too late or show nothing useful — and 49% of vulnerable contracts are exploited within 30 days of going live.

The Extension Is the Front Door of Protocol Trust.

Proof of Audits surfaces the trust signal exactly where risk happens: before a user signs a transaction. Clicking the tabs on the simulator lets you inspect how the extension popup handles real protocol status, auditor records, bytecode verification, and risk warnings at the moment of wallet signature.

Select protocol to simulate extension warning:
https://app.aave.com
Simulated Wallet InteractionWallet.sign()
Aave V4 Core Integration

This transaction will deposit assets into the pool contract at address 0x0e76f1...53beb3.

Who Audited This?
Verified
Audited By:Proof of Audits Cascade Routing (T4-T1)
Score:
285/300(Elite Verified)
Bytecode:
Bytecode Match VerifiedLive runtime bytecode hash matches audited compiler output hash (0x9998...5f7b)
View Full Diligence Proof
The Problem
$17B+cumulative DeFi hack losses — "audited" labels failed to prevent any of them

Protocol scores are self-reported marketing claims with no explainable methodology tying a score to verified evidence. "Audited" labels have failed to prevent $17B+ in cumulative DeFi losses.

DefiLlama Hacks Database · Halborn Top 100 DeFi Hacks Research

How Proof of Audits Gives a Score

A Proof of Audits score is built from the protocol’s audit lifecycle, evidence trail, deployed-code match, and investor-facing risk signals.

01PRE-AUDIT

Pre-Audit Review

Before the core audit starts, Proof of Audits builds the security baseline. The snapshot is locked to prevent source mutations, and structural complexity is scanned.

Intake Validation Pipeline:verify_no_source_mutation.pyrun_static_prescan.pyquality_gate.pyRequired Outputs:• invariant_registry.json• core_audit_brief.md
02CORE AUDIT

Core Audit Routing

Audit scope is divided into clusters. Code is audited through tiered validators with on-chain reputation stakes.

Routing & Allocation:• 1:1 auditor-to-cluster rule• T4 function level (100–130 band)• T3 contract level (150–180 band)• T2 cross-contract | T1 systemAccountability Rules:• Missed Bug = −10 reputation• Principal slash via Escrow contract
03POST-AUDIT

Post-Audit Verification

Every patch undergoes differential reviews, storage layouts are scanned, and compiler gates check for regressions.

Verification Rules:compile_generated_artifacts.py• planning_manifest.json lock• Fuzzing and Halmos prover rerunsRequired Output:• fix_verification_report.md
04DEPLOYMENT

Deployment Match

After deployment, Proof of Audits checks whether the contract users touch is the contract that was reviewed, matching live runtime bytecode against the audited compiler target hash.

Live Checks:• Address book matching• Proxy implementation address check• UNVERIFIED_UPGRADE freezing ruleExtension Output:• Live deployment proof & signal
83individual hacking incidents in Q2 2026 alone — an all-time quarterly record
The Problem

Investors compare protocols by badge count or brand reputation, not by measurable proof strength. Without standardized scoring, capital flows to marketing instead of evidence.

Immunefi Q2 2026 Report

The Score Comes From Proof, Not Marketing.

Proof of Audits scoring is calculated from evidence across the audit lifecycle. A protocol does not get a high score because it says it is safe. It gets a high score when the proof trail supports it.

Pre-Audit EvidenceCompleteness of invariant specs, static analysis, and compilation logs.
Core Audit QualityAuditor validation metrics, severity weight of findings, and conflict checks.
Fix VerificationAst changes scan and regression check rerun validations.
Deployment MatchVerified bytecode hash matches and implementation address lookups.
Admin & Upgrade RiskMulti-sig keys ownership profiles and contract pause roles.
Runtime SignalsSentinel simulated telemetry alerts and oracle health nodes.
Disclosure HonestyTransparency notes detailing verified, pending, or unverified changes.

Score Types & Extension Signals

Different protocols carry different evidence trails. Proof of Audits shows what is verified and what is missing.

Proof of Audits Score

For protocols completing the full lifecycle: Pre-Audit ➔ Core Audit ➔ Post-Audit ➔ Deployment Match ➔ Trust Passport. The strongest score because Proof of Audits controlled the full evidence path.

External / Deployed Protocol Score

For protocols already live before Proof of Audits reviews them. Evaluates available proof, public third-party audits, live bytecode hash matches, and key governance profiles. Useful for the extension, but indicates when proof is externally reported.

Extension Signals

The user-facing transaction signals:

Verified - Audited & MatchedReviewed - Incomplete ProofMismatch - Code MismatchUnverified - No Proof FoundHigh Risk - Warning Active
The Problem

Protocols, auditors, and investors operate in silos. Audit work does not flow into investor-visible proof. Post-hack, teams lose 3+ months of productivity to incident response.

3+ months

of lost productivity per hacked protocol in incident response alone

Built for the Entire Ecosystem

Proof of Audits connects protocols, auditors, and investors into a single, verifiable trust layer.

For Protocol Teams

Turn Your Security Work Into Investor-Ready Trust Proof

Proof of Audits helps protocols convert onboarding, audits, fixes, deployed-code verification, and runtime signals into a live Trust Passport the market can verify.

"Your audit should not disappear into a PDF. Turn it into a living proof trail."Start Protocol Onboarding
For Auditors

Prove Auditor Skill With Verified Work

Proof of Audits turns public audit handles, bio-challenge ownership, accepted findings, severity history, validation accuracy, skill tags, and reliability into tiered routing eligibility.

Verified work creates reputation. Routing follows evidence.Apply as Auditor
For Investors

Review Protocol Risk Before Capital Enters

Proof of Audits gives investors a public protocol index with lifecycle VTI, exact deployed-code match, authority-key evidence, Sentinel status, on-chain badge state, and unresolved review signals in one scan-first view.

"You are not here to trust a badge. You are here to inspect the proof, compare protocols, and decide what deserves diligence."Open Protocol Index
The Problem
20%

of top-100 hacked DeFi protocols had been audited — the rest launched with zero review

Protocols hire auditors by brand name, not by verified skill match to the codebase's actual risk profile. Only 20% of hacked protocols had been professionally audited at all — routing and coverage gaps are the root cause.

Routed by Skill, Tier, and Reputation.

Proof of Audits matches each protocol scope with qualified auditors based on codebase type, security domain, audit tier, past reputation, and conflict-of-interest checks. The goal is simple: the right reviewer gets the right part of the system.

AUDITOR_ROUTING // ACTIVE_MATCH

Auditor Matchmaking

Auditors are not randomly assigned. Proof of Audits routes review work by proven skill, tier eligibility, protocol category, chain experience, and COI safety.

AUDITOR_MATCHMAKING --TARGET=ACTIVE_SCOPE
Skill Tags
Auditors are matched to the exact technical surface they are strongest in.
Tier Eligibility
T4 handles function-level review, T3 handles contract-level review, T2 handles cross-contract review, and T1 handles system-level validation.
Reputation Score
Past accepted findings, missed-bug history, validator accuracy, and review quality affect routing priority.
Conflict Checks
Auditors with protocol conflicts, wallet links, or unsafe overlap are blocked from the assignment path.
INVARIANTS // BASELINE_VERIFICATION

Invariant Baseline Mapping

Before auditors begin, Proof of Audits maps the protocol’s core state rules, trust assumptions, risky flows, and expected invariants. This gives auditors a structured baseline instead of sending them into a cold review.

TRACE STATUS
Baseline mapped
Scope ready for routed review
AUDIT_TIERS // VERIFICATION_CHAIN

Tiered Validation Chain

Each scope moves through the correct validation layer. Lower-level findings are reviewed upward when needed, and high-risk system logic receives stronger validator coverage.

T4
Function-level checks
T3
Contract-level checks
T2
Cross-contract and integration checks
T1
System-level and architecture validation
SPECIALIST_OVERFLOW // ON_DEMAND

Specialist Overflow

When a scope includes advanced surfaces like zero-knowledge circuits, bridges, custom AMMs, oracle design, or multi-chain logic, Proof of Audits can activate specialist auditor pools instead of forcing a generic review path.

ROUTING RESULT
Ready to engage T1/T2 specialists on demand.
$3.4B

stolen in 2025 — the audit-to-production pipeline was broken at every stage

The Problem

Audit work ends at a PDF. No pipeline connects submission → review → fix → deployment → wallet signal. Every break in this chain is where exploits enter.

From Audit Work to Transaction-Time Proof

The complete flow that connects contract compilation, validator checks, and on-chain verification to your wallet.

01

1. Submit Scope

Protocol teams submit repos, contract addresses, and DNS challenge proofs to initialize the intake baseline.

02

2. Pre-Audit Intel

Automatic snapshot verification, compiler validation, and invariant registry stubs are compiled by the pipeline.

03

3. Routed Review

Qualified auditors are assigned 1:1 to contract function clusters, routed by skill tags and reputation.

04

4. Fix Verification

Fix patches run through compiler check gates and Halmos prover regression validations to verify bug fixes.

05

5. Deployment Match

Mainnet contract bytecode matches are executed against audited scope compiler hashes.

06

6. Score Calculation

The trust score compiles evidence, findings severity, upgrade transparency, and key roles governance.

07

7. Extension Signal

The Contract Shield extension displays the verified, mismatch, or risk warning signal in the wallet.

08

8. Diligence Proof

Users and investors click the signal to view the complete immutable audit evidence and logs trail.

The Problem
$285MDrift Protocol (Apr 2026) — NK actors posed as a trading firm, spent months building social trust to compromise admin keys

Auditor reputation is based on marketing and social proof, not on verified work history, finding accuracy, or validation metrics. Social engineering alone was enough to drain $285M from Drift Protocol.

CertiK · Drift Exploit Post-Mortem April 2026

Auditor reputation supports the score.

Full Leaderboard

From audit records to continuous trust.

One proof path connects evidence registry, deployment match, public passport, live monitoring, extension signal, transaction context, and the future trust network.

Current Horizon

Building the continuous trust layer

The roadmap is direction and proof surface, not guarantees. Missing deployment, runtime, or extension evidence stays labeled as pending review, unverified, or not available.

Open Current Surface
Wide ocean map · scroll sideways

Protocols

Convert work into proof

Show identity, scope, audit state, fixes, deployment match, and what is still pending.

Users

Label the interaction

Surface known, changed, mismatched, unknown, or high-risk contract states before action.

Investors

Start diligence from evidence

Make status, gaps, and trust history inspectable instead of asking for badge trust.

Connected evidence route
Present horizon
Epoch 04 · Trench line

Continuous Trust Layer

The present horizon is a live trust layer that keeps watching deployed code, authority changes, audit state, and material protocol movement after the audit ends.

Open Sentinel
Proof checkpoint

The system should explain what changed, what is verified, what is pending review, and what remains unavailable.

Depends on

Protocol Trust Passport

Capabilities
  • Sentinel monitoring
  • Authority change visibility
  • Score history
  • Material update feed
proof-audits-evidence-inspector:~
guest@proof-audits:~$ proof-audits sentinel listen --stream
{
  "epoch": "04",
  "name": "Continuous Trust Layer",
  "status": "BUILDING_ACTIVE_TELEMETRY",
  "stream": {
    "live_block": 18492041,
    "events_scanned": 1520,
    "authority_state": {
      "owner_key": "0x98fd...201",
      "multisig_threshold": "3-of-5",
      "last_key_rotation": "2026-05-12T14:22:00Z",
      "rotation_status": "NORMAL"
    },
    "movement_telemetry": {
      "large_withdrawals": "None",
      "pausable_state": "UNPAUSED"
    }
  }
}
Now active in testing. Continuous sentinel scans deployed bytecode & authority updates.

The destination is a live trust surface, not another audit PDF.

Proof of Audits follows the proof trail from audited code to deployed code, through authority changes, toward the transaction a user is asked to sign.

System_Documentation_Intel

Core Intelligence

Critical protocol operating parameters and mission-specific answers.

End_of_Documentation // More intel available in the Security_Wiki

Turn Security Work into Verifiable Signals.

Submit your protocol for cascading verification, install the Contract Shield browser extension, or apply to join our tiered routing network as an auditor.

System Loading
Proof of Audits

Proof of Audits helps Web3 protocols turn security work into investor-ready trust proof.

Status

Proof surfaces active
Trust Passport, investor view, and extension signals show proof, gaps, and review state.

Proof of Audits

Turn protocol security into proof the market can verify.

© 2026 PROOF_OF_AUDITS