Three engineers can inspect the same bridge and hand you three different documents. One walks it with the drawings and argues with your maintenance plan. One opens the site to fifty inspectors and pays whoever finds the worst crack. One hands you its checklist, its scoring formula and every bridge it has signed off.
I told you that to tell you this. Sherlock sells access to a competitive researcher network. Hacken sells a documented, repeatable process run by its own engineers. Cyfrin sells an in-house research team wrapped in public tooling and a separate competition platform. All three are called a smart contract audit, and comparing the quotes as though they were one purchase is how good work ends up disappointing people.
Every claim below was read on the firm’s own pages on 9 September 2026. Models and prices change, so check that date before relying on this.
The short version
| Sherlock | Hacken | Cyfrin | |
|---|---|---|---|
| What you buy | A staffed review or a public contest, drawn from a researcher network | A documented process run by the firm’s own engineers | An on-staff team, plus a separate competition platform |
| Who reads the code | A senior reviewer owning the engagement, plus researchers competing on the same scope | Two senior auditors in parallel, plus a delivery manager | On-staff researchers, named on the site |
| Publishes a price | No | Yes. From $3,000 to $100,000+ | No |
| Publishes a timeline | Yes. A duration table by code size | Yes. Most audits 2 to 4 weeks | Quoted after a screening call |
| Publishes its severity rules | Judged and calibrated by Sherlock judges | Yes. A formula with four metrics | Community judging, then a lead judge |
| Publishes researcher pay | Around 80% of fees reach researchers | Not applicable, its auditors are employees | Yes. A share formula with a worked example |
| Strongest for | Breadth on a well-specified scope | A process you can hand to procurement | A team that also builds your tooling |
Disclosure, and one rule that should change how you read this. Fidesium is a smart contract audit firm, so we compete with all three. The rule we held ourselves to: no firm’s self-reported aggregate or outcome figure appears on this page, ours included. All four of us publish counters for value secured or audits completed, none of them independently checkable. What is used instead is what each firm publishes about how it works, quoted from the page it was read on.
Who actually reads your code
Sherlock assembles a team per engagement. Its documentation describes collaborative audits as “staffed dynamically”, built “based on your system’s architecture, attack surface, languages, and release risk” rather than on a fixed template. Above that team sits “a designated senior reviewer who owns the engagement end-to-end”, and around it “participation from 500+ potential researchers across the network depending on scope and timing”. It publishes the economics too, which is rare: “in many engagements, ~80% of fees go directly to researchers” (docs.sherlock.xyz).
Hacken uses its own employees, twice over. Its headline model is double coverage: “two senior auditors review in parallel to reduce blind spots and increase accuracy”, with a delivery manager owning scope and timeline. The methodology puts it at code level, “auditors perform manual line-by-line review simultaneously” (hacken.io, docs.hacken.io).
Cyfrin staffs from its own bench, and runs the crowd separately. Its audits page describes “our world-class team of on-staff blockchain security researchers” and lists them by name and role. Competitive review is not folded in. It lives on CodeHawks, a separate platform with its own rules, judges and payouts (cyfrin.io). Ask any of the three for named reviewers and what they have shipped in your language.
How each firm decides what counts as a High
Severity is where two honest reports of the same code end up looking different, and almost nobody compares it.
Hacken publishes a formula. Its methodology scores four metrics, Likelihood, Impact, Complexity and Exploitability, then converts them into one of five severities using a stated equation with numeric thresholds. Exploitability runs from 0 for something anyone can trigger to 2 for something needing a call from the most privileged user, and it moves the result. Agreeing with the weighting matters less than being able to argue with it before you sign (docs.hacken.io).
Sherlock judges centrally, during the contest. Submissions “are reviewed as they come in”, and Sherlock judges “validate issues, deduplicate similar reports, and calibrate severity so the final output is actionable”. Then a 48 to 72 hour escalation window, which usually runs while your team is already fixing things (docs.sherlock.xyz).
Cyfrin splits judging in two. Community judging runs first, then lead judging, then a 48-hour appeals window in which researchers can challenge a decision. Cyfrin also narrowed what counts: since 18 August 2023, CodeHawks has not accepted findings for gas optimisations, quality assurance or informational insights.
None of the three is stricter. The point is that a High from a formula, a High from a calibrating judge and a High from a community vote plus an appeal are three different objects, and your investor will read all three as the same word.
What each firm publishes before you sign
| Published artefact | Sherlock | Hacken | Cyfrin |
|---|---|---|---|
| Price | None public | A range, on the audit page | None public, /pricing returns 404 |
| Sizing method | nSLOC via Solidity Metrics, libraries and imports counted, interfaces and standard imports excluded | After codebase review | After a screening call |
| Duration guidance | Around 500 nSLOC at about 3 days, up to around 6,000 at about 38 days | Most 2 to 4 weeks, simple contracts 5 to 10 business days, complex protocols 4 to 6 weeks | Set by codebase size, given in the quote |
| Full methodology | Process and readiness docs | A versioned document, release 3.0, dated 16 June 2026, named author | Process docs, plus the payout formula |
| Reports | A GitHub archive | An audits index and a documented public API | A report library and a GitHub archive |
Two rows are worth more than they look.
Hacken’s methodology is dated, versioned and inherited. All audits are performed “in accordance with the NIST SP 800-115 – Technical Guide to Information Security Testing and Assessment and the Penetration Testing Execution Standard (PTES)”. It also documents a public audits API at hacken.io/api/audits, needing no authentication, returning audit name, client, date, repository and commit, platforms, languages and findings with severities. If you have ever had to prove a vendor’s track record to procurement, that is the artefact you wanted (docs.hacken.io).
Sherlock’s readiness bar is public and specific. Code must be frozen three days before the start, “final pricing is determined by the size of the codebase at the frozen commit hash”, and the docs ask for “100% passing tests and a target of >80% test coverage at the frozen commit”. Cyfrin’s freeze rule adds a detail worth copying whoever you hire: it covers your own repository too, “as a pull request can leak alpha information to our community” (docs.sherlock.xyz, docs.codehawks.com).
Chains, languages, and where coverage bites
Hacken lists the widest published surface: twelve languages including Solidity, Rust, Move, Go, Cairo and Daml, across more than thirty named platforms. Cyfrin’s own figure is 18 supported chains, naming Solana, Aztec, Starknet, Sui, Aptos and Monad alongside the EVM set, and its Vyper framework Moccasin covers a stack most firms skip. Sherlock is the least specific in public: its FAQ says it supports “major onchain environments” and gives EVM Solidity and Solana Rust as the example.
Sherlock is also honest that its sizing does not transfer. The nSLOC table is for Solidity, and non-Solidity scopes, Solana programs in Rust included, are sized “based on program structure, attack surface, and integration complexity rather than nSLOC”. Ask for the last three reports on your chain, not the best three.
What happens after the report
Hacken gives you two weeks and no cap: “submit unlimited in-scope fixes within two weeks”, re-checked and confirmed to introduce nothing new before statuses are updated in the final report. Its methodology phrases the same window as 10 business days.
Sherlock treats fix verification as a defined stage, “reviewed against the reported exploit path and the protocol’s intended invariants”, and recommends a short follow-up review rather than waving a large patch set through. It also publishes the number nobody wants: after a contest ends, do not expect to launch for two to three weeks.
Cyfrin agrees a mitigation window, re-reviews, issues the final report, and offers an optional Mitigation Review Contest on the fixes, which it notes is much faster than the original.
Three included re-checks, three different shapes. This is where a cheap audit becomes an expensive one, so compare it before you compare headline numbers.
Where each one is genuinely the right call
Sherlock, when the scope is well specified and you want many independent people attacking it at once, or a staffed review and a contest in sequence. Its own guidance recommends exactly that: collaborative audit first “to pressure test the design and verify fixes, then a Contest to add breadth on the hardened release candidate”. Sherlock Shield, its optional exploit payout coverage, is a genuine differentiator, and Sherlock is careful with it: it “is not included by default with every audit”, and “Sherlock does not guarantee payment or the availability of funds”.
Hacken, when the audit has to satisfy somebody other than your engineers. It is the only one of the three publishing a price range, a versioned methodology, a severity formula and a machine-readable audit history, and it holds ISO 27001 certification and states SOC 2 Type II compliance. For an exchange listing or a procurement questionnaire, that paperwork is the product.
Cyfrin, when you want one relationship covering the review, the tooling and your team’s skills. Formal verification, incident response and penetration testing are named services rather than add-ons, and the free layer is real: Aderyn, “an open source, AI powered, Rust-based Solidity static analyzer” in their words, plus the Solodit vulnerability database.
What none of them sells you
An audit does not make a contract safe, and the best statement of that came from one of the three. Sherlock’s FAQ asks “Does Sherlock guarantee the protocol won’t be exploited?” and answers, in full: “No. The goal is to materially reduce risk by identifying and fixing vulnerabilities, clarifying trust assumptions, validating invariants, and maintaining scrutiny as the system evolves.”
That applies to every firm here, ours included. A report describes one commit, and your users are on a different one by Friday. We wrote about that decay in when a smart contract audit actually expires, and it is why all three firms above sell something that runs after the report.
Where Fidesium sits in this
We are a fourth answer, not a bigger version of these three. Our lane is the gap between audits. We re-run audit-grade analysis on every commit, pull request and deployment, and mint each audit as an on-chain NFT so the record is verifiable rather than a PDF in a downloads folder. The tooling is deterministic static and abstract syntax tree (AST) analysis, so the same commit produces the same findings twice, and the people are the core team, not contractors running a scan.
| What it is | |
|---|---|
| Manual audit | From $5,000. Line-by-line human review, logic and economic risk analysis, two rounds of fix verification, a public report (/manual-smart-contract-audits/) |
| Continuous scanning | $399, $799 and $1,499+ a month, manual review available as an add-on on every plan (/pricing/) |
| Beyond the audit | Monitoring, architecture review and bug bounties (/security-services/), plus blockchain penetration testing |
| Public record | 23 published reports across 16 protocols at /audits/, counted on 9 September 2026 |
Where we are not the answer. If you need formal verification, Cyfrin sells it and we do not, and our explainer on what formal analysis actually proves will tell you whether you need it. If the audit has to clear an exchange listing or a procurement review, Hacken’s published compliance position is a real advantage. If you want fifty researchers on a hardened release candidate, that is a contest, and Sherlock and CodeHawks both run them. And if you are going to mainnet with nine figures behind it, our $5,000 floor is not the relevant number. Your scope is.
Frequently asked questions
Sherlock vs Hacken vs Cyfrin: which one should I choose for a smart contract audit?
Choose on what the audit has to do. Sherlock if you want many independent researchers on a well-specified scope, or a staffed review followed by a contest. Hacken if the report must satisfy an exchange, a regulator or a procurement team, because it publishes a price range, a versioned methodology, a severity formula and a machine-readable audit history. Cyfrin if you want one relationship covering the review, the tooling and your team’s training.
Is Sherlock an audit firm or an audit platform?
Both. Sherlock runs staffed engagements it calls collaborative audits, assembling a review team for your specific system, and it runs public audit contests where many independent researchers compete on the same scope. Its documentation describes combining the two: “a designated senior reviewer who owns the engagement end-to-end” plus a competing field. The engagement looks traditional, but the people delivering it come from a network rather than a payroll.
Does Hacken publish its smart contract audit methodology?
Yes, in more detail than anyone else in this comparison. Hacken publishes a versioned methodology document, release 3.0 dated 16 June 2026 with a named author, covering the audit phases, the vulnerability categories it works through, and the requirement that High and Critical findings ship with a proof of concept. It states that audits follow NIST SP 800-115 and the Penetration Testing Execution Standard, and it documents a public audits API needing no authentication.
How does Cyfrin CodeHawks pay security researchers?
By a published share formula rather than a discretionary decision. A medium-severity finding is worth 1 (0.9^(n-1)) / n shares and a high is worth 5 (0.9^(n-1)) / n, where n is the number of researchers who found the same issue, so a finding is diluted the more people spot it and a unique high pays most. Rewards are paid in USDC on ZKsync within 72 hours of the escalation period closing.
Which of Sherlock, Hacken and Cyfrin publishes a price?
Only Hacken. Its audit page states that smart contract audits typically cost from $3,000 to $100,000+, depending on scope, code complexity, integrations and timeline, and adds that pricing can fall outside that range. Sherlock and Cyfrin both quote after scoping and neither has a public pricing page. Sherlock does publish a contest duration table by code size, which is the next best thing.
How do Sherlock, Hacken and Cyfrin decide the severity of a finding?
Three different mechanisms, which is why the same code can produce differently shaped reports. Hacken scores four metrics, Likelihood, Impact, Complexity and Exploitability, and converts them to one of five severities with a published equation. Sherlock judges submissions centrally during a contest, deduplicating and calibrating severity, then runs a 48 to 72 hour escalation window. Cyfrin runs community judging, then lead judging, then 48 hours of appeals.
Do Sherlock, Hacken and Cyfrin cover Solana and Rust?
All three name Rust or Solana on their own pages. Hacken lists twelve languages including Rust, Move, Go and Cairo across more than thirty platforms. Cyfrin names 18 supported chains including Solana, Aztec, Starknet and Sui. Sherlock says it supports major onchain environments, gives Solana Rust as its example, and is explicit that its Solidity sizing method does not apply there, scoping on program structure and attack surface instead.
What happens after the audit report, and is a fix re-check included?
All three include one, and the terms differ enough to change a quote comparison. Hacken lets you submit unlimited in-scope fixes within two weeks and re-checks them before the final report. Sherlock treats fix verification as a defined stage reviewed against the original exploit path, and recommends a short follow-up review if the patch set is large. Cyfrin agrees a mitigation window, re-reviews, and offers an optional mitigation review contest on the fixes.
Get a quote
Tell us the repository, the commit and the file list, and we will come back with a scope and a price. If one of the three above fits you better than we do, we will say so.
Request a quote · Read our published audit reports · See our security services



