Audit Reports

Each project is an investigation, a search for assurance in complex systems.

The work below shows how we approach complexity, find vulnerabilities, and help teams ship safely and with confidence for both their systems and the users who rely on them.

View All Public Reports
DoubleZero
Whiteglove AuditDoubleZero

DoubleZero is a decentralized network protocol optimizing data transmission and reliability across Solana. Our review covered both on-chain Rust programs and off-chain Golang code across the Telemetry, Passport, and Revenue Distribution modules validating access control, latency sampling, and reward precision. Each engagement combined deep manual analysis with custom test coverage to ensure stable performance and precise on-chain behavior across critical systems.

5Findings
7Enhancements Opportunities Found
3Modules Audited
Read Report
GLAM
Whiteglove Audit + Custom FuzzingGLAM

Adevar Labs worked with the GLAM team to secure their programmable investment infrastructure on Solana. Across a comprehensive audit and follow-up reviews, we identified and helped resolve 14 findings, including high-severity risks like stale AUM calculations and external position overpricing. Our team utilized specialized fuzzing and stress-testing harnesses to harden the protocol's architecture against share dilution and unauthorized fund diversions. This collaboration ensured that GLAM's complex integrations are robust and ready for secure public deployment.

14Findings
28Enhancements Opportunities Found
1M+Executions Fuzzed
Read Report
Loopscale
Whiteglove AuditLoopscale

Loopscale is a Solana-native credit protocol enabling structured lending with isolated vaults, cross-collateral positions, and composable strategies. Our audit covered the lending engine, vault isolation logic, and liquidation flows, uncovering critical access control gaps and arithmetic edge cases before launch.

21Findings
10Enhancements Found
2Modules Audited
Read Report
M0 Labs
Whiteglove AuditM0 Labs

The M0 Extensions protocol enables the creation of yield-bearing wrapped tokens built on the M token. Our review combined mathematical modeling of the powf approximation with an extensive fuzzing campaign to validate critical invariants. The audit covered the m_ext and ext_swap programs, assessing access controls, mathematical consistency, and deterministic precision.

6Findings
3M+Executions Fuzzed
2Modules Audited
Read Report
Fystack
Infrastructure AuditFystack

Fystack is a platform that simplifies full-stack Web3 development, enabling teams to build, deploy, and scale decentralized applications with integrated backend services, wallet infrastructure, and payment flows. The Apex Backend Audit was a post-launch hardening review of Fystack's backend service layer, covering API endpoints, authentication and session handling, checkout and payment flows, wallet signing and MPC message handling, webhook functionality, NATS messaging, MongoDB and PostgreSQL configuration, Docker deployment files, and CI/CD configuration. The audit identified 1 Critical, 9 High, 29 Medium, and 23 Low severity issues, alongside 12 enhancement opportunities. Fystack engaged actively throughout: the Critical finding and the majority of High-severity issues were remediated during the audit window.

62 Total Findings
12Enhancement Opportunities
Read Report
Bench
PreauditBench

Bench is an opportunity markets protocol built on Solana using Anchor, with Arcium for confidential compute on the reveal/stake logic. We ran a preaudit on their program ahead of a full audit: AI-assisted scan plus human validation on the codebase at commit 2dc1caf4. We triaged every flagged candidate, cut false positives, and recalibrated severity based on real exploitability. Found 11 validated issues (0 critical, 0 high, 4 medium, 7 low), mostly reward and lifecycle edge cases in reveal/finalization, giving Bench a clear punch list to fix before committing to a full audit.

11Findings
Read Report

Ship Safely.

Whether you're pre-launch or scaling post-TGE, we'll cover every layer; Code, infrastructure and/or operations.