ConsenSys Diligence
Ethereum's most credible smart contract audit firm — backed by ConsenSys
Quick Facts
- Best For
- Ethereum and EVM projects needing audits with institutional credibility and deep Ethereum protocol knowledge
- Typical Engagement
- 2–8 weeks depending on codebase complexity; pricing from ~$30,000+
Overview
ConsenSys Diligence is one of the most credible smart contract audit firms in the ecosystem, backed by ConsenSys — Ethereum's most influential development organisation and creator of MetaMask and Infura. The firm's deep Ethereum protocol knowledge gives it a technical edge for complex Solidity audits, DeFi protocol reviews, and EVM-based security assessments. DiligenceSuit — its in-house automated toolset — supplements manual review to catch vulnerability classes that traditional audits miss. A ConsenSys Diligence audit carries significant credibility signal with institutional investors and protocol users.
Focus Areas
Who They Work With
Notable Audits
How to Engage
Request via consensys.io/diligence; waitlist may apply for complex projects
Frequently Asked Questions about ConsenSys Diligence
How long does a ConsenSys Diligence audit typically take?
ConsenSys Diligence audits typically take 2 to 8 weeks depending on codebase complexity. Simple token contracts at the shorter end; complex DeFi protocols with multiple interacting contracts, upgradeable proxy patterns, and economic edge cases at the longer end. Teams should engage Diligence well before a planned launch — 6-8 weeks minimum lead time is recommended to account for scheduling and potential remediation cycles.
How much does a ConsenSys Diligence audit cost?
Pricing starts from approximately $30,000+ and scales significantly with codebase size and complexity. Large DeFi protocol audits with multiple interacting contracts can reach six figures. ConsenSys Diligence provides pricing estimates following an initial scoping call — the estimate is based on lines of code, complexity, and the specific security concerns relevant to the protocol's architecture.
Which chains and languages does ConsenSys Diligence cover?
ConsenSys Diligence specialises primarily in Ethereum and EVM-compatible chain audits, covering Solidity smart contracts. Its ConsenSys backing and deep Ethereum protocol knowledge give it a natural edge for EVM-based security assessments. For non-EVM chains (Solana, Cosmos, etc.), specialist auditors with chain-specific expertise are generally more appropriate.
Is there a waitlist for ConsenSys Diligence?
A waitlist may apply for complex or large-scale projects, particularly during periods of high demand. Teams should engage Diligence as early as possible in their development cycle — ideally 8-12 weeks before a planned audit start. The firm's website requests allow teams to submit project details for initial assessment before formal scheduling.
What notable projects has ConsenSys Diligence audited?
ConsenSys Diligence's most notable audits include Uniswap V2 and Gnosis Safe — two of the most widely-used smart contract systems in the Ethereum ecosystem. These audits represent the firm's capability and credibility for high-stakes protocol security at the foundational DeFi infrastructure level.
What tools does ConsenSys Diligence use in its audit process?
ConsenSys Diligence supplements manual code review with DiligenceSuite — its in-house automated toolset for vulnerability detection. This combines static analysis, fuzzing, and formal verification approaches to identify vulnerability classes that pure manual review might miss. The integration of automated tooling with senior researcher review is a standard approach for comprehensive smart contract security assessments.
Setting up a business entity?
If you're working with ConsenSys Diligence, you may need a properly structured entity. EntityEngine handles incorporation in 15+ jurisdictions — with fast setup and bank-ready documentation.
Explore incorporation optionsRelated Smart Contract Audit Listings
Trail of Bits
Elite security research firm covering smart contracts, cryptography, and protocol-level security
Best for: The most technically complex security mandates — ZK systems, novel cryptography, and L1/L2 consensus security
CertiK
The world's most widely deployed smart contract audit firm — formal verification at scale
Best for: Teams needing a broadly credible audit with public verification scores, formal verification for high-assurance applications, or fast turnaround
OpenZeppelin
The trusted standard for smart contract security — library creators and auditors of the ecosystem's foundations
Best for: DeFi protocols and token projects using OpenZeppelin libraries, or any project where the audit credential needs to be recognisable to sophisticated DeFi users
This directory is compiled from publicly available information and may contain inaccuracies or outdated details. Listings do not imply endorsement or a commercial relationship unless explicitly stated. If you represent a listed organisation and would like to request amendments or removal, please contact us at support@entityengine.io.