Security data web3 can build on.

One open record per project: who reviewed the code, what they found, what is still open. For every wallet, explorer and team that needs it.

6,589 projects with a record9,769 audit reports$50.37bn held in projects with an audit on Trustblock

Backed by and shown on

  • Bpifrance
  • Etherscan
  • Blockscout
  • Mobula
  • Polygon
  • Starknet

Where a record shows up

The same record can sit where people already look: on a contract's page in a block explorer, or beside a token in a wallet.

Security State
Aave (aave.com)Last audit Jun 2026
No open critical findings
25 audits by 10 firms
ChainSecurity, Consensys and 8 others
Powered by Trustblock
The first lines of a record, as a block explorer shows them on a contract's page. Aave's card on . Open Aave's record
A token swap where the first token carries the label "Audited by HashEx".
An illustration: how a wallet could show a token's label before a swap. The tokens and amounts are made up.

What you can do here

  • Anyone

    Read a project’s record

    Look up a project, a token or a contract address. See what is on record: each audit, its findings and their status, the contracts covered, any incident on record.

    Look up a project
  • Project teams

    Check and show your record

    See what is on record for your project and tell us what to correct. Add the free label to your site; it links to your record.

    Find your project
  • Audit firms

    See your work as data

    The projects you reviewed, with your reports, dates and statuses. Correct them, or publish new reports from your own account. Free.

    Find your firm
  • Developers, wallets, explorers

    Read it through the API

    One request by chain and contract address returns the project’s record. An API key with a monthly allowance is free.

    Open the API docs

What the record holds today, and what is next

A project’s page shows a section only when we hold data for it. Here is the whole picture, as of .

In the record today

  • Audits and findings

    9,700+ audit reports from 52 audit firms. Each finding with its severity and the status the firm gave it, and a link to the report. Reports we host are stored on IPFS, so a report can be checked against its content hash.

  • Contracts in scope

    The deployed addresses and source files each audit names, by chain. More than half of the reports name a deployed address.

  • Verified source

    Whether an address’s source code is verified in a public verification service, shown on the audit page.

  • Incidents, up to Sep 2026

    Exploits and other incidents from a public incident database, attached to a project only through a shared contract address. Nothing after Sep 2026 yet.

Next

  • Incidents up to date

    The same rule, fed again from public sources.

  • Bug bounties

    Whether a project runs a public bounty, where, and its stated maximum.

  • Security contacts

    The contact a project publishes for reports, read from its own site.

Not in the record: ratings of projects, scores of audit firms, or any judgement of code. Trustblock does not review code.

How a record is built

  1. Step 1: A source is published

    An audit firm publishes its report on Trustblock, or we collect a report the firm has already made public.

  2. Step 2: We read it into data

    Findings, severity, status, the date, the contracts or repository in scope. Every line keeps a link to its source.

  3. Step 3: It joins the project’s record

    On the project’s page in the app, on block explorer contract pages, on a label the project adds to its own site, and through the API.

Questions

What is Trustblock?

A public security record for web3 projects: the facts about a project's security, gathered in one place and kept as data you can read and check. Today it is built from published audit reports: which firm reviewed the code, when, what each review found, the status of each finding, and which contracts each report covers. Incidents and bug bounties are being added. The same record shows as a card on contract pages of seven block explorers (Etherscan, BscScan, PolygonScan, BaseScan, Arbiscan, OP Mainnet Etherscan and SnowScan), and it is available through our API.

Where do the reports come from?

From the audit firms. Firms publish their reports on Trustblock themselves, or we collect the public reports they have published on their own sites and GitHub. We list only audits that a project commissioned. Every status you see is the firm's own word, taken from its report.

Does Trustblock rate projects or audit firms?

No. We do not score projects, and we do not rank or score audit firms. The record states what the reports say, with their dates. The judgment stays with you.

Can anyone pay to change a record?

No. Listing is free for audit firms, and nothing paid changes what a record shows, its order or its colour. Our paid products are data access and tools.

How do I use it?

Before you deposit or sign, search the project on app.trustblock.run, or open its contract on Etherscan, BscScan, PolygonScan, BaseScan, Arbiscan, OP Mainnet Etherscan or SnowScan and choose the Cards tab. Builders can show the same record in a wallet, an explorer or a dashboard through the API. Projects can add a free label to their site that links to their record.

Something is wrong or missing. What do I do?

Write to contact@trustblock.run with the report. Audit firms can also sign in and correct a date, a title or a finding's status on their own records. We correct against the report.

Is it free?

Reading the record is free, and so is an API key with a monthly allowance. Larger API plans and data licences are paid.

Where does the value figure come from?

The value held is the total value locked that DefiLlama reports for the lending markets, exchanges and similar venues with an audit on Trustblock, counted once per project, without the token issuers, staking pools and bridges whose tokens they hold, refreshed daily.

Something missing or wrong in a record?

Send the report link or the page address. We check every correction against its source.

Tell us