Compare Top Smart Contract Auditing Companies
1. CertiK
CertiK remains the largest name in Web3 security. It has completed more than 5,500 audits across 20+ blockchains and disclosed over 115,000 vulnerabilities. Its engineers use manual review alongside formal verification engines that mathematically prove how a contract behaves across every reachable state before mainnet deployment.
Its main point of distinction comes after the audit report. Skynet continuously scores live protocols representing roughly $542 billion in monitored market value, allowing teams to see how upgrades, governance votes, and integrations change their risk profile over time.
CertiK also publishes the industry-standard Hack3d security reports, giving prospective buyers unusual visibility into current attack data. Scale has a downside, however. The rekt leaderboard records the $216 million Gala Games incident at a previously reviewed client.
Pros
- Formal verification paired with continuous post-audit Skynet scoring.
- Published incident research keeps methodology aligned with live threats.
- Massive client base demonstrates a repeatable delivery pipeline.
Cons
- Brand recognition attracts projects seeking checkbox audits.
- Several previously reviewed clients appear on the rekt leaderboard.
- Premium pricing compared with boutique alternatives.

2. Hacken
Hacken has protected roughly $430 billion in digital assets through more than 1,600 client engagements, establishing it as a leading choice for exchanges and institutional platforms. Its HackenProof bug bounty arm coordinates 45,000 independent researchers. Together, they have disclosed over 25,000 vulnerabilities and collected $15.7 million in rewards.
Regulatory readiness is Hacken's clearest advantage in 2026. The firm maps deliverables to MiCA and DORA requirements, creating compliance-ready documentation that European entities can provide directly to supervisors. Its Proof of Reserves attestations also verify user deposits for exchanges such as OKX and Bybit.
That institutional emphasis makes Hacken especially well suited to CASPs and custodians, rather than experimental DeFi primitives. Its record is strong without being spotless: the rekt leaderboard includes a $7.8 million Warp Finance exploit at a protocol its engineers had previously reviewed.
Pros
- Compliance-mapped reports suit MiCA and DORA obligations directly.
- Large bug bounty network extends coverage beyond the audit window.
- Proof of Reserves verification builds exchange user confidence.
Cons
- Broad headline metrics are hard to map to individual chains.
- Enterprise orientation may feel heavy for small DeFi teams.
- One historical post-audit incident sits on the rekt leaderboard.

3. Hashlock
Hashlock is Australia's leading smart contract auditor, with more than 500 completed project reviews and roughly $4 billion in assets secured. Engagements center on manual, line-by-line inspection across Ethereum, Solana, and Polygon. A proprietary Security Rating System supports the process, and the firm states a sub-three-hour response time.
Most notable is Hashlock's claim that no fully audited client has suffered a successful exploit, which the public rekt leaderboard currently supports. Its reviews focus heavily on business logic and incentive design. These are precisely the flaw categories automated scanners routinely miss and attackers continue to target.
Security services also continue beyond the initial review. Hashlock's threat monitoring and onchain surveillance watch deployed contracts for anomalies. Separate tokenomics assessments look for poorly designed incentives that can create economic exploit paths even when the underlying code is technically correct.
Pros
- Zero recorded exploits across fully audited client projects.
- Tokenomics review catches economic risks beyond code correctness.
- Fast scoping responses suit teams on tight launch timelines.
Cons
- Smaller global footprint than US and European rivals.
- Limited public documentation of its internal tooling stack.
- Monitoring alerts still require client-side escalation procedures.

4. Trail of Bits
Trail of Bits approaches blockchain engagements as a systems security research firm. Its reviews can extend beyond smart contracts to off-chain keepers, relayers, and admin tooling, all of which modern attackers increasingly target. Operating since 2012, the firm brings cryptography and software assurance expertise that few Web3-native competitors can match.
Much of the industry's core security tooling comes from Trail of Bits. The firm builds and maintains the Slither static analyzer along with the Echidna and Medusa fuzzers, and its consultants use those tools alongside manual review. This research-led approach makes it a default choice for novel architectures, zero-knowledge systems, and consensus-critical infrastructure.
Its engagements tend to run deeper and slower than commodity audits, making them a better fit for complex protocols than straightforward token launches. Elite research still has limits. The rekt leaderboard records a $3.3 million exploit at Raft, which Trail of Bits had previously examined.
Pros
- Unmatched depth on cryptography and off-chain infrastructure review.
- Maintains industry-standard open-source analysis tooling.
- Longest operating history among major Web3 auditors.
Cons
- Engagement style is slower and more resource-intensive.
- Overkill pricing for simple, low-scope token audits.
- Does not market headline assets-secured figures for comparison.

5. Cyfrin
Cyfrin, founded by Patrick Collins in 2023, has developed into a top-tier auditor while combining security work with developer education. The company has secured around $40 billion in assets. Its free Updraft platform has trained over 100,000 students in Solidity, Vyper, and security research fundamentals.
That educational ecosystem feeds back into the firm's auditing work. CodeHawks, its competitive platform, and the Solodit vulnerability database continually expose researchers to new exploit patterns. Clients including ZKsync, Chainlink, and Starknet receive unusually transparent reports, often supplemented with public video walkthroughs.
Cyfrin is particularly suited to teams that want an audit to be collaborative, with their own developers leaving the process more capable than when it began. Its history is shorter than that of legacy competitors, but no fully audited Cyfrin project currently appears on the rekt leaderboard.
Pros
- Education-first model upskills client teams during engagements.
- Clean post-audit record across completed private reviews.
- Free tooling and Solodit database benefit the wider ecosystem.
Cons
- Shorter operating history than decade-old competitors.
- Competitive audits demand strong internal triage from clients.
- Public case-study depth varies across engagement types.

6. Sherlock
Sherlock has completed more than 1,000 audits and protected over $250 billion in TVL through a model based on researcher performance data instead of a fixed internal bench. Its network includes 11,000+ researchers, with proven specialists in areas such as lending, bridges, or cross-chain messaging matched to each codebase.
Audit contests can place hundreds of independent researchers on one scope at the same time. A senior lead anchors the process, while a judging pipeline handles duplicate findings. Major engagements include the Ethereum Foundation's $2 million Fusaka stress test and Ripple's $550,000 XRP Ledger competition.
Sherlock is also the only major auditor that offers financial accountability by repaying protocols up to $2 million when a covered vulnerability is missed. The rekt leaderboard attributes the $197 million Euler exploit to Sherlock. In that case, the firm notably paid claims under its coverage.
Pros
- Performance-ranked staffing matches specialists to each codebase.
- Optional exploit coverage aligns auditor incentives with clients.
- Contest model delivers hundreds of adversarial reviewers per scope.
Cons
- Contest findings require disciplined internal fix management.
- The Euler incident remains the largest audited loss on rekt.
- Coverage terms carry scope limits teams must read carefully.

7. Spearbit (Cantina)
Spearbit is the elite researcher collective behind the Cantina platform. The two brands merged in May 2025 into a single security stack. Their combined network includes more than 9,000 researchers, has secured over $100 billion in onchain value, and serves clients including Coinbase, Uniswap, and Aave.
For private engagements, Spearbit assembles hand-picked teams of Lead Security Researchers to handle some of the industry's highest-stakes reviews. Cantina's public competitions, meanwhile, have distributed $46.7 million across 200+ protocols. Landmark contests include Uniswap v4's $2.35 million competition and the Ethereum Foundation's $2 million Pectra hard-fork review.
In 2026, the platform is moving toward full-lifecycle security. AI-native analysis, managed bug bounties, and continuous coverage are being layered onto point-in-time reviews. Its public record remains strong, with the disputed-scope $12 million Cork Protocol incident serving as the main blemish cited by critics.
Pros
- Access to arguably the deepest elite researcher talent pool.
- Landmark competitions demonstrate capability on flagship codebases.
- Continuous coverage extends protection well beyond launch.
Cons
- Premium tier pricing targets well-funded protocols.
- Marketplace model requires clients to evaluate researcher fit.
- One disputed post-audit incident draws recurring criticism.

8. Halborn
Halborn operates as an offensive security firm whose ethical hackers approach engagements as live attack simulations. Contract review is only part of its work. Teams also conduct penetration tests, phishing campaigns, and social engineering exercises against the web apps, APIs, and internal processes surrounding a protocol.
The firm reports more than $1 trillion in protected assets. Its clients include major networks such as Polygon and Avalanche, along with banks and enterprises moving into digital assets. This broader attack-surface philosophy aligns with 2026 threat data, as wallet compromises and social engineering now exceed pure code exploits as drivers of losses.
SOC 2 certification and alignment with institutional security frameworks help simplify procurement for regulated entities. Halborn's rekt leaderboard entries include MonoX at $31.4 million and Seneca Protocol at $6.4 million, both previously assessed by its teams.
Pros
- Attack-surface coverage extends far beyond contract code.
- Certifications streamline procurement for regulated institutions.
- Offensive mindset mirrors how real adversaries operate.
Cons
- Enterprise scope increases engagement coordination overhead.
- Headline metrics do not break down value by chain.
- Two previously assessed protocols appear on the rekt leaderboard.

9. OpenZeppelin
OpenZeppelin maintains the contract libraries underlying much of the EVM ecosystem, so its auditors have exceptional familiarity with patterns that many codebases inherit. The firm has reviewed millions of lines of code across 30+ chains and protected tens of billions in TVL for protocols such as Compound and Aave.
Its Ethereum Foundation partnership on protocol-level security work reinforces OpenZeppelin's status as an establishment choice for core infrastructure. Audits combine deep manual review with deployment verification. That additional step reduces misconfiguration and post-audit drift, both common causes of real-world incidents even after clean reports.
Demand is the primary limitation. During busy launch periods, scheduling can stretch for smaller teams. The rekt leaderboard also records a $6 million Audius incident involving previously reviewed code, showing why canonical implementations still need ongoing monitoring after deployment.
Pros
- Library authorship gives unmatched EVM pattern expertise.
- Deployment verification reduces post-audit configuration drift.
- Ethereum Foundation collaboration signals institutional trust.
Cons
- Scheduling queues lengthen during busy launch seasons.
- Best results demand strong client engineering readiness.
- EVM focus limits fit for non-EVM architectures.

10. Quantstamp
Quantstamp has secured more than $200 billion in value through 1,100+ engagements since 2017, placing it among the longest-running dedicated Web3 auditors. Its coverage is genuinely chain-agnostic, spanning Ethereum, Solana, Flow, and Cardano. The firm has also audited consensus-critical software, including the Prysm and Teku Ethereum clients.
Multiple Ethereum Foundation grants for scaling research reinforce Quantstamp's credibility at the protocol level. Its reports are known for detailed treatment of subtle risks such as transaction-ordering dependence and timestamp manipulation. This rigor appeals to institutional DeFi teams that need documentation able to withstand investor and regulator scrutiny.
A long operating history also leaves more opportunity for incidents to occur. The rekt leaderboard records exploits at previously audited Alpha Finance and Rari Capital totaling more than $47 million. Quantstamp's extensive public report archive at least allows prospective buyers to assess its current methodology directly.
Pros
- Protocol-level experience includes Ethereum consensus clients.
- Extensive public report archive supports buyer due diligence.
- Chain-agnostic coverage spans EVM and non-EVM ecosystems.
Cons
- Standardized process can feel generic for exotic designs.
- Two significant post-audit incidents sit on the rekt leaderboard.
- Clients must actively scope admin and deployment risks.

Smart Contracts Explained Simply
Smart contracts are blockchain-based programs that execute automatically when predefined conditions are satisfied. Enforceable code replaces intermediaries such as banks and escrow agents. These contracts power token swaps, lending markets, gaming economies, DAO governance, and other applications across every major network.
Permanence is one of their defining characteristics. Once deployed, contract logic generally cannot be quietly patched like traditional software. A single flawed assumption can remain available for attackers to study indefinitely, while billions of dollars may sit behind only a few thousand lines of immutable code.
The code is public as well. Anyone can inspect contract bytecode through explorers such as Etherscan and observe the crypto wallet addresses interacting with it. Attackers therefore operate with perfect information. Most exploits are ordinary software failures exposed to adversaries who have unlimited time to investigate them and can receive instant payouts.

What is a Smart Contract Audit?
A smart contract audit is an independent security review in which external experts examine a protocol's source code before or after deployment. Its purpose is to verify that the contract performs exactly as its documentation promises without exposing behavior an attacker could exploit.
Each finding is documented with a severity rating and proof-of-concept attack path, followed by concrete remediation guidance. The industry relies primarily on two complementary approaches. Serious projects generally use both instead of treating them as alternatives.
1. Manual code review audits
Manual audits depend on human reasoning. Senior researchers read the codebase line by line and map trust boundaries between components. They also test whether stated invariants survive adversarial conditions. Business-logic flaws, broken authorization paths, and dangerous upgrade patterns often emerge here because they rarely match scanner signatures.
A strong manual review looks beyond individual contracts to the way modules interact. Reviewers trace value through routers, proxies, oracles, and admin roles, then simulate realistic attack narratives that can include economic pressure scenarios. Once remediation is complete, they verify the fixes. This depth makes manual review mandatory for any protocol holding meaningful capital.

2. Automated and formal-method audits
Automated analysis can explore enormous numbers of execution paths within minutes by using static analyzers, fuzzers, and invariant testing. Tools such as Slither and Echidna reliably identify reentrancy, integer issues, and unchecked return values. Developers can eliminate these common mistakes early, before spending expensive human-review hours.
Formal verification goes further. It mathematically proves that specified properties hold under a defined model, which is particularly valuable for high-stakes components such as vault accounting or bridge state machines. Proofs, however, are only as reliable as the specifications behind them. Formal methods therefore complement experienced human judgment rather than replacing it.
How to Audit a Smart Contract
A disciplined audit methodology helps ensure vulnerabilities are identified, prioritized, and verifiably resolved before code begins handling real user funds on a live network.
Professional security teams work through these seven stages:
- Documentation Review: Auditors study the whitepaper, specifications, and architecture diagrams to establish how the system is intended to behave. A flaw can only be defined in relation to what the code is supposed to do.
- Automated Analysis: Static analyzers and fuzzers scan the codebase for common vulnerability patterns, clearing routine issues quickly so senior reviewers can focus on problems machines cannot detect.
- Manual Logic Inspection: Experienced researchers work through the code line by line and trace value flows alongside permission boundaries, looking for business-logic and economic flaws specific to the protocol's design.
- Vulnerability Categorization: Each confirmed issue receives a severity rating ranging from critical to informational. This gives developers an objective basis for deciding which fixes must be completed before launch.
- Initial Report Delivery: The team receives a detailed document covering each finding, its exploit scenario, and specific remediation guidance. That report becomes the working checklist during patching.
- Remediation Phase: Developers address each finding, ideally adding fresh test coverage, while documenting accepted risks when the team deliberately chooses not to alter behavior.
- Final Verification: Auditors inspect every patch again to make sure the issue was actually resolved and that the fix introduced no new vulnerabilities before the final report is published.

Smart Contract Security Trends in 2026
The threat landscape in 2026 differs materially from the environment for which many audit methodologies were originally designed. Attackers have moved upstream, while auditors are rapidly industrializing their own tooling with artificial intelligence.
Those changes need to influence engagement scope. A review designed around 2022-era threats can fail to examine the vectors that are draining protocols today.
Attackers Are Moving Beyond the Code
CertiK's H1 2026 data identifies wallet compromise as the most destructive vector, responsible for $444 million in losses across only 33 incidents. The total was led by the $291 million KelpDao RPC compromise. Phishing accounted for another $366 million, with four precision social-engineering operations causing roughly 85% of those losses by targeting carefully selected high-value victims.
Code vulnerabilities were still the most common category, appearing in 204 incidents, yet they caused a comparatively modest $152 million. A growing share involved contracts more than a year old as attackers systematically returned to legacy deployments. Chainalysis meanwhile attributes $2.02 billion of 2025's thefts to North Korean state actors.
Audit scope now needs to include key management and deployment infrastructure alongside operational security and Solidity. Firms that offer penetration testing, monitoring, and incident response are addressing the places where losses actually happen rather than merely padding invoices. Buyers should account for that shift when comparing engagement proposals.

AI Enters the Audit Stack
Artificial intelligence changed both attack and defense in 2026. Nearly every major firm now offers AI-assisted products while maintaining that experienced human researchers retain final judgment over findings.
Here is how AI is changing smart contract security this year:
- Assisted review: Platforms like Sherlock AI and Cantina's AI-native analysis pre-scan codebases for known patterns so human researchers can devote limited review hours to novel logic flaws.
- Finding triage: Machine learning models automatically deduplicate and severity-rank thousands of contest submissions, shortening judging timelines that once consumed weeks of senior researcher attention for each competition.
- Formal verification: AI assists with generating the mathematical specifications required by proof engines, reducing the historical cost barrier that limited formal methods to the wealthiest protocols.
- Attacker tooling: Adversaries use the same models to scan deployed bytecode for exploitable patterns at scale, partly explaining the 2026 increase in attacks on older, forgotten contracts.
- Agent security: Protocols increasingly integrate AI agents that hold keys and execute transactions. Firms such as CertiK now offer dedicated products that evaluate third-party agent skills before execution.
- Human oversight: Credible firms still send AI-generated output through experienced researchers because models can confidently hallucinate vulnerabilities while missing economic attacks that depend on genuine contextual reasoning.

How to Choose a Smart Contract Auditor
Choosing an auditor is fundamentally an exercise in risk management. You are buying expert adversarial attention before real attackers receive their opportunity on mainnet. Evaluating expertise, track record, timelines, and cost in a structured way reduces the risk of an expensive mismatch.
Step 1: Evaluate Technical Expertise
Match demonstrated experience to your exact stack. Even excellent Solidity reviewers may overlook critical issues in Rust, Cairo, or Move codebases.
Key factors to consider during this evaluation:
- Language Mastery: Confirm deep, recent experience with your specific language, whether Solidity, Vyper, Rust, or Move, and look for published reports within that ecosystem.
- Architecture Fit: Verify that the team has audited comparable designs. Lending markets, cross-chain bridges, and NFT infrastructure each present different failure modes.
- Advanced Tooling: Ask which fuzzers, static analyzers, and formal verification engines the team routinely uses, as well as whether it builds or simply licenses its toolchain.
- Research Output: Favor firms that publish vulnerability research and contribute open-source tooling. Active researchers are more likely to stay current as attack techniques change between engagements.
Step 2: Analyze Security Track Record
Marketing metrics carry little weight without independent verification. Before building a shortlist, compare each claim with public audit reports and neutral incident databases.
Evaluate these metrics to gauge their reliability:
- Post-Audit Incidents: Search the rekt leaderboard for exploits involving previously audited clients. Then determine whether the flaw was in-scope, out-of-scope, or added after the review.
- Report Transparency: Give preference to firms that publish complete reports. Hidden findings and vague summaries make actual review depth difficult to judge.
- Client Caliber: Look for repeat business from sophisticated buyers such as exchanges, L1 foundations, and blue-chip protocols, since informed returning clients provide a meaningful quality signal.
- Verified Scale: Treat assets-secured totals as directional marketing. Give more weight to countable facts such as published reports, named clients, and researcher rosters.

Step 3: Assess Delivery Timelines
Launch schedules can determine the shortlist on their own. Leading private-audit firms may be booked for weeks or months, whereas competitive platforms can sometimes begin within days.
Consider these points regarding scheduling and speed:
- Booking Queues: Request the earliest realistic start date in writing. During busy seasons, prestigious firms often quote waits of four to twelve weeks.
- Review Duration: Match the expected timeline to the scope, ranging from days for simple tokens to as much as two months for complex bridges or novel architectures.
- Fix Verification: Check that the quote covers re-reviewing patches. An audit without remediation verification leaves the most dangerous part of the process unexamined.
- Emergency Response: Establish whether rapid support is available for live incidents or urgent patches, preferably backed by contractual response-time commitments.
Step 4: Compare Pricing Structures
Audit spending should reflect the value at risk rather than what competing projects happen to pay. Knowing what drives the quote also makes it easier to negotiate scope intelligently instead of simply accepting a number.
Factors that influence the total cost include:
- Codebase Size: Pricing is based primarily on source lines of code and architectural complexity. Removing dead code before scoping can therefore reduce the invoice directly.
- Methodology Depth: Formal verification and multi-researcher teams cost more than standard review. Those premiums are justified mainly for components securing significant or irreversible value.
- Brand Premium: Established firms charge considerably more than emerging boutiques. Sometimes that premium buys deeper talent; in other cases, it buys little more than the logo on the report.
- Ongoing Retainers: Continuous monitoring, bounty management, and scheduled re-audits turn security into an operating expense. For actively developed protocols, this model frequently outperforms a one-off review.
How Much Does a Smart Contract Audit Cost in 2026?
Smart contract audit pricing spans two full orders of magnitude in 2026. Quotes vary with codebase size and architectural complexity, along with urgency and the reputation tier of the firm hired.
Typical 2026 price ranges break down as follows:
- Simple tokens: Standard ERC-20 or basic NFT contracts generally run $5,000 to $15,000 with boutique firms and often finish within a single working week.
- Standard DeFi: Staking systems, vaults, and mid-complexity protocols usually cost $25,000 to $100,000. Most serious lending or DEX engagements fall within this range.
- Complex systems: Bridges, zero-knowledge circuits, and novel architectures commonly reach $80,000 to $250,000+, reflecting the multi-week work and multiple researchers these attack surfaces genuinely require.
- Audit contests: Competitive platforms use prize pools that range from roughly $20,000 to $200,000, while flagship competitions such as Uniswap v4's have exceeded $2 million.
- Formal verification: Mathematical proof work adds a meaningful premium to standard review pricing and is usually reserved for vault accounting, bridges, and consensus-critical components.
- Continuous security: Monitoring subscriptions, managed bounties, and retainer re-audits introduce recurring costs. Increasingly, these services separate protocols that were audited once from those practicing ongoing security.

Common Smart Contract Vulnerabilities
Most exploits repeat familiar patterns. Understanding those categories helps developers write more defensive code while giving buyers a way to check whether an audit proposal covers the right attack surfaces.
These are the most damaging vulnerability classes in 2026:
- Reentrancy Attacks: External calls that re-enter a contract during execution continue to claim victims, from The DAO through GMX's $42 million 2025 exploit.
- Access Control Failures: Missing or incorrectly configured permissions can allow attackers to invoke privileged functions. This was a factor in the $197 million Euler Finance exploit and countless smaller drains.
- Math and Rounding Errors: Precision flaws in pool arithmetic drove Balancer's $128 million loss in late 2025 as well as the $223 million Cetus overflow exploit on Sui.
- Oracle Manipulation: By distorting price feeds, attackers can borrow against artificially inflated collateral. This was the mechanism behind Mango Markets' $115 million drain and many later attacks.
- Flash Loan Exploits: Uncollateralized instant loans give attackers access to enormous capital within a single transaction, allowing minor pricing or accounting flaws to be amplified into complete drains.
- Proxy Upgrade Abuse: Weakly secured upgrade paths can enable malicious logic swaps, as occurred when ZKasino redirected $33 million of user deposits through an unauthorized change.
- Key and Infrastructure Compromise: Stolen signing keys and hijacked RPC endpoints produced 2026's largest losses, including KelpDao's $291 million incident, while bypassing contract logic altogether.
- Cross-Chain Bridge Flaws: Signature verification gaps and message-passing bugs keep bridges among the most persistent targets. Wormhole's $325 million hack remains the defining example.
Users also need to review their own exposure regularly. One practical starting point is learning how to revoke token permissions for contracts they no longer trust.

Final Thoughts
For a blockchain team, choosing a security partner remains one of the highest-leverage decisions available. A single missed vulnerability can erase the results of every other growth effort.
No audit can guarantee safety. Data from 2026 also shows that attackers increasingly bypass contract code altogether. Even so, layered reviews from reputable firms dramatically reduce the category of preventable failures.
Protocol users can apply the same standard when evaluating projects. Multiple independent audits, active bounties, and continuous monitoring are stronger signals than a single dated PDF.
Our Methodology
We reviewed smart contract auditing companies that remained active and accepting new engagements in August 2026. Claims were verified against primary sources rather than marketing pages. The ranking uses six criteria:
- Trust score: Datawallet's rating out of 5 weighs verified audit output, researcher depth, report transparency, and how each firm has handled incidents at previously reviewed clients.
- Post-audit track record: Every firm was cross-checked against the rekt.news leaderboard. We recorded each attributed incident and then reviewed the original engagement scope to determine whether the exploited code had actually been examined.
- Verified metrics: Audit counts, assets-secured figures, and researcher numbers were sourced from each company's official website and published reports in August 2026. Figures that cannot be independently confirmed are flagged.
- Scope of services: We examined what each engagement includes, covering manual review depth and formal verification as well as monitoring, bounty management, incident response, and post-remediation fix verification.
- Ecosystem coverage: Chain and language support was checked through published reports rather than broad claims. Genuine expertise in Solana, Move, or ZK systems should be visible in a firm's public output.
- Market relevance: We considered 2026 demand signals such as flagship Ethereum Foundation hard-fork reviews and exchange compliance work under MiCA, along with adoption of contest and AI-assisted models.
Research concluded in early September 2026, and each firm's active status was re-verified on the publication date. Our editorial methodology explains how each claim was verified.






