A security audit designed to protect onchain teams facing
unprecedented cyber risk.
What the tier includes
A single audit, full security coverage
Every update re-enters the same loop
Two independent teams, one scope.
Team A uses expert manual review and gets the most out of the fuzzing suite. Team B directs billions of tokens throughout every corner of the codebase to uncover all AI-findable findings.
Competitive incentives reward whichever team finds more, and each team cross-checks the other.
Meet our world-class researchersHelix, the leading AI Auditor.
Helix powers one of the two Keel Formal teams on the audit with an exhaustive search throughout the entire codebase, spending billions of tokens and several days across hundreds of parallel agents.
Humans verify the context, configuration, and depth. Only human verified findings become the final result.
An exhaustive invariant suite around your safety properties.
Keel Formal writes the protocol’s core safety properties as executable invariants, then pressure-tests every reachable state against them. The suite outlives the audit as a reusable harness for fixes, retesting, and every change you ship afterwards.
During the course of the review Security Researchers leverage the fuzzing suite to uncover edge cases that can hardly be found by AI or manual methods.
Keel Formal Funds a $100,000 contest for AI & Human Auditors
The public Defender contest opens the audited scope to a global network of independent security researchers and AI Auditors.
Keel Formal covers a Critical findings pot of $100,000, paid out for any critical severity issue on the scope. Clients can opt to add additional funding for lower severities if desired. Timeline is adjustable, typically lasts 20 days and is non-blocking for deployment.
A hosted bounty with $50,000 in matching.
Keel Formal hosts and manages the bug bounty for you, including $50,000 in Critical bounty matching, so the protocol stays covered. You put up $50,000 and Keel Formal matches it on your bounty.
Benefit from tuned AI triage and known issue tracking, tapped in to the audit process.
Half the package cost back toward offchain risk.
The weakest link is rarely Smart Contracts.
Half of the package cost comes back as credits toward Keel Formal’s offchain assessments — spend it across any combination of the six below to close the offchain gaps.
- OpSec Audit Drift · $285M (read the incident write-up) Signers tricked into blind-signing
- Infrastructure Pentest Mixin · $200M (read the incident write-up) Cloud provider’s database breached
- WebApp Pentest Crypto.com · $34M (read the incident write-up) Withdrawals approved with 2FA bypassed
- API Pentest 3Commas · $22M (read the incident write-up) Exchange API keys stolen and traded
- Offchain Automation Pentest THORChain · $10M (read the incident write-up) Offchain threshold signing broken
- Perimeter Audit CoW Swap · $1.2M (read the incident write-up) Registrar hijacked, frontend swapped
Six months of update review, included.
Ship code to the same scope and Keel Formal keeps reviewing it. For six months after production, up to 2,500 smart contract SLOC, or 10,000 SLOC for offchain codebases. Every change is audited at the same standard.
No matter your shipping cadence, review any changes made to the scope we reviewed up to the SLOC limit (2,500 onchain or 10,000 offchain) split up however you would like.
Protect your systems against the incoming AI threat
Today’s audit demands
Because in 2026, security demands nothing short of 100% coverage.
Agentic cyber threats are mounting, any small opening can and will be exploited for maximum gain.
The problem with a “good” audit
2 squares unreached In 2026, 96% coverage is not secure for customer deposits.
Unreached Covered by Vanguard
The Solution
The Vanguard audit model
- 01 Team A Expert manual review
- 02 Team B Frontier AI, billions of tokens
- 03 Fuzzing Exhaustive invariant suite
- 04 Defender contest $100K reinforcement
- 05 Web2 security Offchain surface closed
- 06 Bug bounty Protective perimeter
- 07 Post-launch updates review Changes re-covered
See what 100% coverage looks like for your system.
Track record
By the numbers
Bring us your highest-value system.
Vanguard is a security audit designed to protect onchain teams facing unprecedented cyber risk.



