FORMAL VERIFICATION

Formal verification with our own tooling

We’ve built out our own tooling and developed a novel verification framework for Solana. We’ve also worked with the Aptos core team to formally verify their standard library.

$1.00B+ Vulnerabilities patched66% Core-severity findings120+ Projects audited

PROOF

What a client said

“Having OtterSec as a security partner has been a fantastic experience for us. They are diligent, fast, creative and very responsive. Basically everything one could ask from a security audit firm.”
Stepan SimkinSquads

WHAT WE’VE PUBLISHED

Formal methods research

Formal verification is one of three techniques on our services page, alongside pentesting and fuzzing.

Anchor program verification

Our research presents a novel framework for formal verification of Solana Anchor programs, with a case study on the Squads multisig.

The Move Prover

We published “The Move Prover: a guide” on our blog.

Limits of formal methods

Robert Chen’s Breakpoint 2023 talk covered why fuzzing and formal verification miss business logic exploits, and the mitigations that catch them.

Choosing the mix

Different systems call for different techniques, so formal verification is used where it fits your system.

QUESTIONS

Questions about formal verification

What formal verification has OtterSec done?

We’ve built out our own tooling and developed a novel verification framework for Solana, and worked with the Aptos core team to formally verify their standard library. Our audits page also lists a K-Lend Formal Verification report.

HOW IT WORKS

From first call to final report

  1. 01

    Initial discussion

    We’ll discuss your goals, timeline, and security needs to see whether we’re a fit.

  2. 02

    Kickoff

    We’ll begin the audit, share findings as they emerge, and ask questions as needed.

  3. 03

    Report delivery

    At completion, we will send you a report with our findings and suggestions for fixes.

READY TO START

Talk to us about verification

We pick the mix of techniques that fits your system, then put our collaborative approach to work on it.

Get an audit