RFP

Independent Smart Contract Audit for Solana Subscription Program

bid window closed
Share
preview · how your link unfurls
tendr.bid
BIDS SEALED
Independent Smart Contract Audit for Solana Subscription Program
buyer · harp.tendr.sol
BID CONTENT PRIVATE
BIDDER PRIVATE
$0
value
0
milestones
0
bids
Jun 17
bids ended
sealed-bid procurement · solana

Objectives

  • Conduct a comprehensive security audit of the Smart Contract for the Solana Foundation's Subscription Program, focusing on vulnerabilities, code quality, and compliance with best practices.
  • Identify and document potential security risks, including but not limited to reentrancy, overflow/underflow, unauthorized access, and improper state management.
  • Provide actionable recommendations to mitigate identified risks and ensure the contract is secure for production use.

Deliverables

  • Detailed security report outlining findings, vulnerabilities, and risk assessment.
  • List of mitigation strategies and recommendations for improving contract security.
  • Summary of code quality metrics, including code complexity, maintainability, and adherence to Solana best practices.
  • High-level summary of the contract's functionality and critical pathways that were reviewed.

Milestones
Milestone 1: Initial Review — Conduct a high-level analysis of the contract's structure, logic, and interactions with the Solana blockchain.
Milestone 2: Deep Dive — Perform a detailed code review, focusing on critical functions, state transitions, and external calls.
Milestone 3: Risk Assessment — Evaluate identified vulnerabilities against established security frameworks and provide a prioritized risk assessment.
Milestone 4: Reporting — Finalize the security report, including recommendations, mitigation strategies, and a summary of the contract's security posture.

Success criteria

  • The security report must be complete, accurate, and include a thorough analysis of the contract's security state.
  • At least 90% of the contract's code must be reviewed and analyzed for security and quality concerns.
  • The report must include a prioritized list of mitigation strategies that are feasible and effective for improving the contract's security.
  • The contract must be deemed secure enough for production use based on the audit findings and recommendations.

Out of scope

  • The audit does not include testing the contract against external attacks or simulating real-world scenarios.
  • The audit does not cover the integration of the contract with other systems or third-party services.
  • The audit does not include the review of non-contract components such as front-end interfaces, APIs, or user authentication mechanisms.
Contract value

-

Set when the buyer awards a winning bid.

0 sealed bids committed

Lifecycle
BiddingRevealAwardedFundedActiveCompleted
Bidding closes
Award by

Bid window expired - buyer can flip to reveal.

How does this lifecycle work?
Bid window opened 2026-06-12T14:52:03.000Z
On-chain references