Blog

Espresso – Batch Authenticator Contract

Espresso Systems requested that we perform a security audit of its Batch Authenticator Contract, which is written in Solidity. Our final audit report was completed on August 13, 2026. To read the full report, including our findings, click here: Report

Read More »

Espresso – Derivation Pipeline Changes

Espresso Systems requested that Least Authority perform a security audit of its derivation pipeline changes for the OP Stack (Go and Rust). Our final audit report was completed on August 11, 2026. To read the full report, including our findings, click here: Report

Read More »

Aligned Layer – Airdrop Contract

Aligned Layer requested that Least Authority perform a security audit of its ClaimableAirdrop.sol contract. ClaimableAirdrop enables Aligned Layer to distribute tokens to early users in a gas-efficient manner by requiring users to provide a Merkle proof when claiming tokens. Our final audit report was completed on July 21, 2026. To

Read More »

Serai – Distributed Key Generation

MAGIC Grants requested that Least Authority perform a security audit of the implementation of Serai’s Distributed Key Generation (DKG), which is premised on Publicly Verifiable Secret Sharing. Serai is a decentralized exchange (DEX) that allows users to trade assets across heterogeneous blockchains through a liquidity-pool (AMM) trading model. Our final

Read More »

Sovright – Argos

Sovright requested that Least Authority perform a security audit of Argos, a recovery workspace for legacy ZecWallet Lite seeds. The application consists of a Rust-based core library, a command-line interface, and a graphical user interface built using Tauri. Its primary function is to scan the Zcash blockchain and perform large-scale

Read More »

AI-Assisted Security Auditing in the Zcash Ecosystem

Least Authority recently conducted an AI-assisted security audit across several security-critical repositories in the Zcash ecosystem at the request of Zcash Community Grants (ZCG). The goal of this work was to explore how AI-assisted workflows can support security review at scale while still relying on careful human verification before any

Read More »

Security Audits, Managed Crowdsourced Security, and Bug Bounty Programs: Complementary, Not Interchangeable

Security audits, managed crowdsourced security platforms, and open bug bounty programs are often treated as interchangeable approaches to security testing. In practice, they serve different roles. While crowdsourced approaches and bug bounty programs are effective at uncovering vulnerabilities in deployed systems, both remain inherently exploratory rather than systematic. Security audits

Read More »

Anza Technology – BLS Signatures Crate

Anza Technology has requested that Least Authority perform a security audit of the BLS Signatures Crate. For this audit, we performed research, investigation, and review of the solana_bls_signatures and solana_bls12_381_syscall crates followed by issue reporting, along with mitigation and remediation instructions as outlined in this report. Our final audit report

Read More »
Archives