Proof of Audits
Back

Check Contract Proof Before a Wallet Decision

The public checker and API show whether an exact contract has attested deployment proof, what changed, and what evidence is missing. Wallet integrations can use the same result contract before signing.

Public service state

Contract checker active

Exact chain + address query. Timestamped verdict. Inspectable reason codes.

Unknown stays unknown

A registry miss is reported as insufficient evidence, not converted into a safety claim.

Use the live checker

Proof of Audits does not guarantee safety. The proof service reports evidence, gaps, and risk signals for an exact contract target.

Live public proof service

Check one deployed contract.

Query the public Proof of Audits registry for an exact chain and address. The result is generated by the live API, not embedded page copy.

Public endpoint

Prefilled with the Aave V4 Core Hub from the public evidence record. A registry miss means Proof of Audits has not published an attested scope for that address. It is not a vulnerability finding.

Reading the public contract registry

This already happened

Wallet warnings need current proof, not audit claims alone.

Frozen withdrawals. Emergency war rooms. Funds gone. Every number here is someone who trusted a badge, a PDF, or a claim — and found out too late that the code, the bridge, or the signer was not what they thought. Proof has to be visible before the signature, not reconstructed after the loss.

2026 losses
$1.1B+

$1.1B gone. By June. In one year.

Not one bug. Not one protocol. Live code, control keys, bridges, signers — every path where trust breaks down before the user can see it. Bitrue reported that 2026 crypto hack losses had surpassed $1.1B by June 11.

Bitrue, June 2026
Hidden source
$36.7M

Hidden source code. $36.7M stolen. Users never saw it coming.

If nobody can see the deployed code, everyone is trusting a black box. Chainalysis found at least $36.7M stolen in six months from protocol-owned contracts with unverified source code.

Chainalysis, June 2026
Bridge proof gaps
$340.7M

$340.7M drained through bridges. One missing check, 14 incidents.

Cross-chain bridges failed 14 times in 2026, including the roughly $292M KelpDAO/LayerZero incident. One missing verification layer became a liquidity shock across chains.

CoinGabbar / PeckShield, June 2026
Why verified channels matter
76%

Real loss: of crypto hack value through April 2026 came from two DPRK-linked attacks, per TRM Labs

Extensions from unknown sources can inject malicious code into wallet interactions. Control-plane compromise is now a major loss path — and 76% of 2026 hack value came from just two state-linked attacks.

Public access paths.

The contract checker and public API are available now. They expose the same evidence contract a wallet integration can use, while keeping raw results open for inspection.

Live now

Web contract checker

Anyone can submit an EVM chain and contract address and inspect the registry result without logging in or connecting a wallet.

Live API

Public proof endpoint

The same public endpoint returns a machine-readable verdict, reason codes, deployment context, and an exact check time.

Available

Wallet integration contract

Wallet clients can consume the proof result. Current public access is the web checker and API, with no unverified install file required.

How wallet integrations use the proof service.

It moves proof from a dashboard into the wallet decision moment, so a user can see the live contract match, key control, missing evidence, and full proof trail before continuing.

Deployment match

Shows whether the contract and proxy implementation still match the reviewed code, or whether the live deployment changed.

Authority keys

Shows who can upgrade, pause, or control critical runtime paths when authority proof exists.

Missing proof

Flags unknown contracts, unpublished code-hash proof, pending deployment review, unresolved findings, and stale evidence.

Full passport

Links from the wallet moment into the full protocol proof page, so users can inspect the evidence before continuing.

$340.7M

lost across 14 bridge attacks where signing-time dependency context would matter

Why signing-time detection matters

The wallet popup says 'Confirm Transaction.' Nothing about the bridge dependency, the verifier quorum, the source verification, or the admin powers. By the time users manually research, the decision is already on-chain.

Proof, gaps, and risk signals before interaction.

The workflow is simple: detect the target, check the proof registry, compare live deployment state, show evidence, and warn when proof is missing or stale.

01

Detect request

A wallet integration reads the chain, target contract, method, and transaction context before the signing decision.

02

Check registry

The exact address is checked against finalized protocol proof, deployment records, and known contract state.

03

Match deployment

Runtime bytecode, proxy implementation, and audited scope must match before a green verdict is shown.

04

Show evidence

The result returns the evidence state, reason codes, and Trust Passport link when public proof exists.

05

Warn clearly

Changed, mismatched, unknown, or high-risk contracts receive a review signal before the user continues.

Why wallet-time signals matter
$292MKelpDAO/LayerZero was the largest single 2026 bridge incident in CoinGabbar's PeckShield-cited roundup

The trust evidence was buried in dashboards and audit pages. It never appeared at the moment the wallet asked for a signature — exactly when the user needed it most.

CoinGabbar 14 Bridge Attacks 2026

Wallet integrations place protocol proof at the signing moment.

The investor page is for comparison. Contract Shield is for the moment when a wallet request needs a decision.

Signal

External Deployed ITS v2 /900 score

Signal

Runtime bytecode and proxy implementation match

Signal

Changed deployment and UNVERIFIED_UPGRADE warnings

Signal

Trust Passport, VTI, and on-chain publication state

Signal

Authority-key evidence and pending key changes

Signal

Wallet request decision before signing

$11.4MVerus-Ethereum Bridge (May 2026) — drained via bridge signature logic gaps that a clear verdict system could flag
Why clear verdicts matter

The wallet showed pass or fail — but not what was verified, what was missing, or what changed since the last audit. A clear verdict system could have flagged the exact gap that got exploited.

CoinGabbar 14 Bridge Attacks 2026

Clear contract verdicts without safety overclaims.

Verified Match

This contract matches a finalized audited scope.

Audited Scope, Deployment Pending

Audit evidence exists, but deployed-code verification is not finalized yet.

Known Protocol, Changed Contract

This protocol is known, but the contract or implementation has changed since the audit.

Scope Mismatch

This contract does not match the audited scope.

Unknown Contract

No Proof of Audits evidence was found for this contract.

High-Risk Signal

A warning signal was found that should be reviewed before continuing.

Proof of Audits does not guarantee safety. The proof service reports evidence, gaps, and risk signals for an exact contract target.