Solady Smart Contract Library Audit
Cantina Security Report
Organization
- @Coinbase
Engagement Type
Spearbit Web3
Period
-
Repositories
Researchers
Low-Level Solidity Library Review of Solady
Solady is a gas-optimized Solidity library used by Coinbase and others to build secure and efficient smart contracts. It includes reusable components for signature validation, ERC4337 account abstraction, upgradeable infrastructure, and calldata decoding tailored to advanced protocol needs.
To validate system safety and reduce the risk of integration bugs, Coinbase engaged Spearbit through Cantina for a security audits review of Solady. The assessment covered critical paths in SignatureCheckerLib, Lifebuoy, ERC721 and ERC4337 components, as well as the Timelock and P256 verification libraries.
Cantina also helps teams secure widely adopted tooling with bug bounty programs, crowdsourced security competitions, and multisig security, reinforcing the safety of shared infrastructure across Web3 ecosystems.
Findings
Critical Risk
2 findings
2 fixed
0 acknowledged
High Risk
3 findings
3 fixed
0 acknowledged
Medium Risk
7 findings
5 fixed
2 acknowledged
Low Risk
8 findings
8 fixed
0 acknowledged
Informational
24 findings
20 fixed
4 acknowledged
Gas Optimizations
11 findings
6 fixed
5 acknowledged