Coinbase

Solady Smart Contract Library Audit

Cantina Security Report

Organization

@Coinbase

Engagement Type

Spearbit Web3

Period

-


Low-Level Solidity Library Review of Solady

Solady is a gas-optimized Solidity library used by Coinbase and others to build secure and efficient smart contracts. It includes reusable components for signature validation, ERC4337 account abstraction, upgradeable infrastructure, and calldata decoding tailored to advanced protocol needs.

To validate system safety and reduce the risk of integration bugs, Coinbase engaged Spearbit through Cantina for a security audits review of Solady. The assessment covered critical paths in SignatureCheckerLib, Lifebuoy, ERC721 and ERC4337 components, as well as the Timelock and P256 verification libraries.

Cantina also helps teams secure widely adopted tooling with bug bounty programs, crowdsourced security competitions, and multisig security, reinforcing the safety of shared infrastructure across Web3 ecosystems.


Findings

Critical Risk

2 findings

2 fixed

0 acknowledged

High Risk

3 findings

3 fixed

0 acknowledged

Medium Risk

7 findings

5 fixed

2 acknowledged

Low Risk

8 findings

8 fixed

0 acknowledged

Informational

24 findings

20 fixed

4 acknowledged

Gas Optimizations

11 findings

6 fixed

5 acknowledged