Deloitte
Deloitte is one of the world's largest and most established professional services firms,...
Vidma is a blockchain security audit company founded in 2019, positioning itself as a leader in smart contract security for EVM-compatible ecosystems including Layer 1 and Layer 2 protocols. The company is headquartered in San Rafael, California, with its core engineering team based in Ukraine — a country recognised for its strong cryptographic and cybersecurity culture.
Vidma began conducting smart contract audits in October 2019, initially operating under partner company brands for its first 105 audits before launching under its own brand in 2022. The firm has since completed 149 audits, served 103 clients, and identified 1,327 total security issues across projects spanning DeFi protocols, token contracts, bridges, launchpads, wallets, exchanges, and marketplaces.
Vidma's primary service offering is Smart Contract Audits — comprehensive security reviews that combine manual code analysis, static analysis tooling, and testing to identify vulnerabilities across severity levels (critical, high, medium, low, informational). The audit process is structured across four phases: research, manual review, testing, and final report formation. Auditors cross-review each other's work, and clients receive a retest after fixing flagged issues. Vidma operates a proprietary transparent scoring system where a score out of 100 is calculated based on the severity and resolution status of identified issues.
The company also offers Ongoing Code Review — a subscription-based security service that integrates a Vidma auditor directly into a client's development workflow. Auditors review each significant code commit and charge per line of code changed rather than by time, making it a cost-efficient option for projects with active, iterative development cycles. Subscribers also receive a discount on full smart contract audits.
The third service is Penetration Testing for blockchain applications, wallets, exchanges, and platforms with rich interfaces. Vidma's ethical hackers simulate real-world attacks across five stages (planning, scanning, exploitation, persistence, reporting) using black-box, white-box, or grey-box approaches.
Vidma publishes its audit portfolio publicly, including sample reports. Recent audits include smart contract security assessments for DeFi protocols implementing multi-approver consensus mechanisms and reward distribution contracts. The firm is an ongoing security partner for multiple projects following initial audits.
Vidma differentiates itself through a rigorous, multi-phase audit methodology, a transparent proprietary scoring system, and flexible engagement models suited to both one-time pre-launch audits and continuous development partnerships. With 149 completed audits and a team rooted in a country with a globally recognised cybersecurity culture, Vidma offers both depth of expertise and a track record of uncovering critical vulnerabilities before they can be exploited.
Share your experience working with Vidma by leaving a review.
Leave a ReviewThis partner has been verified by Web3Connect on 17 Mar 2026
Founded
2019
Team Size
6-9 employees
Vidma provides comprehensive smart contract security services for EVM-compatible...
25 Belle Avenue, San Rafael, California, USA 94901, San Rafael, California, United States
Deloitte is one of the world's largest and most established professional services firms,...
The UCL Centre for Blockchain Technologies (UCL CBT) is a leading European academic...
EY Blockchain is the blockchain technology division of Ernst & Young (EY), one of the...
Founded in 2012, Trail of Bits is a leading cybersecurity research and consulting firm...
Crowe LLP is a leading public accounting and consulting firm that provides comprehensive...
Nadcab Labs is a global blockchain and AI technology company founded in 2017, delivering...