Formal verification at every level of complexity

Hackers look for what testing and audits can miss.

From automated checks to tailored formal proof.

Whatever your smart contract token, stablecoin, or complex protocol Dowsers provides the right level of formal verification. Depth scales with complexity. Results are mathematically proven, not estimated.

1m–1h
Standard ERC-20 analysis
1–3d
Findings or non-standard logic
1–2w
Specific token properties
~1mo
Complex protocol engagement

Engagement Scope

The timeframe depends on what needs to be proven.

A standard ERC-20 can be checked almost instantly. As soon as findings, non-standard mechanics, economic rules, or multi-contract architectures enter the picture, the work shifts from automated analysis to expert interpretation and custom specification.

01
1 minute to 1 hour
Instant analysis

Standard ERC-20 token

For a simple and relatively standard ERC-20, analysis can be almost instant: from a few minutes to around one hour. This is the typical case for a token with no complex logic, no unusual mechanisms, and no significant findings. The goal is to provide a first automated level of assurance quickly, based on generic ERC-20 properties. In practice, a timeout of around one hour avoids properties running indefinitely. For slightly more complex contracts, a 2 to 3 hour window may be more realistic.

02
1 to 3 days
Engineering review

ERC-20 with findings or non-standard logic

When an ERC-20 generates findings, they go through an engineering review before being definitively qualified. This helps avoid false positives, contextualize results, and distinguish actual vulnerabilities from intentional contract behavior. For a standard token, one day may be enough. If the token includes vault logic, fees, restrictions, upgradeability, or proprietary mechanisms, it is more prudent to communicate a 1 to 3 day timeframe, also depending on engineering team availability.

03
1 to 2 weeks
Specific properties

Stablecoin or sensitive token

For a stablecoin, sensitive token, or asset with specific economic rules, the analysis is no longer limited to generic properties. Specific properties must be defined and verified: balance conservation, mint and burn permissions, reserve-related guarantees, freeze mechanisms, transfer rules, economic invariants, or constraints specific to the project model. This requires interpretation, specification work, and sometimes discussions with the client’s team. A realistic timeframe is therefore closer to 1 to 2 weeks.

04
Around 1 month
Tailored FV

Complex protocol or interconnected contracts

For DeFi, lending, AMM, vault, staking, bridge, or multi-contract architectures, the analysis becomes a tailored formal verification engagement. It requires understanding the architecture, identifying critical invariants, modeling relevant scenarios, writing or adapting properties, and interpreting the results. One month is a good reference timeframe for a complex case. A simpler protocol may sometimes be completed in around two weeks, while very large protocols — or engagements with 50 to 100 critical properties — may extend to 3 to 4 months.

What changes with complexity

Generic checks become custom properties.

The more the asset depends on economic logic, permissions, or cross-contract behavior, the more the engagement focuses on defining what correctness actually means for that system.

Token invariants

Balance conservation, transfer rules, supply consistency, mint and burn authorization, and restrictions around holders or roles.

Economic guarantees

Reserve-related constraints, stablecoin-specific assumptions, freeze mechanisms, fee behavior, and model-specific guarantees.

Protocol scenarios

Interconnected contracts, vault flows, lending states, AMM behavior, staking logic, bridge assumptions, and critical scenario modeling.

In short

From near-instant analysis to deep formal verification.

Our offer adapts to the criticality and complexity of the code: from near-instant automated analysis for standard ERC-20 tokens, to an engineering review within a few days when findings are detected, and up to several weeks for stablecoins or tokens requiring specific properties. For complex protocols, formal verification becomes a tailored engagement, typically around one month, and potentially longer when the architecture or number of critical invariants requires deeper work.

Next step

Start with the code. Scale the proof to the risk.

Standard tokens can be analyzed quickly. Complex assets deserve properties that match their real economic and architectural assumptions.

Talk to Dowsers