Formal verification at every level of complexity
Hackers look for what testing and audits can miss.
From automated checks to tailored formal proof.
Whatever your smart contract token, stablecoin, or complex protocol Dowsers provides the right level of formal verification. Depth scales with complexity. Results are mathematically proven, not estimated.
Engagement Scope
The timeframe depends on what needs to be proven.
A standard ERC-20 can be checked almost instantly. As soon as findings, non-standard mechanics, economic rules, or multi-contract architectures enter the picture, the work shifts from automated analysis to expert interpretation and custom specification.
Standard ERC-20 token
For a simple and relatively standard ERC-20, analysis can be almost instant: from a few minutes to around one hour. This is the typical case for a token with no complex logic, no unusual mechanisms, and no significant findings. The goal is to provide a first automated level of assurance quickly, based on generic ERC-20 properties. In practice, a timeout of around one hour avoids properties running indefinitely. For slightly more complex contracts, a 2 to 3 hour window may be more realistic.
ERC-20 with findings or non-standard logic
When an ERC-20 generates findings, they go through an engineering review before being definitively qualified. This helps avoid false positives, contextualize results, and distinguish actual vulnerabilities from intentional contract behavior. For a standard token, one day may be enough. If the token includes vault logic, fees, restrictions, upgradeability, or proprietary mechanisms, it is more prudent to communicate a 1 to 3 day timeframe, also depending on engineering team availability.
Stablecoin or sensitive token
For a stablecoin, sensitive token, or asset with specific economic rules, the analysis is no longer limited to generic properties. Specific properties must be defined and verified: balance conservation, mint and burn permissions, reserve-related guarantees, freeze mechanisms, transfer rules, economic invariants, or constraints specific to the project model. This requires interpretation, specification work, and sometimes discussions with the client’s team. A realistic timeframe is therefore closer to 1 to 2 weeks.
Complex protocol or interconnected contracts
For DeFi, lending, AMM, vault, staking, bridge, or multi-contract architectures, the analysis becomes a tailored formal verification engagement. It requires understanding the architecture, identifying critical invariants, modeling relevant scenarios, writing or adapting properties, and interpreting the results. One month is a good reference timeframe for a complex case. A simpler protocol may sometimes be completed in around two weeks, while very large protocols — or engagements with 50 to 100 critical properties — may extend to 3 to 4 months.
What changes with complexity
Generic checks become custom properties.
The more the asset depends on economic logic, permissions, or cross-contract behavior, the more the engagement focuses on defining what correctness actually means for that system.
Token invariants
Balance conservation, transfer rules, supply consistency, mint and burn authorization, and restrictions around holders or roles.
Economic guarantees
Reserve-related constraints, stablecoin-specific assumptions, freeze mechanisms, fee behavior, and model-specific guarantees.
Protocol scenarios
Interconnected contracts, vault flows, lending states, AMM behavior, staking logic, bridge assumptions, and critical scenario modeling.
In short
From near-instant analysis to deep formal verification.
Our offer adapts to the criticality and complexity of the code: from near-instant automated analysis for standard ERC-20 tokens, to an engineering review within a few days when findings are detected, and up to several weeks for stablecoins or tokens requiring specific properties. For complex protocols, formal verification becomes a tailored engagement, typically around one month, and potentially longer when the architecture or number of critical invariants requires deeper work.
Next step
Start with the code. Scale the proof to the risk.
Standard tokens can be analyzed quickly. Complex assets deserve properties that match their real economic and architectural assumptions.
Talk to Dowsers