> For the complete documentation index, see [llms.txt](https://cdao.gitbook.io/cdao-staking/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cdao.gitbook.io/cdao-staking/dvt-staking/audit.md).

# Audit

### Overview

ContributionDAO engaged **Zellic**, a leading blockchain security firm, to conduct a full smart contract security assessment of the **CDAO Staking Contract**, the core component of our ETH staking platform powered by SSV’s Distributed Validator Technology (DVT).

The assessment was conducted between **March 13 – 18, 2025**, and focused on identifying critical vulnerabilities, business logic flaws, and security risks in the staking infrastructure.

### Key Findings

* ✅ **No critical or high-severity vulnerabilities were found**
* ⚠️ **3 findings identified**
  * 1 Medium severity
  * 2 Low severity
* 🛠 All findings were acknowledged and resolved by ContributionDAO with confirmed remediation commits

### About Zellic

**Zellic** is a premier smart contract auditing firm trusted by major L1s, L2s, and protocol teams. Their team includes world-class security researchers, cryptographers, and competitive hacking champions with deep expertise in:

* EVM, Move, Solana, NEAR, Cairo
* Smart contract logic, DeFi integrations, MEV resistance
* Applied cryptography and protocol-level threat modeling

More about Zellic: [zellic.io](https://zellic.io)

### Full report

📄 <https://docsend.com/view/xmecsmiebaquwnwe>&#x20;
