# Is Cairo audited?

**URL:** <https://community.starknet.io/t/is-cairo-audited/115918>\
**Category:** 🙏 Help and Support\
**Tags:** cairo\
**Created:** [August 20, 2025, 8:25pm UTC](https://community.starknet.io/t/is-cairo-audited/115918 "2025-08-20T20:25:52Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Savio](https://dub1.discourse-cdn.com/flex005/user_avatar/community.starknet.io/savio/32/85815_2.png) [@Savio](https://community.starknet.io/u/Savio)\
**Post date:** [August 20, 2025, 8:25pm UTC](https://community.starknet.io/t/is-cairo-audited/115918/1 "2025-08-20T20:25:52Z")

</div>

I am interested in learning how was Cairo audited, what vulnerabilities were surfaced and addressed, etc.

But having searched through multiple search engines and consulted multiple LLMs, I couldn’t find any public information / reports about Cairo’s audits still.

Is Cairo audited?

---

<div class="post-metadata">

**Author:** ![FeedTheFed](https://dub1.discourse-cdn.com/flex005/user_avatar/community.starknet.io/feedthefed/32/72981_2.png) [@FeedTheFed](https://community.starknet.io/u/FeedTheFed)\
**Post date:** [August 25, 2025, 12:49pm UTC](https://community.starknet.io/t/is-cairo-audited/115918/2 "2025-08-25T12:49:02Z")

</div>

There are many ways to interpret this question as it’s quite broad, I’ll try to address a few

1. Low level CASM constraints: do the constraints in the Cairo AIR when used in the STARK protocol actually reflect that semantics of the architecture. This was actually proven via lean, and is discussed in the following 2022 [paper](https://dl.acm.org/doi/10.1145/3497775.3503675).
2. Code correctness: several audit firms are offering Cairo audits. For example, you can find audits for the OpenZeppelin standards contracts Cairo-library by Zellic in their [repo](https://github.com/OpenZeppelin/cairo-contracts/tree/main/audits). Some of the lower level functionalities that are written in CairoZero had also undergone formal verification via lean, which you can read about in this recent [paper](https://link.springer.com/article/10.1007/s10817-025-09723-y).
3. Compiler correctness: in fact we have two different compilers, Sierra –\> CASM and Cairo–\>Sierra. For the former, you can find related work in the paper from #2, as the CASM code for some libfuncs was shown to satisfy certain semantics. Given the pace of updates and complexity, the Cairo–\>Sierra compiler has not been audited as of yet. Note that this is on par with other big projects such as `solc`, who hasn’t gone through (AFAICT) an end to end audit that generated code reflects the language semantics, but rather only ad-hoc audits of parts of the compilation flow.
