Daml Smart contracts need auditing like Solidity?

Hello everyone, Veselin from Valves Security here.

We’ve been building a security tool for CantonNetwork / DAML, and the results are looking very promising.

Yesterday, I had a great chat with a member of the community who shared an audit report from a well-known security firm for a Canton/DAML project.

Afterward, I found another public DAML audit from the same firm and used the scope of both audits to evaluate our tool.

Here are the results:

• It identified 10 of the 12 validated findings reported across both audits.

• The two missed findings had already been downgraded by our tool because they were classified as informational.

• It also flagged 50+ additional potential issues that we’re currently validating.

Security audits like these can be a significant investment. If you’re building on Canton/DAML we’d love to help.

We’re also considering releasing an open-source version of the tool if there’s enough interest.

Feel free to contact me directly if you’d like to chat or need a faster response: