The Ethereum Foundation has released the findings from its external security review of the Pectra system contracts, confirming that all issues deemed relevant or important have been resolved. The audit results, published in the project's official repository, cover the smart contracts tied to three Ethereum Improvement Proposals: EIP-2935, EIP-7002, and EIP-7251.
According to the foundation, the reviews were conducted with two primary objectives: identifying potential attack vectors and verifying that the contract logic accurately implements the intended functionality as specified in the EIPs. The process followed a multi-phase approach, with each successive audit building on the findings of the previous one.
Four independent security firms participated in the audit rounds: Blackthorn, Dedaub, PlainShift, and Sigma Prime. Between each review cycle, the development team implemented code improvements before proceeding to the next stage of assessment.
In addition to the external audits, the foundation noted that a16z conducted a formal verification of the contracts using the Halmos tool. This verification focused specifically on whether the bytecode aligns with the specification, rather than evaluating the security of the spec itself against potential abuse or malicious use. The foundation explained that this separation of concerns allows auditors and the community to review the specification without being distracted by low-level implementation details.
The full audit reports are now available in the Pectra System Contracts Audits repository. Meanwhile, a bug bounty program is currently running on Cantina, offering rewards of up to $2,000,000 for findings related to Pectra. The Ethereum Foundation emphasized that security of the ecosystem remains a collective effort and thanked all auditors and contributors involved in the process.







