Skip to main content

Security Audits

ComposableCoW has completed multiple independent security audits from reputable firms to validate protocol safety.

Audit History

Ackee Blockchain (2023)

Reviewed core contracts including:
  • ComposableCoW
  • Programmatic order verification
  • Merkle proof validation
  • ERC-1271 signature mechanisms
Their comprehensive assessment examined all core functionality including single orders, merkle tree-based orders, and integration components.

Gnosis Internal Audits

Conducted in two phases:
  1. May/July 2023 - Full contract review with order type implementations and Safe integration
  2. August 2024 - Diff review ensuring subsequent changes maintained security standards

Contract Coverage

Eight contracts received audit clearance:
  • ExtensibleFallbackHandler
  • ComposableCoW
  • TWAP
  • GoodAfterTime
  • PerpetualStableSwap
  • TradeAboveThreshold
  • StopLoss
  • CurrentBlockTimestampFactory

Deployed Addresses

Contracts are consistently deployed across nine networks including Ethereum, Arbitrum, Base, and others.

Vulnerability Reporting

Security issues should be reported to the CoW Protocol Bug Bounty Program or security@cow.fi rather than disclosed publicly. The protocol maintains ongoing security through:
  • Extensive testing
  • Formal verification
  • Open-source review
  • Community participation
Last modified on March 12, 2026