Your audit passed. The exploit still happened.
70% of 2024 crypto exploits hit contracts with a clean prior audit. Not because the audit was wrong. Because the vulnerability didn’t exist in any public database.
Your audit is thorough, accurate, and structurally incomplete.
A security audit reviews the code you submit. It cannot check what upstream maintainers quietly fixed in the months before — or after — your review window closed. Those maintainers have a documented incentive to stay quiet: public disclosure triggers downstream audit requirements, insurance repricing, and user concern. Silence costs them nothing.
Our pipeline analyzed 4,121 patches across 9 ecosystems and found a disclosure rate of 0.44%. That means for every vulnerability that appears in the public databases your threat model uses, 227 others were fixed without any record reaching the outside world. None of those 227 were in your scope. They couldn’t be — they don’t exist in any source you have access to.
This is not a critique of audit methodology. It is a structural data gap that every audit firm in the market faces equally. The Whitenbaker upstream feed closes that gap — giving your team access to the fix history that upstream maintainers never published, so your reports reflect the complete vulnerability surface instead of the disclosed fraction of it.
Three audited protocols. Same upstream bug. Every audit was right. The code was not.
Silent Patch Access
Continuous access to the full Whitenbaker upstream fix database. Search by project, ecosystem, or CWE class. Every finding includes the commit, fix summary, vulnerability class, and severity rating — structured for direct incorporation into audit reports as supplementary findings.
Deliverables
- Full silent patch database — search by project, ecosystem, CWE
- Historical concealment patterns per upstream maintainer
- CVSS-aligned severity ratings per finding
- Fork delta queries — patches missed since branch point
- Export in JSON, CSV, or structured PDF for report appendix
- New patch alerts for projects you are actively monitoring
Audit Overlay
A targeted upstream scan run in parallel with your standard engagement. We map every dependency in the submitted codebase, query our database for silent patches, and deliver a structured findings addendum formatted for direct inclusion in your report — client-ready, sourced, and severity-rated.
Deliverables
- Targeted scan of submitted codebase dependencies
- Silent patch findings per upstream library
- Client-ready addendum — formatted for report inclusion
- Silent patch delta report for forked codebases
- CVSS-aligned severity classification per finding
- Plain-language finding descriptions for each upstream gap
Integrated Feed
The Whitenbaker database connected directly into your audit workflow via API. When an engagement opens, a dependency scan runs automatically. Findings populate your standard report template as structured data. White-label options let you present upstream coverage under your firm’s brand. Post-audit monitoring alerts your team when a client’s dependency chain changes after the report closes.
Deliverables
- API integration — auto-scan on engagement open
- White-label capability — present under your firm’s brand
- Structured data output for report template ingestion
- Post-audit monitoring for retainer clients
- Dedicated analyst for complex or multi-dependency engagements
- Priority SLA — 24-hour turnaround on targeted queries
The firms that add upstream coverage first define what a complete audit means.
Every audit firm in DeFi currently faces the same blind spot. No public source provides upstream patch coverage. The competitive baseline is equal — everyone is missing the same 99.56% of the vulnerability surface. That changes the moment any firm integrates the feed.
An audit that includes silent patch addenda is categorically more complete than one that doesn’t. The first firms to deliver this aren’t offering an upgraded product — they are offering a different product. 70% of exploits hit audited contracts. When the next high-profile incident hits a protocol that had a clean audit from a firm that didn’t run upstream coverage, every client in the market will ask: does your audit check for this?
The right answer needs to already be yes.
The numbers. All of them.
Every rate is published. Type your billing volume. The math is instant.
Silent Patch Access
- Full silent patch database
- Search by project / ecosystem / CWE
- Historical concealment patterns
- Fork delta queries
- Export for report appendix
Audit Overlay
- Targeted dependency scan
- Silent patch findings per library
- Client-ready findings addendum
- Silent patch delta for forks
- CVSS-aligned severity per finding
Integrated Feed
- Everything in Dataset Access
- API for workflow integration
- White-label capability
- Post-audit client monitoring
- Dedicated analyst · Priority SLA
Annual — billings locked at signing. Growth during the contract doesn’t change your rate until renewal.
Dependency Scan
- Full upstream dependency map
- Silent patch exposure report
- Severity breakdown per finding
- Fork impact analysis
Upstream Watch
- Everything in Dependency Scan
- Continuous silent patch feed
- 48-hour detection SLA
- API for CI/CD
Full Advisory
- Everything in Upstream Watch
- Dedicated analyst
- Quarterly security reviews
- Investor-ready reporting
Risk Intelligence Feed
- Continuous silent patch detection
- Protocol-level exposure mapping
- CVSS-aligned severity ratings
- API for actuarial integration
Portfolio Assessment
- Full portfolio exposure analysis
- Per-protocol risk report
- Premium repricing recommendations
- Structured data appendix
Underwriting Intelligence
- Everything in Risk Intelligence Feed
- Pre-binding coverage assessments
- Quarterly underwriting briefings
- Dedicated analyst
Pre-Launch Scan
- Dependency exposure report
- Silent patches in your stack
- Risk profile before launch
- Board-ready summary
Continuous Monitor
- Everything in Pre-Launch Scan
- Ongoing silent patch alerts
- 48-hour detection SLA
- API access
Full Advisory
- Everything in Continuous Monitor
- Quarterly security reviews
- Insurance-readiness assessment
- Dedicated analyst
Portfolio Screen
- Exposure scan across holdings
- Per-protocol risk breakdown
- Silent patch count per position
- LP-ready summary
Due Diligence Feed
- Everything in Portfolio Screen
- Continuous monitoring of holdings
- Pre-investment protocol scans
- Real-time exposure alerts
Full Intelligence
- Everything in Due Diligence Feed
- Quarterly portfolio briefings
- IC-ready risk reports
- Dedicated analyst
Public interest. No charge.
Investigative support. No charge.
- Concealment timelines with commit-level precision
- Evidence of knowledge prior to exploit events
- Downstream exposure mapping for affected parties
- Expert consultation on technical findings
- Chain-of-custody-ready documentation
What you get. What we don’t do.
What You Get
- Silent patch findings across submitted codebase dependencies
- Fork delta reports — patches missed since branch point
- Concealment pattern scoring per upstream maintainer
- Client-ready addendum formatted for report inclusion
- Post-audit monitoring for retainer clients
- White-label option for integrated feed subscribers
What We Don’t Do
- Replace your audit — this is addendum data, not a substitute
- Perform active penetration testing or exploitation
- Provide legal advice or regulatory representation
- Disclose raw vulnerability details to non-subscribers
- Accept protocol payment to suppress findings from addenda
- Issue CVEs or coordinate public disclosure on your behalf
Add what your audit was missing.
Start with the Audit Overlay on your next engagement — see what the upstream commit history reveals that the codebase didn’t show. Or integrate the full feed and make silent patch coverage standard across every report you deliver.
Initial consultation free · All prices published · No sales theater
