For Attestors · Audit Intelligence

Your audit passed. The exploit still happened.

70% of 2024 crypto exploits hit contracts with a clean prior audit. Not because the audit was wrong. Because the vulnerability didn’t exist in any public database.

WBL · FINDING · 0001 Critical
Finding Type Silent Patch — No CVE Issued
Audit Result Clean — No Critical Findings
Upstream Fix Merged 8 months prior to exploit
Public Record No CVE. No advisory. Nothing.
Audit Scope Not covered — upstream dependency
Outcome $7.9M exploit. Audit still valid.
70%
Of exploits hit
audited contracts
0.44%
Disclosure rate
across 9 ecosystems
227×
Silent fixes for every
CVE your audit sees

Your audit is thorough, accurate, and structurally incomplete.

A security audit reviews the code you submit. It cannot check what upstream maintainers quietly fixed in the months before — or after — your review window closed. Those maintainers have a documented incentive to stay quiet: public disclosure triggers downstream audit requirements, insurance repricing, and user concern. Silence costs them nothing.

Our pipeline analyzed 4,121 patches across 9 ecosystems and found a disclosure rate of 0.44%. That means for every vulnerability that appears in the public databases your threat model uses, 227 others were fixed without any record reaching the outside world. None of those 227 were in your scope. They couldn’t be — they don’t exist in any source you have access to.

This is not a critique of audit methodology. It is a structural data gap that every audit firm in the market faces equally. The Whitenbaker upstream feed closes that gap — giving your team access to the fix history that upstream maintainers never published, so your reports reflect the complete vulnerability surface instead of the disclosed fraction of it.

70% Exploits hit audited contracts Of 2024 major crypto exploits targeted protocols with a prior clean audit. The audit passed. The vulnerability existed upstream.
0.44% Disclosure rate, 9 ecosystems Of all security patches we analyzed were ever publicly disclosed. Your current threat model covers less than 1 in 200 actual fixes.
$2.2B Crypto losses, 2024 Total ecosystem losses in a single year. A material share tied to upstream dependency failures no audit firm had visibility into.
227× Silent vs. disclosed fixes For every vulnerability in any public CVE database, 227 others were fixed without disclosure. None of those are in your audit scope.

Three audited protocols. Same upstream bug. Every audit was right. The code was not.

Addendum A · Lending Protocol Fork Chain Post-Mortem
Root ProtocolUpstream lending codebase — silently patched
Audit StatusEach downstream fork had a clean audit at time of exploit
VulnerabilityExchange rate manipulation in upstream dependency
Fix StatusMerged upstream 8+ months before first exploit — never disclosed
CVE IssuedNo. No advisory. No public record of any kind.
Exploits4 separate incidents across 4 forks over 13 months
Total Losses$31.6 million across downstream deployments
Audit verdict on each protocol: No Critical Findings.   Upstream reality: Critical vulnerability with a known fix, no disclosure, no notification to downstream forks. The fix was in the commit history the entire time.
Addendum B · Consensus Engine Active Pattern
EngineWidely-forked consensus layer — CVSS 9.3
VulnerabilityLight client verification bypass enabling undetected chain forks
Downstream12+ chains running forked versions — none notified of upstream fix
Fix StatusShipped without disclosure — no CVE batch issued
Audit GapUpstream dependency — not in scope of any downstream audit
Every audit of every downstream chain was technically correct. The CVSS 9.3 finding existed above the audit boundary, in the dependency layer, completely undisclosed.
Addendum C · Authentication Platform Active Pattern
PlatformAuth infrastructure used across multiple DeFi protocols
VulnerabilityAuthentication bypass — 13 related findings in a single audit cycle
DisclosurePatched silently across multiple releases — zero CVEs issued
Audit GapProtocols audited at code level — platform dependency not reviewed
13 authentication vulnerabilities. Zero CVEs. Zero entries in any public audit addendum. The only record of their existence is in the upstream commit history.
Services · Three Tiers
Tier 01 · Dataset Access

Silent Patch Access

From 50 bps of annual billings  ·  Recurring
You are reviewing a protocol’s dependency chain. You need to know not just what CVEs exist — but what fixes exist that were never assigned a CVE.

Continuous access to the full Whitenbaker upstream fix database. Search by project, ecosystem, or CWE class. Every finding includes the commit, fix summary, vulnerability class, and severity rating — structured for direct incorporation into audit reports as supplementary findings.

Deliverables

  • Full silent patch database — search by project, ecosystem, CWE
  • Historical concealment patterns per upstream maintainer
  • CVSS-aligned severity ratings per finding
  • Fork delta queries — patches missed since branch point
  • Export in JSON, CSV, or structured PDF for report appendix
  • New patch alerts for projects you are actively monitoring
Tier 02 · Per-Engagement

Audit Overlay

From 75 bps of engagement value  ·  Per engagement
A client submits their protocol for audit. Before you open the codebase, you want to know every upstream dependency vulnerability that exists outside the scope of what they submitted.

A targeted upstream scan run in parallel with your standard engagement. We map every dependency in the submitted codebase, query our database for silent patches, and deliver a structured findings addendum formatted for direct inclusion in your report — client-ready, sourced, and severity-rated.

Deliverables

  • Targeted scan of submitted codebase dependencies
  • Silent patch findings per upstream library
  • Client-ready addendum — formatted for report inclusion
  • Silent patch delta report for forked codebases
  • CVSS-aligned severity classification per finding
  • Plain-language finding descriptions for each upstream gap
Tier 03 · Full Integration

Integrated Feed

From 100 bps of annual billings  ·  Recurring
Every engagement your firm takes should automatically include upstream patch coverage — not as an add-on, but as a standard part of what your audit means.

The Whitenbaker database connected directly into your audit workflow via API. When an engagement opens, a dependency scan runs automatically. Findings populate your standard report template as structured data. White-label options let you present upstream coverage under your firm’s brand. Post-audit monitoring alerts your team when a client’s dependency chain changes after the report closes.

Deliverables

  • API integration — auto-scan on engagement open
  • White-label capability — present under your firm’s brand
  • Structured data output for report template ingestion
  • Post-audit monitoring for retainer clients
  • Dedicated analyst for complex or multi-dependency engagements
  • Priority SLA — 24-hour turnaround on targeted queries
Pricing · Published · Per Audience

The numbers. All of them.

Every rate is published. Type your billing volume. The math is instant.

Annual Billings
$
Monthly + annual shown below
Dataset Access

Silent Patch Access

50bps
0.50%
of annual billings · recurring
Monthly

Annual (locked)
  • Full silent patch database
  • Search by project / ecosystem / CWE
  • Historical concealment patterns
  • Fork delta queries
  • Export for report appendix
Per-Engagement

Audit Overlay

75bps
0.75%
of engagement value · per engagement
Per Engagement
  • Targeted dependency scan
  • Silent patch findings per library
  • Client-ready findings addendum
  • Silent patch delta for forks
  • CVSS-aligned severity per finding
Full Integration

Integrated Feed

100bps
1.00%
of annual billings · recurring
Monthly

Annual (locked)
  • Everything in Dataset Access
  • API for workflow integration
  • White-label capability
  • Post-audit client monitoring
  • Dedicated analyst · Priority SLA
Monthly — recalculates each billing cycle based on current billings.
Annual — billings locked at signing. Growth during the contract doesn’t change your rate until renewal.
Minimum engagement: $30,000
Regulatory bodies and law enforcement receive complimentary access to this dataset.
Your TVL
$
Monthly + annual shown below
One-Time

Dependency Scan

1bps
0.01%
of TVL · one-time
Your Cost
  • Full upstream dependency map
  • Silent patch exposure report
  • Severity breakdown per finding
  • Fork impact analysis
Continuous

Upstream Watch

3bps
0.03%
of TVL · recurring
Monthly

Annual (locked)
  • Everything in Dependency Scan
  • Continuous silent patch feed
  • 48-hour detection SLA
  • API for CI/CD
Full Service

Full Advisory

5bps
0.05%
of TVL · recurring
Monthly

Annual (locked)
  • Everything in Upstream Watch
  • Dedicated analyst
  • Quarterly security reviews
  • Investor-ready reporting
Minimum engagement: $25,000
Coverage Volume
$
Monthly + annual shown below
Continuous

Risk Intelligence Feed

8bps
0.08%
of coverage volume · recurring
Monthly

Annual (locked)
  • Continuous silent patch detection
  • Protocol-level exposure mapping
  • CVSS-aligned severity ratings
  • API for actuarial integration
One-Time

Portfolio Assessment

3bps
0.03%
of coverage volume · one-time
Your Cost
  • Full portfolio exposure analysis
  • Per-protocol risk report
  • Premium repricing recommendations
  • Structured data appendix
Full Service

Underwriting Intelligence

12bps
0.12%
of coverage volume · recurring
Monthly

Annual (locked)
  • Everything in Risk Intelligence Feed
  • Pre-binding coverage assessments
  • Quarterly underwriting briefings
  • Dedicated analyst
Minimum engagement: $50,000
Last Round Raised
$
Monthly + annual shown below
One-Time

Pre-Launch Scan

2bps
0.02%
of last round · one-time
Your Cost
  • Dependency exposure report
  • Silent patches in your stack
  • Risk profile before launch
  • Board-ready summary
Continuous

Continuous Monitor

4bps
0.04%
of last round · recurring
Monthly

Annual (locked)
  • Everything in Pre-Launch Scan
  • Ongoing silent patch alerts
  • 48-hour detection SLA
  • API access
Full Service

Full Advisory

6bps
0.06%
of last round · recurring
Monthly

Annual (locked)
  • Everything in Continuous Monitor
  • Quarterly security reviews
  • Insurance-readiness assessment
  • Dedicated analyst
Minimum engagement: $15,000
Crypto AUM
$
Monthly + annual shown below
One-Time

Portfolio Screen

2bps
0.02%
of crypto AUM · one-time
Your Cost
  • Exposure scan across holdings
  • Per-protocol risk breakdown
  • Silent patch count per position
  • LP-ready summary
Continuous

Due Diligence Feed

4bps
0.04%
of crypto AUM · recurring
Monthly

Annual (locked)
  • Everything in Portfolio Screen
  • Continuous monitoring of holdings
  • Pre-investment protocol scans
  • Real-time exposure alerts
Full Service

Full Intelligence

6bps
0.06%
of crypto AUM · recurring
Monthly

Annual (locked)
  • Everything in Due Diligence Feed
  • Quarterly portfolio briefings
  • IC-ready risk reports
  • Dedicated analyst
Minimum engagement: $25,000

Public interest. No charge.

Supervisory bodies receive complimentary access to the full silent patch dataset.
Securities regulators, financial supervisory authorities, and government cybersecurity agencies can access the complete risk intelligence feed at no cost. The data exists to make markets transparent. Charging the entities responsible for transparency would defeat the purpose.

Investigative support. No charge.

Law enforcement agencies receive complimentary access for active investigations.
Silent patches are evidence. When a maintainer fixes a critical vulnerability without disclosure and downstream protocols lose funds, the patch history documents the timeline of knowledge. We provide that evidence to law enforcement at no cost.
  • Concealment timelines with commit-level precision
  • Evidence of knowledge prior to exploit events
  • Downstream exposure mapping for affected parties
  • Expert consultation on technical findings
  • Chain-of-custody-ready documentation
Scope

What you get. What we don’t do.

What You Get

  • Silent patch findings across submitted codebase dependencies
  • Fork delta reports — patches missed since branch point
  • Concealment pattern scoring per upstream maintainer
  • Client-ready addendum formatted for report inclusion
  • Post-audit monitoring for retainer clients
  • White-label option for integrated feed subscribers

What We Don’t Do

  • Replace your audit — this is addendum data, not a substitute
  • Perform active penetration testing or exploitation
  • Provide legal advice or regulatory representation
  • Disclose raw vulnerability details to non-subscribers
  • Accept protocol payment to suppress findings from addenda
  • Issue CVEs or coordinate public disclosure on your behalf
Audited contract exploits: Olympix, “The State of Web3 Security in 2025”. 70% of major exploits targeted previously audited contracts. Disclosure gap: Chainguard, “The Hidden Cost of Silent Patches” (2024). >50% of open-source security fixes never publicly disclosed. Crypto losses: Chainalysis, 2024 Crypto Hacking Report. $2.2B in total crypto losses for 2024. Lending protocol exploit chain: Public incident reports via rekt.news. 4 exploits, 13 months, $31.6M aggregate losses. Internal data: Whitenbaker Labs silent patch detection pipeline. 4,121 patches analyzed, 0.44% disclosure rate across 9 ecosystems.
Close the Gap

Add what your audit was missing.

Start with the Audit Overlay on your next engagement — see what the upstream commit history reveals that the codebase didn’t show. Or integrate the full feed and make silent patch coverage standard across every report you deliver.

Initial consultation free · All prices published · No sales theater