Yes. Two independent firms audited Tari: Coinspect reviewed the layer 1 base node and wallet over 15 weeks, reporting 50 issues including 22 high severity and zero critical. Quarkslab separately audited the Bulletproofs+ cryptography and found no security issues.
Last refreshed September 9, 2026
| Coverage scope | Answer family | Security | |
|---|---|---|---|
| Stable fields | auditor names, engagement dates, severity breakdown, scope percentages, published findings | Dynamic fields | whether a new audit has been commissioned, whether the Ootle layer 2 has since been audited |
Two independent audits, both published. Coinspect audited the layer 1 base node and wallet library. Quarkslab separately audited the Bulletproofs+ range-proof implementation. Both reports are public.
The base layer audit was not a clean bill of health. Coinspect reported 50 issues. Twenty-two were high severity, nearly half the findings. Tari states all were resolved and confirmed resolved by Coinspect.
Zero critical is true, but it is not the whole picture. No finding was rated critical. Coinspect's highest category was high, and it described potential consequences of those high findings as double spends or massive denial of service.
Base node and wallet library, a 15-week engagement completed November 2023, report published February 2024.
| Coinspect | Quarkslab | |
|---|---|---|
| Auditor | Coinspect | Quarkslab |
| Subject | Layer 1 base node and wallet library | bulletproofs-plus range proofs |
| Period | 15 weeks, completed November 2023 | August to October 2023 |
| Findings | 50 issues: 22 high, 9 medium, 10 low, 9 info | 1 low, 2 informational |
| Headline conclusion | No critical issues; high-severity findings could have enabled double spends or denial of service | No particular security issues identified |
The findings clustered, and that was the useful signal. Coinspect's early findings grouped into themes, notably merge mining and data handling. Tari's core developers responded with a new set of processes and guidelines for managing code quality, applied both retroactively and to new code.
High-severity findings then dropped off. Tari reports that after those process changes, high-severity findings fell markedly during the remainder of the engagement.
Has the Ootle layer 2 been audited?
Neither published audit covers the Ootle. Coinspect reviewed the layer 1 base node and wallet, and Quarkslab reviewed the Bulletproofs+ library. Treat layer 2 as unaudited in public unless a first-party source says otherwise.
Were the 22 high-severity issues fixed?
Tari states that all reported issues were resolved and that Coinspect confirmed them as resolved. The report itself is public, so the findings can be read directly rather than taken on the project's summary.
Does 'zero critical issues' mean the code was secure?
It means no finding met the auditor's critical bar. Coinspect's 22 high-severity findings carried potential consequences it described as double spends or massive denial of service, so the absence of a critical rating is not the same as an absence of serious findings.
What does the 60% coverage figure mean?
It describes how much of the base layer was in scope: around 60% of the most critical parts of roughly a quarter of a million lines. Code outside that scope was not reviewed, so it is a statement about the engagement's boundary rather than a quality score.
Who paid for the audits?
The Tari project commissioned the Quarkslab review of bulletproofs-plus. The Coinspect engagement was likewise a Tari-commissioned audit, announced in Tari's own developer updates and published by both parties.