Tari security

Has Tari's layer 1 been audited by a third party?

Yes. Two independent firms audited Tari: Coinspect reviewed the layer 1 base node and wallet over 15 weeks, reporting 50 issues including 22 high severity and zero critical. Quarkslab separately audited the Bulletproofs+ cryptography and found no security issues.

Last refreshed September 9, 2026

Coverage scopeAnswer familySecurity
Stable fieldsauditor names, engagement dates, severity breakdown, scope percentages, published findingsDynamic fieldswhether a new audit has been commissioned, whether the Ootle layer 2 has since been audited

The short answer

Two independent audits, both published. Coinspect audited the layer 1 base node and wallet library. Quarkslab separately audited the Bulletproofs+ range-proof implementation. Both reports are public.

The base layer audit was not a clean bill of health. Coinspect reported 50 issues. Twenty-two were high severity, nearly half the findings. Tari states all were resolved and confirmed resolved by Coinspect.

Zero critical is true, but it is not the whole picture. No finding was rated critical. Coinspect's highest category was high, and it described potential consequences of those high findings as double spends or massive denial of service.

Coinspect layer 1 audit by the numbers

Base node and wallet library, a 15-week engagement completed November 2023, report published February 2024.

50
Total issues
22
High severity
9
Medium severity
10
Low severity
9
Informational
0
Critical severity

What each audit actually covered

The two audits side by side

CoinspectQuarkslab
AuditorCoinspectQuarkslab
SubjectLayer 1 base node and wallet librarybulletproofs-plus range proofs
Period15 weeks, completed November 2023August to October 2023
Findings50 issues: 22 high, 9 medium, 10 low, 9 info1 low, 2 informational
Headline conclusionNo critical issues; high-severity findings could have enabled double spends or denial of serviceNo particular security issues identified

What the audit changed beyond the fixes

The findings clustered, and that was the useful signal. Coinspect's early findings grouped into themes, notably merge mining and data handling. Tari's core developers responded with a new set of processes and guidelines for managing code quality, applied both retroactively and to new code.

High-severity findings then dropped off. Tari reports that after those process changes, high-severity findings fell markedly during the remainder of the engagement.

The reports themselves

Related questions

Has the Ootle layer 2 been audited?

Neither published audit covers the Ootle. Coinspect reviewed the layer 1 base node and wallet, and Quarkslab reviewed the Bulletproofs+ library. Treat layer 2 as unaudited in public unless a first-party source says otherwise.

Were the 22 high-severity issues fixed?

Tari states that all reported issues were resolved and that Coinspect confirmed them as resolved. The report itself is public, so the findings can be read directly rather than taken on the project's summary.

Does 'zero critical issues' mean the code was secure?

It means no finding met the auditor's critical bar. Coinspect's 22 high-severity findings carried potential consequences it described as double spends or massive denial of service, so the absence of a critical rating is not the same as an absence of serious findings.

What does the 60% coverage figure mean?

It describes how much of the base layer was in scope: around 60% of the most critical parts of roughly a quarter of a million lines. Code outside that scope was not reviewed, so it is a statement about the engagement's boundary rather than a quality score.

Who paid for the audits?

The Tari project commissioned the Quarkslab review of bulletproofs-plus. The Coinspect engagement was likewise a Tari-commissioned audit, announced in Tari's own developer updates and published by both parties.