> For the complete documentation index, see [llms.txt](https://docs.molecule.xyz/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.molecule.xyz/security/audits.md).

# Audits

### Audit by Cyfrin

#### Q2 2026 Audit: OnChainLab (Molecule Labs core)

* **Scope:** The modular Lab smart-account stack — `OnChainLab` account (ERC-4337 / ERC-6551 / ERC-7579 / ERC-7739 / ERC-1271), `OnChainLabFactory`, beacon & router, `LabNFT`, ERC-7484 module registry, `RootValidator`, the DID registry, and the `OdfCoAttestVerifier`
* **Outcome:** All fixes were merged before the Base mainnet v0.1.0 deployment, which was made from the audited code

{% embed url="<https://github.com/Cyfrin/cyfrin-audit-reports/blob/main/reports/2026-05-12-cyfrin-molecule-onchainlab-v2.0.pdf>" %}

### Audits by Pashov

#### Q1 2023 Audit: Molecule Vesting

* **Scope:** Token Vesting

{% embed url="<https://github.com/pashov/audits/blob/master/solo/pdf/MoleculeVesting-security-review.pdf>" %}

#### Q2 2023 Audit: IPNFT

* **Scope:** IP-NFTs & Fundraises (CrowdSale, TimelockedToken)

{% embed url="<https://github.com/pashov/audits/blob/master/solo/pdf/IPNFT-security-review.pdf>" %}
