HashCow Publishes Both SolidProof Audit Rounds in Full, Including All Open Findings

02-Sep-2026 Crypto Adventure
HashCow Publishes Both SolidProof Audit Rounds in Full, Including All Open Findings
Sixty percent of the crypto platforms exploited since January 2025 had already been audited. The BNB Chain game studio is publishing the findings it has not closed.

 

PANAMA CITY, September 2, 2026 — HashCow, a Web3 game studio and provable-fairness infrastructure company, today announced the completion of a second smart contract audit round with SolidProof across all six of its contracts. Both rounds have been published in full on a public project page, including the twenty-five findings that remain open.

Publishing the open findings is the unusual part, and there is a number behind the decision. Roughly 60% of the crypto platforms exploited between January 2025 and July 2026 had already completed an independent security audit. That is 147 of 245 incidents, and those audited platforms accounted for 88.44% of the $3.63 billion drained over the period, according to CoinGecko’s 2026 State of Crypto Security Report.

The same report explains why, and the explanation is not that auditors are failing. Only around 11% of the incidents involved a flaw inside conventional audit scope. The rest came in through the doors an audit was never pointed at. Which leaves a reader with a problem that has nothing to do with audit quality: an audit badge on a landing page tells you a review happened. It does not tell you what was reviewed, what the reviewer found, or what is still open.

WHAT THE REPORTS ACTUALLY SAY

At the close of the second round the reports record no Critical, no High and no Medium severity findings. Twenty-five findings remain open. All of them are Low severity or Informational, and all of them are visible in the published report with their current status rather than summarised away.

The scope is stated the same way. The audit was pinned to specific commits in HashCow’s public repositories rather than to a moving branch, so a reader can compile the exact source the auditors read instead of whatever the repository holds today. The contracts are written in Solidity 0.8.34 against OpenZeppelin 5.0.2, with no proxy and no upgrade path.

That last detail is what the company points to when asked why it would publish findings it has not closed.

Our contracts cannot be upgraded, so we are committing permanently to code anyone can read. If a reader has to trust our summary of the audit rather than the audit itself, we have not actually given them anything. Publishing the findings we have not closed costs us a cleaner headline and buys us a reader who can check.

— Mark Lee, Founder and CEO, HashCow

THE TESTING IS PUBLISHED TOO

Alongside the audit, HashCow publishes its own test results: 694 test assertions, 105 static-analysis results triaged with no High severity among them, and 49 of 49 mutation tests caught.

The third figure is the least common in the industry and the most revealing. Mutation testing deletes each protective check in the contracts one at a time and re-runs the suite, on the principle that a test suite which still passes with a guard removed was never testing that guard. Two assertions in HashCow’s own repository were found to be passing for the wrong reason that way, and were rewritten.

WHAT THE ENGINE PROVES, AND WHAT IT DOES NOT

The audited contracts sit underneath VegasLedger, HashCow’s fairness engine. A random number generator produces the game outcome and a verifiable random function produces the cryptographic proof that the outcome was not altered. Results are hashed into a Merkle root anchored on BNB Chain, so any individual result can be checked against the anchor after the session has ended. The engine is licensable to outside studios as a standalone product.

HashCow is unusually specific about the limits of that. The anchor establishes that a record was not changed after it was written. It does not establish that the set of anchored records is complete, and it says nothing at all about how a player played. Both limits are stated in the company’s own documentation rather than left for a reader to discover.

WHERE THE PROJECT STANDS

Team KYC has been completed with SolidProof at Tier Gold. HCOW is a BEP-20 token on BNB Chain with a fixed supply of 200,000,000 and no mint function in the contract. The token has not been issued and has never been listed on any exchange. Mainnet deployment is pending.

None of this makes a project safe, and HashCow does not claim it does. The CoinGecko figures are a reminder that the majority of losses arrive through routes no audit was scoped to cover. What publishing in full changes is narrower and more useful: it moves the question from whether a reader trusts the project to whether a reader can check the project, which is the only version of the question that survives contact with an exploit.

ABOUT HASHCOW

HashCow is a Web3 game studio and provable-fairness infrastructure company. It builds games and the fairness engine underneath them, and licenses that engine to outside studios. HashCow is operated by HASHCOW LABS INC., a sociedad anonima registered in Panama under Public Registry Folio No. 155787645.

LINKS

Audit reports: https://app.solidproof.io/projects/hcow

Website: https://hash-cow.io

Documentation: https://hashcow.gitbook.io/hashcow-docs-2

X: https://x.com/HCOW_Official

Telegram: https://t.me/HASHCOWOfficial

MEDIA CONTACT

work@hash-cow.io

Source for the figures in the opening paragraphs: CoinGecko, 2026 State of Crypto Security Report (245 incidents, January 2025 to July 2026).

This is not an offer to sell securities and makes no representation regarding price or return.

The post HashCow Publishes Both SolidProof Audit Rounds in Full, Including All Open Findings appeared first on Crypto Adventure.

Also read: UiPath (PATH) Stock: What Wall Street Expects from Earnings Thursday
WHAT'S YOUR OPINION?
Related News