Skip to content
Private, independent platform.Private, independent platform: free for clients, funded by a commission paid by vendors.Funding
smart-contract.com

Directory by blockchain

TON smart contract audit and development

Building and auditing on TON: the actor model, asynchronous messages and bounces, FunC and Tact, Jetton design, key risks and how to prepare.

TON is a layer 1 blockchain where each smart contract is an independent actor that communicates with others only through asynchronous messages. This model scales well but makes the flow of a single operation span several transactions. For a project, building on TON means designing and reviewing message chains rather than single function calls.

Building on TON

A user action typically triggers a sequence of messages across several contracts, each processed in its own transaction, so an operation can partly succeed and partly fail. Messages carry value, and a failed message can be returned to its sender as a bounce. Contracts pay for their own storage and computation. Fungible tokens (Jettons) use one wallet contract per holder, rather than a single balance table.

  • Languages: FunC, Tact and Tolk, compiled for the TON Virtual Machine
  • Tooling: the Blueprint framework and its sandbox for testing
  • Not EVM-compatible

What auditors look at

  • Asynchronous flows: intermediate states between messages, race conditions and actions that cannot be rolled back
  • Bounce handling: whether a failed message restores balances and state correctly
  • Sender authentication: verifying that an incoming message comes from the expected contract, for example a legitimate Jetton wallet
  • Gas and value management: enough value forwarded for the whole chain of messages, and storage fees that could freeze a contract
  • Replay protection on external messages and the correct parsing of message data

Before requesting quotes

  • Draw the message flow of each user operation, including failure and bounce paths
  • Specify the language used for each contract and its compiler version
  • Provide sandbox tests covering partial failures, not only successful chains
  • Describe token contracts precisely if you implement Jettons or NFTs

TON smart contract auditors

  • Blaize

    Public informationUkraine

    Ukrainian blockchain development company with a dedicated security audit practice

    • Development
    • Audit

    Ethereum · Polygon · Arbitrum · Solana · Sui · +4 more

  • CertiK

    Public informationUnited States

    Web3 security firm offering manual smart contract audits, formal verification and pentests

    • Audit
    • Penetration testing

    Ethereum · BNB Chain · Polygon · TON · Cosmos

  • Cyfrin

    Public information

    Smart contract audits, penetration testing and security education, maker of Aderyn and Solodit

    • Audit
    • Penetration testing

    Ethereum · ZKsync · Arbitrum · Avalanche · BNB Chain · +8 more

  • Quantstamp

    Public information

    Web3 security firm offering smart contract audits, economic analysis and infrastructure tests

    • Audit
    • Penetration testing

    Ethereum · Solana · Polygon · TON · Avalanche · +3 more

  • Sec3

    Public information

    Solana security firm offering audits, formal verification and post-deployment monitoring

    • Audit

    Solana · TON

  • SlowMist

    Public informationChina

    Blockchain threat intelligence firm auditing exchanges, wallets, blockchains and smart contracts

    • Audit

    Ethereum · TON

  • softstack

    Public informationGermany

    Flensburg Web3 company offering smart contract audits, pentests, development and compliance

    • Development
    • Audit
    • Penetration testing

    Ethereum · Arbitrum · Optimism · Base · Polygon · +8 more

  • Trail of Bits

    Public informationUnited States

    Security firm reviewing smart contracts, nodes and bridges, maker of Slither and Echidna

    • Audit
    • Penetration testing

    Ethereum · Arbitrum · Optimism · Solana · Sui · +4 more

  • Zokyo

    Public informationUnited Arab Emirates

    Smart contract and protocol audits, pentesting, compliance and product development, Dubai

    • Audit
    • Penetration testing
    • Development

    Ethereum · Solana · Polygon · Arbitrum · Optimism · +9 more

TON smart contract developers

  • Blaize

    Public informationUkraine

    Ukrainian blockchain development company with a dedicated security audit practice

    • Development
    • Audit

    Ethereum · Polygon · Arbitrum · Solana · Sui · +4 more

  • RedDuck

    Public informationUkraine

    Web3 engineering partner writing audit-ready smart contracts on EVM chains, Solana and Bitcoin

    • Development

    Ethereum · Polygon · BNB Chain · Arbitrum · Base · +6 more

  • softstack

    Public informationGermany

    Flensburg Web3 company offering smart contract audits, pentests, development and compliance

    • Development
    • Audit
    • Penetration testing

    Ethereum · Arbitrum · Optimism · Base · Polygon · +8 more

  • Zokyo

    Public informationUnited Arab Emirates

    Smart contract and protocol audits, pentesting, compliance and product development, Dubai

    • Audit
    • Penetration testing
    • Development

    Ethereum · Solana · Polygon · Arbitrum · Optimism · +9 more

Describe your project once. Compare with confidence.

Get comparable quotes from vetted developers, then secure your code with an independent auditor.

Get quotes

Free for clients. No commitment.