HomeBlogHow Button Made Smart Contract Audits Boring

How Button Made Smart Contract Audits Boring

Published:
Share this article

Button is building onchain infrastructure that lets users borrow, earn, and trade while maintaining custody of their Bitcoin. Early in development, Button integrated Octane directly into its CI/CD pipeline to surface real issues as code was written, fix them immediately, and avoid costly surprises before launch.

That decision quickly paid off. Button became an Octane power user, running a total of 25 scans during their pre-audit development process.

Building Button Better

This changed how the team built out Button:

  • Security findings surfaced as code was written, not weeks later
  • Engineers fixed issues immediately, while context was still fresh
  • Design decisions were informed by real attack paths, not hypothetical risks

By integrating Octane into CI/CD, Button turned vulnerability detection and remediation into a routine part of development, rather than a high-stress, end-of-cycle event.

As a result of this shift-left security approach, when Button was ready for a manual security review, the codebase was already hardened and clean.

Auditors found no critical vulnerabilities, no high-severity issues, and only a single medium-severity finding, which Octane had already surfaced. Button sent cleaner code off for audit because Octane had already caught the meaningful risk during development.

Source: @0xsallu

Securing Offchain Rust Code

When we released a beta version of a language-agnostic Octane model, Button was one of the first teams to integrate the new tool into its offchain Rust codebase. This expanded continuous security coverage across another critical attack surface.

Security is now continuous and automated across Button’s onchain and offchain infrastructure. By unifying tooling across environments, Button strengthened the entire system and reduced risk across its entire stack.

Make Audits Boring With Octane

Button’s approach shows what’s possible when security is built into development instead of bolted on at the end. With Octane running continuously in CI/CD, teams can catch real issues early, send cleaner code to auditors, and avoid costly remediation cycles down the line.

If you want to save time, reduce security spend, and make your audits boring like Button, reach out today to see what Octane can find in your codebase.

Written by
Share this article

Subscribe to our newsletter

By subscribing you agree to with our Privacy Policy.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.