We've seen some horror stories. It's hard not to get a little irritated when you're the second firm to assess a target and own it up on day 2 with a trivial CBC padding oracle.
All this means is, when you're talking to a potential auditor, ask them hard questions about cryptography. Ask them to describe some of the crypto vulnerabilities they have found on projects. If they talk about "weak keys" or "bad ciphers", they're unserious.
Zooko's team at Least Authority is a serious crypto practice. Engaging Zooko was a good call!
$1000 per auditor/day is less than you'd pay to get someone to run Nessus on your network from a normal firm. Zooko did you an _enormous_ favor. For crypto work, a rate four times as high wouldn't be out of the ordinary.