Web3 security audits at a fraction of the cost.

Hexproof audits smart contracts on EVM chains, Solana and ZK systems using AI agents. An audit costs $999. If we find no High or Critical issues, it costs $499.

agent run (example)
  1. $ hexproof audit github.com/acme/vault/commit/4e1a9c2
  2. › fetching commit 4e1a9c2 ok
  3. › 14 contracts, 2,310 lines of Solidity
  4. › mapping roles, external calls and fund flows
  5. › writing invariants 38
  6. › attacking fund-moving paths 212
  7. › second agent reviewing 9 candidates
  8. HIGHVault.sol:142 first depositor can inflate share price
  9. MEDOracle.sol:67 stale price accepted after sequencer restart
  10. LOWRouter.sol:210 swap has no deadline
  11. › 6 candidates disproved, 3 confirmed
  12. ✓ report ready, emailing results
  • $999per audit
  • $499if no High or Critical issues
  • 1000sof audits in our training data

We already audit on

  • Sherlock
  • Cantina
  • Immunefi

01 / What we do

Agents that read your code the way an auditor does

You send us a link to a GitHub commit. Our agents read the code at that commit, work out what the protocol is supposed to guarantee, and try to break it. A separate agent then tries to disprove each finding. The findings that hold up go into a report, and we email you the link.

The models

The agents use proprietary frontier models for reasoning about the protocol, and open-source models we post-trained on thousands of past audit reports and findings.

Checking findings

When one agent concludes that a path which moves funds is safe, another agent is assigned to break it. Each reported finding is re-checked before it reaches you, to cut false positives.

Where we audit today

The team runs the same agents on Sherlock, Cantina, Immunefi, where findings are judged by the protocol and the platform.

02 / How it works

From commit link to report

  1. 01

    Send a commit link

    The commit pins the exact code we audit, so the report matches what you deploy.

  2. 02

    Pay the $10 deposit

    It keeps out spam requests. We subtract it from your invoice.

  3. 03

    Agents audit the code

    One group of agents looks for bugs. A separate agent then tries to disprove each one before it goes in the report.

  4. 04

    Get the report by email

    We email you a link. Each finding has a severity, an explanation and a suggested fix. Exploitable issues come with a proof-of-concept test.

03 / The report

What a finding looks like

Each finding names the file and line, explains how an attacker would use it, and suggests a fix. When a bug can be exploited, we include a test that reproduces it.

  • CriticalDirect loss of funds, no special conditions
  • HighLoss of funds under realistic conditions
  • MediumLimited loss, or funds temporarily stuck
  • LowMinor issues and hardening
HighH-01 · example

First depositor can inflate the share price and take later deposits

src/Vault.sol:142

140function deposit(uint256 assets) external returns (uint256 shares) {
141    uint256 supply = totalSupply();
142    shares = supply == 0 ? assets : assets * supply / totalAssets();
143    _mint(msg.sender, shares);

An attacker deposits 1 wei, then sends tokens straight to the vault to raise totalAssets(). The next depositor's shares round down to zero, and the attacker withdraws both deposits.

-   shares = supply == 0 ? assets : assets * supply / totalAssets();+   shares = assets.mulDiv(supply + 10 ** _decimalsOffset(), totalAssets() + 1, Math.Rounding.Floor);
✓ Foundry PoC included · confirmed by second agent

05 / Pricing

One price, cheaper if your code is clean

Introductory price

$999 per audit

$499 if we find no High or Critical issues

  • Flat price, no quote needed
  • EVM, Solana and ZK
  • Findings ranked by severity, with suggested fixes
  • Proof-of-concept tests for exploitable issues
  • Each finding checked by a second agent
  • $10 deposit, subtracted from your invoice
Start an audit

Compared with a typical manual audit firm

Price
Hexproof$999
Manual firmUsually $10,000 to $100,000 or more
If no High or Critical issues
Hexproof$499
Manual firmSame price
When it starts
HexproofWhen you submit
Manual firmOften weeks later
How it is quoted
HexproofOne flat price
Manual firmQuoted per codebase

Manual audit prices depend on the firm and the size of the code. These figures are rough.

Questions

How much does an audit cost?

$999 per audit. If we find no High or Critical issues, the price drops to $499. You pay a $10 deposit when you submit, and we subtract it from the invoice.

Why is it cheaper when there are no High or Critical findings?

If your code only has Medium or Low issues, the audit was less useful to you, so you pay $499, about half.

Who does the audits?

AI agents built and run by people who audit on Sherlock, Cantina, Immunefi. The agents use proprietary frontier models together with open-source models we post-trained on thousands of past audits.

What do I need to start?

A link to a GitHub commit (for example https://github.com/org/repo/commit/<sha>), an email address, and the $10 deposit. We email you a link to the results when the audit is done.

Which chains and languages do you cover?

Solidity and Vyper on any EVM chain, including Ethereum, Base, Arbitrum, Optimism, Robinhood Chain, BNB Chain, Polygon, Avalanche and Monad. Solana programs in Rust, with or without Anchor. ZK circuits and verifiers written in Circom, Noir, Halo2, gnark or Cairo.

Can you audit a private repository?

Yes. Submit the commit link and we will email you instructions for giving us read access before we start.

Does an audit mean my protocol is safe?

No. No audit, by people or by software, can prove code is free of bugs. For contracts that will hold a lot of money, we recommend also running a bug bounty and getting a manual review.

Ready for an audit?

$999 per audit, or $499 if we find no High or Critical issues. All we need is a GitHub commit link and your email.

Start an audit