Keleros evaluated many smart contract security tools (static analyzers, symbolic execution, fuzzers, and AI). Most miss issues and generate many FPs esp on complex DeFi contracts. AI sometimes beats specialized tools on simple cases, but struggles once systems get complex.
The test by MagicGrants used AI to audit a real Ethereum contract for ~$5. But it flagged “critical bugs” that weren’t bugs and even suggested fixes that could introduce real vulnerabilities.
This proves that AI without verification ability cannot meet our auditing needs.
https://t.co/HKgzk1o1Pz https://t.co/eK7E7JWeOx
One is "AI is not ready for security audits" from MAGIC Grants.
The other is "Smart Contract Security Tools: A Comprehensive Review" from Kleros.
I’ve been looking into whether AI alone is actually ready to audit Ethereum smart contracts.
Short answer: not really.
Two recent write-ups tested AI tools and existing security scanners. The results are interesting.
Looking ahead, security can’t rely just on audits or pattern checks.
We’re building agentic checkers that actually understand authority flow and execution logic, spotting structural risks before deployment.
Proactive beats reactive.
https://t.co/tQpF0FgMAx
Pity to see such an influential company shut down after a treasury breach.
The problem wasn’t the chain itself, it was a compromised key or account.
Relying on a single signer is extremely risky.
Multisig and keeping keys in separate places is a must.
Today we are announcing that Step Finance, SolanaFloor, and Remora Markets will be winding down all operations.
Following the hack at the end of January we explored every possible path forward, including financing and acquisition opportunities.
Unfortunately, we were unable to secure a viable outcome and have made the difficult decision to end all operations effective immediately.
We are working on a buyback for STEP holders based on a snapshot prior to the incident, and a redemption process for Remora rToken holders. Remora tokens remain backed 1:1.
We are deeply grateful to our community for the support over the years and are confident that this is the best outcome given the circumstances. We want to thank our millions of customers over the years for joining us on this journey.
More details will be shared soon
At @ChainFoxAI , our previous staking setup used multisig from day one.
No single account could move funds.
Security is built into the system, not left to chance.
Work these days:
Initial version of rug-pull detection will be out in 24h.
Pushing the checkers to be more agentic, not just rule-based flags.
Tried the newest doc to spec tools. Promising, but still needs manual work.
Step by step. Build the foundation right.
@ChainFoxAI
Weekend plan:
keep pushing the project following the roadmap.
Priority:
Get the skills right and make the agentic checker solid.
That’s the foundation of everything.
If time allows, integrate rug-pull detection and web risk checks next.
Caught a cold these days.
Still keeping up with work and reading.
Spent some time exploring new security tools,
and digging into model-checking related research.
They may help reduce false positives in checkers and the hallucination of the current LLMs.
Today, we used our own tools to test Chain-Fox website security, found issues, then hardened it.
We also dapted the current detector to be more agent-friendly.
@ChainFoxAI
Trying to deploy checks today for our web security analysis tools.
The goal is not just detection, but a multi-dimensional understanding of web security.
@ChainFoxAI
Now it’s the era of Skills.
Things that felt impossible just a few months ago are now easy to build.
In the new year, with Skills, Chain-Fox will move faster and go further in Web3 security.
@ChainFoxAI
We've launched a new security bounty program for Anchor, offering rewards of up to $100k for vulnerabilities that affect production code.
If you think you’ve found an issue, we want to hear from you. Details on scope and eligibility below ↓
Yield-bearing gold, vaulted with regulated custodians, is now tokenized and available on Solana with @orogoldapp
The golden era of capital markets is here