Over 7 years auditing and formally verifying complex DeFi code, now we've built AutoProver, which leverage LLMs to automate security processes and produce mathematical proofs.
Devs will use it to secure code against LLM attacks. Premium audits continue full force🧵
Rounding errors have drained millions from DeFi protocols.
Certora is building an open source static analysis tool for Solidity to prevent them, and we're participating in the @ethereum Security QF Round from @thedaofund.
Your donation helps us go further ↓
🎉Certora Prover v8.13.0 released - enhancements for EVM, Solana, and Stellar/Soroban
The @Certora Prover is an open-source formal verification engine that proves smart contracts can only behave as intended ... & finds real bugs, otherwise.
And it keeps getting better 👇
This week the @arbitrumdao_gov Security Council froze 30,766 ETH (~$71M) connected to the @KelpDAO exploit, taking it out of reach of the Lazarus Group (a hacking collective with ties to the DPRK).
Certora's VP of Security Labs Elad Erdheim was one of the signers protecting the funds.
Before it all happened, our team flagged two critical edge cases that hadn't been identified yet:
1. If the recovery process wasn't atomic, it would open a window for anyone to drain @arbitrum user funds. Billions of dollars would have been exposed.
2. If the exploiter reduced their balance by even a small amount, the proposed tx would fail, giving them time to move funds before the council could regroup and sign a new one.
Both issues were mitigated before the transaction was finalized: the sequencer could be paused in either scenario, giving the council a 24-hour window to respond.
The tx went through. $71M was protected thanks to smart, thoughtful, and security-first responders.
Certora supports decentralization. And we support the failsafes, circuit breakers, and redundancies that will help the industry mature.
Certora Prover v8.11.3 released 🎉
The @Certora Prover is an open-source formal verification engine that proves smart contracts can only behave as intended ... & finds real bugs, otherwise. And it keeps getting better.
Here’s what’s new 👇
New Review Comment Features in Our Github App
• gh-review indicates when to add a review comment to the PR.
• gh-review-jobs - indicates which jobs to include in the GitHub review comment.
Your AI agent now has access to 20k+ smart contract audit findings.
claudit - one-line install, works with Claude Code & Codex CLI, searches across all @SoloditOfficial findings, open source.
Huge shoutout to @Cyfrin for opening the Solodit API 🫡
Link below 🔗👇
Apyx has successfully completed a smart contract audit conducted by @Certora, marking our second independent smart contract security review.
Security is not optional.
@DoD4uFN@Certora Remember, ... you can only win the Capture the Funds prize one time. But, learning the Prover is a great investment that will pay off in other projects!
Safe Smart Contract Vibe Coding by @SagivMooly Chief Scientist of @Certora
“Vibe coding” in web3 often fails due to missing guardrails.
Full video below 👇🧵
Today @SagivMooly is taking the stage at @EthereumDenver to present:
“Safe Smart Contract Vibe Coding”
If you vibe code, this one’s for you 👀
📅 12:40 PM
📌 Futurllama Stage