Tokenized capital markets need shared standards institutions can trust. That's why Nethermind joined @cmta_ch, bringing engineering and security to digital capital markets in Switzerland, Europe, and beyond. We build and secure the infrastructure behind institutional adoption.
We completed a security review of @VistaPex, a perpetual futures exchange on Avalanche. The review covered the protocol's pooled USDC custody logic and its offchain trade settlement path, which uses SP1 zero-knowledge proofs to verify offchain calculations onchain.
We reported 5 findings, all addressed swiftly by the VistaPex team. Full report:
https://t.co/6y6JVI4ghb
Nethermind Client got significantly faster. We replayed real mainnet blocks: block processing is 20% faster on AMD, 28% faster on ARM. On a batch of eth_call queries, latency dropped 28% on AMD and 34% on ARM.
And these are optimizations on top of a much bigger change: FlatDB, a rework of how the client stores state that's becoming the default soon.
Always tuning.
Most protocols stop at the audit. Lido didn't.
An audit is essential, but it's a snapshot:
New AI models find what older ones and past reviews missed.
New attack vectors surface, and attackers weaponize them fast.
So @LidoFinance had us run AI + experts on already-audited Lido Core: AuditAgent and AgentArena, tuned on their protocol knowledge. Together they went deeper and wider, with less noise.
And it doesn't stop. We re-run AgentArena as new models drop, so coverage gets sharper as the models do.
Full write-up ⬇️
https://t.co/SjKJUH8LkV
AuditAgent's MCP server is live. Start a scan on your contracts and get the results straight in your coding agent
New accounts come with $50 in free credits, enough to run Auditor, our most in-depth scan mode, on your own code.
By popular request, findings can now be grouped by file or by topic too, not just severity. Makes triage a lot faster on a big codebase.
That's Persistent Memory: a per-project knowledge base your scans build on, and one you can edit and check yourself. Run it as the pre-audit baseline, not a replacement for one.
See how it works → https://t.co/lTh1fRKgLN
AuditAgent's latest release learns how your code is meant to work, and keeps that knowledge shared across your team.
The new piece is 𝘊𝘶𝘴𝘵𝘰𝘮 𝘊𝘰𝘯𝘵𝘦𝘹𝘵, a set of Markdown notes you attach to a project, organized in folders, that AuditAgent reads and treats as ground truth before it analyzes your contracts. Write your invariants, architecture, and the behavior to watch for, or let AuditAgent draft those files and keep the parts you want. On every scan, Custom Context steers where and how the review looks.
𝘊𝘶𝘴𝘵𝘰𝘮 𝘊𝘰𝘯𝘵𝘦𝘹𝘵 lives inside Persistent Memory, so it works the way the rest of your memory does. It persists between scans, updates itself each run, and you can share it across your team by email. A teammate attaches their copy of the repo and starts from that same context, so nobody on the team is scanning from scratch.
We also moved the analysis pipeline onto the latest frontier models, raised documentation limits, and improved retrieval. Together they increase recall by roughly 25% on our internal benchmarks.
AuditAgent raises the baseline before an audit, so auditors spend their time on the business logic AI still misses. Custom Context means the whole team feeds that baseline, not just whoever ran the last scan.
Most AI scanners start every run from zero. AuditAgent now keeps a per-project memory. Each scan builds on what it already learned about your codebase, so repeat runs get sharper instead of repeating themselves.
Uniswap ran a free AuditAgent scan, an AgentArena competition on UniswapX, and adopted the AuditAgent Business Plan in three months. Cody Born, Principal Engineer at @Uniswap, on what AuditAgent changed in their development workflow:
A real story of one of our clients who went through AuditAgent -> AgentArena -> Professional Audit:
1/ Developer scan (regularly while development): fixed some issues
2/ Auditor scan (one off): several medium-severity vulnerabilities were identified - fixed.
3/ AgentArena: one high-severity vulnerability and several medium-severity ones - fixed.
4/ Final stage of the professional audit: 0 high-severity and 0 medium-severity vulnerabilities.
Soon we'll publish a case study on it. This was made possible by our multilayered approach to security. Contact me if you have any questions.
2024: Can AI find smart contract vulnerabilities?
2025: Can you act on the output without drowning in false positives?
2026: How fast, what does it cost, what does it cover?
Detection isn't the bottleneck anymore.
AuditAgent, pointed at live deployed code, surfaced a real vulnerability. First accepted submission to a bug bounty program on Immunefi.
Medium severity. Accepted by the project.
Audits cover scope. Formal verification proves properties. AuditAgent runs continuously against what's already live. Nethermind does all three.
2024: Can AI detect smart contract vulnerabilities?
2025: Can you act on the output without drowning in false positives?
2026: How fast does it run, what does it cost, what does it actually cover?
Detection's not the bottleneck anymore. Speed, cost, and coverage are.
A smart account for crypto-to-credit-card payments that switches between direct spending and DeFi credit borrowing. One mode active at a time.
Security review for @hyperbeat's Liquid Bank on @HyperliquidX ⬇️
https://t.co/SviKCJ65Q5
AuditAgent on EVMBench, all 40 repos. 80/120 detections (67%). Best base model: 47%.
The 67% is post-validation. AuditAgent filters findings before surfacing them. Most benchmark numbers don't.
Full methodology and scoring algorithm (open-sourced) in the blog.
AuditAgent now triggers from your GitHub repos, CI pipeline, your API, or directly on a deployed contract.
Four entry points. Same findings report. Vulnerabilities flagged before your auditors touch the codebase.
Nethermind's first intern joined in January 2021. He's now an Ethereum Core Dev.
Since then, the program has put engineers on execution client development, Starknet validator infrastructure, zero-knowledge research, AuditAgent, and formal verification, not simulated projects.
Full 2025 summary report: https://t.co/BeA6jLaMXr
Multiple audits. Years in production. @LidoFinance's smart contracts are among the most reviewed in DeFi.
Three AgentArena competitions ran independent agents on the same scope in parallel. Human auditors validated every finding. Done in days, not weeks.
6 Medium severity issues. 8 Low.
"The validated findings were comparable in quality to those identified by experienced human auditors." — Gregory S., Lido Audit Committee
Two out of three high-severity vulnerabilities on EVMBench detected by AuditAgent. Before any manual review would start.
EVMBench is a standardized benchmark for AI vulnerability detection, built by @OpenAI. We ran all 40 repos.
AuditAgent: 80/120 (67%). Best base model: 56/120 (47%). No repos skipped, run in order.
Recall is one dimension. We evaluate against both recall and precision, and we've open-sourced our evaluation methodology. Full analysis next.
https://t.co/6g9q4lpu2p
Yes, we built it. It's called @Agent4rena_NM.
Two bounty competitions already completed. Third coming soon.
~15 AI security agents are already live on AgentArena, with more coming as security researchers and auditors start building their own agents.
Now we need protocols to start hosting their bounty competitions on AgentArena.
In my view, this is where the future of security is heading.
https://t.co/kIHtwxyIYA