AIToday
Large Language ModelsOpen-Source AIHacker NewsPublished: Jun 30, 2026, 10:00 JST2 min read

Open-source AI tool debuts for smart contract security audits

Open-source AI tool debuts for smart contract security audits

Key takeaway

  • AI Agent Audit, a new open-source Rust tool, helps security auditors find vulnerabilities in Solidity smart contracts by integrating with large language models (AI systems that understand and generate text).

  • The tool is designed to speed up expert manual review rather than replace it, and works with repositories that teams are comfortable sharing with external AI providers.

  • It launched in public beta for auditors, researchers, and protocol development teams.

3 Key Points

  1. What happened

    AI Agent Audit, a Rust command-line tool, launched in public beta to assist security review of Solidity smart contracts. It discovers vulnerabilities, deduplicates findings, generates proof-of-concept code for validated issues, and produces audit reports. The creator used it in Code4rena competitions with encouraging results.

  2. Why it matters

    The tool is designed to accelerate expert manual auditing rather than replace it—targeting smart contract auditors, security researchers, and protocol teams. It integrates with major AI providers (OpenAI/Codex by default, with support for Anthropic, Google, and DeepSeek) and runs locally, meaning repositories are sent to third-party LLM providers you configure. This may help security teams move faster on Solidity codebases, a high-stakes domain where vulnerabilities can lead to financial loss.

  3. What to watch

    The tool is in public beta and not a hosted service; users must run it locally using Rust, Git, Slither, and Foundry or Node.js. The default audit pipeline uses ChatGPT/Codex and gpt-5.5 for active review. Code and documentation are publicly available, and the creator encourages security-conscious teams to audit before sharing their codebase with external model providers.

Ask the AI about this article →

FAQ

What AI providers does the tool support?
The default audit pipeline uses OpenAI (ChatGPT/Codex). The tool also supports Anthropic, Google (Gemini), and DeepSeek as secondary options, though these are not required by the default review path.
Who should use this tool?
The tool is meant for smart contract auditors, security researchers, protocol teams doing internal review, and engineers experimenting with AI-assisted audit workflows on repositories they are allowed to share with external model providers.
Is this a replacement for manual auditing?
No. The tool is explicitly described as meant to accelerate expert review, not replace manual auditing. It is not a hosted service and not a substitute for human validation.

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • Visko raises $10M, launches live AI video model OrbisSiliconANGLE AI · 2h ago
  • Runway unveils Solaris, an AI that generates app interfaces in real timeTHE DECODER · 2h ago
  • Google AI Search flags Facebook users as dangerTHE DECODER · 2h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleSouth Korea to invest $1 trillion(約160兆円) in AI chips, data centers, and robots