We don't flag vulnerabilities. We prove them.
Every finding ships a signed, independently replayable exploit receipt — the exploit executed on a real EVM, moving real value. No proof, no finding.
Other checkers guess. We fork the chain and attempt the sell — execution is the verdict. Ethereum, BNB Chain, Base & Solana. Copying a wallet? Gate the mirror on proof →
Proof Wall
Each row is a vulnerability class we prove by execution — a vulnerable contract broken, a patched control that resists. Receipts are signed and independently verifiable.
| Class | Layer | Severity | Verdict |
|---|---|---|---|
| aggregator_vault_child_donation_nav_inflation | vault accounting / yield-aggregator (Summer.fi-class) | critical | PROVEN |
| arbitrary_delegatecall | classic SWC / DeFi | critical | PROVEN |
| arbitrary_storage_write | access-control / upgradeability | critical | PROVEN |
| assembly_hidden_delegatecall | evasive / obfuscated exploitable | critical | PROVEN |
| backdoor_constructor_owner | evasive / obfuscated exploitable | critical | PROVEN |
| bridge_message_replay | cross-chain / bridge | critical | PROVEN |
The full wall lists all 141 execution-proven classes. Full wall →
Why proof beats opinion
Static analyzers and LLM auditors answer "is there a check here?" They miss the class that costs the most: a check that exists but is wrong. Our verdict is execution truth — the exploit either moves value on a real EVM, or it is not a finding. A signed receipt lets anyone confirm the result without trusting us. Read the Verdict Standard → (no model, prover internals, or detection method disclosed — trade secrets)