Open Beta: Free 3-day Pro trial active — Subscribe to keep access

Announcements

View all →
2026-04-03📌Open Beta: 3-Day Free Pro Trial
2026-03-29📌MythX Shutting Down — Migrate to ContractScan
2026-03-25ContractScan Closed Beta Now Open
6 analysis engines  ·  350+ vulnerability patterns

AI-augmented Solidity audit.
5 engines, 200+ rules,
in under a minute.

Upload a .sol file or paste a GitHub URL. Get a structured vulnerability report — free, no signup needed.

Scan a contract View methodology
Pro Trial — 3d 0h left (0/5 scans today)
No contract handy? Try a sample:
Automatically fetches verified source code from Etherscan / Sourcify
QuickScan — Free Unlimited No signup required Results in seconds
(optional — enables AI report)

Have a license key?

Enter your license key to unlock unlimited scans or additional scan credits.

Analysis engines

Six tools. One report.

Slither
Trail of Bits
~92 detectors

Industry-standard Solidity static analysis. Data flow, CFG traversal, and storage slot inspection.

Read more →
Mythril
ConsenSys Diligence
Pro

Symbolic execution over EVM bytecode. Finds paths no linter can: integer overflows, assertion violations, unprotected ether.

Read more →
Semgrep
Semgrep OSS
201 rules

AST-aware pattern matching. Fast, high-precision rules for known vulnerability classes written by ContractScan.

Read more →
Aderyn
Cyfrin — Rust
Pro

Rust-based Solidity AST scanner from Cyfrin. Detects centralization risks, unsafe casts, and unused returns.

Read more →
4naly3er
Code4rena style
100 checks

Gas optimisation and code quality checks modeled after Code4rena contest standards. Catches inefficiencies reviewers flag.

Read more →
AI Engine
LLM reasoning
Full Scan

LLM-powered business-logic analysis. Flash loan surfaces, oracle risks, MEV exposure, governance attacks — what static tools miss.

Read more →
Full methodology & false-positive notes →

Live Threat Intelligence

● LIVE

Enriched with 1485+ real-world DeFi exploits — collected weekly from 6 authoritative sources to keep detection patterns current with emerging attack vectors.

Live Threat Intelligence

● LIVE

Findings aggregated from public audit reports, competitive auditing platforms, and on-chain post-mortems. Updated daily.

ContractScan automatically collects and indexes real-world DeFi security incidents and professional audit findings from 7 public threat feeds to keep detection patterns current with emerging attack vectors.

🔍 Solodit Audit ReportsiCurated audit findings aggregator by Cyfrin — 16+ top securi…✓ Active
🔬 DeFiHackLabsiOn-chain exploit PoC replays (SunWeb3Sec); primary real-worl…✓ Active
📰 Rekt.newsiDeFi hack post-mortems and investigative analysis via RSS; n…✓ Active
🏆 Code4renaiPublic audit competition platform; high-signal findings from…✓ Active
🛡️ SherlockiAudit + insurance protocol; competitive review reports with …✓ Active
📋 SCV-ListiSmart Contract Vulnerability List — curated CVE-style SCV-ta…✓ Active
📋 SWC RegistryiSmart Contract Weakness Classification registry; authoritati…⏸ Stale
1485+
incidents indexed
7
threat sources
2026-05-03
last collected

Last updated: 2026-05-03  ·  Learn about our methodology →

Need deeper analysis?

Pro unlocks Mythril symbolic execution, Aderyn AST analysis, full AI reports, and CI/CD integration — all in under 60 seconds.

View Pro plans See example report

Latest Security Guides

View all 30 posts →
OpenZeppelin v4 vs v5 Migration: 7 API Changes That Break Your Contracts
OpenZeppelin Contracts v5 was a deliberate API redesign — many widely-used helpers were re...
Solady 0.1.x: EIP-7702 Proxy and What Account Abstraction Developers Need to Know
Solady 0.1.x introduces EIP7702Proxy, ERC7821, and a redesigned account-abstraction stack....
Verified Patch Generation: Why AI-Suggested Solidity Fixes Fail to Compile (and How to Fix It)
AI-generated Solidity patches look perfect — until you paste them into your codebase and w...
ContractScan on Product Hunt