AI-assisted smart contract security review

Use Hackcat to review smart contract code, design local security tests, and examine evidence from authorized forks and test networks.

Who this is for

For developers and independent security researchers reviewing EVM, Solana, or Move projects. Hackcat can help inspect source code, reason about trust boundaries, and develop test hypotheses. The project's chain, dependencies, and available tools determine the checks that are practical.

What to provide

Provide the contract source, compiler and dependency versions, build instructions, intended behavior, and the contracts in scope. Explain privileged roles, upgrade controls, economic invariants, and external dependencies. Identify whether the environment is local, a fork, or an explicitly authorized test network.

Review with Ask mode

Use Ask mode to inspect code paths, explain an access-control rule, reason about signature replay, or review a proposed invariant. It helps structure a review and discuss potential failures; a plausible explanation is not proof that an exploit works.

Execute with Agent mode

Use Agent mode to discover suitable tools, check their installed state, load their documentation, and run supported analyses or tests. For EVM projects, this can include compilation, static analysis, unit tests, and fuzzing when the required tools are available. Request a minimal reproduction for each suspected issue.

Choose an execution environment

Run attack simulations on a local chain, a permitted fork, or an explicitly authorized test network. A connected local environment can provide project-specific dependencies and files. Fork results depend on the selected block and configuration; avoid using production signing keys in test material.

Evidence and deliverables

Request affected code locations, assumptions, test fixtures, commands used, observed results, and remediation. Distinguish a local simulation from a verified real-world impact. Review the proposed fix and repeat relevant tests, including the project's existing regression suite, before making a release decision.

Limits and responsible testing

Hackcat does not provide a guarantee of contract safety or economic soundness. Tool availability varies, and complex protocol interactions still require human review. Never perform destructive actions against live mainnet contracts without explicit authorization; a successful local test does not authorize a mainnet transaction.

Open HackcatHelp CenterConnect a local Agent