Audited, about to ship?
Top auditors miss things. Cecuro catches them.
Make Cecuro your final set of eyes before deployment.
#1 Leading
One exploit can erase everything you built. Cecuro keeps finding the criticals that top auditors miss.
#1 on EVMBench — OpenAI's exploit benchmark
Your protocol could be the next row.
More cases belowEvery project deserves the same protection as billion-dollar protocols.
The same rigor that protects major DeFi, now within reach.
Our AI agents typically run for 8+ hours per audit, systematically exploring attack vectors and edge cases that human auditors, constrained by time and cost, routinely miss.
Traditional audits take weeks because thorough human analysis is slow. Our agents achieve the same depth in hours, with no queues and no compromises.
Top-tier audit quality that was previously reserved for protocols with six-figure security budgets, now accessible to every Web3 project.
These codebases passed top-tier human audits.
Cecuro still found critical bugs. Don't let the next one be you.
Medium finding pending public disclosure
Cecuro identified a Medium-severity vulnerability in a Solidity merkle-tree verification path that was reviewed and missed by SRLabs's May 2026 audit. Full technical writeup and the named project will be published once the issue is fixed and disclosure is appropriate.
Low-severity finding missed across the V3 competition and review
Cecuro identified a Low-severity vulnerability in Alchemix V3 that was reviewed and missed by both the Immunefi competition (298 researchers, 952 reports, $100k pool) and a subsequent Y-Audit review (commit 45e4b08).
Confirmed at commit 45e4b08.
First High finding pending public disclosure
Cecuro identified a High-severity vulnerability reviewed and missed by Hacken's January 2026 audit. Full technical writeup and the named project will be published once the issue is fixed and disclosure is appropriate.
Second High finding pending public disclosure
Cecuro identified a second High-severity vulnerability reviewed and missed by Hacken's January 2026 audit. Full technical writeup and the named project will be published once the issue is fixed and disclosure is appropriate.
Cross-function reentrancy in ServiceManager.create() drains pooled ERC20 deposits via _safeMint callback
ServiceManager.create() registers a new service and mints its ownership NFT via ERC721 _safeMint, which hands control to the recipient's onERC721Received hook before the service's accounting is finalised. From inside that callback an attacker can re-enter the registry's deposit path and act against pooled ERC20 deposits while the contract's state is still mid-update — a classic cross-function reentrancy across the create/deposit boundary. Reviewed and missed by the Zellic V12 AI auditor, which inspected ServiceManager.create() and StakingBase but did not flag the _safeMint reentrancy window.
Reviewed ServiceManager.create() and StakingBase, but did not flag the _safeMint reentrancy window.
Cross-contract reentrancy in liquidation drains the collateral vault via live phantom shares
During liquidation the account is temporarily inflated with "phantom" shares used only for solvency math, and the two collateral tokens are settled one after the other. An external callback fires mid-sequence while the phantom shares are still live, letting a malicious liquidator transfer them out and redeem them for real assets — draining the CollateralTracker and socializing the loss to all depositors. Reviewed and missed by Nethermind's NM-0701 audit; independently confirmed as High (H-02) by the parallel Code4rena "Panoptic: Next Core" competition and since mitigated.
Oracle rebase mask clears 8 bits of spot EMA, corrupting the solvency oracle after large moves
The bitmask used when "rebasing" the packed price-oracle word is sized wrong and erases more bits than intended, wiping part of the stored EMA price values it was supposed to preserve. This corrupts the price feed the solvency checks depend on after large market moves. Missed by Nethermind's NM-0701; confirmed as Medium (M-04) by Code4rena and since mitigated.
Liquidation bonus underflow leaves insolvent accounts unliquidatable or overpays liquidators
The liquidation-bonus formula subtracts collateral balance from the requirement without guarding against the balance being the larger of the two. The V2 solvency rewrite made that state reachable (an account insolvent in one token but flush in the other), so the unsigned subtraction misbehaves — blocking liquidations entirely, or producing a wildly inflated bonus. Missed by Nethermind's NM-0701; confirmed as Medium (M-01) by Code4rena and since mitigated.
Per-leg zero-width credits overwritten instead of accumulated, mis-valuing multi-leg positions
When computing a position's required collateral, the credit for zero-width legs is overwritten on each loop iteration instead of summed. Positions with multiple such legs are mis-valued, which can trigger erroneous liquidations. Missed by Nethermind's NM-0701; confirmed as Medium (M-02) by Code4rena and since mitigated.
Liquidation / force-exercise DoS via manipulable spot-vs-TWAP stale-oracle check
A short-lived spot-price manipulation can trip the StaleOracle guard inside dispatchFrom, blocking time-critical liquidations, force exercises, and premium settlements for as long as the attacker holds the price off-band. Missed by Nethermind's NM-0701; confirmed as Medium (M-06) by Code4rena and since mitigated.
Internal oracle is cheaply manipulable via slot0 tick across 64-second epochs
The internal oracle ingests an easily-influenced spot tick, and once updated in a 64-second epoch it can't be corrected until the next one. An attacker can front-run legitimate updates and nudge the oracle across epochs (e.g. with flash loans) to skew the price used in risk calculations. Missed by Nethermind's NM-0701; confirmed as Medium (M-11) by Code4rena and since mitigated.
Nethermind's NM-0701 reviewed the panoptic-v2-core liquidation, oracle, and collateral-settlement paths — the same shared core logic — but did not flag any of these six issues. Each was independently confirmed by the parallel Code4rena "Panoptic: Next Core" competition (later commit 29980a74) and has since been mitigated by Panoptic.
High finding pending public disclosure
Cecuro identified a High-severity vulnerability that was reviewed and missed by four independent audits — Cantina Code, GetRecon, 0xMacro, and Octane Security. Full technical writeup and the named project will be published once the issue is fixed and disclosure is appropriate.
High finding pending public disclosure
Cecuro identified a High-severity vulnerability that was reviewed and missed by four independent audits — Cantina Code, GetRecon, 0xMacro, and Octane Security. Full technical writeup and the named project will be published once the issue is fixed and disclosure is appropriate.
Most tools surface-scan your code in seconds. A Cecuro audit coordinates ~180 specialized agents for an average of 8 hours, investigates every contract from adversarial angles, and reproduces each finding with a runnable proof-of-concept before it reaches your report.
Getting started is simple. Connect your code and receive a comprehensive smart contract audit in just a few hours.
Select your repository, branch, and commit, then submit for auditing.
Our AI agents spend ~8 hours systematically probing attack vectors, tracing execution paths, and testing exploit scenarios across your entire codebase.
Identifies vulnerabilities with detailed explanations and suggested fixes. Resubmit your fixes to verify remediation.
Receive your comprehensive audit report with professional documentation ready for stakeholders.
Proven across two independent benchmarks. Not just better than AI models. Better than protocols with up to 11 audits from top firms.
the detection rate of the best frontier AI model
more value protected vs the same model without our architecture
audits from top firms missed exploits that Cecuro detected
Cecuro

Detection rate (%) on the EVMBench dataset (117 vulnerabilities from Code4rena competitions). Best variant shown per model family.
Purpose-built AI security system
Same model, no security specialization
Tested on 90 real exploits that caused $228M in losses. Both systems ran the same frontier model. The difference is entirely Cecuro's purpose-built security architecture.
EVMBench results from the industry benchmark by OpenAI, Paradigm, and OtterSec. Real-world exploit data sourced from Anthropic's SCONE-bench and DeFiHackLabs. Both confirm that specialized architecture, not model size, is the key differentiator in AI smart contract security.
Who needs an AI audit?
Cecuro consistently finds what top firms miss.
$0M+
drained from DeFi protocols in 2026 alone
Hack Radar →Top auditors miss things. Cecuro catches them.
Make Cecuro your final set of eyes before deployment.
You should be. Bugs lurk for months.
Re-audit shipped code before adversaries find them.
First audit? Tight budget? Start with the leading AI auditor, at a fraction of the cost of a traditional human audit.
We tested on 90 contracts that were exploited in the real world.
Cecuro detected 92% of the vulnerabilities humans had already missed.
90 contracts exploited in the real world for $228M — despite existing security reviews.
of the vulnerabilities that human auditors had already reviewed and missed
Sources: Anthropic SCONE-bench · DeFiHackLabs · Security Boulevard
The only viable defense is AI-powered security that evolves at the same pace.
Protect your protocol with the leading agentic auditor.
"Cecuro caught real issues that were independently confirmed by our human senior auditors. The findings were well-reasoned, clearly explained, and actionable. For an AI-powered audit, the signal-to-noise ratio was impressive. We came away with genuine improvements to our codebase and will definitely be using Cecuro on future codebases."
Utkir
CTO at Zyfai
"We ran Cecuro alongside our existing audit process and it flagged a critical finding that separate manual reviews had missed. Saved us from what could have been a serious incident."
Founder
DeFi
Stay updated with the latest insights on smart contract security, blockchain trends, and Web3 development best practices.

Anthropic's Mythos preview found thousands of zero day bugs in weeks. Here is what that means for Web3 security, and why smart contracts need their own defender.

Cecuro achieved 87.17% detection on EVMBench, nearly double the next-best AI system, making Cecuro industry-leading in AI smart contract auditing. Here's what the benchmark tells us about AI smart contract security.

A full breakdown of every major smart contract exploit in May 2026, from the $11.6M Verus bridge hack to THORChain's threshold signature breach.
Cecuro's research team tracks every public exploit and publishes detailed write-ups.
On June 9, 2026, the identity-focused network Humanity Protocol suffered a devastating administrative breach resulting in financial losses exceeding $31 million.
On June 4, 2026, the BYToken contract on the BNB Chain was exploited for approximately $87,400 (146. 6 BNB) via a flash-loan price manipulation attack.
On June 4, 2026, the ATM token protocol on the BNB Chain was exploited for approximately $243,500 due to a fatal logic flaw in its custom transfer function mechanism.

Real-time exploit alerts, new hacks, and security events — free, on Telegram and X.