Audits the proof, not just the contract
Models the malicious prover end-to-end—the threat Solidity-only tools structurally can't see.
AI smart-contract & ZK security
Two audit engines, one pipeline. A state-of-the-art Solidity / EVM auditor, plus the first AI system that audits zero-knowledge circuits, provers, and verifiers end-to-end—deeper than a scanner, at a fraction of the cost of a manual audit.
Confidential Reports · Privacy focused · zero data retention
The zero-knowledge engine
Most AI auditors stop at your Solidity. AuditAid keeps going—into the circuits, provers, and verifiers the rest of the market leaves to humans.
Models the malicious prover end-to-end—the threat Solidity-only tools structurally can't see.
Pairs every witness assignment against its constraint and flags any a prover can set freely—confirmed by non-uniqueness, not guesswork.
Maps every off-chain check that isn't enforced in-circuit—the most common ZK bug class, and invisible to contract-only review.
Pairing-equation completeness, public-input binding, and chain / contract / recipient checks—including SP1 and RISC0 program-ID substitution.
Concrete field values and minimized counterexamples, with formal SMT proof where it applies. Built for signal, not noise.
Circuit, prover, verifier, and rollup contracts are audited together and cross-checked—so bugs that span layers don't slip between them.
The EVM / Solidity engine
EVMbench is the OpenAI × Paradigm benchmark for AI smart-contract auditors—117 curated, real-world vulnerabilities. Here is how AuditAid's detection recall compares to the published field.
AuditAid's figures are self-reported: we ran the public EVMbench dataset and graded it locally with the same prompt and model as the official harness, without a leaderboard submission. All other results are taken from the public EVMbench leaderboard (testmachine.ai/evmbench) as of June 2026. EVMbench scores detection by recall; the false-positive rate is AuditAid's own measurement and is not reported by other entrants.
Scanning is free—you only pay after you approve the quote.
Deeper than a scanner. Structured like a firm engagement—without the calendar.
Point us at a repo or upload an archive, review every .sol file, and pick exactly what's in scope.
Your price comes straight from in-scope lines of code on a public formula—no hidden tiers, no model surcharges.
Server-side agents run the complete methodology while you watch progress live, then download the report and PoCs.
One full-depth pipeline, tuned to wherever you sit in the lifecycle.
Cut audit costs before you book a firm. Run AuditAid on every pull request for inline comments on new vulnerabilities, and reach your manual audit with the Criticals and Highs already fixed.
Surface the majority of Critical and High findings in a fraction of the time, auto-triage static-analysis noise, and spend senior hours on the bugs that truly need a human.
Compete on Code4rena, Sherlock, Cantina and Immunefi with an edge: AuditAid ships a runnable proof-of-concept for every confirmed finding—so you submit a working exploit, not just a claim.
Run independent diligence before you commit capital—a reproducible, structured security report with proof-of-concept tests for every confirmed finding, not a vibe check.
AuditAid's agents are model-agnostic by design. We've engineered each skill to remove the guesswork—telling the model exactly how to perform every task instead of hoping it reasons its way there. The result is better findings at lower cost than platforms that lean on raw frontier models.
What developers, audit firms, and protocol teams ask before their first audit.
AuditAid is an AI smart-contract security auditor that audits both Solidity/EVM contracts and zero-knowledge circuits end-to-end, delivering structured, reproducible findings with proof-of-concept exploits at a fraction of the cost of a manual audit.
In our run of the public EVMbench benchmark, AuditAid reached 88% detection recall (103 of 117) at 0.0025 false positives per line of code—higher recall than every published result on the EVMbench leaderboard.
On EVMbench—the OpenAI × Paradigm benchmark and the closest thing to an independent standard—AuditAid reports the highest published detection recall to date: 88% (103 of 117 real-world vulnerabilities), ahead of the next-best published result (Azimuth/TestMachine, 78.6%) and far above raw models like GPT-5 or Claude used without an audit harness (38–54%). AuditAid's figure is self-reported, graded with EVMbench's own GPT-5 judge. It also audits zero-knowledge circuits, which most Solidity auditors don't.
Yes. AuditAid audits Circom, Noir, Halo2, and zkVM (SP1/RISC0) circuits, provers, and verifiers—not just the Solidity around them. It is the first AI auditor to cover ZK circuit soundness across this stack.
Pricing is a transparent public formula based on effective in-scope lines of code (roughly $0.28–$0.30 per line, $50 minimum). Blank lines and comments are excluded, documentation is free context, and you see the quote before you pay.
No. AuditAid reduces cost and time by finding the majority of Critical and High vulnerabilities, triaging static-analysis noise, and shipping proof-of-concept exploits, so human auditors focus on the issues that need judgment.
Yes. A GitHub App integrates with your pipeline and comments inline on newly introduced vulnerabilities on every pull request, with org-level isolation.