Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 3 min read

I ran my Solidity scanner on the 10 most-audited codebases in web3. Here's every flag.

The hard part of a security scanner isn't finding things. It's not drowning the real issues in noise. A tool that flags forty non-issues trains you to ignore it β€” and then it misses the one that matters. So when I built

The hard part of a security scanner isn't finding things. It's not drowning the real issues in noise.

A tool that flags forty non-issues trains you to ignore it β€” and then it misses the one that matters. So when I built OpenClaw Audit (a free, MIT heuristic Solidity scanner), I held it to one bar: silence on sound code.

To prove it stays quiet, I ran it across ten of the most-reviewed Solidity codebases in the ecosystem β€” libraries that thousands of protocols depend on and that have been audited many times over β€” and hand-verified every flag. Here's exactly what came out.

The numbers

Run on each library's source (tests, mocks and dependencies excluded), latest main:

Codebase Source files Candidates Notes
OpenZeppelin Contracts 247 0 Completely clean.
forge-std 31 0 Clean.
Uniswap Permit2 16 0 Clean.
PRBMath 40 0 Clean.
Uniswap v2-core 11 1 A defensible CEI-ordering candidate on createPair β€” worth a human's eyes, not a false alarm.
Uniswap v3-core 40 1 initialize() flagged β€” false positive: pool init is permissionless by design.
Uniswap v4-core 46 1 Same as v3 β€” permissionless initialize(), false positive.
Solmate 20 2 One real, known flag (ERC-4626 first-depositor inflation, omitted by design); one rounding false positive.
Morpho Blue 17 2 Two reentrancy false positives β€” formally verified, correct effects-before-interactions.
Solady 140 7 All false positives: documented tx.origin rescue, UUPS auth the heuristic can't parse, intentional math ordering.
Total 608 14 ~2.3% of files flag anything; 4 of 10 codebases perfectly clean.

What this actually shows

It stays silent on sound code. Zero findings across OpenZeppelin, forge-std, Permit2 and PRBMath β€” the most-audited code in web3, where naive tools carpet-bomb false positives.

When it does flag, the flags are explainable β€” not random. They cluster on genuinely interesting spots: a permissionless initializer, a documented rescue mechanism, a library that deliberately leaves inflation protection to the integrator. A human clears each in seconds. That's the point.

It catches real, known design gaps. The Solmate first-depositor-inflation flag is a true observation: that ERC-4626 implementation omits the virtual-share defense OpenZeppelin's adds. The scanner surfaces the difference.

My favorite result is Solady: zero flags across 140 files of hand-written, gas-golfed assembly β€” the kind of code that makes lesser tools panic. The raw call() in SafeTransferLib looks like the classic unchecked-call bug, but it verifies success AND the return value AND that the address has code. Correct restraint: there was nothing to report.

Verify it yourself β€” one command

Every number above is reproducible. You don't have to trust me:

pipx run --spec git+https://github.com/juan23z/openclaw-audit openclaw-audit \
  https://github.com/OpenZeppelin/openzeppelin-contracts
# β†’ 0 candidate observations across 247 client .sol contracts

Swap the URL for any codebase above β€” or your own repo β€” and check the numbers. That's the whole idea: a claim you can verify, not one you have to trust.

Use it on your own code

Point it at a repo and get a Markdown + HTML report in seconds, or drop it into CI as a GitHub Action and get a scan on every PR:

# .github/workflows/security.yml
name: security
on: [push, pull_request]
permissions: { contents: read, pull-requests: write }
jobs:
  audit:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: juan23z/openclaw-audit@v1

It's free and MIT. Findings are heuristic candidates β€” verify before acting (the report labels every one).

Shipping to mainnet and want a human on it? I do fast, honest smart-contract reviews for small protocols β€” a hand-verified Quick Scan is $49 (one contract, 48h, and if the report isn't useful you don't pay). Full calibration report and services at juan23z.github.io.

πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.