almondo@audit ~ % scan --scope ./contracts
AI-Driven Security Audits for Smart Contracts.
Every finding comes with a proof-of-concept you can run and a fix you can apply.
Submitted through live bug bounty programs. The programs prohibit disclosure and several submissions are still open, so no protocol or finding is named here.
A short list you can act on, not a long list you have to triage.
Producing a long list of findings is easy. Producing a short one you can trust means throwing most of them away, and that is where the work goes.
-
Findings you can reproduce and fix.
Each one ships with a proof-of-concept you can run against your own code and concrete countermeasures to mitigate it, alongside its severity and exploit path.
-
Extensive detection.
Multiple models that specialize in vulnerability research, each working the same code independently.
-
Extensive validation.
Only findings that survive an extensive independent validation process reach the report, and a human reviews it before you see it.
-
01
You send the scope.
A repository, a commit, and what you want covered.
-
02
Almondo runs.
Multiple independent analysis passes over the code. Every potential finding goes through an extensive independent validation process before it makes the report.
-
03
You get the report.
Reviewed, scoped, reproducible.
- EVM
- Solidity, any EVM-compatible chain
- Solana
- Rust
- Sui
- Move
- Aptos
- Move
- AppSec
- General codebases outside blockchain
Additional ecosystems on request.
The benchmarks this industry runs on do not measure what matters.
They score a binary crashing or a token drained, ignore whole classes of impact, and apply no penalty at all for false positives. Under that scoring, a tool that emits 500 junk findings alongside 3 real ones outranks one that emits 2 real findings and nothing else.
An independent benchmark of Almondo is in progress, built to a different standard:
- Scored by real severity, not by dollars extracted
- False positives carry a penalty, because in practice they cost you time
- A dataset large enough that non-determinism does not pick the winner
The scorecard gets published here when it exists.
Almondo Labs is built by Shkedo, a security researcher with 7 years of experience across offensive security R&D and blockchain security.
Most recently a blockchain security researcher at Starkware: vulnerability research on smart contracts, real-time monitoring of on-chain incidents, security tooling for crypto investigations and operations, and created an AI auditor for automated smart contract vulnerability detection.
Before that, in the IDF. In Unit 8200, built a new project in exploits and vulnerability research from the ground up, integrating LLMs and carrying it from initial design to a working MVP as its sole contributor.
Earlier, led a seven-person red-team and blue-team R&D group in the JCDD, after developing attack operations and instructing cyber defenders in malware analysis and forensics.
Try it out for free!
Tell Almondo what to look at and it will run against it. The first run is free for teams that are a good fit, and every request is read and answered individually. NDA available on request.