almondo@audit ~ % scan --scope ./contracts

AI-Driven Security Audits for Smart Contracts.

Every finding comes with a proof-of-concept you can run and a fix you can apply.

EVMSolanaSuiAptos
00Results so far
12 valid vulnerabilities found in live protocol code
$30.9M in assets those vulnerabilities put at risk
8 live protocols covered so far

Submitted through live bug bounty programs. The programs prohibit disclosure and several submissions are still open, so no protocol or finding is named here.

01What you get
every findingproven, rated, and ready to fix

A short list you can act on, not a long list you have to triage.

Producing a long list of findings is easy. Producing a short one you can trust means throwing most of them away, and that is where the work goes.

  • Findings you can reproduce and fix.

    Each one ships with a proof-of-concept you can run against your own code and concrete countermeasures to mitigate it, alongside its severity and exploit path.

  • Extensive detection.

    Multiple models that specialize in vulnerability research, each working the same code independently.

  • Extensive validation.

    Only findings that survive an extensive independent validation process reach the report, and a human reviews it before you see it.

02How it works
processscope in, run, report out
  1. 01 You send the scope.

    A repository, a commit, and what you want covered.

  2. 02 Almondo runs.

    Multiple independent analysis passes over the code. Every potential finding goes through an extensive independent validation process before it makes the report.

  3. 03 You get the report.

    Reviewed, scoped, reproducible.

03Coverage
targets4 chains, + appsec
EVM
Solidity, any EVM-compatible chain
Solana
Rust
Sui
Move
Aptos
Move
AppSec
General codebases outside blockchain

Additional ecosystems on request.

04Benchmarking
benchmarkin progress

The benchmarks this industry runs on do not measure what matters.

They score a binary crashing or a token drained, ignore whole classes of impact, and apply no penalty at all for false positives. Under that scoring, a tool that emits 500 junk findings alongside 3 real ones outranks one that emits 2 real findings and nothing else.

An independent benchmark of Almondo is in progress, built to a different standard:

  • Scored by real severity, not by dollars extracted
  • False positives carry a penalty, because in practice they cost you time
  • A dataset large enough that non-determinism does not pick the winner

The scorecard gets published here when it exists.

Read the full article ->

05Who's behind it
built byshkedo

Almondo Labs is built by Shkedo, a security researcher with 7 years of experience across offensive security R&D and blockchain security.

Most recently a blockchain security researcher at Starkware: vulnerability research on smart contracts, real-time monitoring of on-chain incidents, security tooling for crypto investigations and operations, and created an AI auditor for automated smart contract vulnerability detection.

Before that, in the IDF. In Unit 8200, built a new project in exploits and vulnerability research from the ground up, integrating LLMs and carrying it from initial design to a working MVP as its sole contributor.

Earlier, led a seven-person red-team and blue-team R&D group in the JCDD, after developing attack operations and instructing cyber defenders in malware analysis and forensics.

LinkedIn

06Request a free trial
reviewedindividually

Try it out for free!

Tell Almondo what to look at and it will run against it. The first run is free for teams that are a good fit, and every request is read and answered individually. NDA available on request.

Chain / language

Requests are reviewed individually. Sending this is not an approved trial.