Quick Answer

  • An automated scanner speeds up triage — a fast function and pattern-hit inventory on an unfamiliar codebase — it does not find the business-logic bugs that actually pay out on Immunefi, Code4rena, or Sherlock.
  • Paste code, upload a file, or scan a deployed contract by address (Ethereum, BSC, Polygon, Arbitrum, Optimism) to get an attack-surface read in under a minute.
  • Platform-specific workflow guides below for Immunefi, Code4rena, Sherlock, and Cantina.
For Security Researchers

The Bug Bounty Hunter's Toolkit

I built this for people auditing their own contract before launch. Then I noticed bounty hunters were pasting Etherscan links into the wrong box — trying to triage other people's code, not their own. Here's the honest version of what this tool can and can't do for you.

What This Actually Speeds Up
  • Function and modifier inventory on code you've never seen
  • Obvious pattern hits — missing access control, reentrancy shape, unchecked returns
  • Deciding fast which files are boilerplate vs. custom logic worth your time
  • Pulling verified source straight from a block explorer when there's no clean repo
What It Won't Do
  • Find the business-logic bug that actually wins the bounty
  • Understand a protocol's specific economic assumptions
  • Write your proof of concept or your report
  • Replace reading the actual scope document

Why I'm Not Selling This as "Find Bugs, Win Bounties"

Because it isn't true, and you'd figure that out in your first contest. The findings that actually pay on Code4rena and Sherlock are almost always something specific to how a protocol handles its own state or economics — a rebase token that breaks an assumption somewhere three functions away, a liquidation path that doesn't account for a fee. Pattern matching doesn't see that. Nothing that runs in under a minute does.

What pattern matching is genuinely good at: telling you, across forty files you've never opened, which ten actually have custom logic and which thirty are a fork of a library you've read a dozen times already. That's not a small thing when a Code4rena contest gives you a week and Sherlock's escalation process punishes rushed, thin reports. Time you don't spend re-deriving a function map by hand is time you spend on the two or three contracts that actually matter.

I'd rather tell you that straight than have you paste a real contract in, get a clean scan, submit nothing based on it, and decide the tool is useless. It's not useless. It's a triage pass, not a researcher.

What a Triage Pass Actually Looks Like
  1. Get the in-scope contracts — paste the code, upload the files, or scan a deployed address directly if there's no clean repo.
  2. Read the function list and flagged patterns. Ignore severity scores. You're looking for "what's unusual here," not "what's already labeled a bug."
  3. Cross off the files that are just OpenZeppelin imports with a thin wrapper — you've read that code before, it's not where the time should go.
  4. Spend the rest of your window on what's left, manually, the way you always have.

Frequently Asked Questions

Duron Epps, Founder — SmartContractAuditor.ai
Last updated August 2026

Get Oriented Before You Start Reading Line by Line

Paste code, upload a file, or scan a deployed contract by address. Free to start.

Free scan · No sales call · Not a replacement for your own research