Keep known vulnerabilities
from becoming repeat incidents.

Keep known vulnerabilities
from becoming repeat incidents.

An open-source project for discovering and sharing smart contract vulnerability signatures
without exposing source code. An official Lab project of Linux Foundation Decentralized Trust.

An open-source project for discovering and sharing smart contract vulnerability signatures without exposing source code. An official Lab project of Linux Foundation Decentralized Trust.

How We Break It

Analyze vulnerabilities
without sharing source code.

Source code stays private. Identifying details are removed, the remaining structure
is hashed, and only those hashes are compared. What is shared is a pattern—not the code.

Source code stays private. Identifying details are removed, the remaining structure is hashed, and only those hashes are compared. What is shared is a pattern—not the code.

Step 01

Step 01

Normalization

Remove identifying elements such as variable names, function names, comments, and strings.

Step 02

Step 02

Salt + Hash

Add a unique salt to the remaining structure and convert it into a hash, preventing recovery of the original code.

Step 03

Step 03

Matching

Compare signatures instead of source code. A match identifies the same vulnerable pattern.

Check for known vulnerabilities. Keep your source code private.

Find out whether vulnerability patterns discovered in other projects also appear in your code, without sharing the original source externally.

Two-Track Detection

Fast detection. Deeper discovery.

Different tasks call for different methods. Real-time checks use deterministic matching without an LLM; signature discovery uses LLMs to process large document sets.

Different tasks call for different methods. Real-time checks use deterministic matching without an LLM; signature discovery uses LLMs to process large document sets.

Track 01

RUNTIME

Deterministic checks in real time

Crawl deployed onchain contracts and compare them against the signature database. Recheck for vulnerabilities added after deployment to support ongoing issuer monitoring obligations. This process does not use an LLM.

No LLM Required

TEE / Enclave

Real-Time Monitoring

Track 02

OFFLINE

Signature discovery at document scale

Extract signatures from audit reports, proof-of-concept code, and patches. LLMs process documents at scale, with human review before results enter the database.

Audit Report Processing

PoC Extraction

Patch Analysis

Who It Is For

One signature.
Four ways to use it.

Open source supports different workflows: pre-deployment checks,
reusable audit findings, and continuous post-deployment monitoring.

Open source supports different workflows: pre-deployment checks, reusable audit findings, and continuous post-deployment monitoring.

01

01

Developers

Check your contracts against known signatures before deployment.

02

02

Security Teams & Auditors

Turn audit findings into signatures that can be reused in future engagements.

03

03

Security Token Issuers & Financial Institutions

Continuously check against industry signatures without disclosing source code, helping address vulnerabilities discovered after deployment.

04

04

AI Agents

Query vulnerability data directly through MCP integration.

Tiers & Open Source Scope

Clear about what is open.

We distinguish between publicly available capabilities and partner-only access, so you know what open source includes and what requires membership.

Public Tier

Open to Everyone
Open to Everyone

Access public signature data with an intentional delay relative to the real-time feed. Official Model Context Protocol (MCP) support lets external LLM agents query it directly.

Premium Tier

For Partner Financial Institutions
For Partner Financial Institutions

Access a combined database synchronized in real time and advanced signal search. Queries are recorded in a separate, encrypted audit trail.

Access a combined database synchronized in real time and advanced signal search. Queries are recorded in a separate, encrypted audit trail.

Open Source Scop

Signature Extractor · Matching Engine · Signature Schema

Proof In Context

Working with the organizations behind the standards.

Working with
the organizations behind the standards.

LFDT Lab Project
LFDT Lab Project

Linux Foundation Decentralized Trust

LFDT Lab Project

Linux Foundation Decentralized Trust

MITRE
MITRE

Maintains ATT&CK and CVE threat intelligence standards

MITRE

Maintains ATT&CK and CVE threat intelligence standards

Financial Security Institute
Financial Security Institute

Advisory Committee Participation

For Enterprises

For deeper integration,
explore Partner Trust.

OpenReagent is the open-source track within our three delivery models. For project-based audits, advisory, or institutional solutions, explore Partner Trust.

OpenReagent is the open-source track within our three delivery models. For project-based audits, advisory, or institutional solutions, explore Partner Trust.