Reagent
Reagent

Reagent · Smart contract security,
from development to operations

Reagent · Smart contract security, from development to operations

Reagent · Smart contract security,
from development to operations

Code is the contract, and a flaw is a loss of assets.
Reagent is a smart-contract security suite that unites automated vulnerability detection,
formal verification, and vulnerability-intelligence sharing in a single flow.

Code is the contract, and a flaw is a loss of assets. Reagent is a smart-contract security suite that unites automated vulnerability detection, formal verification, and vulnerability-intelligence sharing in a single flow.

Code is the contract, and a flaw is a loss of assets.
Reagent is a smart-contract security suite that unites automated vulnerability detection,
formal verification, and vulnerability-intelligence sharing in a single flow.

The Problem

Code is
the contract,
and a flaw is
a loss of assets.

Code is the contract, and a flaw is a loss of assets.

Code is the contract,
and a flaw is a loss of assets.

Once deployed, smart contracts are hard to change, and testing or manual audits alone cannot catch every risk.

Once deployed, smart contracts are hard to change, and testing or
manual audits alone cannot catch every risk.

01

Irreversible loss

Once recorded, a transaction cannot be undone. Smart-contract hacks caused roughly $1.7B in losses in 2024 alone.

02

Code Is Law

Deployed code executes exactly as written. A single small vulnerability can lead to hundreds of millions in losses, so prevention before deployment matters most.

Smart contracts execute exactly as written, without exception. This immutable nature means even minor vulnerabilities can lead to catastrophic financial losses, as there's no room for human intervention after deployment.

03

The limits of testing and manual audits

Tests only confirm "no problem in this case." Around 30% of vulnerabilities are found even after an audit, and results depend on the auditor's skill.

While blockchain networks operate continuously, traditional security teams face human limitations. The industry average response time after detecting an attack is over 4 hoursan eternity when billions are at stake.

04

No cross-institution vulnerability sharing

Vulnerabilities each institution finds stay siloed, so the same attack types recur. Fund recovery after an attack is under 20%.

Modern attacks like the Bybit incident combine technical exploits with social engineering. Hackers increasingly utilize sophisticated methods that blend smart contract vulnerabilities, cross-chain weaknesses, and human susceptibility.

Track Record

A proven security track record

A proven security track record

SOOHO.IO's Reagent brings AI-based automation to blockchain security. Concentrating Sooho.io's expertise as a leader in smart-contract auditing since 2019, this system is a digital guardian that protects blockchain networks around the clock.

0
0
0

K+

security audit reports issued

01

$

$

$

0
0
0

.

.

.

0
0
0

B

B

B

+

in digital assets protected

in digital assets protected

02

0
0
0

.

.

.

0
0
0

K+

vulnerabilities detected pre-deployment

vulnerabilities detected pre-deployment

03

0
0
0

+

partnerships

partnerships

04

The Suite

Not a single product, but a security suite covering the full development lifecycle

Not a single product, but a security suite covering the full development lifecycle

Not a single product, but a security suite covering the full development lifecycle

Reagent consists of three products, each mapped to a stage of the smart-contract development lifecycle (SDLC): automated detection during development, mathematical proof before deployment, and vulnerability sharing after deployment — all in one continuous flow.

Smart Contract Development Lifecycle (SDLC)

Step 01

Analysis

Step 02

Design

Step 03

Development

Reagent Analyzer

Step 04

Testing

Reagent Verifier

Step 05

Release

Step 06

Operations

OpenReagent

Reagent products by stage

We support full-lifecycle security —
from blockchain-security training at the planning stage through operations.

We support full-lifecycle security — from blockchain-security training at the planning stage through operations.

01 · Development stage

Reagent Analyzer

Automated vulnerability detection · static analysis

Automatically detects security vulnerabilities in smart contracts under development using 26 rules. Combining pattern-based static analysis with taint analysis, it catches reentrancy, access-control, integer-overflow, and other issues.

26 detection rules (based on SWC · EEA EthTrust)

Supports Solidity and Go (Chaincode)

~15 sec per 1,000 lines · SARIF/PDF reports · CI/CD integration

02 · Pre-deployment

Reagent Verifier

Formal verification · proving "bug-free" mathematically

Mathematically proves that a contract satisfies its defined security spec — even in areas testing cannot reach — providing reproducible, objective safety proofs that manual audits cannot guarantee.

Verifies upgrades, proxies, inheritance, and invariants

Auto-generates counterexample tests (.t.sol) on verification failure

ERC20 · ERC721 · access-control presets · CLI/CI integration

03 · Testing to operations

OpenReagent

Vulnerability-intelligence sharing · open source

Automatically extracts vulnerability signatures from audit reports and shares them safely across institutions without exposing sensitive information — keeping you continuously prepared for vulnerabilities discovered after deployment.

Bytecode matching — detection within seconds per contract

PSI-based privacy-preserving sharing

Linux Foundation Decentralized Trust standard · OSS

Spotlight · OpenReagent

Security that grows stronger over time

SOOHO.IO's Reagent brings AI automation to blockchain security, creating a system that never sleeps. Built on our expertise as security pioneers since 2019, Reagent monitors blockchain networks 24/7, detecting and responding to threats in real-time.

01

Stay prepared
after deployment

Stay prepared after deployment

It doesn't end with a single audit. By continuously matching newly discovered vulnerability signatures, it checks risks even in already-deployed contracts.

02

Value that
compounds

Value that compounds

As signatures accumulate and more institutions join, detection coverage widens. Network effects increase the solution's value over time.

03

Global standard ·
zero adoption cost

Global standard · zero adoption cost

Built to international standards in collaboration with Linux Foundation Decentralized Trust. Released as open source (OSS), so you can start with no adoption cost.

Why Reagent

Why Reagent is different

It augments manual audits, not replaces them.

By automating code analysis that takes people days, it frees auditors to focus on higher-value business-logic review — going beyond the limited rules and high false-positive rates of open-source tools.

01

It proves results reproducibly and objectively.

Where results once depended on auditor skill, formal verification mathematically proves the absence of bugs — leaving verification evidence suited to financial regulation.

02

It supports multiple languages and chains.

Supports both Solidity and Go (Chaincode), targeting EVM-compatible chains. SARIF-standard output integrates naturally into existing development pipelines.

03

It uses international-standard open source.

Built on the SWC Registry and CWE classifications, and transparently validated under Linux Foundation Decentralized Trust governance.

04

Application

What Reagent protects

What Reagent protects

What Reagent protects

CBDC · Stablecoins · PBM

In domains requiring national-financial-infrastructure-grade security, it automatically verifies the accuracy of issuance and redemption and the safety of permission management.

CBDC · Stablecoins · PBM

In domains requiring national-financial-infrastructure-grade security, it automatically verifies the accuracy of issuance and redemption and the safety of permission management.

Large-scale DeFi protocols

Mathematically guarantees core invariants (e.g., sum of all balances = total supply) for protocols handling large funds — DEXs, lending, vaults.

Large-scale DeFi protocols

Mathematically guarantees core invariants (e.g., sum of all balances = total supply) for protocols handling large funds — DEXs, lending, vaults.

Upgradeable · Enterprise

Verifies data safety across version upgrades in proxy-pattern upgradeable contracts, meeting enterprise security requirements.

Upgradeable · Enterprise

Verifies data safety across version upgrades in proxy-pattern upgradeable contracts, meeting enterprise security requirements.

Security-audit firms

Adds formal verification and automated signature generation to manual audits, deepening audit rigor and reliability.

Security-audit firms

Adds formal verification and automated signature generation to manual audits, deepening audit rigor and reliability.

Adoption Process

How Reagent adoption works

1. Consultation

1. Consultation

1. Consultation

Assess your blockchain environment and security requirements

Assess your blockchain environment and security requirements

2. Automated scan

2. Automated scan

2. Automated scan

Detect code vulnerabilities automatically with Analyzer

Detect code vulnerabilities automatically with Analyzer

3. Formal verification

3. Formal verification

3. Formal verification

Prove core logic mathematically with Verifier

Prove core logic mathematically with Verifier

4. CI/CD integration

4. CI/CD integration

4. CI/CD integration

Embed security checks into your development pipeline

Embed security checks into your development pipeline

5. Intelligence integration

5. Intelligence integration

5. Intelligence integration

Prepare for post-deployment vulnerabilities with OpenReagent

Prepare for post-deployment vulnerabilities with OpenReagent

Prove your smart contract's
safety with Reagent.

Prove your smart contract's safety with Reagent.

From pre-deployment vulnerability scanning to formal verification
and post-deployment vulnerability intelligence, we'll propose
a security setup tailored to your environment.

From pre-deployment vulnerability scanning to formal verification and post-deployment vulnerability intelligence, we'll propose a security setup tailored to your environment.

SOOHO.IO Inc.

CEO: Jisu Park

Business Reg: 238-88-01053

Tel: 070-4121-8936
Fax: 02-6971-9109
Email: contact@sooho.io
Address: B1, 126 Teheran-ro, Gangnam-gu, Seoul, SOOHO.IO

Ⓒ2026. SOOHO.IO Inc. All Rights Reserved.

Stablecoin Platform

Stablecoin Service

Blockchain Security

SOOHO.IO Inc.

CEO: Jisu Park

Business Reg: 238-88-01053

Fax: 070-4121-8936
Email: contact@sooho.io
Address: B1, 126 Teheran-ro, Gangnam-gu, Seoul, SOOHO.IO

Ⓒ2026. SOOHO.IO Inc. All Rights Reserved.

Stablecoin Platform

Stablecoin Service

Blockchain Security

SOOHO.IO Inc.

CEO: Jisu Park

Business Reg: 238-88-01053

Fax: 070-4121-8936
Email: contact@sooho.io
Address: B1, 126 Teheran-ro, Gangnam-gu, Seoul, SOOHO.IO

Ⓒ2026. SOOHO.IO Inc. All Rights Reserved.

Stablecoin Platform

Stablecoin Service

Blockchain Security