Platform

Analysis engine

The engines under the workbench. They recover what deployed code can do — EVM bytecode or a Solana program — then prove each finding by executing it, on the pinned fork (EVM) or the captured account set (Solana).

The analysis engine

Program analysis that starts from bytecode, not trust

Under the workbench are analysis engines built for deployed code — EVM bytecode and Solana (SVM) programs. On EVM, the engine reconstructs what a contract can do from the bytecode itself, then proves what it found by executing it.

  • Inputdeployed bytecode
  • Sourceoptional
  • Recoverscontrol-flow, storage-flow, value-flow
  • Outputa runnable proof-of-concept, pinned to a block
  • Control-flow, storage-flow, and value-flow graphs recovered from raw bytecode
  • Concolic calldata solving to reach guarded branches fuzzing can't hit by chance
  • MorphVM deobfuscation — lifts byte-VM dispatchers that hide selectors into readable logic
  • Deterministic replay: every finding is a runnable PoC pinned to a fork block
  • Source and verified ABIs enrich the analysis — they're never required
On Solana

A second engine analyzes programs over the account model, and proves each finding by execution

  • Unita program and the accounts it touches
  • SourceRust, read and analyzed; no Anchor toolchain, so nothing is compiled
  • Detectorstwenty program detectors over the account model; each finding proven or refuted by execution
  • Evidencecompute units, logs and account diffs; SARIF export
Where it surfaces

One engine — two panels and an engine capability

The same analysis drives the Composer and MorphVM panels auditors work in, and fuzzing is an engine capability that drives concolic execution; there is no fuzzing panel.

Composer

Builds multi-step transaction sequences against the fork, so a candidate is rebuilt as the exact calls that cause it.

  • Works ona pinned fork
  • Outputa replayable sequence

Concolic execution

Generates and mutates calldata against deployed bytecode; concolic solving reaches the guarded branches chance never hits.

  • Inputdeployed bytecode
  • Guided byconcolic calldata solving
  • Statusengine capability — there is no fuzzing panel

MorphVM

Lifts byte-VM dispatchers that hide selectors into readable logic, so obfuscated contracts analyze like ordinary ones.

  • Targetobfuscated dispatchers
  • Outputlifted, readable logic

Source optional.

Source and verified ABIs enrich the analysis. The engine never requires them.