DeFi Security AllianceRequest an audit
Menu

DeFi Security Alliance · Tool directory

Web3 & smart contract security tools

Find tools for code review, fuzzing, formal verification, transaction analysis, wallet protection and security operations. Compare what each tool does, where it fits and what its results cannot establish.

Listed tools
156
Categories
21
Review date

Choose by security task

Search the directory

Find a tool for your security task

Browse 24 entries at a time, ordered by primary task and name. Search and filters cover all 156 tools. Confirm exact chain and version support at the source.

121-144 of 156 tools.Download CSV
  • EVMRepository

    Rabby Wallet

    Review EVM transactions and interact with dapps through a wallet that presents pre-signing risk information.

    Documentation reviewed

    Limitations & source status
    Before using
    Simulation and warnings cannot guarantee the safety of a transaction or protect a disclosed seed phrase.
    Source status
    Documentation reviewed
  • EVMWeb app / service

    Revoke.cash

    Inspect token approvals and remove selected allowances on supported networks.

    Documentation reviewed

    Limitations & source status
    Before using
    Revocation requires an on-chain transaction and does not recover assets already transferred.
    Source status
    Documentation reviewed
  • MultichainWeb app / service

    GoPlus Security

    Query token, address, approval and related security signals through the GoPlus API platform.

    Documentation reviewed

    Limitations & source status
    Before using
    Field availability varies by endpoint and chain. Unknown results need explicit handling.
    Source status
    Documentation reviewed
  • EVMWeb app / service

    Honeypot.is

    Simulate token trading and inspect honeypot-related checks through a token-analysis API.

    Documentation reviewed

    Limitations & source status
    Before using
    Results depend on supported routes and current state. Sellability can change after the check.
    Source status
    Documentation reviewed
  • MultichainWeb app / service

    Quick Intel

    Inspect token contracts and associated risk signals using the Quick Intel analysis tools and APIs.

    Documentation reviewed

    Limitations & source status
    Before using
    Confirm supported chains and the meaning of individual flags before using them as a decision rule.
    Source status
    Documentation reviewed
  • SolanaWeb app / service

    Rugcheck

    Inspect Solana token signals such as holder concentration, liquidity and token metadata before interaction.

    Provider page only

    Limitations & source status
    Before using
    A token-risk report is a snapshot and cannot establish future liquidity or issuer behavior.
    Source status
    Provider page only
  • EVMWeb app / service

    TokenSniffer

    Inspect automated token scam flags, similarity information and optional holder or liquidity metrics.

    Documentation reviewed

    Limitations & source status
    Before using
    A score summarizes selected signals. It does not guarantee that a token will remain safe to trade.
    Source status
    Documentation reviewed
  • EVMWeb app / service

    AuditBase

    Use a hosted Solidity scanner to collect potential findings and structured risk-report outputs.

    Documentation reviewed

    Limitations & source status
    Before using
    Review evidence behind each finding. Generated risk and compliance labels need separate validation.
    Source status
    Documentation reviewed
  • EVMWeb app / service

    ChainGPT Smart Contract Auditor

    Generate AI-assisted smart contract review output through the ChainGPT auditor product.

    Documentation reviewed

    Limitations & source status
    Before using
    Reproduce findings and inspect missed logic. Model-generated output is not proof of correctness.
    Source status
    Documentation reviewed
  • EVMWeb app / service

    Olympix

    Integrate automated Solidity analysis and testing assistance into a development security workflow.

    Documentation reviewed

    Limitations & source status
    Before using
    Evaluate actual findings on representative code before relying on provider performance claims.
    Source status
    Documentation reviewed
  • EVMWeb app / service

    Sherlock Audit Engine

    Evaluate Sherlock Audit Engine, which combines AI analysis with security-researcher review in an engagement workflow.

    Documentation reviewed

    Limitations & source status
    Before using
    This is a review service workflow. Confirm scope and researcher involvement for the specific engagement.
    Source status
    Documentation reviewed
  • EVMWeb app / service

    SolidityScan

    Submit Solidity projects or deployed contracts to a hosted scanner and review vulnerability reports.

    Documentation reviewed

    Limitations & source status
    Before using
    An automated report and score require independent triage and do not constitute a complete manual audit.
    Source status
    Documentation reviewed
  • MultichainWeb app / service

    Audit Builder

    Explore DeFi Security Alliance's workflow for preparing, storing and compiling smart contract audit reports.

    Documentation reviewed

    Limitations & source status
    Before using
    Confirm current product access and plan terms. Report generation does not validate the underlying findings.
    Source status
    Documentation reviewed
  • EVMWeb app / service

    HashEx ABI Encoder

    Encode Solidity function or constructor parameters into ABI-compatible calldata using a web interface.

    Provider page only

    Limitations & source status
    Before using
    Check types and parameter order. Encoding correctness does not establish transaction safety.
    Source status
    Provider page only
  • EVMWeb app / service

    HashEx Fork Checker

    Compare forked smart contract code using HashEx's published fork-checking interface.

    Provider page only

    Limitations & source status
    Before using
    Code similarity does not establish equivalent permissions, deployment state or security.
    Source status
    Provider page only
  • EVMRepository

    Scaffold-ETH 2

    Build a local Ethereum application and test interface for contract experiments and reproducible demonstrations.

    Documentation reviewed

    Limitations & source status
    Before using
    A development scaffold is supporting infrastructure. Production integrations need their own review.
    Source status
    Documentation reviewed
  • EVMRepository

    Smart Contract Sanctuary

    Search a collected corpus of verified smart contract sources for implementation examples and comparison.

    Documentation reviewed

    Limitations & source status
    Before using
    A collected source file is neither an audit endorsement nor a guarantee of current deployed behavior.
    Source status
    Documentation reviewed
  • EVMRepository

    sol2uml

    Generate Solidity class diagrams and storage visualizations to understand a contract system.

    Documentation reviewed

    Limitations & source status
    Before using
    Diagrams can simplify relationships. Validate storage and inheritance details against compiler artifacts.
    Source status
    Documentation reviewed
  • EVMRepository

    solgrep

    Search Solidity syntax structures to locate relevant declarations and patterns across a review scope.

    Documentation reviewed

    Limitations & source status
    Before using
    Structural matches are navigation aids and need manual analysis of their context.
    Source status
    Documentation reviewed
  • EVMRepository

    Solidity Metrics

    Measure Solidity code structure and produce scope information for audit preparation.

    Documentation reviewed

    Limitations & source status
    Before using
    Line counts and complexity indicators help scope work but do not measure security quality.
    Source status
    Documentation reviewed
  • MultichainWeb app / service

    Solodit

    Search published smart contract findings and mitigations to identify relevant bug patterns during review.

    Documentation reviewed

    Limitations & source status
    Before using
    A historical finding is context. Confirm whether its assumptions apply to the target code.
    Source status
    Documentation reviewed
  • EVMRepository

    Surya

    Generate Solidity contract graphs, inheritance views and inspection reports while mapping a codebase.

    Documentation reviewed

    Limitations & source status
    Before using
    Graph output needs manual interpretation and may not represent every dynamic interaction.
    Source status
    Documentation reviewed
  • MultichainDeveloper tool

    Burp Suite

    Analyze HTTP traffic and test dapp frontends, backend APIs and authentication flows.

    Documentation reviewed

    Limitations & source status
    Before using
    Available automation depends on the edition and HTTP testing does not analyze on-chain execution.
    Source status
    Documentation reviewed
  • RustRepository

    cargo-audit

    Check Rust dependency lockfiles against RustSec advisories as part of a smart contract or infrastructure build.

    Documentation reviewed

    Limitations & source status
    Before using
    Only known advisory coverage is checked. Application logic and unpublished vulnerabilities remain outside scope.
    Source status
    Documentation reviewed

From question to evidence

Choose a security tool workflow

These combinations are editorial starting points. Select the tools that match your artifact and threat model, then record enough context for another reviewer to reproduce the result.

Review a Solidity protocol

Start with
Pinned commit, compiler settings, deployment addresses and written invariants.
Expected evidence
Triaged detector findings, reproducible tests and failing invariant sequences.
Review boundary
Add roles, oracle states, upgrade paths and cross-contract assumptions that generic detectors cannot infer.
Design a contract fuzzing campaign

Check a critical property

Start with
A precise statement about balances, permissions or state transitions, plus environmental assumptions.
Expected evidence
A counterexample, a completed proof within the model or an explicitly inconclusive result.
Review boundary
Record loop bounds, external-call summaries, solver limits and proof obligations that remain open.
Define the wider audit scope

Review a Solana program

Start with
Program source, IDL where available, account constraints and the deployed program identifier.
Expected evidence
Account-state tests, fuzzing failures and a separate reproducible-build comparison.
Review boundary
Exercise signer, ownership, PDA, CPI, account-reuse and upgrade-authority assumptions.
Scope a Solana security review

Inspect an unverified EVM contract

Start with
Chain, address, runtime bytecode, implementation address where applicable and relevant transactions.
Expected evidence
Candidate functions, storage clues, reconstructed logic and traces to investigate.
Review boundary
Resolve proxies and corroborate inferred behavior. A selector lookup or decompiler cannot authenticate original source.
Investigate privileged contract behavior

Check a token before interaction

Start with
Exact chain and contract address, intended swap route and current allowance state.
Expected evidence
Dated risk signals covering permissions, trading behavior, liquidity, holders and approvals.
Review boundary
Use chain-appropriate tools. A clean scan cannot predict future owner actions or make a token an investment recommendation.
Understand honeypot-check limitations

Investigate and monitor a deployment

Start with
Contract inventory, transaction hashes, protocol invariants, alert recipients and response permissions.
Expected evidence
Reproducible traces, tested alert conditions and evidence attached to an owned incident workflow.
Review boundary
Distinguish detection from response. Test notification delivery and approval boundaries before enabling automation.
Plan on-chain monitoring

Review a zero-knowledge circuit

Start with
Circuit source, constraint artifacts, witness assumptions, public inputs and verifier integration.
Expected evidence
Constraint warnings, uniqueness results, witness tests and proof-verification artifacts.
Review boundary
Confirm the circuit encodes the intended statement, then review application binding and replay protection separately.
Review replay and domain boundaries

Check the code-to-deployment boundary

Start with
Dependency lockfiles, build configuration, artifacts, signing policy and the target deployment.
Expected evidence
Dependency findings, secret-scan results, an artifact inventory and signature-verification evidence.
Review boundary
Connect artifact identity to deployed bytecode and review the dapp frontend and administrative signing path.
Prepare an incident-response plan

Compare by the question answered

Common tool comparisons

How six common comparisons change the review workflow
ComparisonWhat differsSelection criterion
Slither vs Mythril

Slither analyzes source and compiler structures with detectors and inspection outputs.

Mythril explores EVM bytecode symbolically to seek vulnerability candidates.

Use source analysis for broad triage. Use symbolic exploration for additional execution evidence. Compare reproducible findings, not raw warning counts.
Foundry vs Echidna vs Medusa

Foundry combines development tests, invariant campaigns and fork-based workflows.

Echidna and Medusa focus on property-driven fuzzing campaigns and transaction sequences.

Run the same meaningful property and reachable-state setup before comparing campaign results. Preserve seeds, corpus, duration and tool versions.
Halmos vs Certora vs Kontrol

Halmos and Kontrol bring symbolic reasoning to Solidity-test-oriented workflows.

Certora uses CVL specifications and a verification service.

Choose based on the property, specification language, environment modeling and whether the proof completes within your resource budget.
Source verification vs security verification

Sourcify and solana-verify compare a build with a deployed artifact.

Formal tools reason about specified properties. Tests exercise selected behaviors.

Record these as separate evidence fields. A matching source build says nothing by itself about access control or economic safety.
Token scanner vs approval checker

Token scanners report selected contract, trading, holder and liquidity signals.

Approval checkers inspect permissions already granted by a wallet.

Use both for their respective questions. Revoking an allowance does not change a token contract or recover stolen assets.
Transaction simulator vs live monitor

A simulator evaluates a proposed transaction against a chosen state.

A monitor evaluates observed activity or state against configured detection rules.

Preserve the simulation inputs, then define the conditions that should trigger alerts after deployment. Neither replaces an incident owner.

Evidence & review scope

How this directory was assembled

DeFiSec reviewed 172 candidate tools and retained 156 entries across 21 categories. The September 5, 2026 source review excluded 16 candidates because of duplicate destinations or insufficient current product evidence. It retained 11 entries with legacy or maintenance notices, 5 with research or prototype notices and five supported only by provider-page evidence.

  1. Identify a concrete task. Include scanners, analyzers, testing frameworks, verification tools, investigation interfaces and supporting security infrastructure. A compiler or reporting tool is labeled by its actual role.
  2. Check a primary destination. Inspect official documentation, a project repository or the provider page; record the check date, response, redirects and content hash where available.
  3. Separate purpose from assurance. Describe the documented function and its review boundary. Documentation review does not establish runtime availability, active maintenance, license rights, price or detection quality.
  4. Preserve negative evidence. Record excluded candidates and visible maintenance notices. Count a suite once unless a separately named component has a distinct workflow.

Tools were not installed or benchmarked. Paid plans and transaction execution were not tested. Entries are not ranked by quality; inclusion is not an audit endorsement. Audit Builder is a DeFi Security Alliance product and is identified in its description.

For the wider review process, consult Ethereum's contract-testing guide, Trail of Bits' secure-contract guidanceand the OWASP Smart Contract Security Verification Standard. Product-specific evidence is linked from every card.

Practical questions

Web3 security tools FAQ

Which Web3 security tool should I start with?

Start with the artifact and question you have: source code for static analysis, a testable invariant for fuzzing, bytecode for reverse engineering or a deployed address for monitoring. Use the workflow table to assemble a small set of complementary tools, then check the source-linked requirements for your chain and build.

Are the listed tools free or open source?

The directory includes repositories, developer tools and hosted services. A public repository does not by itself establish license permissions and an accessible product page does not establish a free plan. Pricing and license terms were not audited in this review. Confirm both at the linked source.

Can a scanner or AI tool replace a smart contract audit?

A scanner can surface specific patterns or candidate findings. It cannot establish that the system meets every business rule, trust assumption or economic invariant. Require reproducible evidence for findings and review missing scenarios, integrations, privileges and deployment controls.

Which tools work for Solana, Move, Cairo, TON and CosmWasm?

Use the ecosystem filter and the dedicated categories. Solana account execution, Sui objects, Aptos resources, Starknet account contracts, TON messages and CosmWasm host behavior require different harnesses. A language label is not a promise of support for every chain or compiler version.

Does a honeypot check prove a token is safe?

It provides evidence about selected checks at a particular time. Trading routes, fees, permissions, liquidity and contract implementation can change. Record the exact chain and address and inspect individual signals instead of treating a score as a guarantee.

Why are archived and prototype tools included?

They help readers reproduce historical reports, understand older workflows and identify replacements. Legacy and research notices are visible in each affected card and can be selected with the status filter. Inclusion is not a recommendation to deploy a deprecated or experimental implementation.

What did DeFiSec actually verify?

The review checked primary repository, documentation and provider URLs, recorded response status and redirects and inspected the stated purpose and relevant maintenance notices. Five entries have only provider-page evidence and are labeled accordingly. Tools were not installed or benchmarked, paid access was not tested and detection quality was not measured.

How can I reproduce or reuse the directory review?

Download the catalog as CSV or JSON and the dated source-review CSV. Each listed tool has a source URL and check date. The source review also records exclusions, response status and a content hash where a response was obtained. These files preserve the review snapshot. They do not promise that a destination remains unchanged.