
01 / 05 — Coverage
Findings by severity, with the site’s own note that a severity label alone does not prove an exploit.
- Live
An AI security agent for smart contracts: it indexes 21,000+ verified smart contracts across 15 EVM networks and keeps its multi-agent audit reports open to everyone.

Brief
An AI agent that audits smart contracts and shows its evidence.


01Challenge
New verified smart contracts go live on EVM chains all the time, far faster than anyone can review them by hand. The evidence that exists is scattered, and AI “findings” are easy to generate and hard to trust. The brand wanted an agent that finds contracts, audits them with many specialised AI agents and publishes every result with the evidence behind it, including what is not proven.
02Approach
We started from the open-source BugChainIndexer and added an audit pipeline on the open-source Plamen framework: extract, audit, test, judge, ingest. Then came operator controls, case files that show the status of every finding, and “The Dossier”, an editorial identity in which the agent reports in the first person. An operating charter keeps messages, posts and any transaction behind the owner’s approval.
03Result
AAA is live at theaaa.xyz: 21,000+ contracts on 15 EVM networks, 52 completed multi-agent audits and 437 recorded findings, every report open to read without signing up. The newest reports say how each finding was checked.
Highlights
CH. 01—06
Chapters
AAA (Autonomous Audit Agent) is a smart-contract security product we built for the brand. Scanners collect verified source from 15 EVM networks; a multi-agent audit built on the open-source Plamen framework reviews it in eight phases, tries to confirm serious findings with Foundry tests and publishes each report as an open case file.
CH. 01 / 06 — Product & design
AAA speaks in the first person and lays out its work as an intelligence briefing: coverage, procedure, capabilities and findings. The site’s counters are read live from the same database that powers the dashboard.
Coverage
Findings by severity, with the site’s own note that a severity label alone does not prove an exploit.
PL. 01 — Coverage · theaaa.xyz/#stats

01 / 05 — Coverage
Findings by severity, with the site’s own note that a severity label alone does not prove an exploit.

02 / 05 — Procedure
A sticky step index with three illustrations: the index, the lookup and the eight-phase audit.

03 / 05 — Capabilities
“Built for real audit work, not demos.”: an evidence bento and a severity taxonomy.

04 / 05 — Findings
A news wire that prints file and line, and case cards with a severity-coloured spine.

05 / 05 — End of briefing
The close, again in the first person: “I’m already working. Come watch.”

01 / 05 — Coverage
Findings by severity, with the site’s own note that a severity label alone does not prove an exploit.

02 / 05 — Procedure
A sticky step index with three illustrations: the index, the lookup and the eight-phase audit.

03 / 05 — Capabilities
“Built for real audit work, not demos.”: an evidence bento and a severity taxonomy.

04 / 05 — Findings
A news wire that prints file and line, and case cards with a severity-coloured spine.

05 / 05 — End of briefing
The close, again in the first person: “I’m already working. Come watch.”
CH. 02 / 06 — How it works
Scanners collect verified source from 15 EVM networks. An operator starts an audit from the contract page; the system extracts the code into a Foundry project, runs the multi-agent audit and writes the report back into the index.
Scheduled scanners over public RPC: source, metadata, balances and proxy targets in one place, searchable by a line of code.
PL. 01 — The index
01
The index
Scheduled scanners over public RPC: source, metadata, balances and proxy targets in one place, searchable by a line of code.

02
The verified source
Verified source is stored and readable on the contract page. For an audit it is extracted into a Foundry project with the exact compiler version.

03
The audit
Eight phases of multi-agent analysis. If the AI provider’s quota runs out, the audit pauses and resumes by itself, and the operator can cancel it from the dashboard.
Audit · Plamen
Schematic · no real data
04
The case file
The report is stored with every finding’s severity and location; the newest reports add a status and an evidence tag. Anyone can read it without signing up.

01
The index
Scheduled scanners over public RPC: source, metadata, balances and proxy targets in one place, searchable by a line of code.

02
The verified source
Verified source is stored and readable on the contract page. For an audit it is extracted into a Foundry project with the exact compiler version.

03
The audit
Eight phases of multi-agent analysis. If the AI provider’s quota runs out, the audit pauses and resumes by itself, and the operator can cancel it from the dashboard.
Audit · Plamen
Schematic · no real data
04
The case file
The report is stored with every finding’s severity and location; the newest reports add a status and an evidence tag. Anyone can read it without signing up.

CH. 03 / 06 — Multi-agent audit
The audit runs on the open-source Plamen framework, in eight phases: recon, breadth, depth, fuzzing, attack chains, PoC tests, a skeptic and a judge, then the report. Dozens of AI agents share the work.
Demo · schematicRecon
A map of the contract: functions, roles, external calls and known public incidents.
What it checks
Recon
Schematic · no real data
01 / 05 — RECON
Recon
A map of the contract: functions, roles, external calls and known public incidents.
What it checks
Recon
Schematic · no real data
02 / 05 — BREADTH
Breadth
Parallel agents sweep the whole codebase, each by its own vulnerability class.
What it checks
Breadth
Schematic · no real data
03 / 05 — DEPTH · FUZZ
Depth & fuzzing
Domain agents trace token flow and state while fuzz campaigns hunt for broken invariants.
What it checks
Depth & fuzzing
Schematic · no real data
04 / 05 — CHAIN · POC
Chains & PoC
Weak findings are combined into chains, and serious hypotheses get a Foundry test that has to pass.
What it checks
Chains & PoC
Schematic · no real data
05 / 05 — JUDGE · REPORT
Judge & report
A skeptic challenges serious findings, a judge decides, and demoted findings stay visible in the report with their original severity.
What it checks
Judge & report
Schematic · no real data
01 / 05 — RECON
Recon
A map of the contract: functions, roles, external calls and known public incidents.
What it checks
Recon
Schematic · no real data
02 / 05 — BREADTH
Breadth
Parallel agents sweep the whole codebase, each by its own vulnerability class.
What it checks
Breadth
Schematic · no real data
03 / 05 — DEPTH · FUZZ
Depth & fuzzing
Domain agents trace token flow and state while fuzz campaigns hunt for broken invariants.
What it checks
Depth & fuzzing
Schematic · no real data
04 / 05 — CHAIN · POC
Chains & PoC
Weak findings are combined into chains, and serious hypotheses get a Foundry test that has to pass.
What it checks
Chains & PoC
Schematic · no real data
05 / 05 — JUDGE · REPORT
Judge & report
A skeptic challenges serious findings, a judge decides, and demoted findings stay visible in the report with their original severity.
What it checks
Judge & report
Schematic · no real data
CH. 04 / 06 — Honest severity
In the newest reports every finding carries a status and a tag: a passing PoC test, a code trace only, or contested and demoted. The demotion stays visible and the original severity is kept.
Route
PL. 01 — The whole audit: PoolFees on Base, five findings
Route


Route
CH. 05 / 06 — Autonomy with rules
AAA reads and indexes by itself. An audit starts when the operator launches it, and anything that leaves the system, such as a message to a protocol or a public post, waits for the owner’s review and approval.
Demo · schematicAAA
Autonomous Audit Agent
01 / 03 — reads only
AAA
Autonomous Audit Agent
Verified source from block explorers, public RPC, prices and public incident notes, stored in its own PostgreSQL index.
An audit starts only when the operator launches it from the contract page; its report is written to the index.
Messages to protocols and public posts go through the owner’s review first.
AAA
Autonomous Audit Agent
Verified source from block explorers, public RPC, prices and public incident notes, stored in its own PostgreSQL index.
An audit starts only when the operator launches it from the contract page; its report is written to the index.
Messages to protocols and public posts go through the owner’s review first.
CH. 06 / 06 — Result
The index grows with every scan, and every report is open to anyone without signing up. The counts were read from theaaa.xyz on 30 Sep 2026.
contracts indexed
EVM networks
completed multi-agent audits
recorded findings
audit phases

PL. 01—04



Contact
Want something like this?
30 minutes, no commitment. You’ll leave with concrete ideas for your website, processes or product.
Pick a time that suits you in our calendar.
Tell us about the project. We reply within a few hours on business days.
Tell us about the project. We reply within a few hours on business days.