All projects
Jan 2025 – Feb 2026Featured project

Contract Guard: Autonomous Bug Bounty Hunter

24/7 AI-powered smart contract vulnerability detection & autonomous PoC generation for Immunefi bug bounties.

TypeScriptNext.jsSolidityFoundryClaude AIBullMQSupabasePlaywright

Gallery

Landing page

1 / 15

At a glance

  • 19 EVM-compatible chains supported
  • 13+ vulnerability classes detected (V01–V13)
  • Autonomous Foundry PoC generation & mainnet fork verification
  • Claude AI-powered audit engine (Sonnet 4)
  • Self-learning system that improves from past detections
  • Telegram alert integration with instant notifications

The Problem

The Immunefi bug bounty ecosystem pays out millions of dollars per year for smart contract vulnerabilities, yet the process of monitoring hundreds of in-scope contracts, classifying vulnerability patterns, and writing Foundry exploit proofs is entirely manual. A skilled auditor might review 3–5 protocols per week. I wanted to see if an autonomous system could do this continuously, around the clock.

How It Was Built

The system is a TypeScript monorepo with a Next.js frontend and a background job engine powered by BullMQ. At its core, a scheduler periodically fetches active Immunefi programs, discovers their in-scope smart contract addresses across 19 EVM chains, and queues analysis jobs.

Each contract is decompiled and sent to a Claude AI pipeline that classifies it against 13+ known vulnerability categories (reentrancy, price manipulation, flash loan attacks, access control bypasses, and more). When a potential issue is found, the system auto-generates a Solidity proof-of-concept test using Foundry, forks the relevant mainnet, executes the exploit, and captures the result. Successful exploits trigger an instant Telegram notification with full context.

All state (scanned contracts, findings, and exploits) is persisted in Supabase. Playwright is used to interact with protocol frontends where on-chain analysis alone isn't sufficient.

Why I Built It

I've been fascinated by the intersection of AI and blockchain security for years. After reading through dozens of post-mortems for major DeFi hacks, I noticed that most vulnerabilities follow repeatable patterns, the kind a well-prompted language model could potentially detect at scale.

This project was my attempt to productize that intuition. It's also a forcing function for me to go deeper into Solidity internals, EVM execution, and the Foundry testing ecosystem. Building the self-improving feedback loop (where past detections inform future scans) was the most intellectually rewarding part.

What's Next

The current system handles static vulnerability pattern matching well. The next frontier is dynamic analysis: actually simulating complex multi-transaction attack sequences, modeling liquidity conditions, and reasoning about cross-protocol dependencies. I'm also exploring fine-tuning a smaller model on the existing detection corpus to reduce inference latency and cost per scan.