Automated smart-contract auditing platform by @credshields

✅ Audit Complete. We've successfully completed a smart contract audit on @DustLabsX. Dust rounds up onchain swaps and automatically invests the difference into a basket of tokenized blue chip stocks. Website: roundupdust.com
Audit complete, fixes verified. Dust v0.6.4 is live. The Dust contracts were audited by @CredShields , one of the most respected security firms in the space, with a long list of protocols behind them. Twelve findings, zero critical. We fixed every one, redeployed on new contracts, and @CredShields re reviewed and marked each fix confirmed. Withdrawals were never affected at any point. The full report is public, findings and fixes side by side: github.com/Credshields/audit… This is exactly what an audit is for. You don't bring in a second set of eyes to be told everything's perfect. You do it to find what you missed while it's still cheap to fix, fix it, and prove it. Every fix in this release ships with a test that replays the auditor's exact scenario. What it means for you: the contracts running your round-ups have been reviewed twice by a team whose job is breaking things, every keeper action is bounded on-chain, and your money can only move into your own vault or back to your wallet. Not a promise, that's what the code allows. New in v0.6.4: the audited contracts, a "Stop sweeps" switch, refunds shown on any partially filled purchase, and a cleaner funding screen. Used Dust before this week? Open app.roundupdust.com, connect, and the card at the top shows your balance on the old contracts. Withdraw in two clicks, then set your basket and cap again. The old contracts stay withdrawable forever, so no rush. Thanks to the @CredShields team for a thorough job and a fast retest.
9
9
26
1,162
✅ Audit Complete. We've successfully completed a smart contract audit on @axcess_finance. Axcess Finance is an onchain private credit platform where every loan is isolated per vault, pre underwritten before funding, and backed by a first loss buffer. Website: axcess.finance
1
7
749
✅ Audit Complete. We've successfully completed a smart contract audit on @CarbonfiHQ. CarbonFi provides transparent and verifiable infrastructure for global carbon markets, combining AI driven verification with decentralized settlement to enable trusted climate finance at scale. Website: carbonfi.io
🚨 Security Milestone: CarbonFi is Now Audited. We have completed a comprehensive smart contract audit with CredShields—one of the industry's most respected blockchain security firms. 38 findings identified. 36 fixed. 2 acknowledged. Security is not a feature. It is the foundation of trust. The Breakdown: 🔴 2 Critical → Resolved 🟠 2 High → Resolved 🟡 8 Medium → Fixed 🔵 15 Low → Fixed ⚪ 11 Informational → Fixed Every core contract—staking, marketplace, NFT minting, retirement, CarbonDEX—has been rigorously reviewed and strengthened. Institutional capital demands institutional-grade security. CarbonFi is building the infrastructure for the next generation of carbon markets. This audit is not a checkbox—it is a statement of commitment. 🔗 Full Report: dashboard.credshields.com/r/… #CarbonFi #CredShields #ClimateFinance #Web3
1
1
3
385
Most founders think hacks come from genius attackers. They don't. They come from shortcuts taken to ship faster. We're breaking down what teams keep getting wrong in 2026, live with @antier_official. Thursday, 12:30 PM UTC. Set a reminder. nitter.net/i/spaces/1NGarrXrgOgJj…
3
6
460
✅ Audit Complete. We've successfully completed a smart contract audit on @aveniaio. Avenia is a cross border payments infrastructure layer designed to streamline capital movement between global markets and Latin America. Website: avenia.io
1
1
258
✅ Audit Complete. We've successfully audited the smart contract for @predexxyz. Predex is a real-time blockchain prediction market and binary options platform powered by AI-driven oracle protection. Website: predexmarkets.xyz
1
170
Arc Explorer now includes smart contract security insights powered by SolidityScan. Users can view real-time security scores, explore categorized vulnerabilities, and access detailed threat analysis directly within the @arc explorer interface. testnet.arcscan.app/
1
3
7
1,288
🚨 Security Incident on @Base: Loss: ~102K USDC + ~9.3M mUSD Vector: Phishing + Unlimited Token Approval basescan.org/tokentxns?a=0x9… The sequence: • Victim approved malicious address • Allowance increased • Drainer executed transferFrom Two-layer attack: Approval abuse + social engineering If you don’t recognize the contract, don’t approve it. If you approved it, revoke it. #staySAFU
3
10
956
Final Day – Calling all bug hunters The #FindTheBug challenge concludes today.Last chance to spot the hidden vulnerability. Find the bug and share the correct answer below Win $500 worth of free access to SolidityScan
7
2
26
1,644
Smart contracts don’t fail randomly. They fail in patterns. The OWASP Smart Contract Top 10 defines those patterns. Use the Top 10 to > Threat-model before you ship > Lock down privilege and upgrade paths > Encode invariants as tests > Secure every external boundary
5
34
62
2,481
Day 4 – Calling all bug hunters The #FindTheBug challenge continues.This one might trick you. Find the bug and share the correct answer below Win $500 worth of free access to SolidityScan
17
7
41
3,293
Day 3: Calling all bug hunters The #FindTheBug challenge continues. We’ve made this one a bit harder let’s see who gets it right. Find the bug and share the correct answer below Win $500 worth of free access to SolidityScan
28
4
103
6,037
Day 2: Calling all bug hunters The #FindTheBug challenge continues. Find the bug and share the correct answer below Win $500 worth of free access to SolidityScan
20
5
85
5,203
Calling all hunters The #FindTheBug challenge is here. Find the bug and share the correct answer below Win $500 worth of free access to SolidityScan
2
6
15
1,469
Starting tomorrow: Find the Bug Challenge Every day, we’ll post a smart contract snippet with a hidden vulnerability. Your task? Just find the bug. At the end of the week, we’ll announce the winners. Winners receive 1 month of free access to SolidityScan.
7
26
38
7,687
134 incidents. $3.6B lost. And 83% of it came from just two things. We tracked every major Web3 hack in 2025. The patterns will change how you think about security. Read the full report: credshields.com/resources#st…
12
18
39
1,928
SolidityScan is proud to sponsor Rekkathon. Rekkathon is a national-level offline hackathon bringing together builders, innovators, and problem-solvers from diverse tech backgrounds, with @devfolio and @ETHIndiaco as sponsors. Top prizes: 🏆 1️⃣ First – $2,000 in SolidityScan credits 2️⃣ Second – $1,500 in SolidityScan credits 3️⃣ Third – $1,000 in SolidityScan credits Plus: 5 Runner-ups – $500 each in SolidityScan credits 30 Participants – $100 each in SolidityScan credits 📌 Feb 6–8, 2026, NIT Hamirpur, India
11
23
32
1,027
if you deploy smart contracts without doing this…you’re just hoping nothing breaks. Watch before one bug costs you everything.
9
8
59
2,173
In 2025, Web3 security failures were not limited to isolated smart contract bugs. Many of the most severe incidents stemmed from systemic control-plane, infrastructure, and operational failures. Key findings from our 2025 analysis include: > Over $3.6B in reported losses across the ecosystem. > 83% of losses stemmed from control-plane and infrastructure failures. > Clear, evidence-backed security priorities teams should address moving into 2026. Understanding these patterns is critical. Preventing future exploits requires looking beyond individual vulnerabilities and addressing the underlying systems that enable them. The full analysis is shared in the comments.
1
2
8
382
Security meets simplicity on @xone_chain. SolidityScan is now integrated with Xone Explorer, bringing real-time smart contract threat analysis directly to developers and users. View the security score, identify vulnerabilities, and access the full security report, all from the explorer interface. Learn more: 🔗 discover.credshields.com/sol…
1
9
44
2,469
Exciting news! SolidityScan is now integrated with @xone_chain! 🚀 With this integration, @xone_chain enables developers to leverage SolidityScan’s advanced smart contract scanning and risk assessment tools to build safer dApps. Developers on Xone can now: ☑️ Scan smart contracts instantly for vulnerabilities ☑️ Get detailed risk assessments before deployment ☑️ Build safer dApps with proactive security insights Together, we’re building a safer and more secure Web3 future. Read more on our blog: discover.credshields.com/sol…
5
9
23
1,610
Big news! 🎉 SolidityScan has partnered with @techfund_inc to elevate Web3 security for Hi AUDIT, combining our AI-powered scanning solutions with TECHFUND’s proven audit expertise. Together, we’re advancing hybrid security automation to make Web3 safer, smarter, and more resilient.
2
4
12
1,910
Big news! SolidityScan is now integrated with @cursor_ai. Bringing real-time smart contract scanning to the AI-powered code editor. Detect vulnerabilities as you build and ship safer Web3 applications effortlessly. Install the plugin now from the Cursor Marketplace and start securing your code. Secure smarter with Cursor!
1
6
537
Exciting news! SolidityScan is now integrated with @windsurf. Scan your smart contracts for vulnerabilities, gas optimizations, and security insights, all within the coding environment itself. Install the plugin now from Windsurf Marketplace and start securing your code.
1
7
511
UXLINK(@uxlinkofficial)  has suffered a major security breach involving its multi-signature wallets. A malicious actor executed a delegateCall exploit, removed the admin role, and reassigned control to a new multisig. Official PSA:
Urgent Security Notice We have identified a security breach involving our multi-signature wallet, resulting in a significant amount of cryptocurrency being illicitly transferred to both CEXs and DEXs. Our team is working around the clock with both internal and external security experts to identify the root cause and contain the situation. We have already reached out to major CEXs and DEXs to urgently freeze suspicious UXLINK deposits and are coordinating closely with them to prevent further movement of funds. The incident has been reported to the police and relevant authorities to accelerate legal action and recovery efforts. We remain fully committed to transparency and will continue providing timely updates to the community as new developments arise.
1
1
7
877
Can you spot the subtle bug that can break permit integrations? Join the #FindTheBug challenge and put your debugging skills to the test! #SmartContracts #BugHunt #Web3
2
7
532
Found this TokenSwap contract in the wild. Looks like it has some "emergency" logic when token transfers fail... Can you drain all the funds? Join our #FindTheBug challenge and showcase your debugging skills! #SmartContracts #BugHunt #Web3
3
12
550
The contract always returns uint256.max for the special spender — can you spot the subtle bug? Join our #FindTheBug challenge and put your debugging skills to the test! #SmartContracts #BugHunt #Web3
1
9
506
From auditing smart contracts manually to building AI-powered security scanners — our journey has been all about keeping Web3 secure. One of our favorite milestones? Integrating SolidityScan with @etherscan — bringing 450+ vulnerability checks right into the place where millions of developers and users already verify contracts. This wasn’t just an integration — it was a step toward making Ethereum safer at scale, giving instant security insights to anyone, anywhere. Here’s to 10 years of Etherscan being the go-to for transparency, trust, and tooling in Ethereum. The next decade? Let’s make it even more secure. #10YearsofEtherscan
1
2
12
7,546
Can you spot the bug in this simple donation contract? Take on the #FindTheBug challenge and showcase your debugging expertise! #SmartContracts #BugHunt #Web3
2
13
669
Expected behavior: Users can withdraw up to 50% of their current balance. Actual behavior: Something’s off… Can you spot the bug that’s breaking the logic? 🔍 Join the #FindTheBug challenge and put your smart contract skills to the test! #SmartContracts #BugHunt #Web3
3
4
431
10 years of Ethereum 💚 Now securing 50+ EVM chains with SolidityScan. #Ethereum10
2
8
423
On 28th July, 2025, SuperRare's (@SuperRare) RareStakingV1 contract was hacked, losing ~$730K USD (~11.9M $RARE) due to a flawed access control in updateMerkleRoot()  function's require check. SolidityScan was able to detect SuperRare's access control bug in just one scan!
6
4
10
3,334
Bob just patched the classic Uniswap V2 oracle library by upgrading it to pragma solidity ^0.8.0. He says it protects against old arithmetic bugs. Can you spot the high-risk bug? Take on the #FindTheBug challenge and uncover the flaw! #SmartContracts #BugHunt #Web3
1
7
469
🚨 On 15th July 2025, Arcadia Finance (@ArcadiaFi) was exploited for ~3.5M USD due to an unchecked external call in SwapLogic._swapViaRouter(). Read the full hack analysis here: blog.solidityscan.com/arcadi…
The team is aware of unauthorized transactions via a Rebalancer. Remove all permissions for asset managers. More information will follow.
3
2
9
2,170
🚨 Bitcoin hits $122K! 🚨 A new all-time high for the world’s largest crypto. Institutional demand is surging, ETF inflows are booming, and $122K could just be the beginning. The next phase of crypto is officially underway. #Bitcoin
1
5
273
CredShields is on the ground at @EthCC 2025! EthCC[8] is underway in Cannes, France, and we’re excited to be part of the action from June 30 to July 3. Join us to explore how CredShields is helping secure the next generation of blockchain projects through cutting-edge audit services and AI-powered tools. Let’s talk Web3 security and build a safer blockchain ecosystem together.
1
2
298
CredShields at @EthCC 2025! We’re excited to announce our participation in EthCC[8], taking place from June 30th to July 3rd in Cannes, France. Join us to explore how CredShields is helping secure the next generation of blockchain projects through cutting-edge audit services and AI-powered tools. Let’s talk Web3 security and how we’re contributing to a safer blockchain ecosystem.
3
5
251
On June 26, 2025, ResupplyFi (@ResupplyFi) lost ~$9.56M after an attacker manipulated the oracle price of an ERC4626 vault via a classic donation attack. The inflated price caused exchangeRate = 0, letting them bypass solvency checks and borrow $10M reUSD with just 1 wei of collateral. Read the detailed hack analysis here: blog.solidityscan.com/resupp…
12
8
497
Can you spot the critical business logic bug in this "secure" NFT contract? The mint function includes a reentrancy guard, there's a 10-minute cooldown before selling, and users pay 0.1 ETH to mint but receive only 0.09 ETH when selling. Take part in the challenge to win a monthly subscription to the SolidityScan Individual Plan worth $200. To win, be the first to comment with the correct answer. To enter, simply sign up on SolidityScan and follow us on X. #FindTheBug
5
6
367
Thinking about a career in Web3 security or want to bulletproof your smart contracts? Dive into the biggest risks, legal challenges, and the roadmap to becoming a smart contract auditor. Plus, discover how SolidityScan is reshaping the audit game. 🔗 Read the full blog: solidityscan.com/discover/sm…
1
1
4
286
Meta Pool (@meta_pool) was exploited on June 17, 2025, due to an unprotected mint() function inherited from OZ's ERC4626, allowing an attacker to mint 9,702 mpETH without depositing ETH. Although the tokens were notionally worth ~$27M, only ~$142K was drained due to limited liquidity. A sharp reminder that inherited functions must always be reviewed. 🔎 Read the full hack analysis: blog.solidityscan.com/meta-p…
3
294
Can you spot the subtle time-based vulnerability in this yield farming contract? Take part in the challenge to win a monthly subscription to the SolidityScan Individual Plan worth $200. To win, be the first to comment with the correct answer. To enter, simply sign up on SolidityScan and follow us on X. #FindTheBug
4
1
309
Choosing the wrong audit firm can cost you more than just funds—it could cost you your future. Learn how to choose the right smart contract audit partner—and why firms like CredShields are setting new security benchmarks in Web3. 🔗 Read the full blog: discover.solidityscan.com/ho…
3
283
SolidityScan is now live on the @Blockchair dApp Gallery! View real-time security scores across multiple chains, right from the contract address pages. With a single click, unlock full security reports — including risk levels, threat summaries, and recommended fixes powered by 450+ AI-based vulnerability detectors.
4
227
Can you spot the business logic flaw that's costing the protocol money? Take part in the challenge to win a monthly subscription to the SolidityScan Individual Plan worth $200. To win, be the first to comment with the correct answer. To enter, simply sign up on SolidityScan and follow us on X. #FindTheBug
2
3
332
Happy to share with all Sonic builders that we’ve recently added support for @SonicLabs on our platform — you can now run instant security scans on verified contracts deployed to the Sonic Mainnet and Testnet. Just drop the contract address to get a security score, threat analysis, and a PDF report — no setup needed. 🔍 Try it now: solidityscan.com/quickscan
1
4
18
5,215