We completed the security review of @LidoFinance NEST: automated LDO buybacks and DAO-owned liquidity.
The report is public.
How NEST works, what we found, what shipped ↓
Three EVM fuzzers ran 8 hours each on a benchmark with 153 reachable bugs. Bug discovery is close to logarithmic and nearly flat after the first hour: Wake found 73, Foundry 72, Echidna 71.
An agent-written harness ran on the same contracts: 150 bugs at minute 37, all 153 at
At @ethbelgrade, @michprev demonstrated how static analysis affected recall in an AI audit.
Three GPT-5.6 models audited the same Go codebase with and without static-analysis MCP tools.
Recall is the percentage of known issues found. Out of 55:
Sol: 38 with MCP tools, 39
This week at @Web3SecSummit Belgrade, @michprev benchmarked three EVM fuzzers: Echidna, Foundry, Wake. The benchmark: five maze contracts containing 153 reachable bugs; each tool gets 8 hours to find them.
Foundry generates 11.6x more transactions per second than Echidna. Bugs
SPEAKER ANNOUNCEMENT 📣
AI can already find smart contract bugs by reading code. So, do we still need fuzzing?
@michprev, author and lead developer of Wake, joins Web3 Security Summit to answer exactly that.
See you in Belgrade 🫡