Security · 3h ago
Solidity scanner flags only 14 issues across 10 top audited codebases
An open-source Solidity scanner, OpenClaw Audit, found only 14 candidate issues across 608 source files from the 10 most-audited web3 codebases. Four codebases returned zero flags, including OpenZeppelin Contracts and Uniswap Permit2. Most flags were false positives, but some highlighted real design trade-offs, like Solmate's missing inflation attack protection.
Meridian48 take
The low flag count is a testament to the quality of these audited codebases, but the tool's false positives underscore that automated scanners still need human judgment to separate signal from noise.
Read the full reporting
I ran my Solidity scanner across the 10 most-audited codebases in web3. Here's every flag. →
DEV Community
soliditysmart-contract-security