All work

Autonomous AI · smart-contract security

KTHULHU Overmind

Autonomous, AI-driven smart-contract security auditing — engineered for near-zero false positives through adversarial certainty and formal verification.

Visit kthulhu.co
AI Development·Web2/3 Development
KTHULHU Overmind orchestration canvas — a live audit pipeline visualised as a node graph over the KTHULHU watermark.
112+
merged PRs
13,000+
indexed findings
3-phase
verification pipeline
EVM + SVM
multi-chain

An enterprise-grade, autonomous smart-contract auditing platform. It orchestrates specialised AI agents, formal-verification tools, and dynamic blockchain forks to turn probabilistic auditing into mathematically verified vulnerability detection — live on kthulhu.co with active user audits and a USDC credit system.

See it in action

Product walkthrough · 4:16

The problem

Traditional AI-powered auditors share the same failure modes:

  • Context blindness — LLMs hallucinate without seeing real execution paths.
  • False-positive epidemic — reports routinely claim 90%+ noise from lexical bias and stochastic reasoning.
  • No mathematical proof — vulnerabilities reported without formal verification or exploit confirmation.
  • Single-model risk — no adversarial red-teaming to challenge the reasoning.

Tier 1 — Foundational swarm

Sourcing & triage: a unified ingestion pipeline that normalises diverse source formats into structured analysis.

  • Continuous ingestion of public contracts from GitHub, blockchain RPC, and security competitions.
  • Scope-aware ingestion with 200KB / 40-file caps and nSLOC counting.
  • Attack-surface mapping via repository-skeleton injection for cross-contract context.
  • Chunked map-reduce primary hunter for efficient distributed analysis.

Tier 2 — Ensemble reasoning

Adversarial certainty: reasoning decomposed into atomic, independently verifiable units to drive down false positives.

  • Primary reasoning — Claude Opus for enterprise-grade analysis.
  • Verification skeptic — GPT-OSS-120B via Cloudflare Workers AI for aggressive red-teaming.
  • Chain-of-Verification — independent agents challenge every finding.
  • Typed scenario decomposition — cross-file recall lifted from 50% to 66.7%.

Tier 3 — Formal verification

The bleeding edge: mathematical proof of viability — every reported bug reproduces in a test.

  • Halmos — bounded symbolic execution generating provable invariants.
  • Medusa + hevm — property-based fuzzing and symbolic execution to surface invariant violations.
  • Ephemeral forks — isolated, containerised Anvil mainnet forks spin up per audit for risk-free proof-of-concept testing.
  • Execution-path tracing — every finding traced back to actual bytecode execution.

Inside the product

AaveV3 FlashVault audit advancing through the KTHULHU pipeline with findings streaming in.
A live audit advancing through the pipeline — triage, ensemble reasoning, verification and reporting, with findings streaming in by severity.
The finding lifecycle state machine — identified, pending, confirmed, disputed, dismissed.
Every finding moves through a typed state machine. Nothing reaches a report without passing verification.
A confirmed finding with impact analysis and a reproducible proof-of-concept exploit.
A confirmed finding, traced to a reproducible proof-of-concept exploit on a mainnet fork.

Built with

Claude OpusWorkers AI (GPT-OSS-120B)HalmosMedusahevmAnvil mainnet forksNeonVoyage AICloudflare

Want one built like this?

The engineering behind KTHULHU Overmind is available for your system.