live · 14 chains · 18k contracts indexed

Every contract on-chain. Every audit a click away.

Visualisa indexes verified smart contracts across 14 EVM networks. Look up any address to see live security findings inline. Or trigger a fresh autonomous audit on demand — powered by Plamen, the best-in-class multi-agent audit framework.

0
Contracts indexed
0
Audits completed
0
Vulnerabilities surfaced
Live coverage

Indexed at scale, audited with depth.

Every number on this page is queried live from the same Postgres that powers the dashboard. No vanity metrics.

0
Verified contracts indexed
14 EVM networks · live
0
Autonomous audits completed
multi-agent · proof-of-concept verified
0
High & critical findings
21 critical · 132 high
0
Total vulnerabilities surfaced
17 low · 254 medium · 132 high
The flow

Index. Look up. Or audit on demand.

The full loop, from on-chain deployment to security findings on your screen.

01 · Index

Every verified contract on every chain.

Continuous scanners stream verified contracts from Ethereum, BSC, Arbitrum, Optimism, Base, Polygon, Linea, Scroll, and more. Verified source, deployment metadata, ERC-20 balances, and proxy targets all land in one queryable place — ready to look up the moment they hit-chain.

01
02 · Look up

Paste an address — read findings instantly.

Open the dashboard, drop in any address. If the contract is already audited, every Critical / High / Medium finding renders inline with full description, location, PoC results, and remediation guidance. No signup, no API keys.

02
03 · Or audit on demand

Not audited yet? Spin up a Plamen run.

Add any contract manually and trigger a fresh audit. Plamen orchestrates 40-100 specialized AI agents across recon, breadth, depth, fuzz, chain analysis, PoC verification, and skeptic-judge. Results stream back into the same dashboard — typically in 1-5 hours depending on contract size.

Plamen·autonomous multi-agent audit framework
03
What's inside

Built for actual audit work, not demos.

Every tile maps to real code in production. The dashboard you'll open is wired to all of it.

Powered by Plamen

Plamen is the autonomous Web3 audit framework Visualisa runs under the hood. ~40-100 specialized AI agents across 8 phases: recon, breadth, depth iter 1+2 (Devil's Advocate), fuzz, chain analysis, PoC verification, skeptic-judge, report assembly. Best-in-class — and open source.

Audit on demand

Drop any address into the dashboard. If we don't have an audit yet, click to trigger one. Plamen takes it from there — results stream back into the same UI when complete.

13 EVM networks

Ethereum, BSC, Arbitrum, Optimism, Base, Polygon, Linea, Scroll, Mantle, Gnosis, Avalanche, OpBNB, MegaETH — one query interface.

Severity, scored honestly

4-axis confidence (Evidence, Consensus, Quality, RAG). TRUSTED-ACTOR downgrade rules. Skeptic-judge reviews every Critical and High before persistence — so you don't see noise.

PoC-verified findings

Phase 5 of every audit writes runnable Foundry tests. Pass / fail / revert is recorded. Findings on the dashboard carry [POC-PASS] tags when mechanically proven.

Compound attack chains

Postcondition→precondition matching across all findings. Discovers exploits where one bug's side effect enables another bug's attack path.

Source-aware extraction

Handles Etherscan single-file, multi-file solc-j, and standard JSON formats. Auto-detects Foundry source roots, derives remappings on the fly. Just works.

Live findings ticker

Critical and high findings flow through the dashboard in real time. Click any contract to see severity badges and the full report inline.

Pause + resume

Multi-hour audits survive rate limits. Session state persisted continuously; resume from the exact phase boundary with one command — no re-runs from scratch.

No signup. No API key. Free.

Every counter on this page renders from a 5-minute Postgres cache. No rate limits, no paywall — built to run as a public good for the Web3 security community.

Live findings

Real bugs from real audits.

Every finding below is sourced directly from contract_audit_findings — no marketing fluff, no manufactured screenshots.

Verification
ethereum·UniversalSwapAndBridgeV3
Harm Premise
ethereum·Token
Claimed Harm
subtensor·Token
Irrevocable Token Registration Locks In Systematic Creator Fee Hijacking Indefinitely
subtensor·BrainFactory
External Substrate Validator Slash Permanently Bricks adminWithdrawAlpha - No Admin Malice Required
subtensor·LendingPoolV1
DEFAULT_DELEGATE_HOTKEY Rotation Severs Pre-Rotation Withdrawal Routes - Stranded Deposits With Bank-Run Dynamics
subtensor·LendingPoolV1
adminMoveAlpha Stake Desync Locks All Subsequent withdrawAlpha Calls on Affected Subnet - Bank-Run Lockout
subtensor·LendingPoolV1
CONTRACT_COLDKEY Rotation Zeroes Stake Read, Triggering Permanent adminWithdrawAlpha Underflow DoS
subtensor·LendingPoolV1
adminMoveAlpha Accounting Desync Permanently Bricks adminWithdrawAlpha via Underflow
subtensor·LendingPoolV1
depositAlpha Two-Phase Operation Is Not Atomic - Cross-Layer EVM/Substrate Revert Boundary Strands User Stake
subtensor·LendingPoolV1
depositAlpha Uses delegatecall to Subtensor Staking Precompile - Latent EVM Storage Slot Corruption
subtensor·LendingPoolV1
Indefinite Pause With No User Exit Path and Asymmetric Admin Access
subtensor·LendingPoolV1
Verification
ethereum·UniversalSwapAndBridgeV3
Harm Premise
ethereum·Token
Claimed Harm
subtensor·Token
Irrevocable Token Registration Locks In Systematic Creator Fee Hijacking Indefinitely
subtensor·BrainFactory
External Substrate Validator Slash Permanently Bricks adminWithdrawAlpha - No Admin Malice Required
subtensor·LendingPoolV1
DEFAULT_DELEGATE_HOTKEY Rotation Severs Pre-Rotation Withdrawal Routes - Stranded Deposits With Bank-Run Dynamics
subtensor·LendingPoolV1
adminMoveAlpha Stake Desync Locks All Subsequent withdrawAlpha Calls on Affected Subnet - Bank-Run Lockout
subtensor·LendingPoolV1
CONTRACT_COLDKEY Rotation Zeroes Stake Read, Triggering Permanent adminWithdrawAlpha Underflow DoS
subtensor·LendingPoolV1
adminMoveAlpha Accounting Desync Permanently Bricks adminWithdrawAlpha via Underflow
subtensor·LendingPoolV1
depositAlpha Two-Phase Operation Is Not Atomic - Cross-Layer EVM/Substrate Revert Boundary Strands User Stake
subtensor·LendingPoolV1
depositAlpha Uses delegatecall to Subtensor Staking Precompile - Latent EVM Storage Slot Corruption
subtensor·LendingPoolV1
Indefinite Pause With No User Exit Path and Asymmetric Admin Access
subtensor·LendingPoolV1
Free · No signup · Live now

Look up a contract.
See its bugs. Or audit it now.

18k verified contracts indexed and ready to query. Pre-audited findings render instantly. New audits run on demand, powered by Plamen.