AI Smart Contract Security Analysis and PoC Generation Framework
Version 6.0 | What's New in v6.0 | Changelog
Aether is a Python-based framework for analyzing Solidity smart contracts, generating vulnerability findings, producing Foundry-based proof-of-concept (PoC) tests, and validating exploits on mainnet forks. It combines Solidity AST parsing, taint analysis, control flow graph analysis, cross-contract analysis, Halmos symbolic execution, 180+ pattern-based static detectors, a collaborative multi-agent LLM pipeline (GPT/Gemini/Claude) with shared SAGE institutional memory, 14 protocol archetypes, a 75+ exploit knowledge base, ML-calibrated detection, token quirks detection, invariant extraction, related contract context resolution, and advanced context-aware filtering into a single persistent full-screen TUI.
Collaborative Agent Pipeline — The deep analysis pipeline transforms from 5 independent passes to 5 collaborative agents sharing structured knowledge through SAGE institutional memory:
docker compose up -d to start.SAGE Institutional Memory — Aether now learns from every audit, reducing false positives and improving finding quality over time:
SageFeedbackManager.sync_detector_accuracy() identifies high/low performing detectors and stores dos/don'ts reflectionsdocker compose up -d starts SAGE; config via sage_enabled/sage_url in ~/.aether/config.yamlContributors: Thanks to @sashavdv for fixing hardcoded path variables (PR #1) and @pro258b for identifying the missing validate_anthropic_key() method (PR #2).
SAGE is a persistent institutional memory system powered by BFT consensus. See the SAGE project for full documentation.
# Install SAGE Python SDK
pip install sage-agent-sdk
# Start SAGE (Docker required)
docker compose up -d
# Run Aether — SAGE auto-seeds on first launch
python aether.py
# Regenerate seed fixtures after updating knowledge bases (dev only)
python -c "from core.sage_seeder import SageSeeder; SageSeeder.generate_seed_fixtures()"
Audit 1 → Findings + FPs → Record outcomes in SAGE
↓
Audit 2 → SAGE recalls FP patterns → Fewer false positives
↓
Audit 3 → Richer institutional context → Better severity calibration
↓
Audit N → Institutional expert-level knowledge → Bug-bounty-quality findings
PoC Auto-Execution — Generated Foundry PoCs now automatically compile and execute:
forge test --json integration runs PoCs immediately after compilationPoCTestResult dataclass for structured pass/fail/error reportingPOC_TESTING phase in JobManager for live progress tracking in the TUIHalmos Symbolic Execution — Formal verification via symbolic execution:
HalmosRunner for executing Halmos symbolic tests against generated propertiesHalmosPropertyGenerator for auto-generating verification properties from extracted invariantsHalmosSymbolicNode pipeline node integrated at validation Stage 1.95enable_symbolic_verification, halmos_timeoutControl Flow Graph Analysis — Compiler-level control flow understanding:
BasicBlock, CFGEdge, ControlFlowGraph dataclasses in solidity_ast.pybuild_cfg(), get_dominators(), get_loop_headers(), format_cfg_for_llm() for structural analysisparse_assembly_block() for inline assembly supportML Feedback Loop — Historical outcome-based calibration:
AccuracyTracker.record_finding_outcome() for tracking submission results and bounty earningsget_detector_accuracy() and get_detector_weights() for per-detector performance statsDetectorStats dataclass tracking true/false positives and historical accuracyEnhancedVulnerabilityDetector based on detector track recordRelated Contract Context — LLM analysis now sees full dependency source code:
RelatedContractResolver automatically discovers parent, interface, library, and dependency contractsTech Debt Cleanup — 8,500 lines of dead code removed:
ai_ensemble.py, audit_engine.py, fork_verifier.pyslither_project_cache from database managerSolidity AST Parsing — Aether v4.0 adds compiler-backed code analysis via py-solc-x, moving beyond regex-only static analysis: