Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
aether — AI Smart Contract Security Analysis and PoC Generation Framework | Kitploit
Tools/GitHubGitHub/l33tdawg/aether
Static AnalysisExploit FrameworksVulnerability AnalysisFuzzingCryptographyPenetration TestingBinary AnalysisMachine LearningLearning & EducationAI Security
GitHubl33tdawg/aether
6511185 months agoReviewed by Kitploit

aether

AI Smart Contract Security Analysis and PoC Generation Framework

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Aether v6.0 — Smart Contract Security Analysis Framework

Version 6.0 | What's New in v6.0 | Changelog

Aether is a Python-based framework for analyzing Solidity smart contracts, generating vulnerability findings, producing Foundry-based proof-of-concept (PoC) tests, and validating exploits on mainnet forks. It combines Solidity AST parsing, taint analysis, control flow graph analysis, cross-contract analysis, Halmos symbolic execution, 180+ pattern-based static detectors, a collaborative multi-agent LLM pipeline (GPT/Gemini/Claude) with shared SAGE institutional memory, 14 protocol archetypes, a 75+ exploit knowledge base, ML-calibrated detection, token quirks detection, invariant extraction, related contract context resolution, and advanced context-aware filtering into a single persistent full-screen TUI.

What's New in v6.0

Collaborative Agent Pipeline — The deep analysis pipeline transforms from 5 independent passes to 5 collaborative agents sharing structured knowledge through SAGE institutional memory:

  • Shared session memory — Each pass stores findings, dismissals, and verified protections in a per-audit SAGE session. Later passes receive "Prior Pass Intelligence" instead of flat text summaries.
  • Dismissals as first-class records — When Pass 3 dismisses a concern (e.g., "reentrancy protected by nonReentrant modifier"), Pass 5 won't re-flag it. This directly eliminates the #1 source of duplicate findings.
  • Challenge mechanism — Later passes can override prior dismissals, but must provide NEW evidence. "Pass 3 didn't see the callback path through this other function" is valid. "I disagree" is not.
  • Cross-pass confirmation — When multiple passes independently confirm a finding, confidence gets a 15% boost. Cross-confirmed findings are prioritized in reports.
  • SAGE required — Institutional memory is now required, not optional. No SAGE = no audit. Run docker compose up -d to start.

What's New in v5.0

SAGE Institutional Memory — Aether now learns from every audit, reducing false positives and improving finding quality over time:

  • Pre-trained knowledge base — Ships with 170 institutional memories: 75 exploit patterns, 63 protocol archetype checklists, 12 token quirk categories, 20 curated historical exploits (DAO, Wormhole, Euler, Ronin, Curve, and more)
  • Pipeline integration — SAGE recalls historical findings and exploit patterns in deep analysis Passes 3 and 5; stores audit learnings post-pipeline for future recall
  • Feedback loop — Confirmed findings get stored as high-confidence facts; rejected findings (false positives) get stored so future audits avoid them. AccuracyTracker outcomes automatically feed into SAGE
  • Validation pipeline — New Stage -1: SAGE known FP check filters findings that match previously rejected patterns before any other validation runs
  • Detector accuracy sync — SageFeedbackManager.sync_detector_accuracy() identifies high/low performing detectors and stores dos/don'ts reflections
  • Auto-seed on startup — First launch with SAGE Docker running auto-seeds the pre-trained knowledge base. Version-aware: skips if already seeded
  • TUI integration — SAGE ON/OFF status with memory count displayed in the CostBar
  • Docker deployment — docker compose up -d starts SAGE; config via sage_enabled/sage_url in ~/.aether/config.yaml
  • Graceful degradation — SAGE being unavailable never breaks any audit functionality

Contributors: Thanks to @sashavdv for fixing hardcoded path variables (PR #1) and @pro258b for identifying the missing validate_anthropic_key() method (PR #2).

SAGE Quick Start

SAGE is a persistent institutional memory system powered by BFT consensus. See the SAGE project for full documentation.

# Install SAGE Python SDK
pip install sage-agent-sdk

# Start SAGE (Docker required)
docker compose up -d

# Run Aether — SAGE auto-seeds on first launch
python aether.py

# Regenerate seed fixtures after updating knowledge bases (dev only)
python -c "from core.sage_seeder import SageSeeder; SageSeeder.generate_seed_fixtures()"

How SAGE Improves Audits

Audit 1 → Findings + FPs → Record outcomes in SAGE
                                    ↓
Audit 2 → SAGE recalls FP patterns → Fewer false positives
                                    ↓
Audit 3 → Richer institutional context → Better severity calibration
                                    ↓
Audit N → Institutional expert-level knowledge → Bug-bounty-quality findings

What's New in v4.7

PoC Auto-Execution — Generated Foundry PoCs now automatically compile and execute:

  • forge test --json integration runs PoCs immediately after compilation
  • JSON result parsing with PoCTestResult dataclass for structured pass/fail/error reporting
  • Fork-mode support for mainnet validation of exploits against live state
  • New POC_TESTING phase in JobManager for live progress tracking in the TUI

Halmos Symbolic Execution — Formal verification via symbolic execution:

  • HalmosRunner for executing Halmos symbolic tests against generated properties
  • HalmosPropertyGenerator for auto-generating verification properties from extracted invariants
  • HalmosSymbolicNode pipeline node integrated at validation Stage 1.95
  • Config options: enable_symbolic_verification, halmos_timeout
  • Graceful degradation if Halmos is not installed — skips symbolic verification without errors

Control Flow Graph Analysis — Compiler-level control flow understanding:

  • BasicBlock, CFGEdge, ControlFlowGraph dataclasses in solidity_ast.py
  • build_cfg(), get_dominators(), get_loop_headers(), format_cfg_for_llm() for structural analysis
  • Assembly block parsing via parse_assembly_block() for inline assembly support
  • Branch-aware taint propagation in the taint analyzer for path-sensitive analysis
  • CFG context injected into deep analysis Pass 2 alongside taint data

ML Feedback Loop — Historical outcome-based calibration:

  • AccuracyTracker.record_finding_outcome() for tracking submission results and bounty earnings
  • get_detector_accuracy() and get_detector_weights() for per-detector performance stats
  • DetectorStats dataclass tracking true/false positives and historical accuracy
  • Confidence weight adjustment in EnhancedVulnerabilityDetector based on detector track record
  • Severity calibration from historical data injected into deep analysis Pass 5

Related Contract Context — LLM analysis now sees full dependency source code:

  • RelatedContractResolver automatically discovers parent, interface, library, and dependency contracts
  • Project mode uses inter-contract relationship analysis; single-file mode parses import statements
  • Per-pass budget system: 200K chars for Gemini Flash passes, 100K for Claude, 50K for GPT
  • Standard libraries (@openzeppelin, solmate, solady) summarized to interface-only to save budget
  • Single-file audits auto-discover sibling .sol files for context

Tech Debt Cleanup — 8,500 lines of dead code removed:

  • Deleted: ai_ensemble.py, audit_engine.py, fork_verifier.py
  • Removed all ai_ensemble references from CLI, audit runner, TUI screens, report generator
  • Removed slither_project_cache from database manager
  • Removed formal verification stubs from enhanced audit engine

What's New in v4.0

Solidity AST Parsing — Aether v4.0 adds compiler-backed code analysis via py-solc-x, moving beyond regex-only static analysis:

Download Tool