Can Claude Audit Smart Contracts? Zero-Shot Vulnerability Detection Across Five SWC Classes

https://hackernoon.imgix.net/images/smart-contract-security-jjy8o5l0lk3ny2i6krwdkfv0.png

A zero-shot experiment: one prompt, five known-vulnerable contracts from the SmartBugs Curated benchmark, and an unexpected pattern in how an LLM judges severity.

  • Model: Claude Sonnet 4.6 · Claude Pro
  • Protocol: Zero-shot · fresh context per contract
  • Benchmark: SmartBugs Curated (ICSE 2020)

Claude Sonnet 4.6 found a security bug in each of the five contracts I tested — all of them — without providing a hint, example or setting up anything special. In addition, it placed every single finding at the highest level of risk — Critical — whether the bug was truly critical or not. This combination of great detection ability versus overconfidence in rating is the practical use of this test.

WHY SMART CONTRACT SECURITY IS CATEGORICALLY DIFFERENT

A Smart Contract is a program running on top of the Ethereum Blockchain. It can never be fixed once it has been implemented. It is public, permanent, and will run...

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE

Read more

https://i.pcmag.com/imagery/articles/030oXKoaHKcJsu7VUdTprsb-1.fit_lim.size_1200x630.v1779312243.jpg

SpaceX S-1: Starlink had 10.3M subscribers in Q1 2026, a 105% increase YoY; SpaceX's “Connectivity” business, which is primarily Starlink, made $11.3B in 2025

Sponsor Posts Niantic Spatial: World models need real-world data — Scaniverse is the gateway to spatial services — self-serve and built for AI and robotics. Large-area 3D reconstruction from 360° cameras and precise localization, anywhere machines operate. App Spotlight: Quo for Zoho CRM — App Spotlight brings you hand-picked solutions that enhance your