WALSEC Documentation

Autonomous Smart Contract Security Auditing on Sui

What is WALSEC?

WALSEC is an autonomous multi-agent AI system that analyzes, exploits, and evaluates Sui Move smart contracts for security vulnerabilities. Built for the Sui Hackathon 2026, it combines three specialized AI agents with decentralized storage (Walrus) and on-chain proof (Sui blockchain) to deliver comprehensive, immutable audit results.

Key Features

  • Three-agent autonomous audit pipeline
  • 15+ vulnerability pattern detection
  • Auto-exploit simulation & impact estimation
  • One-click vulnerability patching
  • Decentralized storage via Walrus
  • Immutable on-chain audit records on Sui
  • Ask Walsec: AI Terminal Assistant
  • Wallet-Persistent Memory: Chat history tied to wallet
  • Dedicated AI Output Viewer with one-click code copy

Why WALSEC?

  • Autonomous: No manual review needed — agents work independently
  • Comprehensive: Covers arithmetic, access control, reentrancy, and more
  • Immutable: Results stored on-chain, cannot be tampered with
  • Decentralized: Walrus storage ensures no single point of failure
  • Actionable: Auto-fix generates production-ready secure code

Architecture

WALSEC uses a three-agent pipeline powered by LangGraph, where each agent specializes in a distinct phase of the security audit.

AGENT_01

Analyzer

Deep pattern recognition engine that scans Sui Move bytecode for vulnerability patterns using symbolic execution and heuristic analysis.

Overflow detectionReentrancy analysisAccess control auditCWE mapping
AGENT_02

Executor

Autonomous exploit simulation agent that constructs theoretical attack vectors and estimates the real-world impact of each finding.

Attack vector constructionValue estimationDifficulty ratingTx sequence modeling
AGENT_03

Evaluator

Final arbiter that synthesizes all findings into a definitive audit artifact with severity rating, risk score, and remediation steps.

Severity classificationRisk scoringRemediation guidanceArtifact generation

Supporting Infrastructure

Walrus Decentralized Storage

All audit artifacts are stored on Walrus — a decentralized storage network that shards and replicates data across nodes. No central point of failure, censorship-resistant, and permanently accessible.

Sui On-Chain Proof

Every audit record is committed to the Sui blockchain via a wallet transaction. This creates an immutable, verifiable record tied to your wallet identity with full provenance trail.

Getting Started

1

Connect Your Wallet

Click Connect Wallet in the top bar. WALSEC requires a Sui wallet (Sui Wallet, Ethos, etc.) for on-chain audit persistence. The app will not initialize the swarm until a wallet is connected.

2

Submit a Contract

Paste your Sui Move smart contract code into the editor, or select from pre-loaded vulnerable demo samples (VAULT_OVERFLOW, ACCESS_CONTROL_BYPASS).

3

Initialize the Swarm

Click Initialize Swarm to start the three-agent audit pipeline. Watch real-time progress as each agent completes its phase. The pipeline typically takes 30-90 seconds.

4

Review Results

Once complete, review the audit artifact showing vulnerability details, severity, risk score, and CWE classification. Click See Vulnerability for full JSON details.

5

Apply Fix (Optional)

Click Apply Fix to auto-generate secure, production-ready code. The fix is applied with a typing animation and includes proper assertions, capability checks, and safe arithmetic patterns.

Vulnerability Types

WALSEC detects 15+ vulnerability categories in Sui Move smart contracts.

Arithmetic OverflowCritical

Integer overflow/underflow in arithmetic operations without bounds checking.

Access Control BypassCritical

Missing or incorrect capability checks allowing unauthorized operations.

ReentrancyHigh

State modification after external call allowing recursive re-entry attacks.

Unauthorized WithdrawalCritical

Missing ownership verification enabling fund theft.

Integer UnderflowCritical

Subtraction below zero without underflow protection.

Missing Capability CheckHigh

Admin functions lacking proper AdminCap verification.

Unchecked Return ValueMedium

Ignoring return values from critical function calls.

Type ConfusionHigh

Improper type handling leading to unexpected behavior.

Resource LeakMedium

Failure to properly transfer or destroy resources.

Infinite LoopMedium

Unbounded loops that can exhaust gas or hang execution.

Privilege EscalationCritical

Ability to gain elevated permissions through contract manipulation.

Oracle ManipulationHigh

Price feed or external data source manipulation.

Front-RunningMedium

Transaction ordering exploitation in DEX or auction contracts.

Zero-Amount BypassMedium

Missing zero-value checks allowing dust attacks.

Logic ErrorLow

Business logic flaws that deviate from intended behavior.

Audit Pipeline

The audit pipeline is orchestrated by LangGraph and runs through six phases.

01

SUBMIT

Contract code is received and validated. Wallet connection verified for on-chain persistence.

02

ANALYZE

AGENT_01 scans bytecode for vulnerability patterns using symbolic execution and heuristic analysis.

03

EXECUTE

AGENT_02 constructs theoretical exploit vectors, models attack sequences, and rates difficulty.

04

EVALUATE

AGENT_03 synthesizes findings into a final artifact with severity, risk score, and remediation.

05

STORE

Artifact stored on Walrus decentralized storage. Audit record committed to Sui blockchain.

06

FIX

Optional auto-patch generates secure code with proper assertions and capability checks.

Pipeline Configuration

// Timeout configuration
LLM_TIMEOUT_MS = 50_000        // Per-node LLM call timeout
PIPELINE_TIMEOUT_MS = 170_000  // Overall pipeline timeout
MAX_DURATION_MS = 180_000      // API route max duration
WALRUS_TIMEOUT_MS = 8_000      // Non-blocking Walrus fetch

API Reference

POST /api/audit

Submit a smart contract for autonomous security audit.

// Request
{
  "code": "module vault::pool { ... }",
  "contractName": "VAULT_OVERFLOW"
}

// Response
{
  "success": true,
  "artifact": {
    "contractName": "VAULT_OVERFLOW",
    "vulnerabilities": [
      {
        "type": "Arithmetic Overflow",
        "severity": "Critical",
        "description": "...",
        "cwe": "CWE-190",
        "riskScore": 9.5,
        "affectedLines": [15, 22]
      }
    ],
    "agent_consensus": "...",
    "status": "completed",
    "txHash": "0x...",
    "walrusBlobId": "..."
  }
}

POST /api/walrus

Store audit artifact on Walrus decentralized storage.

// Request
{
  "artifact": { ... },
  "contractName": "VAULT_OVERFLOW"
}

// Response
{
  "success": true,
  "blobId": "walrus_blob_id...",
  "epoch": 428
}

Ask Walsec (Terminal Interface)

The "Ask Walsec" page (/config) is a retro-futuristic AI terminal. It requires a wallet connection to unlock. Your chat history and terminal session are permanently tied to your connected wallet address. Disconnecting your wallet will securely lock the terminal.

Generated code is elegantly presented in the dedicated AI Output Viewer on the right panel, complete with a language header and a one-click COPY button.

Terminal Commands

CommandDescription
helpShow all available commands
clearClear terminal output
statusShow system and swarm status
historyShow audit history from on-chain records
agentsList active AI agents and their status
threatsShow detected threat statistics
networkDisplay network and node information
scan <addr>Simulate vulnerability scan on address
pingCheck network latency to nodes
hash <text>Generate deterministic hash of text
exportDownload terminal logs as .txt file
uptimeShow system uptime statistics
versionShow WALSEC version info

On-Chain Integration

Move Contract: walsec_registry

WALSEC uses a Sui Move smart contract to store audit records on-chain. Each audit creates an immutable record tied to the operator's wallet.

// Event emitted on each audit
public struct AuditRecorded has copy, drop {
    operator: address,
    contract_name: String,
    severity: String,
    risk_score: u8,
    num_vulnerabilities: u64,
    timestamp_ms: u64,
    walrus_blob_id: String,
}

How It Works

  1. User connects their Sui wallet to the application
  2. Audit pipeline completes and generates the artifact
  3. Artifact is stored on Walrus decentralized storage
  4. A transaction is sent to the walsec_registry contract
  5. The AuditRecorded event is emitted on-chain
  6. History is loaded from on-chain events via sui_queryEvents

Contract Addresses

Package ID: 0x2d3f7e...  (testnet)
Module:     walsec_registry
Network:    Sui Testnet

Contract Samples

WALSEC includes pre-loaded vulnerable demo contracts for testing.

VAULT_OVERFLOW

A liquidity pool contract with an arithmetic overflow vulnerability in the deposit function. The share calculation can overflow when large amounts are deposited, allowing an attacker to mint excessive shares.

Arithmetic OverflowInteger UnderflowZero-Amount Bypass

ACCESS_CONTROL_BYPASS

An admin-controlled contract missing proper capability verification. The withdraw function lacks AdminCap checks, allowing any user to drain the contract's funds.

Access Control BypassUnauthorized WithdrawalMissing Capability Check

Auto-Fix Output

When a fix is applied, WALSEC generates complete, production-ready code with:

  • Error code constants (EOverflow, EUnderflow, EInvalidAdminCap)
  • Assertion guards (assert!(amount > 0, EZeroAmount))
  • Capability verification (assert!(_cap.id == pool.admin_cap_id, EInvalidAdminCap))
  • Safe arithmetic with overflow checks
  • Proper resource handling and transfer semantics

Tech Stack

Frontend

  • Next.js 16 — React framework with App Router
  • TypeScript — Type-safe development
  • CSS Custom Properties — Vigilant Void design system

Blockchain

  • Sui — Layer 1 blockchain with Move language
  • @mysten/dapp-kit — Wallet connection & tx handling
  • Sui Move — Smart contract language

AI Pipeline

  • LangGraph — Multi-agent orchestration
  • Gemini 2.5 Flash — LLM for analysis & generation
  • @langchain/google-genai — LangChain adapter

Storage & Memory

  • Walrus — Decentralized blob storage
  • Sui Events — On-chain audit record persistence
  • Memwal SDK — Wallet-tied semantic memory for Chat & Audit Logs

FAQ

How long does an audit take?

The full three-agent pipeline typically completes in 30-90 seconds depending on contract complexity and LLM response times. Each agent has a 50-second individual timeout.

Is my contract code sent to a third party?

Contract code is processed by Gemini AI (Google) for vulnerability analysis. Results are stored on Walrus decentralized storage and recorded on Sui blockchain.

Can I audit any Sui Move contract?

Yes. Paste any Sui Move module code into the editor. The system also includes pre-loaded vulnerable demo samples for testing.

What happens after I click Apply Fix?

The system replaces your contract code with a secure, production-ready version that includes proper assertions, capability checks, error codes, and safe arithmetic patterns. The change is animated with a typing effect.

Do I need a wallet to use WALSEC?

Yes. A Sui wallet connection is required to initialize the swarm and persist audit records on-chain. The wallet gate ensures all audits are tied to a verifiable identity.

How are audit results stored?

Results are stored in two places: (1) Walrus decentralized storage for the full artifact JSON, and (2) Sui blockchain as an on-chain event for immutable proof.

What vulnerability types are detected?

WALSEC detects 15+ categories including arithmetic overflow, access control bypass, reentrancy, unauthorized withdrawal, missing capability checks, and more. See the Vulnerability Types section for the full list.