WALSEC Documentation
Autonomous Smart Contract Security Auditing on Sui
What is WALSEC?
WALSEC is an autonomous multi-agent AI system that analyzes, exploits, and evaluates Sui Move smart contracts for security vulnerabilities. Built for the Sui Hackathon 2026, it combines three specialized AI agents with decentralized storage (Walrus) and on-chain proof (Sui blockchain) to deliver comprehensive, immutable audit results.
Key Features
- Three-agent autonomous audit pipeline
- 15+ vulnerability pattern detection
- Auto-exploit simulation & impact estimation
- One-click vulnerability patching
- Decentralized storage via Walrus
- Immutable on-chain audit records on Sui
- Ask Walsec: AI Terminal Assistant
- Wallet-Persistent Memory: Chat history tied to wallet
- Dedicated AI Output Viewer with one-click code copy
Why WALSEC?
- Autonomous: No manual review needed — agents work independently
- Comprehensive: Covers arithmetic, access control, reentrancy, and more
- Immutable: Results stored on-chain, cannot be tampered with
- Decentralized: Walrus storage ensures no single point of failure
- Actionable: Auto-fix generates production-ready secure code
Architecture
WALSEC uses a three-agent pipeline powered by LangGraph, where each agent specializes in a distinct phase of the security audit.
Analyzer
Deep pattern recognition engine that scans Sui Move bytecode for vulnerability patterns using symbolic execution and heuristic analysis.
Executor
Autonomous exploit simulation agent that constructs theoretical attack vectors and estimates the real-world impact of each finding.
Evaluator
Final arbiter that synthesizes all findings into a definitive audit artifact with severity rating, risk score, and remediation steps.
Supporting Infrastructure
Walrus Decentralized Storage
All audit artifacts are stored on Walrus — a decentralized storage network that shards and replicates data across nodes. No central point of failure, censorship-resistant, and permanently accessible.
Sui On-Chain Proof
Every audit record is committed to the Sui blockchain via a wallet transaction. This creates an immutable, verifiable record tied to your wallet identity with full provenance trail.
Getting Started
Connect Your Wallet
Click Connect Wallet in the top bar. WALSEC requires a Sui wallet (Sui Wallet, Ethos, etc.) for on-chain audit persistence. The app will not initialize the swarm until a wallet is connected.
Submit a Contract
Paste your Sui Move smart contract code into the editor, or select from pre-loaded vulnerable demo samples (VAULT_OVERFLOW, ACCESS_CONTROL_BYPASS).
Initialize the Swarm
Click Initialize Swarm to start the three-agent audit pipeline. Watch real-time progress as each agent completes its phase. The pipeline typically takes 30-90 seconds.
Review Results
Once complete, review the audit artifact showing vulnerability details, severity, risk score, and CWE classification. Click See Vulnerability for full JSON details.
Apply Fix (Optional)
Click Apply Fix to auto-generate secure, production-ready code. The fix is applied with a typing animation and includes proper assertions, capability checks, and safe arithmetic patterns.
Vulnerability Types
WALSEC detects 15+ vulnerability categories in Sui Move smart contracts.
Integer overflow/underflow in arithmetic operations without bounds checking.
Missing or incorrect capability checks allowing unauthorized operations.
State modification after external call allowing recursive re-entry attacks.
Missing ownership verification enabling fund theft.
Subtraction below zero without underflow protection.
Admin functions lacking proper AdminCap verification.
Ignoring return values from critical function calls.
Improper type handling leading to unexpected behavior.
Failure to properly transfer or destroy resources.
Unbounded loops that can exhaust gas or hang execution.
Ability to gain elevated permissions through contract manipulation.
Price feed or external data source manipulation.
Transaction ordering exploitation in DEX or auction contracts.
Missing zero-value checks allowing dust attacks.
Business logic flaws that deviate from intended behavior.
Audit Pipeline
The audit pipeline is orchestrated by LangGraph and runs through six phases.
SUBMIT
Contract code is received and validated. Wallet connection verified for on-chain persistence.
ANALYZE
AGENT_01 scans bytecode for vulnerability patterns using symbolic execution and heuristic analysis.
EXECUTE
AGENT_02 constructs theoretical exploit vectors, models attack sequences, and rates difficulty.
EVALUATE
AGENT_03 synthesizes findings into a final artifact with severity, risk score, and remediation.
STORE
Artifact stored on Walrus decentralized storage. Audit record committed to Sui blockchain.
FIX
Optional auto-patch generates secure code with proper assertions and capability checks.
Pipeline Configuration
// Timeout configuration LLM_TIMEOUT_MS = 50_000 // Per-node LLM call timeout PIPELINE_TIMEOUT_MS = 170_000 // Overall pipeline timeout MAX_DURATION_MS = 180_000 // API route max duration WALRUS_TIMEOUT_MS = 8_000 // Non-blocking Walrus fetch
API Reference
POST /api/audit
Submit a smart contract for autonomous security audit.
// Request
{
"code": "module vault::pool { ... }",
"contractName": "VAULT_OVERFLOW"
}
// Response
{
"success": true,
"artifact": {
"contractName": "VAULT_OVERFLOW",
"vulnerabilities": [
{
"type": "Arithmetic Overflow",
"severity": "Critical",
"description": "...",
"cwe": "CWE-190",
"riskScore": 9.5,
"affectedLines": [15, 22]
}
],
"agent_consensus": "...",
"status": "completed",
"txHash": "0x...",
"walrusBlobId": "..."
}
}POST /api/walrus
Store audit artifact on Walrus decentralized storage.
// Request
{
"artifact": { ... },
"contractName": "VAULT_OVERFLOW"
}
// Response
{
"success": true,
"blobId": "walrus_blob_id...",
"epoch": 428
}Ask Walsec (Terminal Interface)
The "Ask Walsec" page (/config) is a retro-futuristic AI terminal. It requires a wallet connection to unlock. Your chat history and terminal session are permanently tied to your connected wallet address. Disconnecting your wallet will securely lock the terminal.
Generated code is elegantly presented in the dedicated AI Output Viewer on the right panel, complete with a language header and a one-click COPY button.
Terminal Commands
| Command | Description |
|---|---|
help | Show all available commands |
clear | Clear terminal output |
status | Show system and swarm status |
history | Show audit history from on-chain records |
agents | List active AI agents and their status |
threats | Show detected threat statistics |
network | Display network and node information |
scan <addr> | Simulate vulnerability scan on address |
ping | Check network latency to nodes |
hash <text> | Generate deterministic hash of text |
export | Download terminal logs as .txt file |
uptime | Show system uptime statistics |
version | Show WALSEC version info |
On-Chain Integration
Move Contract: walsec_registry
WALSEC uses a Sui Move smart contract to store audit records on-chain. Each audit creates an immutable record tied to the operator's wallet.
// Event emitted on each audit
public struct AuditRecorded has copy, drop {
operator: address,
contract_name: String,
severity: String,
risk_score: u8,
num_vulnerabilities: u64,
timestamp_ms: u64,
walrus_blob_id: String,
}How It Works
- User connects their Sui wallet to the application
- Audit pipeline completes and generates the artifact
- Artifact is stored on Walrus decentralized storage
- A transaction is sent to the walsec_registry contract
- The
AuditRecordedevent is emitted on-chain - History is loaded from on-chain events via
sui_queryEvents
Contract Addresses
Package ID: 0x2d3f7e... (testnet) Module: walsec_registry Network: Sui Testnet
Contract Samples
WALSEC includes pre-loaded vulnerable demo contracts for testing.
VAULT_OVERFLOW
A liquidity pool contract with an arithmetic overflow vulnerability in the deposit function. The share calculation can overflow when large amounts are deposited, allowing an attacker to mint excessive shares.
ACCESS_CONTROL_BYPASS
An admin-controlled contract missing proper capability verification. The withdraw function lacks AdminCap checks, allowing any user to drain the contract's funds.
Auto-Fix Output
When a fix is applied, WALSEC generates complete, production-ready code with:
- Error code constants (
EOverflow,EUnderflow,EInvalidAdminCap) - Assertion guards (
assert!(amount > 0, EZeroAmount)) - Capability verification (
assert!(_cap.id == pool.admin_cap_id, EInvalidAdminCap)) - Safe arithmetic with overflow checks
- Proper resource handling and transfer semantics
Tech Stack
Frontend
- Next.js 16 — React framework with App Router
- TypeScript — Type-safe development
- CSS Custom Properties — Vigilant Void design system
Blockchain
- Sui — Layer 1 blockchain with Move language
- @mysten/dapp-kit — Wallet connection & tx handling
- Sui Move — Smart contract language
AI Pipeline
- LangGraph — Multi-agent orchestration
- Gemini 2.5 Flash — LLM for analysis & generation
- @langchain/google-genai — LangChain adapter
Storage & Memory
- Walrus — Decentralized blob storage
- Sui Events — On-chain audit record persistence
- Memwal SDK — Wallet-tied semantic memory for Chat & Audit Logs
FAQ
How long does an audit take?
The full three-agent pipeline typically completes in 30-90 seconds depending on contract complexity and LLM response times. Each agent has a 50-second individual timeout.
Is my contract code sent to a third party?
Contract code is processed by Gemini AI (Google) for vulnerability analysis. Results are stored on Walrus decentralized storage and recorded on Sui blockchain.
Can I audit any Sui Move contract?
Yes. Paste any Sui Move module code into the editor. The system also includes pre-loaded vulnerable demo samples for testing.
What happens after I click Apply Fix?
The system replaces your contract code with a secure, production-ready version that includes proper assertions, capability checks, error codes, and safe arithmetic patterns. The change is animated with a typing effect.
Do I need a wallet to use WALSEC?
Yes. A Sui wallet connection is required to initialize the swarm and persist audit records on-chain. The wallet gate ensures all audits are tied to a verifiable identity.
How are audit results stored?
Results are stored in two places: (1) Walrus decentralized storage for the full artifact JSON, and (2) Sui blockchain as an on-chain event for immutable proof.
What vulnerability types are detected?
WALSEC detects 15+ categories including arithmetic overflow, access control bypass, reentrancy, unauthorized withdrawal, missing capability checks, and more. See the Vulnerability Types section for the full list.
