Kagex · Ecosystem Security

The security
reputation layer
for smart contracts

Continuous AI security analysis on every pull request — distilled into one score that protocols publish, users check, and the ecosystem learns to trust.

Working product Pilot phase Solidity · GitHub-native
01 / 14

Problem

Security is a snapshot.
Code is a stream.

$3.4B
stolen from crypto platforms and users in 2025 — up 37% year over year
$1.4B
lost in a single incident (Bybit, Feb 2025) — the largest crypto theft ever
$25–250k
typical cost of one manual audit engagement — weeks of scheduling for a point-in-time report

An audit certifies one commit. Every commit after it ships unreviewed — and that's where regressions, rushed fixes, and upgrade mistakes live. Teams know this; they just can't afford an audit per pull request.

Sources: Chainalysis Crypto Crime Report 2026; industry audit pricing.

02 / 14

Solution

An AI security layer that reviews
every change — the day you install it

1
Install the Kagex GitHub App
One click. No pipeline changes, no SDK, no sales call.
2
Label a PR kagex-security
Multi-agent AI analysis runs on the changed contracts, steered by the team's own trust assumptions.
3
Verdict lands in the PR
Findings with fixes, an updated security score, and what changed since the last scan.
Security score
89 91 +2
✅ 3 fixed ❌ 1 new ⚠ 2 persisting
03 / 14

Product — built and running today

Not a deck-stage idea.
A working platform.

  • Multi-agent analysis pipeline on Claude, grounded in a curated knowledge base: 420+ vulnerability patterns from 800+ documented exploits
  • GitHub-native end to end: OAuth sign-in, one-click App install, label-triggered PR scans, results as PR comments
  • Per-repo audit scope + team assumptions (text or PDF/DOCX) fed to the agents
  • Issue lifecycle with fingerprint dedup: dismissed issues never resurface on unchanged code; every resolution requires the fixing PR link
  • Security score + regression detection on every scan; exportable audit-style reports
  • Durable job pipeline, full activity logging, admin analytics, workspace approval gating

Built end-to-end by a lean AI-augmented team in weeks — the same cost curve that makes the product possible makes the company capital-efficient.

04 / 14

The wedge

One number the CTO tracks.
One diff the engineer trusts.

Category breakdown
Access Control
98
Reentrancy
100
Upgradeability
71
Oracle Safety
83
ERC Compliance
96
Math
74
Business Logic
79
  • Regression detection. Every scan diffs against the last: newly introduced issues are flagged the moment they appear, verified fixes are credited.
  • Management gets a KPI that moves week over week; engineers get instant, specific feedback in the PR they're already reviewing.
  • Noise dies fast. Dismiss a false positive once; it never returns while the code is unchanged.
05 / 14

Security profiles

A security rating for
every protocol

Every scanned protocol gets a public score card — a live badge and a profile any wallet, explorer, or user can read. Think Moody's, for on-chain code.

Yield Vault
AAA
96 ↑ +3
Reentrancy100
Access control94
DEX Router
A
83 → 0
Oracle safety78
Math81
Lending Market
BBB
71 ↑ +5
Upgradeability64
Business logic76

Illustrative cards — real ratings come from each protocol's scans.

The badge goes stale if scanning stops, so trust decays honestly. And like a rating agency, the rule is absolute: the score can never be bought, boosted, or staked into.

06 / 14

Beyond findings

Not just what's wrong
proof, tests, and docs

Security documentation, generated
Auto-drafted, audit-ready threat models: actors, assets, trust assumptions, privileged actions, and the full attack surface — the document auditors usually build by hand, produced from the code.
Attack paths, simulated
Not "possible reentrancy" — the actual exploit path, step by step, with an auto-generated Foundry PoC executed in a sandbox: exploit reproduced, funds at risk quantified.
Invariants & fuzz, suggested
From a contract, Kagex proposes the invariants that must hold (totalAssets >= totalSupply, PPS never decreases) and generates the fuzz harnesses to test them.
Example attack path
Attacker deposits
calls withdraw()
fallback re-enters
shares not yet burned
funds drained

Each of these is a public good on its own — better docs, stronger tests, and reproducible proof raise the security bar for every team, not just the report's recipient.

07 / 14

Why now

Three curves crossed

AI writes the code
Copilot/Cursor-era teams ship contract code faster than any human review process can absorb. Volume of unaudited change is exploding.
AI can now audit it
Frontier models reached audit-grade reasoning on Solidity in the last 18 months. The unit economics of "review everything" finally work.
The category is validated — and open
AI scanning is a proven, funded category (Octane Security raised $6.75M in 2025). But no one has built the open trust layer above it — a shared, public security standard.

Source: Octane seed announcement, April 2025 (PRNewswire / SecurityWeek).

08 / 14

Who this helps

Security that lifts the
whole ecosystem

Every
EVM team that ships Solidity — Kagex is chain-agnostic, so one tool raises the security floor across every ecosystem it touches
$3.4B
lost to exploits in 2025 — most from code that changed after its last audit. Continuous review is the gap Kagex closes
Public
by design: free tier for pilots, an open security score any protocol can publish, and a knowledge base that benefits every builder

Fewer exploits, safer users, and a shared, verifiable security standard the whole ecosystem can read — that's the public good a grant accelerates.

09 / 14

Built to last

A grant builds it;
revenue keeps it alive

Not a recurring dependency
  • Grant support funds specific deliverables — not indefinite operating costs
  • A free pilot tier keeps Kagex open to teams that can't pay, while paid subscriptions cover inference and sustain the project after the grant
  • Inference is the only usage-scaled cost; prompt-caching the knowledge base cuts it ~90%, so the project is cheap to keep running
Lasting public value
  • An open security score any protocol can publish and any wallet or explorer can read
  • A continuously-expanding, exploit-derived knowledge base that improves every scan
  • Fewer exploits across the ecosystem — the return on the grant is measured in prevented losses, not just revenue
10 / 14

Competition

Everyone finds bugs.
Nobody keeps score.

Manual auditsContest platformsOctaneKagex
Continuous, per-PR coverage
Security score + regression deltaspartial
Cross-scan issue memory (no repeat noise)
Team assumptions steer the analysis
Public, verifiable reputation layer
Entry price$25k+ / engagement$30k+ / contestsubscriptionfrom $3k / seat / yr

Audits and contests stay complementary — Kagex makes them cheaper (cleaner code in) and durable (regression watch after). The open, public reputation layer is the gap no one else fills.

11 / 14

Traction & roadmap

Product done. Distribution next.

Now
  • Platform live end-to-end: scans, score, regression, badges, PR automation
  • Free pilot cohort onboarding — hand-picked Solidity teams
  • Every pilot produces the two assets that matter: a case study and a public badge
Next 12 months
  • Paid conversion of pilots; seasonal leaderboards & public protocol rankings
  • Threat-model & security-docs generation; invariant + fuzz test generators
  • Attack simulator: auto-generated Foundry PoCs, executed in sandbox — "exploit reproduced, 125 ETH at risk"
  • Open for Review & bug bounties — protocols open a scan to vetted human auditors; AI triage feeds the marketplace. AI finds → humans verify → protocols fund bounties: the security network forms.
  • Public score API for wallets & explorers — the reputation layer opens
12 / 14

Gamified security

Security work that
shows off

Earn XP for real fixes
+150 for a rescan-verified critical fix, +10 per scanned PR. Points come only from making code safer — never from spend.
Climb the leagues
Bronze → Silver → Gold → Platinum → Diamond → Titan. "We reached Diamond security" is a tweet and a hiring signal.
Collect badges
Zero Criticals · 365 Days No Regression · 100 Safe PRs · Full ERC-4626 Compliance — embeddable proof of a security culture.
Future: KAGE token
Service-side utilities only — staked compute tiers, certification bonds, bounty pools. Earned, never sold. Deferred, with counsel.

XP, leagues, and badges run today — rewarding teams for safer code, which is exactly the outcome the ecosystem wants. One rule is permanent: points and any future token never touch the score.

13 / 14

What grant support enables

Fund the deliverables that
make the score a standard

DeliverableWhat ships
Public score API An open endpoint so wallets, explorers, and dashboards can read a protocol's Kagex score — turning it into shared ecosystem infrastructure.
Attack simulator Auto-generated, sandbox-executed Foundry PoCs that prove an exploit is real — not just flagged. The highest-value security deliverable.
Invariant & fuzz generation AI-suggested invariants and fuzz harnesses from a contract — giving every team stronger tests, not just findings.
Knowledge-base expansion Continuously growing the exploit-derived pattern library — a public good that sharpens every scan for every user.
Free tier & pilots Keep Kagex open to teams that can't pay, so the security floor rises across the whole ecosystem, not only for well-funded protocols.
Grant is scoped to deliverables
  • Milestone-based — funding maps to the specific work above, sized to each program
  • Revenue and a free tier sustain the project after the grant — not a recurring dependency
  • Impact measured in exploits prevented and teams protected, reported openly

Kagex — make shipping safe code visible.   [email protected] · kagex.dev

14 / 14
↑ ↓ or scroll · 14 slides