labs@atheron:~/open-source/lens$ lens scan ./contracts
Atheron Lens
Catch contract bugs before you deploy.
An open-source static analyser for smart contracts. It reads your code, flags the bugs auditors find most often and tells you how to fix each one.
// status
In development.
Lens is being built now. The source opens on GitHub at launch, and the link will appear on this page that day.
- source
- Opens at launch
- licence
- Apache-2.0 and MIT
- command
lens
// what it does
A second pair of eyes on every commit.
Lens checks your contracts without running them. It looks for known patterns of risk and reports each finding with where it is, why it matters and a hint for the fix.
- Around 25 high-signal checks in the first release: reentrancy, unchecked calls, access control, tx.origin, delegatecall and proxies, initialisers, precision, signature replay, randomness, oracle manipulation and gas denial of service.
- Reports as SARIF for GitHub code scanning, and as Markdown for people.
- One binary per platform, fast enough for a large project in seconds.
- No network calls while it scans. Your code stays on your machine.
// who it is for
Anyone who ships contracts.
01
Contract developers
02
Teams before an audit
03
Reviewers and auditors
// languages
Every major contract language.
One engine, with each language as a plug-in. The first release covers the EVM; the others follow in this order.
- EVM
- Solidity and Vyperfirst release
- Rust
- Solana (native and Anchor), CosmWasm, ink!next
- Move
- Aptos and Suinext
- Cairo
- Starknetnext
- WebAssembly
- Compiled Wasm contracts, whatever language they came fromnext
// quick start
One command to scan.
Lens is a command line tool called lens. This is how it works in the version we are building; details may change before launch.
// Scan a folder of contracts
lens scan ./contracts// Write a SARIF report for GitHub code scanning
lens scan ./contracts --format sarif > lens.sarif// Run it on every pull request
- name: Atheron Lens
run: lens scan ./contracts --format sarif > lens.sarifInstall steps for each platform are published with the source at launch.
// sample report
What a finding looks like.
An example of the report Lens writes for one finding. The contract and the line are made up for this page.
HIGH reentrancy contracts/Vault.sol:42
withdraw() sends ETH before it updates balances[msg.sender].
A contract that calls back into withdraw() can drain the vault.
fix: update the balance first (checks, effects, interactions),
or guard withdraw() with a reentrancy lock.// in your editor
Findings as you type.
After the command line, Lens comes to editors through a language server, in this order:
- VS Code, on the Marketplace and Open VSX (so Cursor, Windsurf and VSCodium too)
- Remix IDE
- JetBrains IDEs
- Neovim, Zed, Helix, Sublime Text and Emacs
// licence
Free, under two licences.
Lens is dual licensed under Apache-2.0 and MIT. Pick the one that suits you.
// need more
Want a person on it too?
A tool finds patterns. Our engineers can review your contracts by hand, with Lens as the starting point.