Skip to content
AtheronLABS

You're visiting from the United States. Prices are shown in US dollars. Not right?

labs@atheron:~/open-source/lens$ lens scan ./contracts

Atheron Lens

Catch contract bugs before you deploy.

An open-source static analyser for smart contracts. It reads your code, flags the bugs auditors find most often and tells you how to fix each one.

// status

In development.

Lens is being built now. The source opens on GitHub at launch, and the link will appear on this page that day.

source
Opens at launch
licence
Apache-2.0 and MIT
command
lens

// what it does

A second pair of eyes on every commit.

Lens checks your contracts without running them. It looks for known patterns of risk and reports each finding with where it is, why it matters and a hint for the fix.

  • Around 25 high-signal checks in the first release: reentrancy, unchecked calls, access control, tx.origin, delegatecall and proxies, initialisers, precision, signature replay, randomness, oracle manipulation and gas denial of service.
  • Reports as SARIF for GitHub code scanning, and as Markdown for people.
  • One binary per platform, fast enough for a large project in seconds.
  • No network calls while it scans. Your code stays on your machine.

// who it is for

Anyone who ships contracts.

01

Contract developers

Find the obvious bugs yourself, on every save or commit, before a reviewer does.

02

Teams before an audit

Clear the easy findings first, so the paid audit time goes to the hard questions.

03

Reviewers and auditors

A fast first pass over a codebase, with findings you can export and track.

// languages

Every major contract language.

One engine, with each language as a plug-in. The first release covers the EVM; the others follow in this order.

EVM
Solidity and Vyperfirst release
Rust
Solana (native and Anchor), CosmWasm, ink!next
Move
Aptos and Suinext
Cairo
Starknetnext
WebAssembly
Compiled Wasm contracts, whatever language they came fromnext

// quick start

One command to scan.

Lens is a command line tool called lens. This is how it works in the version we are building; details may change before launch.

// Scan a folder of contracts

lens scan ./contracts

// Write a SARIF report for GitHub code scanning

lens scan ./contracts --format sarif > lens.sarif

// Run it on every pull request

- name: Atheron Lens
  run: lens scan ./contracts --format sarif > lens.sarif

Install steps for each platform are published with the source at launch.

// sample report

What a finding looks like.

An example of the report Lens writes for one finding. The contract and the line are made up for this page.

HIGH  reentrancy  contracts/Vault.sol:42

  withdraw() sends ETH before it updates balances[msg.sender].
  A contract that calls back into withdraw() can drain the vault.

  fix: update the balance first (checks, effects, interactions),
       or guard withdraw() with a reentrancy lock.

// in your editor

Findings as you type.

After the command line, Lens comes to editors through a language server, in this order:

  • VS Code, on the Marketplace and Open VSX (so Cursor, Windsurf and VSCodium too)
  • Remix IDE
  • JetBrains IDEs
  • Neovim, Zed, Helix, Sublime Text and Emacs

// licence

Free, under two licences.

Lens is dual licensed under Apache-2.0 and MIT. Pick the one that suits you.

// need more

Want a person on it too?

A tool finds patterns. Our engineers can review your contracts by hand, with Lens as the starting point.

Atheron Lens | Atheron Network Labs