Smart-contract security · Web3

Security that proves it.

Every other auditor hands you an opinion. OmniAudit hands you a runnable proof — an exploit executed on a forked chain that actually moved funds. No proof, no finding. Near-zero false positives.

Instant pre-check — no email needed. Then get the deterministic, proof-backed report. Badge, reports, API & monitoring check out in one click below; high-ticket audits are scoped with you.
A replay of one exploit we actually re-executed — Poly Network, 2021, $611M. Not a simulation of your contract.
Proven on real EVM ERC-3643 / T-REXERC-1400ERC-7518 Uniswap · PancakeFoundry fork executionSigned receipts
141 attack classes proven by execution · read any of them
The per-receipt transparency log is not yet publishing: the signed receipts the engine produces are not being appended to it, so there is nothing to recompute. Every number above is instead reproducible from the artifacts in the repository.
The incident wall

21 / 32 real exploits, re-executed — not described.

We take a historical hack, fork mainnet at the block it happened, and run the attack again. It either drains the fork or it does not. 21 / 32 catalogued incidents are re-proven that way — $2.03B of publicly reported loss. For scale: in the independent re-evaluation of EVMbench, no AI agent produced a profitable end-to-end exploit in 110 attempts on contamination-free incidents.

$611MPoly Network2021 · keeper cross-contract -> forged cross-chain unlockre-proven on a fork $200MPancakeBunny2021 · flash-loan-inflated mint pricere-proven on a fork $197MEuler Finance2023 · donation + missing liquidity/health checkre-proven on a fork $190MNomad bridge2022 · message-verification init flawre-proven on a fork $150MParity multisig freeze2017 · unprotected initializer -> selfdestruct via delegatecallre-proven on a fork $130MCream Finance2021 · reentrancyre-proven on a fork

See all 32 incidents, re-proven and queued →

Platform & pricing

Detect. Execute the exploit. Prove the fix.

One platform for the whole lifecycle — and every product is priced right here. One-click checkout on everything self-serve, no “contact sales” wall. A deterministic verifier under each one means the output is evidence, not a guess.

Free — start now

Free proof scan

$0 / runs online

Paste a contract at the top of the page — a proof-backed verdict, emailed to you. No card, no account.

Get started ↑
Self-serve · one-time

Token risk report

$750 / token

Owner powers, mint / pause / blacklist, fee-on-transfer, honeypot — each proven by execution, not guessed.

Get started →

Fix verification

$2,500 / pass

We re-run the exploit against your patch and prove funds can no longer move. “Proven fixed” — a claim no scanner can make.

Get started →
Subscriptions · monthly

Screening / Verdict API

$199–$2,500 / mo

Programmatic, proof-backed verdicts — put the “is it safe?” answer where your users already are.

Get started — Dev · $199/mo → Pro · $799/mo → Enterprise · $2,500/mo →

CI pre-deploy gate

$99 / team / mo · coming soon

A proof gate in your pipeline — every deploy is verified before it ships, so nothing goes live unproven.

Coming soon

Continuous monitoring

$500 / contract / mo · waitlist

Re-verify on every upgrade; alert the moment a risk becomes proven-exploitable — not just suspicious.

Talk to sales
Consultation · talk to sales

Proof-backed audit

from $4,000

Token, protocol or bridge. Every finding ships a reproducible exploit + a proven fix.

Talk to sales →

Bounty AI-judge / advisory

$5,000

An un-gameable deterministic adjudicator for contests — only proven exploits pay — plus token-design advisory.

Talk to sales →

Transaction firewall rolling out

early access

Pre-sign screening stops the malicious transaction before it's signed — drain patterns and hostile contracts, caught at the moment of action.

Talk to sales →

Security-token audit (RWA)

from $15,000

ERC-3643 / ERC-1400 / ERC-7518 + the identity, key and compliance layers — proven by execution.

Talk to sales →
Why OmniGuard

Everyone ships suspicion. We ship evidence.

01

Proof, not opinion

The deterministic verifier is a capability no incumbent ships. We prove the exploit moves funds — and prove the fix stops it.

02

Defense in depth

Layered isolation with strict trust boundaries, designed assuming daily attack.

03

Built to be attacked

We audit ourselves with our own product and design our own surface for the worst case.

04

Institutional governance

Sensitive actions are protected with institutional-grade controls, the way top custodians safeguard assets.

Access

Prove your contract before the market does.

The free scan runs online. The self-serve products check out in one click above — high-ticket audits and RWA engagements are scoped directly with you.

Contact

Tell us what you're building.

Which tier you need, and what you want proven. We reply from a verified @omniguardlabs.com address — we never ask for keys, seed phrases, or funds.

Don't take our word for it — check the work first: $2.03B of real exploits re-proven 21 / 32 historical incidents re-executed 141 attack classes proven 0 false proofs