Archive position — measured, not model output
3 likes on Devpost
128 of the 7,856 archived projects have more likes, and 93 share exactly 3 — so this project's #129 place in the like-ranked listing is a tie-break inside that group, not a ranking.
Projects (log scale)
Likes on Devpost. ▲ marks this project's group.
Show the figures
| Likes | Projects | Share of archive |
|---|---|---|
| 0 | 5,592 | 71.2% |
| 1 | 1,758 | 22.4% |
| 2 | 285 | 3.6% |
| 3–4 | 132 | 1.7% |
| 5–9 | 75 | 1.0% |
| 10+ | 14 | 0.2% |
Executive Summary
What the company appears to be
Attest is a self-reported AI-led Solidity auditor that claims to read whole contracts, design relevant tests, direct tools like Foundry and Slither, and turn noisy evidence into clear security conclusions. It operates as a local browser-based application with a Node.js backend, integrating AI reasoning with deterministic developer tooling.
What changed
The project is described as an MVP built during a hackathon, evolving beyond a basic "upload contract and ask GPT for an opinion" approach to incorporate real security tooling, test generation, and structured audit workflows. It positions itself as a platform that uses AI to coordinate between source code, tools, evidence, and conclusions.
Single most important open question
Is there sufficient evidence in the self-reported description to support claims about product maturity, scalability, or commercial viability beyond the MVP stage?
Note
This analysis is based entirely on the author’s own description. No third-party verification, traction data, revenue figures, or customer feedback are available.
What The Product Actually Is
The description states that Attest is an AI-led Solidity auditor designed to:
- Read and trace complete Solidity contracts.
- Identify meaningful security and logic concerns.
- Generate contract-specific Foundry tests.
- Run and normalize evidence from tools like Slither, Aderyn, Solhint, Foundry, and Anvil.
- Deploy eligible contracts to disposable local chains.
- Cross-check analyzer warnings against the full source instead of presenting every detector result as a vulnerability.
- Produce concise Markdown and JSON audit artifacts.
- Preserve a readable worklog showing what was examined, what ran, and how the final assessment was reached.
It does not modify or repair submitted contracts; all actions are read-only. The system is built to run locally in a browser-based interface backed by Node.js.
Claim
Attest combines AI judgment with deterministic tools for reproducible evidence.
Evidence Described as such in the write-up.
Inference The product is structured around a workflow that begins with AI reasoning, followed by tool-directed verification and evidence cross-checking.
Support
Implied from the described audit pipeline steps.
Positioning & Claim Evolution
The description indicates Attest positions itself as:
- An intelligent auditor that coordinates between source code, security tools, test environments, and conclusions.
- A platform that makes contract-specific security thinking accessible earlier in development.
- Not a replacement for experienced auditors but rather an assistant to developers.
It evolved from a basic GPT-based demonstration into a system combining AI reasoning with real tooling and structured workflows.
Claim
Attest is not just a “GPT opinion” but a system that integrates AI with deterministic tools.
Evidence Stated in the write-up under "Accomplishments."
Inference The project aims to democratize access to disciplined, contract-specific security analysis.
Support
Implied from the long-term goal described.
Target Customer & ICP
The description does not explicitly name target customers or define an ideal customer profile (ICP). However, it implies:
- Developers working with Solidity smart contracts.
- Teams looking for early-stage contract auditing capabilities.
- Users who want to understand what tools are being used and how conclusions are reached.
It is described as a tool for both new and experienced developers, suggesting a broad ICP that includes those unfamiliar with security tooling.
Claim
The product targets developers working with Solidity contracts.
Evidence Implied from the use case and audience described.
Inference It may appeal to teams seeking early-stage auditing or those looking for clarity in security assessments.
Support
Suggested by the focus on “contract-specific” and “disciplined” thinking.
Business Model & Pricing Evidence
There is no mention of pricing, monetization strategy, or business model in the description. The project is described as an MVP built during a hackathon with no indication of commercial readiness or revenue streams.
Claim
No evidence of pricing or business model.
Evidence Not stated anywhere in the provided text.
Technical & Delivery Signals
Key technical elements include:
- Local browser-based interface.
- Node.js backend.
- Integration with tools such as Foundry, Slither, Aderyn, Solhint, Anvil.
- Support for local deployment and disposable chain environments.
- AI-driven workflow that leads the process, then uses tools to confirm or challenge its conclusions.
- Vibe-coded development approach using Codex integration.
Claim
The system runs locally with a Node.js backend and integrates multiple security tools.
Evidence Described in "How we built it."
Inference The architecture supports reproducible execution and evidence normalization.
Support
Suggested by the mention of deterministic tooling and structured workflow.
Traction & Maturity Signals
There is no evidence of traction, customers, revenue, or adoption beyond the MVP stage. The project is explicitly described as an MVP built during a hackathon.
Claim
No traction or maturity signals.
Evidence Stated in the context section and throughout the write-up.
Competitive Context
The description does not reference competitors or market positioning. It focuses on internal development and workflow design rather than external competitive analysis.
Claim
No evidence of competitive landscape.
Evidence Not provided.
Key Risks & Red Flags
- Unproven commercial viability: The project is described as an MVP with no revenue, customers, or traction.
- Limited tool integration: While several tools are mentioned, the description does not confirm full support or performance across all listed tools.
- AI dependency risk: Reliance on AI for judgment without clear validation mechanisms raises concerns about consistency and accuracy.
- Local-only execution model: May limit scalability or accessibility for enterprise users.
- No pricing or monetization strategy: Indicates lack of business planning beyond MVP.
Inference The product may struggle to scale beyond the hackathon prototype without significant development and commercialization effort.
Support
Based on lack of evidence for traction, pricing, or tool maturity.
Diligence Questions To Ask The Founders
- What specific metrics or KPIs are used to evaluate the accuracy of AI-generated conclusions?
- How does Attest handle false positives from static analyzers and ensure relevance of findings?
- Are there plans for cloud-hosted versions or enterprise integrations?
- Has the team tested Attest on real-world contracts beyond the MVP scope?
- What is the roadmap for integrating additional tools like Echidna, Halmos, Mythril, and SMTChecker?
- How does Attest plan to differentiate itself from existing open-source auditors or commercial platforms?
Investment/Partnership Verdict
Attest is described as a hackathon MVP that demonstrates potential in combining AI with deterministic security tooling. However, there is no evidence of traction, revenue, customers, or a defined business model.
Verdict Early-stage product with promising technical foundations but unproven commercial viability.
Confidence Level Low — due to lack of external validation and absence of any financial or adoption data.
Inference If the team can demonstrate improvements in accuracy, scalability, and monetization, this could be a viable investment opportunity.
Support
Based on the described workflow and tool integration, which suggest strong technical capability.
Source
Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.
The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.
