README.md
September 19, 2026 · View on GitHub
██╗███████╗██╗ ██╗███████╗ ██████╗ █████╗ ███╗ ██╗ ███████╗██╗ ██╗███╗ ███╗
██║██╔════╝██║ ██║██╔════╝██╔════╝██╔══██╗████╗ ██║ ██╔════╝██║ ██║████╗ ████║
██║█████╗ ██║ ██║███████╗██║ ███████║██╔██╗ ██║█████╗█████╗ ██║ ██║██╔████╔██║
██ ██║██╔══╝ ╚██╗ ██╔╝╚════██║██║ ██╔══██║██║╚██╗██║╚════╝██╔══╝ ╚██╗ ██╔╝██║╚██╔╝██║
╚█████╔╝███████╗ ╚████╔╝ ███████║╚██████╗██║ ██║██║ ╚████║ ███████╗ ╚████╔╝ ██║ ╚═╝ ██║
╚════╝ ╚══════╝ ╚═══╝ ╚══════╝ ╚═════╝╚═╝ ╚═╝╚═╝ ╚═══╝ ╚══════╝ ╚═══╝ ╚═╝ ╚═╝
Produce a heat map of likely bugs - in seconds, for pennies - built with TypeSafe's Jev.
Warning: this is a 100% vibe-coded proof of concept. I did not read one line of the code. Use at your own risk.
Quick start
Python 3.11+ and a TypeSafe API key (console.typesafe.ai).
Installation
git clone https://github.com/devtooligan/jevscan-evm.git && cd jevscan-evm
pip install aiohttp
cp .env.example .env # then set TYPESAFE_API_KEY in .env
Usage
python jevscan.py /path/to/repo
Results land in out/<repo>/HEATMAP.md. Settings (which folder, which files, thresholds) live in jevscan.toml; pass your own overrides with --config — see docs/CONFIG.md.
What it checks
| Layer | Questions | From |
|---|---|---|
| General | 2 | "Is there any exploitable bug?" and "Is there a bug that lets an attacker steal or lock funds?" |
| Categories | 14 | OWASP Smart Contract Top 10, SWC, Immunefi (TAXONOMY.md) |
| Detectors | 343 | Sourced from Cyfrin audit-checklist (the Solodit checklist) and evm-cortex by Chris Cashwell |
Example: USSD
The Sherlock USSD contest (May 2023), 8 of 12 files scanned: HEATMAP.md.
89% chance of a critical bug · 91% chance of at least one exploitable bug · hottest file:
USSDRebalancer.sol
Speed and cost: One file, 14 checks:
- GPT-5.6 (high reasoning) 57 seconds and 3.9¢
- Jev 0.7 seconds and costing 0.015¢ -- about 80× faster and 260× cheaper.
| File | Crit | Any | Access | Proxy | Oracle | Econ | Reentry | Shares | Math | Sigs | Xchain | Tokens | Logic | DoS | MEV | LowLvl |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
oracles/StableOracleDAI.sol | 🟧 | 🟥 | 🟩 | 🟩 | 🟥 | 🟨 | 🟩 | 🟩 | 🟥 | 🟩 | 🟩 | 🟩 | 🟨 | 🟨 | 🟩 | 🟩 |
USSDRebalancer.sol | 🟥 | 🟥 | 🟧 | 🟨 | 🟥 | 🟨 | 🟧 | 🟥 | 🟥 | 🟩 | 🟩 | 🟥 | 🟥 | 🟥 | 🟥 | 🟩 |
USSD.sol | 🟥 | 🟥 | 🟥 | 🟧 | 🟥 | 🟧 | 🟧 | 🟧 | 🟥 | 🟩 | 🟩 | 🟥 | 🟥 | 🟧 | 🟥 | 🟩 |
oracles/StableOracleWBTC.sol | 🟧 | 🟥 | 🟩 | 🟩 | 🟥 | 🟨 | 🟩 | 🟩 | 🟧 | 🟩 | 🟩 | 🟩 | 🟩 | 🟩 | 🟩 | 🟩 |
oracles/StableOracleWETH.sol | 🟧 | 🟧 | 🟩 | 🟩 | 🟥 | 🟩 | 🟩 | 🟩 | 🟧 | 🟩 | 🟩 | 🟩 | 🟩 | 🟩 | 🟩 | 🟩 |
oracles/StableOracleWBGL.sol | 🟨 | 🟧 | 🟩 | 🟩 | 🟥 | 🟩 | 🟩 | 🟩 | 🟧 | 🟩 | 🟩 | 🟩 | 🟩 | 🟩 | 🟩 | 🟩 |
oracles/UniswapV3StaticOracle.sol | 🟨 | 🟨 | 🟩 | 🟩 | 🟨 | 🟩 | 🟩 | 🟩 | 🟨 | 🟩 | 🟩 | 🟩 | 🟨 | 🟩 | 🟩 | 🟩 |
Migrations.sol | 🟩 | 🟨 | 🟩 | 🟩 | 🟩 | 🟩 | 🟩 | 🟩 | 🟩 | 🟩 | 🟩 | 🟩 | 🟩 | 🟩 | 🟩 | 🟩 |
🟥 70% or more · 🟧 50% to 70% · 🟨 30% to 50% · 🟩 under 30%
Strongest hits
| File | Function | What it found | Confidence | Contest finding |
|---|---|---|---|---|
oracles/StableOracleDAI.sol | getPriceUSD | Unsafe Chainlink price feed consumption without staleness/validity/sequencer checks | 97% | H-1 |
oracles/StableOracleWBTC.sol | getPriceUSD | Unsafe Chainlink price feed consumption without staleness/validity/sequencer checks | 97% | M-7 |
oracles/StableOracleWETH.sol | getPriceUSD | Unsafe Chainlink price feed consumption without staleness/validity/sequencer checks | 97% | H-11 |
USSD.sol | approveToRouter | Unsafe ERC20 transfer calls without return-value checks or SafeERC20 wrapper | 96% | none judged (real pattern) |
USSD.sol | calculateMint | Missing sanity/range check on oracle price allows flash-crash price manipulation | 95% | M-7 |
Contest finding: the judged issue it matches.
How it did in other benchmarks
| Contest | Confirmed findings | Identified the file and bug type with ≥ 70% confidence | Identified the function | False positives |
|---|---|---|---|---|
| Monolith · Sherlock · Dec 2025 | 7 | 6 | 5 | 3 |
| Beedle · CodeHawks · Jul 2023 | 42 | 27 | 18 | 1 |
| USSD · Sherlock · May 2023 | 22 | 20 | 16 | 0 |
Identified the file: the file scored 70% or more on the finding's bug type. Identified the function: the function it ranked highest for that bug type was the judged one, or one on that bug's exploit path: a caller, a callee, or where the bad value is produced or used. False positives: things it reported at 70% or more that were wrong. Reviews: Monolith, Beedle, USSD.
Full results: Monolith · Beedle · USSD
More
Details, benchmarks, and how to sync or add detectors: docs/DETAILS.md
Credits and license
Detectors come from the Cyfrin audit-checklist and evm-cortex by Chris Cashwell (MIT). Answers come from Jev by TypeSafe. MIT license. See LICENSE.