VegaSec self-audit reference
We run VegaSec against fictional internal fixtures so buyers can see what a vulnerable vs remediated Solidity contract looks like through the same pipeline used on real submissions.
- Synthetic internal contracts. Not deployed, not sold, no token launch implied.
- Findings are static-analysis output. No human operator review has been attached.
- Both sides use the same scanner toolchain (slither + semgrep) and the same audit pipeline.
- The remediation delta shows what was removed from the report. It is not a guarantee of safety.
Remediation delta
Total findings removed
+9
Critical + high removed
+5
Actionable findings removed
+8
Positive numbers mean the fixed fixture has fewer findings of that class than the vulnerable fixture. They do not mean the fixed fixture has been verified by a human auditor.
Deterministic cockpit fixture
Reference audit replay
Honest stage-by-stage view of what VegaSec ran against this contract. Automated stages do not replace a human operator review.
Audit intake
Passed320ms replay12:00 PMNormalize the submitted contract target and confirm it can enter the Solidity audit lane.
Next: Acquire verified source or scan the pasted Solidity source.
Source acquisition
Passed1.4s replay12:00 PMResolve pasted source or verified explorer source without treating malformed input as demo data.
Next: Validate the analyzer toolchain against the acquired source.
Toolchain validation
Passed2.3s replay12:00 PMConfirm the configured static analyzers can run and produce parseable output.
Next: Run static analysis and capture raw detector evidence.
Static analysis
Passed7 findings8.8s replay12:00 PMRun static analyzers against the sandboxed source and collect raw detector evidence.
Next: Normalize detector output into one deduped finding set.
Finding normalization
Passed7 findings1.1s replay12:00 PMDedupe detectors, classify vulnerability classes and compute severity-weighted risk.
Next: Review exploitability conservatively against confidence and limitations.
Exploitability review
Partial7 findings1.9s replay12:00 PMFrame automated findings with conservative exploitability and limitation notes.
Next: Draft remediation notes from the normalized evidence.
- Automated exploitability review is conservative and does not replace a manual exploitability assessment.
Remediation draft
Partial7 findings1.5s replay12:00 PMPrepare remediation-oriented evidence for the shareable report artifact.
Next: Attach an operator review artifact before claiming human review.
- Remediation notes are generated from detector evidence and require project-specific engineering review.
Operator review
Blocked0ms replay12:00 PMRecord whether a human operator artifact exists before buyer escalation.
Next: Attach a real operator review artifact before claiming human review.
- No operator review artifact is attached to this automated scan.
- Human operator review has not been attached to this automated scan yet.
Finalization
Partial7 findings620ms replay12:00 PMPublish the automated report artifact or explain why the scan failed closed.
Next: Share the report with explicit limitations and review state.
Artifact: Automated Solidity report · vega-self-audit-vulnerable
- Final report is an automated static-analysis artifact; no operator review artifact is attached.
Before remediation
VegaTokenVulnerable.sol
Intentionally unsafe Solidity fixture used to demonstrate VegaSec's automated detectors.
Solidity evidence report
9 audit findings
Severity distribution
Executive summary
- 9 findings surfaced (3 critical, 2 high, 2 medium, 1 low, 1 informational).
- CRITICAL · tx.origin is used for authorization in the vulnerable self-audit fixture. — exploitability unknown.
- CRITICAL · Low-level value transfer to msg.sender occurs before effects are applied. — exploitability unknown.
- CRITICAL · selfdestruct is reachable in the vulnerable self-audit fixture. — exploitability unknown.
- Automated static analysis only. A human operator review has not been attached to this report.
- criticalAccess controlConfidence: unknownExploitability: unknownDetector: semgrep
tx.origin is used for authorization in the vulnerable self-audit fixture.
- Affected location
- VegaTokenVulnerable.sol:24
- Detector / source
- semgrep · semgrep:vegasec-tx-origin-auth
Evidence
tx.origin is used for authorization in the vulnerable self-audit fixture.
VegaTokenVulnerable.sol:24require(tx.origin == owner, "origin owner only");
Exploitability notes
Analyzer did not report a confidence level; treat as unverified until reviewed.
Remediation
Gate privileged functions behind a tested role/ownership pattern (e.g. OpenZeppelin Ownable/AccessControl). Avoid tx.origin for authorization.
Limitations
- Analyzer did not report confidence; fail closed and treat the finding as unverified.
- Static analysis did not prove exploitability; do not present this as an exploit claim.
- criticalUnchecked callConfidence: unknownExploitability: unknownDetector: semgrep
Low-level value transfer to msg.sender occurs before effects are applied.
- Affected location
- VegaTokenVulnerable.sol:39
- Detector / source
- semgrep · semgrep:vegasec-low-level-call-untrusted
Evidence
Low-level value transfer to msg.sender occurs before effects are applied.
VegaTokenVulnerable.sol:39(bool ok,) = payable(msg.sender).call{value: amount}("");Exploitability notes
Analyzer did not report a confidence level; treat as unverified until reviewed.
Remediation
Check the boolean return of low-level call/delegatecall/send and revert on failure with a descriptive reason string.
Limitations
- Analyzer did not report confidence; fail closed and treat the finding as unverified.
- Static analysis did not prove exploitability; do not present this as an exploit claim.
- criticalCentralizationConfidence: unknownExploitability: unknownDetector: semgrep
selfdestruct is reachable in the vulnerable self-audit fixture.
- Affected location
- VegaTokenVulnerable.sol:47
- Detector / source
- semgrep · semgrep:vegasec-selfdestruct
Evidence
selfdestruct is reachable in the vulnerable self-audit fixture.
VegaTokenVulnerable.sol:47selfdestruct(payable(owner));
Exploitability notes
Analyzer did not report a confidence level; treat as unverified until reviewed.
Remediation
Document the trust boundary, set up time-locked multisig ownership, and surface admin-only functions in the deployment runbook.
Limitations
- Analyzer did not report confidence; fail closed and treat the finding as unverified.
- Static analysis did not prove exploitability; do not present this as an exploit claim.
- highAccess controlConfidence: highExploitability: highDetector: slither
VegaTokenVulnerable.mintForReview uses tx.origin for authorization. A phishing contract can preserve the original owner origin while changing msg.sender.
- Affected location
- VegaTokenVulnerable.sol:24
- Detector / source
- slither · slither:tx-origin
Evidence
VegaTokenVulnerable.mintForReview uses tx.origin for authorization. A phishing contract can preserve the original owner origin while changing msg.sender.
Exploitability notes
High-confidence detection of a severe pattern; treat as exploitable until disproven by manual review.
Remediation
Gate privileged functions behind a tested role/ownership pattern (e.g. OpenZeppelin Ownable/AccessControl). Avoid tx.origin for authorization.
Limitations
- High analyzer confidence, still requires source-level review before promotion.
- Exploitability is inferred from a severe high-confidence static signal, not from a live exploit proof.
- Analyzer output did not include a source excerpt for this finding.
- highAccess controlConfidence: highExploitability: highDetector: slither
VegaTokenVulnerable.retireFixture can selfdestruct the contract behind an unsafe origin check.
- Affected location
- VegaTokenVulnerable.sol:47
- Detector / source
- slither · slither:suicidal
Evidence
VegaTokenVulnerable.retireFixture can selfdestruct the contract behind an unsafe origin check.
Exploitability notes
High-confidence detection of a severe pattern; treat as exploitable until disproven by manual review.
Remediation
Gate privileged functions behind a tested role/ownership pattern (e.g. OpenZeppelin Ownable/AccessControl). Avoid tx.origin for authorization.
Limitations
- High analyzer confidence, still requires source-level review before promotion.
- Exploitability is inferred from a severe high-confidence static signal, not from a live exploit proof.
- Analyzer output did not include a source excerpt for this finding.
- mediumTimestamp dependenceConfidence: unknownExploitability: unknownDetector: semgrep
block.timestamp influences reviewer selection and should not be treated as randomness.
- Affected location
- VegaTokenVulnerable.sol:30
- Detector / source
- semgrep · semgrep:vegasec-block-timestamp-rng
Evidence
block.timestamp influences reviewer selection and should not be treated as randomness.
VegaTokenVulnerable.sol:30picked = reviewers[block.timestamp % reviewers.length];
Exploitability notes
Analyzer did not report a confidence level; treat as unverified until reviewed.
Remediation
Treat block.timestamp as a coarse value with miner influence; prefer block-number windows for short-term invariants and add tolerance bands.
Limitations
- Analyzer did not report confidence; fail closed and treat the finding as unverified.
- Static analysis did not prove exploitability; do not present this as an exploit claim.
- mediumOracle manipulationConfidence: mediumExploitability: mediumDetector: slither
VegaTokenVulnerable.unsafeReviewerLottery derives selection from block.timestamp, which is not safe randomness.
- Affected location
- VegaTokenVulnerable.sol:30
- Detector / source
- slither · slither:weak-prng
Evidence
VegaTokenVulnerable.unsafeReviewerLottery derives selection from block.timestamp, which is not safe randomness.
Exploitability notes
Medium-confidence detection; manual review required before relying on the finding either way.
Remediation
Use multi-source price feeds (e.g. Chainlink + TWAPs) and validate freshness/deviation before consuming oracle data on-chain.
Limitations
- Medium analyzer confidence; manual review should confirm the code path and preconditions.
- Exploitability depends on deployment context, permissions, balances, and reachable preconditions.
- Analyzer output did not include a source excerpt for this finding.
- lowCentralizationConfidence: unknownExploitability: unknownDetector: semgrep
Hardcoded reviewer address creates centralization and rotation risk in this fixture.
- Affected location
- VegaTokenVulnerable.sol:12
- Detector / source
- semgrep · semgrep:vegasec-hardcoded-address
Evidence
Hardcoded reviewer address creates centralization and rotation risk in this fixture.
VegaTokenVulnerable.sol:12address public reviewer = 0x1111111111111111111111111111111111111111;
Exploitability notes
Analyzer did not report a confidence level; treat as unverified until reviewed.
Remediation
Document the trust boundary, set up time-locked multisig ownership, and surface admin-only functions in the deployment runbook.
Limitations
- Analyzer did not report confidence; fail closed and treat the finding as unverified.
- Static analysis did not prove exploitability; do not present this as an exploit claim.
- informationalUnchecked callConfidence: highExploitability: lowDetector: slither
VegaTokenVulnerable.withdrawReviewCredit uses a low-level call to msg.sender.
- Affected location
- VegaTokenVulnerable.sol:39
- Detector / source
- slither · slither:low-level-calls
Evidence
VegaTokenVulnerable.withdrawReviewCredit uses a low-level call to msg.sender.
Exploitability notes
Informational signal; not directly exploitable without additional context.
Remediation
Check the boolean return of low-level call/delegatecall/send and revert on failure with a descriptive reason string.
Limitations
- High analyzer confidence, still requires source-level review before promotion.
- Direct exploitability is not established; keep the signal as a remediation/checklist item.
- Analyzer output did not include a source excerpt for this finding.
Limitations
- VegaSec runs static analysis only. Findings can include false positives, miss patterns the configured detectors do not cover, and never replace manual auditor judgement.
- Scan ran slither and semgrep against a single sandboxed copy of the source. Multi-file dependency analysis beyond what slither resolves automatically is out of scope.
- This report is not a certification, audit attestation, or financial advice.
Audit pipeline
Audit cockpit
Honest stage-by-stage view of what VegaSec ran against this contract. Automated stages do not replace a human operator review.
Audit intake
Passed320ms replay12:00 PMNormalize the submitted contract target and confirm it can enter the Solidity audit lane.
Next: Acquire verified source or scan the pasted Solidity source.
Source acquisition
Passed1.4s replay12:00 PMResolve pasted source or verified explorer source without treating malformed input as demo data.
Next: Validate the analyzer toolchain against the acquired source.
Toolchain validation
Passed2.3s replay12:00 PMConfirm the configured static analyzers can run and produce parseable output.
Next: Run static analysis and capture raw detector evidence.
Static analysis
Passed9 findings8.8s replay12:00 PMRun static analyzers against the sandboxed source and collect raw detector evidence.
Next: Normalize detector output into one deduped finding set.
Finding normalization
Passed9 findings1.1s replay12:00 PMDedupe detectors, classify vulnerability classes and compute severity-weighted risk.
Next: Review exploitability conservatively against confidence and limitations.
Exploitability review
Partial9 findings1.9s replay12:00 PMFrame automated findings with conservative exploitability and limitation notes.
Next: Draft remediation notes from the normalized evidence.
- Automated exploitability review is conservative and does not replace a manual exploitability assessment.
Remediation draft
Partial9 findings1.5s replay12:00 PMPrepare remediation-oriented evidence for the shareable report artifact.
Next: Attach an operator review artifact before claiming human review.
- Remediation notes are generated from detector evidence and require project-specific engineering review.
Operator review
Blocked0ms replay12:00 PMRecord whether a human operator artifact exists before buyer escalation.
Next: Attach a real operator review artifact before claiming human review.
- No operator review artifact is attached to this automated scan.
- Human operator review has not been attached to this automated scan yet.
Finalization
Partial9 findings620ms replay12:00 PMPublish the automated report artifact or explain why the scan failed closed.
Next: Share the report with explicit limitations and review state.
Artifact: Automated Solidity report · vega-self-audit-vulnerable
- Final report is an automated static-analysis artifact; no operator review artifact is attached.
Source (2036 chars)
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.20;
/// @title VegaTokenVulnerable
/// @notice Fictional internal VegaSec self-audit fixture only. Not deployed, not sold, no financial promise.
/// @dev This intentionally unsafe contract exists so VegaSec can prove vulnerable-vs-fixed audit deltas.
contract VegaTokenVulnerable {
string public constant FIXTURE_SCOPE = "VegaSec fictional internal self-audit fixture";
mapping(address => uint256) public balances;
address public owner;
address public reviewer = 0x1111111111111111111111111111111111111111;
uint256 public reviewRound;
constructor() payable {
owner = msg.sender;
balances[msg.sender] = 1_000_000;
}
receive() external payable {}
function mintForReview(address account, uint256 amount) external {
// Intentional issue: tx.origin authorization can be phished through another contract.
require(tx.origin == owner, "origin owner only");
balances[account] += amount;
}
function unsafeReviewerLottery(address[] calldata reviewers) external returns (address picked) {
require(reviewers.length > 0, "reviewers required");
// Intentional issue: block.timestamp is miner/validator-influenced and unsafe as randomness.
picked = reviewers[block.timestamp % reviewers.length];
reviewer = picked;
reviewRound += 1;
}
function withdrawReviewCredit(uint256 amount) external {
require(balances[msg.sender] >= amount, "insufficient credits");
// Intentional issue: external low-level call before effects enables reentrancy-style drains.
(bool ok,) = payable(msg.sender).call{value: amount}("");
require(ok, "transfer failed");
balances[msg.sender] -= amount;
}
function retireFixture() external {
// Intentional issue: tx.origin gate plus selfdestruct is unsafe and should never ship.
require(tx.origin == owner, "origin owner only");
selfdestruct(payable(owner));
}
}
After remediation
VegaTokenFixed.sol
Remediated counterpart of the vulnerable fixture, showing what the static-analysis report looks like once the obvious patterns are addressed.
Solidity evidence report
0 audit findings
Executive summary
- No detector raised a finding against the submitted source. This is not a guarantee of safety; manual review remains required.
- Automated static analysis only. A human operator review has not been attached to this report.
Limitations
- VegaSec runs static analysis only. Findings can include false positives, miss patterns the configured detectors do not cover, and never replace manual auditor judgement.
- Scan ran slither and semgrep against a single sandboxed copy of the source. Multi-file dependency analysis beyond what slither resolves automatically is out of scope.
- This report is not a certification, audit attestation, or financial advice.
Audit pipeline
Audit cockpit
Honest stage-by-stage view of what VegaSec ran against this contract. Automated stages do not replace a human operator review.
Audit intake
Passed320ms replay12:00 PMNormalize the submitted contract target and confirm it can enter the Solidity audit lane.
Next: Acquire verified source or scan the pasted Solidity source.
Source acquisition
Passed1.4s replay12:00 PMResolve pasted source or verified explorer source without treating malformed input as demo data.
Next: Validate the analyzer toolchain against the acquired source.
Toolchain validation
Passed2.3s replay12:00 PMConfirm the configured static analyzers can run and produce parseable output.
Next: Run static analysis and capture raw detector evidence.
Static analysis
Passed0 findings8.8s replay12:00 PMRun static analyzers against the sandboxed source and collect raw detector evidence.
Next: Normalize detector output into one deduped finding set.
Finding normalization
Passed0 findings1.1s replay12:00 PMDedupe detectors, classify vulnerability classes and compute severity-weighted risk.
Next: Review exploitability conservatively against confidence and limitations.
Exploitability review
Partial0 findings1.9s replay12:00 PMFrame automated findings with conservative exploitability and limitation notes.
Next: Draft remediation notes from the normalized evidence.
- Automated exploitability review is conservative and does not replace a manual exploitability assessment.
Remediation draft
Partial0 findings1.5s replay12:00 PMPrepare remediation-oriented evidence for the shareable report artifact.
Next: Attach an operator review artifact before claiming human review.
- Remediation notes are generated from detector evidence and require project-specific engineering review.
Operator review
Blocked0ms replay12:00 PMRecord whether a human operator artifact exists before buyer escalation.
Next: Attach a real operator review artifact before claiming human review.
- No operator review artifact is attached to this automated scan.
- Human operator review has not been attached to this automated scan yet.
Finalization
Partial0 findings620ms replay12:00 PMPublish the automated report artifact or explain why the scan failed closed.
Next: Share the report with explicit limitations and review state.
Artifact: Automated Solidity report · vega-self-audit-fixed
- Final report is an automated static-analysis artifact; no operator review artifact is attached.
Source (2125 chars)
// SPDX-License-Identifier: MIT
pragma solidity ^0.8.20;
/// @title VegaTokenFixed
/// @notice Fictional internal VegaSec self-audit fixture only. Not deployed, not sold, no financial promise.
/// @dev Shows remediation evidence for the paired vulnerable fixture.
contract VegaTokenFixed {
string public constant FIXTURE_SCOPE = "VegaSec fictional internal self-audit fixture";
mapping(address => uint256) public balances;
address public owner;
bool private locked;
event ReviewCreditsMinted(address indexed account, uint256 amount);
event ReviewCreditWithdrawn(address indexed account, uint256 amount);
modifier onlyOwner() {
require(msg.sender == owner, "owner only");
_;
}
modifier nonReentrant() {
require(!locked, "reentrant call");
locked = true;
_;
locked = false;
}
constructor() payable {
owner = msg.sender;
balances[msg.sender] = 1_000_000;
}
receive() external payable {}
function mintForReview(address account, uint256 amount) external onlyOwner {
require(account != address(0), "account required");
// Remediation: use msg.sender with explicit owner control instead of origin-based authorization.
balances[account] += amount;
emit ReviewCreditsMinted(account, amount);
}
function selectReviewer(address[] calldata reviewers, uint256 index) external onlyOwner returns (address picked) {
require(reviewers.length > 0, "reviewers required");
require(index < reviewers.length, "index out of range");
// Remediation: deterministic operator-selected review routing; no timestamp-derived randomness.
picked = reviewers[index];
}
function withdrawReviewCredit(uint256 amount) external nonReentrant {
require(balances[msg.sender] >= amount, "insufficient credits");
// Remediation: checks-effects-interactions before a bounded native transfer.
balances[msg.sender] -= amount;
payable(msg.sender).transfer(amount);
emit ReviewCreditWithdrawn(msg.sender, amount);
}
}
What this reference is, and is not
- This is a public reference artifact, not a certification or audit attestation.
- The contracts on this page are fictional VegaSec internal fixtures, not products and not investments.
- VegaSec runs static analysis only. Real audits also need human review.
- No real brand, project or asset is implied by the fixtures or by this report surface.