Last updated a week ago
Late discovery of vulnerabilities in Aiken code causes costly delays and increases the risk of exploits. There is no accessible, Cardano-specific tool to surface issues early in the developer workflow
An early vulnerability detection system for Aiken smart contracts powered by AI. Combining rule-based heuristic and a fine-tuned LLM model trained with TxPipe's audit knowledge base and experience.
This is the total amount allocated to by TxPipe - Early Aiken vulnerability detection using AI.
1/4
Architecture Design and Project Scaffold
Cost: $ADA 28,800
Delivery: Month 1 - Dec 2025
2/4
Heuristics Engine Development
Cost: $ADA 26,400
Delivery: Month 2 - Jan 2026
3/4
LLM Fine-tuning
Cost: $ADA 26,400
Delivery: Month 3 - Feb 2026
4/4
Final Report
Cost: $ADA 14,400
Delivery: Month 4 - Mar 2026
NB: Monthly reporting was deprecated from January 2024 and replaced fully by the Milestones Program framework. Learn more here
Please provide your proposal title
by TxPipe - Early Aiken vulnerability detection using AI
Enter the amount of funding you are requesting in ADA
96000
Please specify how many months you expect your project to last
7
Please indicate if your proposal has been auto-translated
No
Original Language
en
What is the problem you want to solve?
Late discovery of vulnerabilities in Aiken code causes costly delays and increases the risk of exploits. There is no accessible, Cardano-specific tool to surface issues early in the developer workflow
Supporting links
Does your project have any dependencies on other organizations, technical or otherwise?
No
Describe any dependencies or write 'No dependencies'
no dependencies
Will your project's outputs be fully open source?
Yes
License and Additional Information
Apache 2.0
Please choose the most relevant theme and tag related to the outcomes of your proposal
Developer Tools
Mention your open source license and describe your open source license rationale.
Apache 2.0 was chosen because it is a permissive and business-friendly license, widely adopted across the open-source ecosystem, and it provides legal clarity with explicit patent protection for contributors and users.
How do you make sure your source code is accessible to the public from project start, and people are informed?
The repository will be public from day one, with all development activity shared transparently. Updates will be announced through public channels, and a dedicated Discord channel will allow direct community interaction.
How will you provide high quality documentation?
A comprehensive public documentation site will be maintained, including user guides, developer references, and contribution guidelines, following the same high standards established in TxPipe’s previous open-source projects.
Please describe your proposed solution and how it addresses the problem
Security remains one of the most critical challenges for Cardano dApp developers, particularly in the early stages of protocol design. Vulnerabilities caught late in the development cycle lead to costly delays, reduced trust, and potential on-chain exploits.
At the same, the Cardano community has been gathered knowledge of best-practices and known footguns which is very useful for building Cardano smart contracts. This knowledge base should be used as early as possible in the development process to reduce costs and improve security.
This project addresses that gap by giving developers an accessible, audit-informed analysis tool that identifies risks early—combining deterministic heuristics with AI models trained on real audit data. By making high-quality security feedback available directly in local development workflows, it helps strengthen the overall security posture of the Cardano ecosystem while lowering the barrier to building robust, mainnet-ready protocols.
TxPipe is particularly well positioned to develop such a tool, drawing on extensive experience in auditing methodologies, vulnerability pattern recognition, and structured reporting formats. Having conducted more than 25 audits for top-tier Cardano projects, the team has deep insight into common pitfalls and best practices in smart contract security. Data which will be used both for definition of heuristics and training of the AI models.
The tool is NOT intended to replace formal third-party audits, but rather to improve the development workflow by enabling earlier detection and remediation of issues before formal review.
A comprehensive solution for this problem requires an approach that combines different analysis strategies. We envision a final solution that incorporates the following features:
Please define the positive impact your project will have on the wider Cardano community
What is your capability to deliver your project with high levels of trust and accountability? How do you intend to validate if your approach is feasible?
TxPipe is an active member of the Cardano ecosystem
TxPipe has been developing open-source tools for the Cardano ecosystem for over 2 years and we're not going anywhere. Evidence of our commitment can be found by evaluating the continuous activity of our public code repositories.
Experience developing in the Cardano ecosystem
TxPipe has helped developed several dApps for the Cardano ecosystem. This experience allows us to evaluate the feasibility of the project and its potential benefit from a developer's perspective.
Successful Catalyst proposals
We have successfully completed several Catalyst proposals. This may serve as evidence that our team has the required capabilities to fulfill these type of projects.
Development process will be public and open-source
Both the output and the development process will be public and open-source. This approach provides an easy way for the Catalyst team and the Cardano community to evaluate the progress at each step of the process.
Milestone Title
Project Scaffold and Architecture
Milestone Outputs
Acceptance Criteria
Evidence of Completion
Delivery Month
1
Cost
28800
Progress
10 %
Milestone Title
Heuristics Engine Development
Milestone Outputs
Acceptance Criteria
Evidence of Completion
Delivery Month
3
Cost
26600
Progress
50 %
Milestone Title
LLM Fine-tuning
Milestone Outputs
Acceptance Criteria
Evidence of Completion
Delivery Month
6
Cost
26200
Progress
90 %
Milestone Title
Final Report
Milestone Outputs
Acceptance Criteria
Evidence of Completion
Delivery Month
7
Cost
14400
Progress
100 %
Please provide a cost breakdown of the proposed work and resources
Total Request: ₳96,000 (0.6 ADA/USD)
How does the cost of the project represent value for the Cardano ecosystem?
The bulk of the budget falls under the software development category. TxPipe has extensive experience in the field, allowing it to provide good value for money. The hourly rates are defined using fair market prices. The estimation for the level of effort takes into account all of the optimizations that our team is capable of providing after years of experience developing software solutions in the Cardano ecosystem.
Terms and Conditions:
Yes