Radar: Static Analyzers for Rust Smart Contracts | Tomer Bar - AuditWare
Ethereum Denver·Mon, Mar 9, 2026, 12:00 AM
Tomer talks: - Building static analyzers for scale and practical engineering challenges - Building a pythonic DSL over the AST structure, for readable template-based heuristic contributions - How radar's design was built to fit LLM-based mass vulnerability detections across multiple codebases
Transcript
Hello Denver. Uh my name is Tommer. I'm going to talk about static analysis in the era of AI agents. So this is me. I'm CTO at Auditor.
So we're an auditing firm. uh been a security engineer for the past decade or so uh like doing open source work uh auditing smart contracts. Yeah. So uh we do a couple of uh interesting stuff in auditware. Um part of those is our open source suite.
So as you can see on the screen we got a bunch of cool stuff going on. We got the W3S which is a web 3 operational security standard. Uh we got radar that does static analysis for smart contracts, Rust, solidity. We got um multisig monitor that does uh safe wallet multisig uh analysis monitoring subspicious uh transactions and all that. Uh so as I've said we've doing uh we've been doing audits for quite a while now and we also have sentry which is our platform for the more larger uh projects and protocols to protect them continuously after they on board and on sentry we also utilize our open source work uh as APIs to basically get the full suite going.
Okay, so I'm here today to talk to you about specifically Radar from the open source tooling that we just discussed about and I like to start with demos. I know it's like a bit unconventional. Uh this is radar from the normal uh user perspective uh aspect at least. So it is a CLI tool uh you can run it uh from wherever. Um you just run it across like any smart contract you want.
It does like extraction of a supports rust, solidity and a bunch of frameworks. And it has a cool template uh based design uh that's fits perfectly to uh how AI is used to lock down security research uh perspectives uh in our age. So you got this on the screen like Python logic that's locking down the security researchers perspective and you can run it and reuse it. So we're going to talk about that. Okay.
So uh yeah. So who uses uh security tooling uh specifically static analysis where AI basically is doing everything today. It's like 2026. Uh so we know that everyone can just like run a cloud or copilot security review style uh uh audit which is very concerning especially from a security perspective and we have like I don't know if you like to listen to stock overflow because I'm not sure anyone uses stack overflow anymore um but if you look to statistic it's like constantly an uptrend of uh developers using AI without like fully blind let's say to generate tests uh generate uh security test all of that. So uh if a developer especially smart contracts ones used to know exactly what's going on in their code and spend and write every line it's no longer the case.
Um yeah and specifically more concerning is the fact that also security firms. So you already did like your own vibe auditing as a protocol developer then you go to hire a security professional and you don't know if that professional too is using AI to perform the audits. So that's just like the market uh uh status right now. There's a lot of stuff to battle it. Um specifically about radar first like the value propos proposition especially uh because static analysis is sort of underpowered against the AI based uh checks uh is basically we say this instead of using AI to do code audits or code checks or whatever you call it find bugs in my contract uh we say there's another step in the middle using radar is that you tell the AI to run radar templates And then you get sort of like a deterministic result that you can reuse, share with other security researchers.
And the point here is that you don't lose value and you don't lose more tokens practically because if we are talking about running onchain which we'll talk about it what Ryder is designed to uh then we're talking about like constantly reuse of uh the same queries unefficiently and people don't have that funds to spend on tokens as much. Uh so what we do is when we save it like as a temp python template and we let it uh like on a small scale VPS to run using radar we can get a lot more value and checks in the same amount of funds basically. Um so how are we doing this? Let me jump over here. Um we've had a lot of design considerations and debates internally about what exactly is it for because a normal static analysis if we take like a slider or not even web 3 but static analysis tooling in general it's meant to be used like by a developer auditor across one codebase and that's it take the results and go.
Uh we're not in that approach. We built this entire thing to not be first like as a convenient thing for end user but first be convenient for apps that want to integrate this as a continuousing monitoring scanning service. Uh same goes for like app developers and like for security hunters that looks wants to look at the same vulnerability across a large amount of contracts. So this is the entire idea and design behind radar. uh we found it to be especially uh starting to get like uh worth the uh the complexity of it when you have like more than 200 contracts you want to scan at uh the same period of time.
So that's where like it gets exponentially just like quicker and more efficient. We chose a template based approach uh inspired on nuclei. So if there's like web two uh in the crowd web two professionals then everyone knows this. It's like the best applicative uh scanner open source project there is in my opinion and it has like a huge success by the fact that it created easy templates to be reused. So instead of writing the entire program the developers do the core logic and then the researchers don't have to be necessarily uh aware of the how the engine runs just like the template language.
So that is what we wanted to achieve with a small caveat because uh it gets pretty crazy. Uh what Nuclei did is they had a YAML uh uh language which is very simple. It's not like a programming uh language and researchers got crazy with it because as time grew uh they tried to do like inner for loops nested for loops it just got crazy and this is like not a readable template in any way. So uh we chose Python instead and that is also like a debate because uh I know that uh a lot of folks would have rather seeing Rust as the language because that's like how it goes right now and I personally love Rust. Uh we found that specifically for AI generated templates AI does better uh just generating Python for example.
Uh you can give it like uh uh what is the best language to use for to build this project? it will say wow definitely rust because ABC and then you say okay implement it and it starts off Python so there's been research on that very interesting uh also it's like readable to humans because I love rust again not readable uh which brings us to what exactly how are we performing the static analysis um well okay from the picture then reject is not really relevant uh just like for obvious reasons uh the main uh debate it was between LLVM IR uh two as so if you're not familiar uh breaking down a means just like taking down a contract and tokenizing into a tree it looks like a JSON structure and then it's very easy to understand the code rather than reax or so on llvm also uh is queryable in a similar manner uh just felt again not in the readable manner more as and we will only be successful in this project if researchers would have fun writing templates. Uh so that's like a point on the EST and to do that uh from RAS based contracts which is the origin of radar was like a RAS base uh uh static analysis tool uh is we just like used Rust C native uh library to generate a or to compile Rust and just did like a small trick to wrap it around to be importable like as a Python model. So that's like uh that opened up to immediately to be able to run like native rust and core rust stylus rust a lot of static analysis out the box all plugged into the same engine. Recently also we added solidity to it.
So that's very cool. Yeah. And this is like a template. So we seen the the nuclear template before. It's not that uh different.
The template itself is YAML and then you have this uh rule in the middle. Uh the rule just says uh iterate we like get the for you. We inject it into this tiny rule here. We iterate the nodes for you. A simple for loop uh accept try conditions and you just whatever you want to do to uh define or like basically to describe your uh bug pattern, you just Python it.
And this works amazing with AI. On top of that, uh we added like a utility functions. So as even uh if it sounds like simple just like rules against an AD, it's still very complex and not necessarily um mapped to how our human brains work. So we created a full full list for every time we wanted to write our own detection for bugs. we found uh we thought okay it will be cool if given an AD node we can find all its parent etc etc uh and basically it creates sort of like a mini language that you can just chain call to find stuff in as quickly again good for humans good for AI and uh there's the uh security concern aspect because uh basically you're running GitHub templates that run Python rule on your device or like on Docker, but it's still on your device.
Uh, so what we did is we like uh stripped out anything that we we managed to come up with that's dangerous about Python because all we do is just like iterate a and don't do network calls, no like subprocess be open and we did like a tiny white list then before we execute the Python itself, we do this check that no one is doing anything uh suspicious again with parsing but that's different as but you get the point. Um so yeah that's like mostly the the logic behind what we did. So if we take it back to like what how we imagine you working with it and like how we managing uh you utilizing radar for your purposes. So uh you could be like a security auditor or just anyone interested in doing like any sort of mass vulnerability detection across many contracts out there. So we don't take care of the contract retrieval part yet, but you can be creative with that.
What we say is like that. Uh let's say you're a security researcher and you find like a bug or you're doing like your audits and you do it like whatever. Uh at some point you find uh a certain detection that you say okay this happened here. This is very complex. I can't like write like a simple rule for it.
Uh but I know for sure other contracts are going to fall for that specific pattern. Uh so what you're going to do is you're going to have AI and of course with human in the loop generate a radar template that define exactly what you want to say. But the cool part here is that you define it once, you test it once, you share it with your peers, you review it and that's it. It's not like a uh sometimes true, sometimes not. It's like scientific deterministic result.
It's not like a cloud code security review. Every time we'll give you a different answer. You can't trust it. This is something you generate with yourself using AI end up with a tiny tiny Python script that AI is optimized to work against and you can just spray it uh practically. So uh scraping your targets again that's also a very common thing uh especially uh in the web two world and the nuclear example from before.
Then we had like react to shell uh two months back. So like 3 hours after react to shell dropped, there was a newly signed template by a security researcher. The community reviewed it. Uh and people who wanted to see if they're vulnerable, Caesar, CTO's could run it. H and they can run it sort of safely because there was not much code to to see okay is this tiny script doing something bad and trying to like uh exploit the fact that I'm vulnerable and I am in a rush and introduce malware.
So for example like to uh extend on that like on the react to shell example we've seen a lot of Python scripts that like equivalent to what I'm talking here um that says quick protect yourself check if you're vulnerable. What in fact it did was uh try to get like API keys from developers not reading the code and running Python in a rush with two stars. Uh this is why we're trying to ecosystem that whole manner. So going back to my original point is we want the same thing to happen for web 3 and when there's like a new bug pattern coming out we want researchers to do this uh similar contribution. So we will be able to secure contracts at a scale rather is like already uh like ready for that.
The only thing we need is more contributors and more templates. We are like in around uh 30 right now. We aim for like the thousands. Uh and yeah, so for like uh personal uh researcher incentives alone, you don't have to share these templates. You're free to spin up your own VPS, run raider on it.
It's like one command and you can just run your own templates and only contribute the one that you want and that's the the whole process. So you can report it, get your bounty at scale, not like one project at a time. uh when you're done and when like the pattern is exhausted and like no longer relevant then we'd love your contribution. Uh yeah so that's like the cycle that we want [snorts] to achieve with radar. Uh yeah so that's basically it.
So again my name is Tommer. Uh I'm from audit. My team is right here. We'd love to talk to you down stage. If anyone has any questions uh free to uh speak up or talk later.
That's it. Thank you so much, guys.
Automatic transcript — names and jargon may be misspelled.