mozg.betaSign in

explore / Security / mozg

Smart Contract Auditor

Answer like a security auditor reviewing EVM smart contracts: the concrete vulnerability patterns (reentrancy, oracle manipulation, access control, signature replay, rounding and the rest), how each is exploited in practice with real incident mechanics, how to detect it in code, and the specific fix — with tool commands and checklist items, not general advice.

43 notes · updated 2026-08-04 · trained 96%

since last sitting: +3 newly passed · −1 lost — this brain is learning

Ask it things like

answers 27/28 on its latest exam
Why is using tx.origin for authentication always a finding?Access Control & Authorization
What makes an initializer unprotected in an upgradeable contract, and how is it exploited?Access Control & Authorization
Why does handling token decimals() incorrectly break cross-token vaults?Arithmetic & Rounding
Where does integer division rounding actually lose money — give me the precise mechanic and a real example?Arithmetic & Rounding
How do fee-on-transfer tokens break deposit() accounting?Arithmetic & Rounding
What checks does a safe Chainlink price feed need before I use it for liquidations or critical logic?Oracle Manipulation & MEV
Should my liquidation or collateral pricing logic use DEX spot price (e.g., Uniswap V2 reserves)?Oracle Manipulation & MEV
What should I check in the proxy admin and upgrade flow itself?Proxy & Upgradeability

Paid brain

$49.00once · keeps working as the author updates it

Buying unlocks the notes for your agents and for you. Paid from your balance; 95% goes to the author. A brain can be copied once it is readable, so there are no refunds after the first read — decide from the exam questions and preview below. How paying works.

Sign in to buy

What it can answer

28 checks
96%
Oracle Manipulation & MEV5 / 5
Token Integration Hazards5 / 5
Access Control & Authorization4 / 4
Arithmetic & Rounding4 / 4
Reentrancy Detection & Mechanics4 / 5
Signature & Replay Attacks3 / 3
Proxy & Upgradeability2 / 2
exam badge — share this score →

What is inside

Note titles, so you can judge before you buy. The contents unlock on purchase.

  • I see withdraw() calling token.transfer() to the caller — is it reentrant? · Reentrancy Detection & Mechanics
  • The concrete reentrancy audit checklist — what do I look for in code? · Reentrancy Detection & Mechanics
  • Where does integer division rounding actually lose money — the precise mechanic? · Arithmetic and rounding
  • Which common 'findings' are actually false positives I shouldn't report? · Audit workflow and tooling
  • What separates a $5k audit report from a $50k one? · Audit workflow and tooling
  • How do I write a finding that a client will actually fix? · Audit workflow and tooling
  • How should I read an unfamiliar codebase in the first hours of an audit? · Audit workflow and tooling
  • When should I use echidna or mythril instead of slither/foundry? · Audit workflow and tooling

Licence

Closed

Readable through MCP only. No export, no copying.