AI Daml Auditor Workoshop

,

Good day, everyone! I’d like to invite you to an online workshop we’re hosting on September 29 at 14:00 UTC, as part of HackCanton Season 3.

We’ll show how Hacken’s AI Auditor works on a real Daml contract, walk through the findings, and discuss what to check when reviewing applications on Canton.

If you’re curious to see the tool in action and discuss the findings with the speakers, you’re welcome to join.

Register here: Daml Smart Contract Audit: Live AI Security Analysis · Luma

1 Like

What did the AI Auditor find in the Daml smart contract? 4 takeaways for builders from yesterday’s session with :backhand_index_pointing_down:

• Łukasz Wolski, Technical Lead, Hacken: “Canton removes reentrancy, gas, and delegatecall. The risk moves to different places: authority, validation, visibility, and state. None of these things produces a compiler error.”

• Kornel Światłowski, Smart Contract Auditor, Hacken: “When you put a house as collateral, the cash is supposed to be released only after both sides sign the contract. In this case, one person signed the contract, and the same person signed it again. The owner of the house cannot accept or decline the offer. The loan is created without his or her acceptance.”

• Ales, CPO, NODERS Team: “In lending, the counterparty is exactly who has a motivation to close a loan early. Who gets to declare a write-off is a business decision, not something any party to the contract should be able to trigger. How should teams think about insider risk from their own counterparties?”

• Farrukh Odinaev, Solutions Engineer, Hacken: “In our tests, when we tried to reduce false positives, we found an inverse correlation with the findings reported. The more you want to lower false positives, the fewer findings you get. You make your net too narrow, and it stops catching all important bugs.”

Watch Hacken’s Daml AI Auditor in action, followed by the findings review: https://www.youtube.com/watch?v=MJgHhGLmUdQ