← Back to minia2a

๐Ÿ›ก๏ธ Instant Smart Contract Audit

Get your smart contract checked before you deploy โ€” in minutes, not weeks. No $5k invoices, no audit-firm waitlists. Pay per audit with USDC on Base.

๐Ÿ’ฐ Audits start at just $2 โ€” your first one is free per signed wallet โ€” run a static pre-check for the price of a coffee, then upgrade to the $20 AI deep audit if you want full business-logic coverage. No $5k invoices, no waitlists. The free first audit draws on a shared pool of 20 audits per day across all callers: while it has room your first call returns results with no payment, and once the day's pool is spent every wallet gets a 402 saying the cap was reached. Available, not guaranteed.
๐Ÿงฉ The pre-deploy bundle: $2 static + $20 AI deep = $22. Run the $2 scan to catch the classic exploit classes, then the $20 deep audit for business-logic and economic-model coverage. Two endpoints, one complete first-pass audit before you ship.
๐Ÿ›ก๏ธ Verified & live โ€” real USDC settlement on Base. Both tiers are pay-per-call endpoints that settle real USDC on-chain (first audit free per signed wallet โ€” capped at a shared 20/day platform-wide, so available, not guaranteed; no registration, no off-chain credit ledger): /x402/smart-contract-audit ($2) and /x402/ai-audit ($20) return HTTP 402, and every payment lands as a verifiable Base transaction.

Audit options

ServicePriceCoversTime
Static pre-check
x402/smart-contract-audit
$2Reentrancy ยท access control ยท integer overflow ยท unvalidated calls< 30s
AI deep audit
x402/ai-audit
$20Business-logic & economic-model analysis โ€” what static scanners miss ยท Solidity / Rust / Move~2 min
Full protocol report
PoC-verified
$200โ€“$1,000Complete report per module โ€” attack paths, code evidence, fixes, with reproducible forge PoC for verified findingsby arrangement

What you get

How it works

  1. Submit your contract source to the service (source, code, or base64 via source_b64)
  2. Pay with USDC (x402 micropayment โ€” the gateway gives you a 402 challenge, you send payment, get the result)
  3. Receive a severity-ranked findings report in minutes
๐Ÿ”ง SDK note: the @x402 SDK caps automatic payments at $1 by default. For the $2 and $20 audits, set spendControls: false (or raise maxAmountPerPayment) in your client.
Audit your contract โ†’
or call x402/ai-audit for the deep review
๐Ÿ“ฌ Questions about your contract? Email [email protected].

FAQ

How much does a smart contract audit cost?

Formal audits run $5,000โ€“$50,000 and take weeks. minia2a's static pre-check is $2 and the AI deep audit is $20 โ€” results in minutes. It's a fast pre-launch check, not a substitute for a professional audit on high-value contracts.

What does the static audit check?

Four classic exploit classes: reentrancy (including checks-effects-interactions violations), access-control gaps, integer overflow, and unvalidated external calls.

What does the AI audit find that static can't?

Business-logic and economic-model vulnerabilities โ€” incentives, accounting flows, governance edge cases that pattern scanners miss. It's sampled 3ร— for stability and reports the highest severity honestly.

Is it a substitute for a formal audit?

No. It's a fast, honest pre-launch check to catch critical issues before deployment. High-value contracts should still get a professional audit โ€” but catching a reentrancy bug before you deploy is worth $2.

Which chains?

The AI audit supports Solidity (EVM/Base/Arbitrum/etc.), Rust (Solana/Anchor), and Move (Sui/Aptos). Payment settles on Base.

Why minia2a for audits

minia2a is a permissionless x402 micropayment marketplace โ€” pay per API call with USDC on Base, no subscription, no KYC, no $5k invoices. The audit vertical is our deepest capability: deterministic static analysis plus AI deep review, severity-ranked findings, and every payment settled as a verifiable on-chain transaction. 5% platform fee โ€” 0% through 2026.

Most trust signals in agent payments are post-payment: a seller earns a reputation score only after settlements have already happened. minia2a inverts that. Our audit vertical verifies a contract, a token, or an endpoint's payment logic before you spend USDC โ€” pre-payment verification, not post-payment scoring. When you're deciding whether to pay an unknown endpoint, a backward-looking score arrives too late; a pre-payment check is the decision itself.

What it actually finds — 9 worked examples

Each page shows the vulnerable contract, the finding the audit returned, and the fix. Read one before you decide whether the scan is worth $2.

Case studies & audit reports — 12 real audits

Real audits of live protocols, anonymized under responsible disclosure. Each post shows the vulnerabilities our AI found and how it proves them.

Auditing the other side — verify before you pay

This page audits your contract. But before you pay any x402 endpoint, verify it is real: the $5 Payment-Integration Trust Check (x402/payment-audit) submits any x402 endpoint and checks whether it resists forged payments, replay, and honeypot payTo — returns SAFE, RISK, or NOT_X402. Read the methodology →