Ultrafuzz is an agentic orchestrator for smart contract fuzzing and threat hunting
This tool initializes a protocol repository with editable prompts and topology, runs specialized agents, collects generated fuzz tests and findings, and serves a local dashboard plus final report for review.
Security note
We strongly recommend running Ultrafuzz only on ephemeral, isolated virtual machines that can be safely discarded after use. Agents run in an unrestricted, skip-permissions workflow, which means they may unintentionally install or access dangerous tooling or sensitive credentials. Prompts, model choices, and target behavior can influence the actions agents take on the host and may result in unintended or destructive consequences. Do not run Ultrafuzz on a developer workstation, persistent environment, or any machine containing valuable data or credentials. Ultrafuzz is still under active development and has not necessarily undergone a complete security audit. Its implementation may contain unknown or undiscovered vulnerabilities.
Review the checked-in
.ultrafuzz/prompts/before launching a campaign. See Security for the full posture.
Tell your agent:
Run Ultrafuzz on my project and monitor it from start to finish.
If any node fails, for example, due to cyber refusals, resume from where it left off.
Use the same authentication method we're using, and the best model at its highest reasoning effort,
high concurrency limits, and the default audit profile.
If you need to install any dependencies, ask for my approval first.
- Start Here
- Specification
- Tutorials
- How-To Guides
- Reference
- Prompt Catalog
- Explanation
- CLI
- Config
- Eval Suites
- EVMBench integration
- Schemas
- Security
- Licensing
Longitudinal results from the public benchmark suite. See Eval Suites for methodology.
