Knowdit: Agentic Smart Contract Vulnerability Detection with Auditing Knowledge Summarization
arXiv cs.AI / 3/30/2026
💬 OpinionIdeas & Deep AnalysisModels & Research
Key Points
- Knowdit is proposed as a knowledge-driven, agentic framework to detect smart contract vulnerabilities that are difficult to catch with automated tools due to project-specific DeFi business logic.
- The approach builds an auditing knowledge graph from historical human audit reports, linking shared DeFi economic “semantics” to recurring vulnerability patterns.
- For new projects, a multi-agent workflow iteratively generates specifications, synthesizes test harnesses, runs fuzzing, and performs reflective refinement using shared working memory.
- Evaluations on 12 Code4rena projects (75 known vulnerabilities) show Knowdit achieves full detection of high-severity issues and 77% of medium-severity issues with only 2 false positives, outperforming baselines.
- When applied to six real-world projects, Knowdit found 12 previously unknown high-severity and 10 previously unknown medium-severity vulnerabilities, indicating strong practical potential.
💡 Insights using this article
This article is featured in our daily AI news digest — key takeaways and action items at a glance.
Related Articles

Mr. Chatterbox is a (weak) Victorian-era ethically trained model you can run on your own computer
Simon Willison's Blog
Beyond the Chatbot: Engineering Multi-Agent Ecosystems in 2026
Dev.to

I missed the "fun" part in software development
Dev.to

The Billion Dollar Tax on AI Agents
Dev.to

Hermes Agent: A Self-Improving AI Agent That Runs Anywhere
Dev.to