▐ homomorph ▌
HOMOMORPH

find the bugs that hide inside encrypted computation

A one-line install CLI that audits fhEVM confidential contracts for the mistakes plaintext tools cannot see: broken ciphertext ACLs, missing input proofs, unverified decryptions and leaky control flow. Runs locally. Nothing leaves your machine.

$ curl -fsSL https://homomorphic.sh | sh

macOS and Linux · x86_64 and arm64 · no sudo · sha256 + minisign verified · read the script

real output, captured from the CLI

homomorph scan ./contracts

  ◇ archive 3 files · 3 first-party · 0 deps · 0 artifacts · 2584 bytes

◆ Ciphertext-aware

Solidity linters see bytes32 handles. homomorph tracks encrypted values from FHE.fromExternal through arithmetic into storage, and knows which ACL grant each write needs.

◆ Silent, retroactive, systemic

FHE bugs do not revert. They mint value under encryption, publish a balance to the world, or lock funds behind a handle nobody can decrypt. Ciphertexts live forever, so the leak is permanent.

◆ Offline by default

Analysis runs on your machine. --upload shares findings only (rule, file name, line) to a link you control. Source code is never sent. --format sarif plugs into GitHub code scanning.

12 rules and counting

What it finds

Full rule catalogue →

Builders

Shipping confidential tokens, sealed-bid auctions or private governance on fhEVM. Run it in CI, fail on high, sleep better.

Researchers

Each rule documents a concrete FHE bug class with the failing and fixed pattern. Parameter security and CKKS leakage checks are next on the roadmap.

Auditors

Triage a codebase in seconds, then spend your hours on threshold-key trust, decryption oracles and the composition with plaintext state.

get started

$curl -fsSL https://homomorphic.sh | sh

then homomorph scan . inside your project · homomorph login for report history · curl homomorphic.sh/banner for the wordmark