Adventures in Automated Smart Contract Testing: A Spark Is Born
The article recounts the author's early journey into automated smart contract testing, describing how they developed a tool called GASER to find gas-cost vulnerabilities in Ethereum smart contracts. The post details the initial spark of the idea, the technical challenges faced, and the early experimental results from the project.
Background
- Gustavo Grieco is a security researcher who works on automated analysis of smart contracts. This blog describes his early experiments that led to what became **Medusa** (formerly called "crytic/spark"), a fuzzer for Ethereum smart contracts.
- *Fuzzing* is a testing technique that throws random or semi-random inputs at a program to crash it or trigger bugs. For smart contracts, fuzzers generate random sequences of function calls with random parameters to find logic errors, security flaws, or crashes.
- This post covers the 2019–2020 period, when most Ethereum smart contract testing was manual or used symbolic execution tools like Mythril. Fuzzing for EVM bytecode was still immature.
- The key insight: existing test generation tools struggled with deeply nested control flow (e.g., reaching a specific require/if inside multiple branches). Grieco devised a way to guide fuzzing using *taint tracking plus library callbacks*, which became the core idea of Medusa.
- The work was done at **Trail of Bits**, a well-known security firm that builds several open-source smart contract analysis tools (Slither, Echidna, Manticore). Medusa is now their flagship EVM fuzzer.
Max Weinbach says he had early access to OpenAI's new model GPT-5.6 Sol, calling it his favorite model by far. He highlights that it never gives up and will keep reasoning until it's done. OpenAI announced that GPT-5.6 Sol, along with Terra and Luna, will launch publicly on Thursday, with preview access expanding globally now.
The US government ordered Anthropic to suspend access to its Fable 5 and Mythos 5 models for all customers, citing a potential jailbreak technique that involved asking the model to review a codebase for vulnerabilities—a capability Anthropic says is available in other public models. Access was abruptly cut off on June 12.
Andrej Karpathy announces the release of Claude Fable 5, the same underlying model as Mythos but with added safeguards. He calls it a major step forward, particularly for long problem-solving sessions on difficult tasks, and describes it as state-of-the-art on nearly all benchmarks with exceptional performance in software engineering, research, and vision.
Roman Storm warns that the legal theory in his case could set a precedent making open-source developers liable for how others use their code, potentially criminalizing the mere publication of privacy, messaging, or crypto tools. He notes that developer Michael Lewellen cannot publish lawful code due to prosecution fears, and argues this chilling effect extends beyond any single case.
Meta's engineering culture is deteriorating under Mark Zuckerberg and Scale AI CEO Alexandr Wang, who have introduced keyboard tracking, reassignments to data labeling, and AI-centric performance metrics. Critics argue this incentivizes performative AI use, drives away experienced engineers, and contributed to a major Instagram hijacking incident caused by AI-written and AI-reviewed code.