Catch the exploit before
it drains you
Snitch watches every contract you deploy or hold, simulates pending transactions against it, and warns you seconds before funds move.
[block 21,304,881] watching 38,204 contracts
⚠ ALERT 0x9f2c…a41 — reentrancy in withdraw()
├ sim: drains 412.6 ETH via fallback loop
├ proof: poc.t.sol passed · 0.4s
└ alert signed & delivered in 9s
[block 21,304,882] drain blocked — no funds moved
Detection that reaches the mempool
Most monitoring tells you what already happened. Snitch works on transactions that have not landed yet.
Mempool exploit detection
We simulate every pending transaction against your contracts before it lands. If it drains value, you know while it is still in the mempool, not after the block confirms.
Bytecode-level diffing
Proxy upgrades, admin changes, and self-destruct paths are diffed on deploy. Snitch flags a contract that quietly gained a mint or transfer-owner path.
Attack simulation
Every alert ships with a runnable Foundry proof of concept, so you can confirm the exploit path yourself instead of trusting a vague risk score.
Multi-chain coverage
Ethereum, Base, Arbitrum, Optimism, and Polygon. One watchlist, one alert channel, every chain you deploy to.
One-line integration
Drop a single RPC endpoint into your wallet, bot, or treasury stack. No dashboard required to receive the signal.
Signed alerts
Every alert is signed by Snitch and verifiable onchain. Your automation can trust the source without a shared secret.
Three steps to a second set of eyes
Point Snitch at your contracts
Paste addresses, or connect a wallet and Snitch discovers what you hold and deploy.
Snitch watches the mempool
Every pending tx touching your contracts is simulated against current state.
You get the alert in seconds
Telegram, webhook, email, or an onchain event — with a runnable proof of the exploit path.
Free forever for your first three contracts
No card, no sales call. Watch your contracts, get the alerts, decide whether you need more.
Questions
Does Snitch hold my keys?
No. Snitch is read-only. It watches public chain state and the mempool. It never signs, never holds funds, and never needs a private key.
How fast are alerts?
Median 11 seconds from transaction entering the mempool to alert delivery. We front-run only with information — what you do with the warning is your call.
Can I run it myself?
The detection engine ships as a self-hosted binary on the Treasury plan. Sentinel and up get webhook parity with the hosted version.
What if there is a false positive?
Every alert includes the simulated call trace and a Foundry proof. If it does not reproduce, it did not happen, and we want the report.
Your contracts are already being read
The only question is whether you see the exploit first.