Snitch

Snitch documentation

Snitch watches contracts and delivers signed exploit alerts. This guide covers the hosted API. A self-hosted binary is available on the Treasury plan.

Quickstart

Install the CLI and authenticate:

npm install -g @snitch/cli
snitch login --token $SNITCH_TOKEN

Add a contract to your watchlist:

snitch watch 0x9f2c...a41 --chain base --label "Vault v2"

# → watching 1 contract
# → alerts → telegram, webhook

Core concepts

A watch is a contract plus the set of alert channels attached to it. Every pending transaction that touches a watched contract is simulated against current state. If the simulation moves value the caller is not entitled to, Snitch raises a detection.

A detection carries the call trace, the estimated value at risk, and a Foundry proof. Alerts are signed so downstream automation can verify the source.

API reference

All endpoints are authenticated with a bearer token.

GET    /v1/watches              list watches
POST   /v1/watches              create a watch
DELETE /v1/watches/:id          remove a watch
GET    /v1/detections           list detections
GET    /v1/detections/:id       detection + proof

Create a watch:

curl https://snitch.biz.id/v1/watches \
  -H "Authorization: Bearer $SNITCH_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "address": "0x9f2c...a41",
    "chain": "base",
    "label": "Vault v2"
  }'

Webhooks

Snitch posts every detection to your webhook as JSON, signed with an HMAC-SHA256 header so you can verify authenticity.

POST /your-endpoint
X-Snitch-Signature: sha256=...

{
  "id": "det_01H...",
  "chain": "base",
  "contract": "0x9f2c...a41",
  "type": "reentrancy",
  "value_at_risk_usd": 1042210,
  "proof_url": "https://api.snitch.biz.id/proofs/det_01H...",
  "detected_at": "2026-10-09T06:51:00Z"
}

Self-hosted

The Treasury plan ships the detection engine as a self-hosted binary. Point it at your own RPC endpoints and keep all telemetry inside your infrastructure.

snitch-engine run \
  --rpc $RPC_URL \
  --watch-file watches.yaml \
  --webhook https://internal.yourco.dev/snitch

Need something not covered here? Contact the team.