On-chain activity
Almanax
almanax.ai
Almanax is an AI-native application security platform that replaces the traditional annual smart contract audit with continuous, automated vulnerability detection embedded directly in the software development workflow.
The Problem
Web3 teams have historically relied on point-in-time security audits: expensive, slow engagements that cover a snapshot of code and go stale the moment the next pull request merges. The interval between vulnerability disclosure and active exploitation has compressed dramatically as tooling for attackers improves. Almanax was built on the premise that security has to move at the speed of code—reviewed on every commit, not once a year.
What Almanax Does
Almanax functions as an AI security engineer integrated into a team's existing GitHub workflow. After installing the Almanax GitHub app on one or more repositories, developers gain two core capabilities:
Continuous pull request review. Every PR is analyzed by the platform before it can merge. Almanax flags security issues—including complex, multi-step vulnerabilities that static analysis tools miss—and surfaces contextual feedback inline, within the pull request. Risky code can be blocked from reaching the main branch automatically.
Retrospective codebase scanning. Beyond ongoing reviews, teams can run a manual scan of the entire existing codebase to surface vulnerabilities introduced before Almanax was installed.
Both modes rely on state-of-the-art large language models augmented with real-time threat intelligence and the ability to ingest custom project documentation. The platform produces findings with full context rather than generic pattern matches, and it can generate committable patch suggestions and draft pull requests to resolve identified issues.
Blockchain-Specialized Models
The core differentiator for Web3 teams is that Almanax operates ecosystem-specialized models trained on the security patterns of specific blockchain environments: Solana, EVM-compatible chains, Stellar, and Aptos. This allows the platform to reason about program-specific attack surfaces—such as Solana's account model and cross-program invocation risks—that a generic code analysis tool would not understand. The Solana Foundation recognized this by providing Solana ecosystem builders with a one-year Almanax subscription to encourage secure development practices across the network.
Key Platform Capabilities
Automated threat modeling. Almanax analyzes system architecture to generate threat models continuously. It maps attack surfaces from code structure, identifies trust boundaries across services, and classifies threats using the STRIDE framework. Threat models update as the codebase evolves rather than sitting as static documents.
Natural language security rules. Teams define custom security policies in plain English rather than complex DSL syntax. This allows non-security engineers to encode team-specific risk tolerance and business logic into the scanning process.
Agent learning. The platform builds project-specific memory from developer interactions. Dismissed findings train the agent to reduce false positives over time, and the system learns codebase-specific patterns and the team's risk preferences.
Third-party alert triaging. When external vulnerability databases flag a library or dependency, Almanax performs reachability analysis to determine whether the vulnerable code path is actually exercised in the project, eliminating noise from alerts that do not apply.
Enterprise deployment options. The platform is available as a cloud service and can be self-hosted for organizations with data residency requirements. Customer code is never used to train Almanax models. Role-based access controls and organization management are included.
Web3 Security Atlas
In December 2024, Almanax launched the Web3 Security Atlas, an open-source project designed to track vulnerabilities, exploits, and security best practices across the Web3 ecosystem, covering Solana, Ethereum, Base, and Stellar. Partners on the initiative include TRM Labs, AnChain.AI, and Hypernative, with backing from the Stellar Development Foundation.
Customers and Partners
Almanax reports scanning over 100 million lines of code. Named customers and ecosystem partners include Solana, Privy, Aptos Labs, Stellar, Dfns, Hypernative, Algorand, Axal, and 0G. The team has responsibly disclosed hundreds of vulnerabilities to organizations including Ripple, Coinbase, and Fireblocks, and identified security issues in code written by Ethereum co-founder Vitalik Buterin.
Notable integrations announced in 2025 and 2026 include a partnership with Keplr for operational security and CI/CD hardening, a compliance integration with Vanta, a partnership with the Algorand Foundation to support its accelerator program, and a collaboration with mcp-use on security for AI agent tool protocols.
Team and Funding
Almanax was founded in 2024 by Francesco Piccoli, Giorgio Demarchi, and Maxwell Watson and is headquartered in New York. The company received pre-seed backing from defy.vc and was accepted into NVIDIA's Inception Program. In January 2025, Almanax raised $1 million in a seed round from Blockchain Builders Fund, Exor Ventures, Vento Ventures, Italian Angels for Growth, Eden Ventures, and Moonbase.
Acquired by depthfirst
In June 2026, Almanax announced it was joining depthfirst, a product security company positioning itself as a category leader in application security—comparable to what Palo Alto Networks represents for network security or CrowdStrike for endpoints. The combined team intends to extend Almanax's AI-driven security capabilities across enterprise software stacks beyond Web3.
Tokens
Almanax has no protocol token. It is a commercial SaaS product with subscription-based pricing, including a seven-day free trial and enterprise licensing tiers.
Solana Fit
Almanax occupies the developer security tooling layer of the Solana ecosystem. Rather than being a protocol that runs on-chain, it is a development-time infrastructure product that helps Solana program authors catch vulnerabilities before deployment. The Solana Foundation's decision to subsidize team subscriptions reflects the ecosystem's interest in raising the security baseline for programs deployed to the network. For any team building on Solana that wants continuous, automated code review with Solana-specific vulnerability knowledge, Almanax is one of the few purpose-built options available.
Contents
- The Problem
- What Almanax Does
- Blockchain-Specialized Models
- Key Platform Capabilities
- Web3 Security Atlas
- Customers and Partners
- Team and Funding
- Acquired by depthfirst
- Tokens
- Solana Fit
Solana Token Markets