Skip to content

Security & trust, one engine

Every attack surface.
One security engine.

ANTHRION red-teams AI agents, web apps, APIs and Web3 — plus code and endpoint trust — in a single scanner. Normalized findings, real-time results, crypto-native, pay per scan.

AI/Web/API/Web3/Code/Endpoint

ANTHRION scanAI / LLM attack scan
Done
target · agent.example/chatscan · 7f3c9a2e
3 findings1Critical2High0Medium0Low
  • Prompt injection: direct instruction overrideprompt-injection
    Critical
  • System prompt leakage: verbatim disclosuresystem-prompt-leakage
    High
  • Tool execution without user approvalexcessive-agency
    High
Report · severity · remediationView report

One engine for indie builders, crypto communities and AI-agent developers — from a single prompt-injection probe to a full multi-surface audit.

9
Scan types
6
Attack surfaces
LLM01–10
OWASP-aligned
USDC
Base & Solana

01Scanners

Every surface your agents touch.

One engine, one report format. Run a single probe or a full multi-surface audit — findings come back normalized, severity-ranked, with remediation.

Differentiator

AI / LLM attack scan

An adaptive AI red-team engine that attacks your agent the way a real adversary would — static probes escalate into an adaptive attacker. Point it at a live endpoint, or paste a system prompt to test it before you ship.

Detects
  • Prompt injection
  • Jailbreaks
  • System-prompt leakage
  • Excessive agency
  • Insecure output

Web app scan

Dynamic testing of a live site in a real browser — injection, XSS, auth and misconfiguration on the rendered surface.

API security scan

Probes an API endpoint for broken auth, injection and data exposure across its routes.

Web3 dApp scan

Wallet-injection and frontend checks plus on-chain context — what a malicious dApp could ask a wallet to sign.

Code & repo

White-box taint analysis, leaked-secret detection, code-similarity and a GitHub trust score — from a repo URL.

Endpoint trust

Verify an x402 endpoint before you pay it, monitor its health over time, and check it against the public trust registry.

02How it works

From target to report, in real time.

  1. 01

    Choose a target

    A live endpoint, a public repo, or paste a system prompt. Pick one scan or queue several across surfaces.

  2. 02

    Pay per scan

    USDC on Base or Solana — one free scan per wallet. Or let an AI agent pay autonomously over x402, no human in the loop.

  3. 03

    Watch it run, live

    The engine streams progress as it works — probes, then an adaptive attacker — so you see findings the moment they land.

  4. 04

    Get the report

    Normalized severity, evidence and remediation for every finding. Download it, or share a link.

Scan runningScan progress
Running
  1. Static probesLayer 1 · completed
  2. Adaptive attackerLayer 2 · completed
  3. Evaluating responsesLayer 2 · category · running

Streamed live as the scan runs.

03x402

Paid by agents — and trust for x402 itself.

ANTHRION uses x402 to get paid: agents settle a scan autonomously, no human in the loop. And ANTHRION is itself trust infrastructure for x402 — it verifies, monitors and registers endpoints so the ecosystem knows what is safe to pay.

Agents pay autonomously

An AI agent calls the scanner and settles payment over x402 — machine to machine.

ANTHRION x402Machine-to-machine
x402
  1. agentPOST /scan
  2. server402 Payment Required
  3. agentpays USDC via x402
  4. serverscan started · streaming
  5. serverscan DONE

Illustrative exchange — no human in the loop.

Trust layer for x402

ANTHRION verifies, monitors and registers other x402 endpoints — so agents know what is safe to pay.

ANTHRION x402 verifyx402 endpoint verify
Verified
endpoint · api.example/paid
Trust score92 / 100
  • Endpoint reachableOK
  • 402 handshake well-formedOK
  • Payment details consistentOK
  • No anomalies detectedOK

Illustrative — verify, monitor & register. An indicator, not a guarantee.

04Pricing

Pay per scan. Nothing else.

No seats, no subscriptions. You pay for the scans you run, on-chain — the way a crypto-native product should work.

Launch pricing

Free

during launch · then pay-per-scan

  • One free scan per wallet to start
  • USDC on Base & Solana — no card, no KYC
  • No subscription, no balance lock-in
  • AI agents can pay autonomously over x402
Start a scan

An indicator of risk — not a guarantee of security.

05FAQ

Questions, answered.

Crypto-native, non-custodial, and built for agents as much as for people.

  • AI agents and LLM endpoints, web apps, APIs and Web3 dApps — plus code and repos and the trust of x402 endpoints. One engine, one normalized report format across every surface.

Find the holes before they do.

Run your first scan free. Every surface, one engine, results in real time.