Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Hacken AI Auditor now supports Daml

3 min read

Hacken’s AI Auditor now supports Daml, bringing automated security analysis to applications built on Canton.

The Daml capability was developed as part of Hacken’s work with the Canton ecosystem, alongside the participant-local monitoring and risk-scoring stack supported by the Canton Development Fund.

Why Daml needs a specialised AI security audit

Daml’s security model depends heavily on authorisation, party relationships, interfaces, and contract lifecycle. A vulnerability may only become visible when several templates are considered together.

That’s why Daml applications require a different approach to security review. What looks correct in the code alone can still create problems in production environment when permissions, participants, and contracts interact.

Hacken’s AI Auditor now understands these Daml-specific patterns. It can analyse an application in context, identify potential security issues, and help teams see where a deeper review may be needed.

The result is a practical first security check before deployment or a full manual audit.

DAML Security areas covered by AI Auditor

Before the security analysis starts, the pipeline builds context around the application: parties, signatories, observers, controllers, interfaces, implementations, and relationships between templates.

It then groups the code by semantic function rather than simply sending files to a model one by one.

From there, the audit runs several specialised passes covering four main scope areas:

  • Authority and contract lifecycle — Authorisation boundaries and the security of contract state transitions
  • Interfaces and settlement — Whether implementations meet interface requirements, particularly in settlement flows
  • Coupled contract state — Consistency between contracts that represent related business states or conditions
  • Amounts, identifiers and time boundaries — Validation and handling of amounts, party identifiers and time-dependent conditions

Potential findings go through a separate verification pass before being included in the output. Where useful, the system can also draft a proof of concept to help reproduce a finding.

The result is a security assessment that is specific to how Daml applications actually work, rather than a generic AI-generated code review.

Hacken’s DAML AI Auditor vs traditional AI Audit

A general AI code audit can review Daml syntax and identify patterns that look suspicious. Yet, its biggest limitation will be context. Without understanding Daml’s authorisation, privacy, and contract lifecycle, an AI model can miss issues that only become apparent across related contracts and workflows.

Hacken’s AI Auditor takes a different approach. It first builds the relevant application context, then analyses the code against Daml-specific security patterns and risks.

This includes the patterns and security considerations described in Hacken’s Daml Design Patterns and Security Analysis, covering areas such as authorisation, privacy, contract lifecycle and common Daml application patterns.

Traditional AI audit

Hacken AI Auditor

Reviews code primarily at the file or code-fragment level

Analyses Daml code in the context of related contracts and workflows

Applies general-purpose security patterns

Uses Daml-specific security patterns and analysis criteria

Can produce findings without sufficient application context

Builds application context before generating findings

Treats potential findings as the primary output

Verifies findings before they are included in the assessment

The result is a more targeted AI-assisted assessment of Daml security, designed to identify issues that depend on how the application is structured and how its different components interact.

Built through work with the Canton ecosystem

Hacken’s Daml support was developed through its work with the Canton ecosystem.

On 26 August 2026, the Canton Development Fund approved Hacken’s proposal for an open-source, participant-local monitoring and risk-scoring stack under the daml-tooling, dApp integration, and regulatory compliance categories.

As part of this work, Hacken extended its AI Auditor to understand Daml applications and their specific security model.

Canton teams can now use the Daml AI Auditor as an initial security assessment before deployment or a full manual audit.

Five free Daml AI Auditor assessments

To mark the addition of Daml support, Hacken is opening five free AI Auditor assessment slots for teams building on Canton.

The assessment can help you understand where your Daml application's main security surfaces are and whether a deeper manual review is warranted.

Full manual Daml security audits are also 50% off through 11 October 2026.

Apply for a free Daml AI Auditor assessment.

Subscribe to our newsletter

Be the first to receive our latest company updates, Web3 security insights, and exclusive content curated for the blockchain enthusiasts.

Speaker Img