mythril
Security analysis tool for Ethereum smart contracts
Decision gist · record as of 2026-08-14
Yes, with conditions. Mythril is actively maintained and has no known vulnerabilities. Install it if you develop or audit Ethereum smart contracts and need bytecode-level security analysis. The high install friction and alpha status mean you should expect setup complexity and test it in a controlled environment first. For production audits, consider whether MythX's optimized tools better suit your workflow.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.7 or later; high install friction suggests Docker (mythril/myth) may be the simpler deployment path than pip on some systems.
- Installation carries high friction: the package has no runtime dependencies listed but requires compiled components or system libraries (evidenced by the tar.gz distribution).
- The project is actively maintained with recent commits and a solid community presence (4259 stars), but setup complexity may require Docker or careful environment configuration.
License · maintenance · safety
MIT (permissive) — MIT license is permissive and poses no restrictions on use, modification, or distribution in your own projects.
last release 2024-03-27 (870 days) · last repo commit 2026-04-27 · 4,259 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 81,441 downloads/mo, #14,227 on PyPI
Alternatives
Verify before relying
pip install mythril
myth analyze <solidity-file>
# or analyze from blockchain:
myth analyze -a <contract-address> -t 3- Whether the package's compiled dependencies are available pre-built for all major platforms or require local compilation.
- Current state of SMT solver integration and whether Z3 or other solvers must be installed separately.
- Performance characteristics and typical analysis time for production-scale contracts.
What it is and what it does
Mythril is a static analysis tool that examines EVM bytecode—the compiled form of smart contracts—to find security flaws before deployment. It works by simulating contract execution paths symbolically and using constraint solvers to detect vulnerabilities like unprotected self-destruct, reentrancy, and other known attack vectors. The tool supports Ethereum and other EVM-compatible blockchains (Hedera, Quorum, Vechain, Roostock, Tron).
It's designed as a command-line utility: you point it at a Solidity file or a deployed contract address, specify how many transaction sequences to explore, and it reports findings with severity levels, affected functions, and remediation guidance. The tool is part of the ConsenSys security ecosystem and feeds into the MythX platform, though Mythril itself is the open-source foundation for bytecode-level analysis.
Use it for
- Audit a Solidity smart contract before mainnet deployment to catch high-severity vulnerabilities.
- Analyze deployed contract bytecode on-chain to verify security properties without source code access.
- Integrate into CI/CD pipelines to automatically flag security issues during contract development.
- Research EVM bytecode patterns and vulnerability detection techniques using symbolic execution.
- Verify remediation of known vulnerabilities by re-analyzing after code changes.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, with conditions.
Mythril is actively maintained and has no known vulnerabilities. Install it if you develop or audit Ethereum smart contracts and need bytecode-level security analysis. The high install friction and alpha status mean you should expect setup complexity and test it in a controlled environment first. For production audits, consider whether MythX's optimized tools better suit your workflow.
Install
mythril on PyPI
Before you install
Installation carries high friction: the package has no runtime dependencies listed but requires compiled components or system libraries (evidenced by the tar.gz distribution). The project is actively maintained with recent commits and a solid community presence (4259 stars), but setup complexity may require Docker or careful environment configuration.
Requires Python 3.7 or later; high install friction suggests Docker (mythril/myth) may be the simpler deployment path than pip on some systems.
License in practice
MIT license is permissive and poses no restrictions on use, modification, or distribution in your own projects.
Quickstart
pip install mythril
myth analyze <solidity-file>
# or analyze from blockchain:
myth analyze -a <contract-address> -t 3
Verify before relying
- Whether the package's compiled dependencies are available pre-built for all major platforms or require local compilation.
- Current state of SMT solver integration and whether Z3 or other solvers must be installed separately.
- Performance characteristics and typical analysis time for production-scale contracts.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.7.0 |
| Install friction | High. Source build required |
| Runtime dependencies | None |
| Maintenance | Actively maintained 870 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 81,441 / month, #14,227 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 3 - AlphaIntended Audience :: Science/ResearchLicense :: OSI Approved :: MIT LicenseProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: Software Development :: Disassemblers |
Evidence: mythril-0.24.8.tar.gz
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “ethereum smart contract security analysis”
- mythrilMythril analyzes EVM bytecode for security vulnerabilities in smart…
- ethereum-dasmDisassembles Ethereum EVM bytecode into assembly instructions and…
- slither-analyzerSlither is a static analysis framework for Solidity and Vyper smart…
Give your agent the search over MCP, or paste the wish link into any chat.
More Disassemblers packages
pyelftools parses and analyzes ELF binary files and DWARF debugging information in pure Python, with no external dependencies.
Install it if you need to read or analyze ELF binaries or debug information from Python.
Disassembles VBA p-code from Microsoft Office documents to reveal the compiled macro instructions that actually execute, regardless of whether source code is present.
However, do not rely on it for modern Office versions (2010+) without testing—the package is abandoned and has known disassembly gaps in 64-bit Office 2016.
Pwntools is a CTF framework and exploit development library providing tools for writing exploits, assembling/disassembling code, interacting with remote services, and analyzing binaries.
Install it if you work on exploit development, security research, or CTF challenges; skip it if you don't need those capabilities.
Hachoir parses and displays binary files as a tree of typed fields, letting you inspect and edit individual bits, bytes, and structures within any binary stream.
Maps each value in a JSON document to its source location (line, column, character position) and JSON Pointer path, enabling precise error reporting and source-aware JSON processing.
SMDA is a recursive disassembler library that recovers control flow graphs from binary files and memory dumps, supporting x86/x64, AArch64, .NET CIL, and Dalvik bytecode with output as functions, basic blocks, and instruction-level edges.
Install it if you need to extract control flow structure from binaries or memory dumps; avoid it if you only need basic disassembly without CFG analysis or if you…
See also ethereum-dasm · slither-analyzer · vyper · py-evm · eth-tester · evmdasm · eth-brownie · clvm · crosshair-tool · pyevmasm