A list of resources about
- Secureum: Secureum Bootcamp for Smart Contract Security Auditing is an intense 3-month program. Created by the great @0xRajeev The core focus will be Ethereum Smart Contract Security Auditing. The covered topics will include Ethereum, Solidity, Smart Contract Security & Audits.
- Secureum Mind Map
- Etherscan: The Ethereum Blockchain Explorer.
- BSCScan: BNB Smart Chain Explorer.
- Etherchain
- PolygonScan: Polygon PoS Chain Explorer.
- Blockchain.com Explorer
- Blockchair
- BlockCyphera
- CoinMarketCap Block Explorer
- BTC.com Block Explorer
Ripple (XRP) Explorer
Monero block explorer
Web Descentralized Explorer
- SWC Registry: The Smart Contract Weakness Classification Registry (SWC Registry) is an implementation of the weakness classification scheme proposed in EIP-1470. It is loosely aligned to the terminologies and structure used in the Common Weakness Enumeration (CWE) while overlaying a wide range of weakness variants that are specific to smart contracts.
- List of Security Vulnerabilities
- Ethereum Smart Contract Security Best Practices maintained by ConsenSys Dilligence
- Ethereum Security Post
- SigmaPrime Blog, Solidity Security: Comprehensive list of known attack vectors and common anti-patterns.
- Introducción a Hacking y Seguridad de Smart Contracts en Ethereum: Training of 4+ hours by Martin Abbatemarco
- Introducción a Ethereum Development: by Martin Triay
- Solidity Documentation
- Solidity By Example
- CryptoZombies: Learn Solidity through play a game
- Solidity & Vyper Cheat Sheet
- GitHub
- Solidity Gitter Chatroom bridged to Solidity Matrix Chatroom
- Cheat Sheet
- Solidity Blog
- Solidity Twitter
- Documentation
- Vyper by Example
- Learn.Vyperlang.org for learning Vyper by building a Pokémon game.
- GitHub
- Vyper Gitter Chatroom
- Cheat Sheet
- Update Jan 8, 2020
Capture the Flag (CTF) is a special kind of information security competitions
- Capture the Ether
- The Ethernaut
- Damn Vulnerable DeFi Created by the great Martin Abbatemarco
- Security Innovation Blockchain CTF
- GOAT Casino
- Paradigm CTF
- Blocksec CTFs: a list of all of them
Tool | Link | Desc |
---|---|---|
Slither | link | Static analysis framework with detectors for many common Solidity issues. It has taint and value tracking capabilities and is written in Python. |
MythX | link | MythX is a professional-grade cloud service that uses symbolic analysis and input fuzzing to detect common security bugs and verify the correctness of smart contract code. Using MythX requires an API key from mythx.io. |
Mythril | link | The Swiss army knife for smart contract security. |
Contract-Library | link | Decompiler and security analysis tool for all deployed contracts. |
MadMax | link | Static analysis tool for gas DoS vulnerabilities. |
Gigahorse | link | Fast binary lifter and program analysis framework written in Datalog. |
Echidna | link | The only available fuzzer for Ethereum software. Uses property testing to generate malicious inputs that break smart contracts. |
Manticore | link | Dynamic binary analysis tool with EVM support. |
Oyente | link | Analyze Ethereum code to find common vulnerabilities, based on this paper. |
Securify | link | Fully automated online static analyzer for smart contracts, providing a security report based on vulnerability patterns. |
SmartCheck | link | Static analysis of Solidity source code for security vulnerabilities and best practices. |
Octopus | link | Security Analysis tool for Blockchain Smart Contracts with support of EVM and (e)WASM. |
sFuzz | link | Efficient fuzzer inspired from AFL to find common vulnerabilities. |
Vertigo | link | Mutation Testing for Ethereum Smart Contracts. |
Solidity Visual Developer | link | This extension contributes security centric syntax and semantic highlighting, a detailed class outline, specialized views, advanced Solidity code insights and augmentation to Visual Studio Code. |
tintinweb | link | Visual Studio Code Extensions by tintinweb |
- Solidity Scan: Smart-contract scanning tool built to discover vulnerabilities & mitigate risks in your code.
- Dedaub Contract Library: Smart Contract Code Explorer
- DApp Radar: Discover, Track & Trade Everything DeFi, NFT and Gaming
- EthTx Transaction Decoder:EthTx is an open source decoder of blockchain transactions.
- Online Solidity Decompiler
- Token Sniffer: This site scans contracts for known scams, computes helpful token metrics, and maintains a list of scams
- Token FOMO: Every token deployed in the last 24 hours
- Rugdoc
- Is This Coins a Scam?
- Token Analyzer: Token Analyzer to detect potential scams.
- Honeypot Detector for BSC Network
- Bad Bitcoin.org
Titulo | Desc | web | Año | Video |
---|---|---|---|---|
TrustX | a first-of-its-kind technical event dedicated to the Ethereum security ecosystem | https://www.secureum.xyz/trustx | 2022 | Videos |
Ekoparty Security Conference | Latin American Security Conference with a Space dedicated to Blockchain Security | http://ekoparty.org | Since 2005 | Videos |
Blockchain Security Space at Ekoparty | Latin american community dedicated to share the knowledge about differents Security Blockchain topics. | Website | 2022 | Videos |
Defcon - Blockchain Village | One of the world's largest and most notable hacker conventions, held annually in Las Vegas, Nevada. | https://blockchainvillage.net | 2019 | Videos |
Defcon - Blockchain Village | One of the world's largest and most notable hacker conventions, held annually in Las Vegas, Nevada. | https://blockchainvillage.net | 2020 | Videos |
Defcon - Blockchain Village | One of the world's largest and most notable hacker conventions, held annually in Las Vegas, Nevada. | https://blockchainvillage.net | 2021 | Videos |
Off The Chain Conference | A CURIOUSLY STRONG BLOCKCHAIN AND CRYPTOCURRENCY SECURITY CONFERENCE | https://www.offthechaincon.com | 2022 | Videos |
Unchained Blockchain Security Conference | A two days virtual conference featuring global Blockchain veterans presenting their novel ideas, stories, and experiences around creating a secured Web3.0 ecosystem. | https://razzorsec.ml/unchained.html | 2022 | Videos |
DeFi Security 101 | This is a one-day crash course on DeFi security at Stanford, just before DeFi Security Summit. The goals are to prepare students for the DSS event and attract them to perform research in this space. The course is in-person only. | https://defisecuritysummit.org/defi-security-101/ | 2022 | |
First Annual DeFi Security Summit | First Annual DeFi Security Summit -PAUL & MILDRED BERG HALL, STANFORD, AUGUST 27-28 | https://defisecuritysummit.org/ | 2022 | |
The Science of Blockchain Conference 2022 | The conference focuses on technical innovations in the blockchain ecosystem, and brings together researchers and practioners working in the space. We are interested in the application of cryptography, decentralized protocols, formal methods, and empirical analysis, to improving the security and scalability of blockchain deployments. We aim to foster collaboration among practitioners and researchers working on blockchain protocol development, cryptography, distributed systems, secure computing, crypto-economics, and economic risk analysis. | https://cbr.stanford.edu/sbc22 | 2022 | |
ETHLatam | AGOSTO 11-12-13 2022, Buenos Aires Argentina | https://ethlatam.org/ | 2022 | Videos |
- Rekt
- Week In Ethereum
- Blockchain Threat Intelligence
- MDMA: Monday DeFi Market Alpha
- Chainalysis Weekly Newsletter
PDF Documentation & Books link
- Ethereum Evm Illustrated - Takenobu T.
- Mastering Ethereum - Andreas M. Antonopoulos, Gavin Wood
- ETHEREUM:Yellow Paper
- Certik Defi Security Report 2021-v6
- SMART CONTRACTS SECURITY VERIFICATION STANDARD - Securing
- A Survey of Verification, Validation and Testing Solutions for Smart Contracts - Chaı̈maa Benabbou, Önder Gürcan
- Fundamentos Blockchain - Joan Amengual
- Tokens - Joan Amengual
- CheatSheet Solidity