The Smart Contract Security Field Guide for Hackers¶
Understanding the range of attacks on smart contracts is essential work for developers, auditors, and bug bounty hunters. The following articles are an educational resource for building offensive security skills and for identifying and preventing common vulnerabilities in smart contract systems.
| Category | Description |
|---|---|
| ABI Hash Collisions | Insights into the consequences of ABI hash collisions on smart contracts. |
| Ambiguous Evaluation Order | Solidity's ambiguous evaluation order and potential weaknesses. |
| Approval Vulnerabilities | Token approvals, their security risks, and concrete exploits that result in the loss of user funds. |
| Exposed Data | The dangers of storing PII and related artifacts on-chain. |
| Frontrunning | The role of frontrunning in blockchain and related potential exploits. |
| Griefing | The implications of griefing for the operations of smart contracts. |
| Incorrect Parameter Order | The common pitfall of providing a set of parameters ordered differently than expected. |
| Inline Assembly | How Yul assembly blocks disable the compiler's safety guarantees and the exploits that follow. |
| Oracle Manipulation Attacks | Security vulnerabilities associated with centralized and decentralized oracles. |
| Reentrancy Attacks | The threat of reentrancy attacks to the security of smart contracts. |
| Signature-related Attacks | How malfunctioning signature validation can compromise smart contracts. |
| Unexpected Ether Transfers | Risks and precautions related to unexpected Ether transfers in smart contracts. |
| Unprotected Swaps | Swaps that aren't slippage-protected and how attackers can exploit them for profit. |
| Use of tx.origin | Risks around using tx.origin for authorization, especially after the Pectra network upgrade. |