{"id":75636,"url":"https://github.com/fabionoth/awesome-web3-security","name":"awesome-web3-security","description":"A curated list of awesome Web3 Security.","projects_count":50,"last_synced_at":"2026-08-18T08:00:24.358Z","repository":{"id":258749334,"uuid":"869705160","full_name":"fabionoth/awesome-web3-security","owner":"fabionoth","description":"A curated list of awesome Web3 Security.","archived":false,"fork":false,"pushed_at":"2026-06-08T21:06:09.000Z","size":92,"stargazers_count":31,"open_issues_count":2,"forks_count":9,"subscribers_count":2,"default_branch":"main","last_synced_at":"2026-07-29T21:05:21.912Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/fabionoth.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2024-10-08T18:37:51.000Z","updated_at":"2026-07-25T23:45:19.000Z","dependencies_parsed_at":"2025-08-05T14:15:56.605Z","dependency_job_id":null,"html_url":"https://github.com/fabionoth/awesome-web3-security","commit_stats":null,"previous_names":["fabionoth/awesome-web3-security"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/fabionoth/awesome-web3-security","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fabionoth%2Fawesome-web3-security","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fabionoth%2Fawesome-web3-security/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fabionoth%2Fawesome-web3-security/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fabionoth%2Fawesome-web3-security/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/fabionoth","download_url":"https://codeload.github.com/fabionoth/awesome-web3-security/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/fabionoth%2Fawesome-web3-security/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36761116,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-06T04:43:03.162Z","status":"online","status_checked_at":"2026-08-18T02:00:06.197Z","response_time":52,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"created_at":"2024-10-31T08:25:04.017Z","updated_at":"2026-08-18T08:00:24.358Z","primary_language":null,"list_of_lists":false,"displayable":true,"categories":["\u003ca name=\"databases\"\u003e Databases/Books and References","\u003ca name=\"playgrounds\"\u003e Playgrounds","\u003ca name=\"bugbounty\"\u003e BugBounty","\u003ca name=\"tools\"\u003e\u003c/a\u003e Tools","\u003ca name=\"ctf\"\u003e CTF","\u003ca name=\"standards\"\u003e Standards"],"sub_categories":["\u003ca name=\"others\"\u003e Other tools","\u003ca name=\"sast\"\u003e SAST/DAST/Unity Test Analysis","\u003ca name=\"os\"\u003e OS","\u003ca name=\"testing\"\u003e Testing","\u003ca name=\"fuzzers\"\u003e Fuzzers","\u003ca name=\"forensics\"\u003e Forensics"],"readme":"# Awesome Web3 Security\n\n[![Awesome](https://cdn.rawgit.com/sindresorhus/awesome/d7305f38d29fed78fa85652e3a63e154dd8e8829/media/badge.svg)](https://github.com/sindresorhus/awesome)\n\nIt is a collection of awesome software, libraries, documents, books, resources, and cool stuff about **web3** security.\n\nThanks to all [contributors](https://github.com/fabionoth/awesome-web3-security/graphs/contributors). You're awesome. This wouldn't be possible without you! The goal is to build a categorized, community-driven collection of very well-known resources.\n\nList links and description \n* **[Tools](#tools)**\n  * [Forensics](#forensics)\n  * [Testing](#testing)\n  * [SAST/DAST/Unity Test Analysis](#sast)\n  * [OS](#os)\n  * [Fuzzers](#fuzzers)\n  * [Other tools](#others)\n* **[BugBounty](#bugbounty)**\n* **[CTF](#ctf)**\n* **[Playgrounds](#playgrounds)**\n* **[Standards](#standards)**\n* **[Databases/Books and References](#databases)**\n    \n\n## \u003ca name=\"tools\"\u003e\u003c/a\u003e Tools\n### \u003ca name=\"forensics\"\u003e Forensics\n* [abi-decompiler](https://github.com/Decurity/abi-decompiler) - The purpose of abi-decompiler is to implement a simple tools to recover ABI of EVM smart contracts, including function names.\n* [DeDaub](https://app.dedaub.com/decompile) - The Dedaub decompiler takes Ethereum Virtual Machine (EVM) bytecode and produces more readable Solidity-like code.\n* [Panoramix](https://github.com/palkeo/panoramix) -This is an EVM decompiler.\n### \u003ca name=\"testing\"\u003e Testing\n* [BSCheck](https://bscheck.eu/) - Free Binance Smart Chain token analyzer\n* [QuillCheck](https://check.quillai.network/) - Safeguard your web3 investments with our AI Agent. Uncover honeypots, understand token permissions, and get comprehensive market insights. Shield yourself from rugpulls and scam tokens. DYOR here!\n* [RektRadar](https://rektradar.io/) - Real-time Ethereum scam detector with mempool monitoring, deployer graph analysis, and factory pattern detection. Catches rug pulls mid-broadcast, flags honeypots before liquidity is added.\n* [Rugscreen](https://rugscreen.com/) - Catches rugpulls before you lose money.\n* [Sharpe Rug Check](https://www.sharpe.ai/rug-check) - Live token risk scanner for honeypot, liquidity, holder, ownership, and authority signals.\n* [TokenSniffer](https://tokensniffer.com/) - Automated scam detection, auditing, and metrics\n* [Rug PUll Detector](http://rugpulldetector.com/) - Find the smart contract of the token and copy solidity code\n### \u003ca name=\"sast\"\u003e SAST/DAST/Unity Test Analysis\n* [Brownie](https://eth-brownie.readthedocs.io/en/stable/) - Brownie is a Python-based development and testing framework for smart contracts targeting the Ethereum Virtual Machine.\n* [Ethereum Security Box](https://github.com/trailofbits/eth-security-toolbox) - This repository contains scripts to create a Docker container preinstalled and preconfigured with all of Trail of Bits’ Ethereum security tools.\n* [Foundry](https://github.com/foundry-rs/foundry) - Foundry is a blazing fast, portable and modular toolkit for Ethereum application development written in Rust.\n* [Hardhat](https://hardhat.org/) - Hardhat is a development environment for Ethereum software\n* [Manticore](https://github.com/trailofbits/manticore) - Manticore is a symbolic execution tool for the analysis of smart contracts and binaries.\n* [Mythril](https://github.com/ConsenSys/mythril) - Mythril is a security analysis tool for EVM bytecode\n* [Mythx](https://mythx.io/) - Create a MythX account, link your Ethereum address, and generate API keys\n* [Olympix](https://github.com/olympix) - Scanning for vulnerabilities, or automating test generation. \n* [Octopus](https://github.com/FuzzingLabs/octopus) - Octopus is a security analysis framework for WebAssembly module and Blockchain Smart Contract.\n* [Scribble](https://github.com/ConsenSys/scribble) - A Solidity runtime verification tool for property-based testing.\n* [Security2](https://github.com/eth-sri/securify2) - Securify 2.0 is a security scanner for Ethereum smart contracts supported by the Ethereum Foundation and ChainSecurity.\n* [Slither](https://github.com/crytic/slither) - Slither is a Solidity \u0026 Vyper static analysis framework written in Python3\n* [Surya](https://github.com/ConsenSys/surya) - Surya is an utility tool for smart contract systems. It provides a number of visual outputs and information about the contracts' structure.\n* [SmartCheck](https://github.com/smartdec/smartcheck) - SmartCheck is an extensible static analysis tool for discovering vulnerabilities and other code issues in Ethereum smart contracts written in the Solidity programming language.\n* [Truffle Suite](https://archive.trufflesuite.com/) - The most comprehensive suite of tools for smart contract development\n### \u003ca name=\"os\"\u003e OS\n* [ZIION](https://www.ziion.org/) - ZIION is the first open-source, end-to-end, pre-compiled, multi-architecture, multi-protocol blockchain security testing and development solution\n### \u003ca name=\"fuzzers\"\u003e Fuzzers\n* [ChainFuzz](https://github.com/ChainSecurity/ChainFuzz) - ChainFuzz requires a truffle project with correct migration files to fuzz a project.\n* [Echidna](https://github.com/crytic/echidna) - Echidna is a Haskell program designed for fuzzing/property-based testing of Ethereum smart contracts.\n* [Foundry](https://github.com/foundry-rs/foundry) - Foundry is a blazing fast, portable and modular toolkit for Ethereum application development written in Rust.\n### \u003ca name=\"others\"\u003e Other tools\n* [ETH-Toolbox](https://eth-toolbox.com/) - EthToolbox v1.1 is a set of useful tools for Ethereum developers.\n* [dethcode](https://github.com/dethcrypto/dethcode) - View source of deployed Ethereum smart contracts in VS Code\n* [GetBlock](https://getblock.io/) - a Blockchain-as-a-Service (BaaS) platform that provides a fast and easy API connection to RPC full nodes for 50+ blockchains.\n* [TWZRD Agent Intel](https://intel.twzrd.xyz) - On-chain trust scoring for AI agent wallets on Solana. MCP server for verifying agent wallet identity and behavioral history before x402 micropayments — identity layer for autonomous AI agents operating in Web3. [MCP](https://intel.twzrd.xyz/mcp)\n## \u003ca name=\"bugbounty\"\u003e BugBounty\n* [Hacken Proof](https://hackenproof.com/) - Expert web3 bug bounty and crowdsourced audit platform\n* [Immunefi](https://immunefi.com/) - Web3's bug bounty platform\n## \u003ca name=\"ctf\"\u003e CTF\n* [blocksec-ctfs](https://github.com/blockthreat/blocksec-ctfs) - A curated list of blockchain security Wargames, Challenges, and Capture the Flag (CTF) competitions and solution writeups.\n* [Capture the Ether](https://capturetheether.com/) - the game of Ethereum smart contract security\n* [CryptoHack](https://cryptohack.org/) - A free, fun platform for learning modern cryptography\n* [ciphershastra](https://ciphershastra.com/) - A place where you can enhance your Security Skills by solving and learning from CTF-like challenges.\n* [Damn Vulnerable DeFi](https://www.damnvulnerabledefi.xyz/) - The training ground for security researchers, developers and educators to dive into smart contract security.\n* [Hack the TON](https://www.hacktheton.com/) - Hack the TON is a TON based wargame inspired by The Ethernaut, played in the TON Virtual Machine.\n* [The Ethernaut](https://ethernaut.openzeppelin.com/) - The Ethernaut is a Web3/Solidity based wargame inspired by overthewire.org\n## \u003ca name=\"playgrounds\"\u003e Playgrounds\n* [Remix Ethereum](https://remix.ethereum.org/) - No more words. Everybody knows Remix\n* [Rust Playground](https://play.rust-lang.org/) - The Rust Playground\n* [TON Network Playground](https://ide.ton.org/) - TON Network IDE\n## \u003ca name=\"standards\"\u003e Standards\n* [ERC 20](https://ethereum.org/en/developers/docs/standards/tokens/erc-20/) - The ERC-20 introduces a standard for Fungible Tokens, in other words, they have a property that makes each Token be exactly the same (in type and value) as another Token.\n* [OWASP Smart Contract](https://owasp.org/www-project-smart-contract-top-10/) - The OWASP Smart Contract Top 10 is a standard awareness document that intends to provide Web3 developers and security teams with insight into the top 10 vulnerabilities found in smart contracts.\n## \u003ca name=\"databases\"\u003e Databases/Books and References\n* [Chainlist](https://chainlist.org/) - Helping users connect to EVM powered networks\n* [REKT](https://rekt.news/leaderboard/) - Rekt News is a leading online platform offering timely and concise information on decentralized finance (DeFi), blockchain, and the cryptocurrency industry\n* [Smart Contract Security Chapter](https://github.com/ethereumbook/ethereumbook/blob/develop/09smart-contracts-security.asciidoc) - Chapter 9 from Ethereum book.\n\n","projects_url":"https://awesome.ecosyste.ms/api/v1/lists/fabionoth%2Fawesome-web3-security/projects"}