Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

Awesome Lists | Featured Topics | Projects

https://github.com/chainflag/awesome-blockchain-security

A curated list of awesome things related to Blockchain security
https://github.com/chainflag/awesome-blockchain-security

List: awesome-blockchain-security

Last synced: about 1 month ago
JSON representation

A curated list of awesome things related to Blockchain security

Awesome Lists containing this project

README

        

# awesome-blockchain-security

## Blogs

- [Security | Ethereum Foundation Blog](https://blog.ethereum.org/category/security/)
- [OpenZeppelin blog](https://blog.openzeppelin.com/)
- [Blockchain | Trail of Bits Blog](https://blog.trailofbits.com/category/blockchain/)
- [Consensys Diligence Blog](https://consensys.net/diligence/blog/)
- [PeckShield Inc. Blog](https://blog.peckshield.com/)
- [Seebug blockchain](https://paper.seebug.org/category/blockchain/)
- [Emin Gün Sirer](https://hackingdistributed.com/)
- [Phil Does Security](https://pdaian.com/blog/)
- [samczsun](https://samczsun.com/)
- [cmichel](https://cmichel.io/ )

## CTFs

- [Ethernaut](https://ethernaut.openzeppelin.com/)
- [Capture the Ether](https://capturetheether.com/challenges/)
- [EtherHack](https://etherhack.positive.com/#/)
- [Security Innovation Blockchain CTF](https://blockchain-ctf.securityinnovation.com/)
- [Damn Vulnerable DeFi](https://www.damnvulnerabledefi.xyz/)
- [Paradigm CTF - 2021](https://github.com/paradigm-operations/paradigm-ctf-2021)
- [Defihack](https://www.defihack.xyz/)

## Solidity Security References

- [SWC Registry](https://swcregistry.io/)
- [Decentralized Application Security Project](https://www.dasp.co/)
- [Solidity Security Considerations](https://docs.soliditylang.org/en/latest/security-considerations.html)
- [Ethereum Smart Contract Security Best Practices](https://consensys.github.io/smart-contract-best-practices/)
- [Examples of Solidity security issues](https://github.com/crytic/not-so-smart-contracts)

## Public Blockchain Vulnerabilities

- [Go Ethereum Security Advisories](https://github.com/ethereum/go-ethereum/security/advisories)
- [Bitcoin CVE wiki](https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures)
- [Bitcoin CVE list](http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=bitcoin)
- [Bitcoin Weaknesses](https://en.bitcoin.it/wiki/Weaknesses)
- [Ethereum Foundation Vulnerability Disclosures](https://github.com/ethereum/public-disclosures/)

## Incidents

- [Blockchain Graveyard](https://magoo.github.io/Blockchain-Graveyard/)
- [Blocksec Incidents](https://github.com/m4xx101/blocksec-incidents)

## Tools

- [EthTx Transaction Decoder](https://ethtx.info/)
- [Ethereum Virtual Machine Opcodes](https://www.ethervm.io/)
- [Ethereum Signature Database](https://www.4byte.directory/)
- [Eveem.org Decompiler](https://eveem.org/)
- [Dune Analytics](https://dune.xyz/home)
- [Security Tools](https://consensys.github.io/smart-contract-best-practices/security-tools/)
- [Bloxy](https://bloxy.info/)
- [Tenderly](https://dashboard.tenderly.co/)
- [Tutela](https://tutela.xyz/)

## Audit reports

- [Trail of Bits](https://github.com/trailofbits/publications)
- [OpenZeppelin](https://blog.openzeppelin.com/security-audits/)
- [Consensys Diligence](https://consensys.net/diligence/audits/)
- [Blockchain Security Database](https://consensys.github.io/blockchainSecurityDB/)
- [Quantstamp](https://certificate.quantstamp.com)
- [Slowmist](https://github.com/slowmist/Knowledge-Base/tree/master/open-report)
- [PeckShield](https://github.com/peckshield/publications/tree/master/audit_reports)
- [Arcadia Group](https://arcadiamgroup.com/audits/audit.html)
- [Mixbytes](https://github.com/mixbytes/audits_public/)

## Forums

- [StackExchange Ethereum Security](https://ethereum.stackexchange.com/questions/tagged/security)

## Bug Bounty Platform

- [ETHEREUM Bounty Program](https://bounty.ethereum.org/)
- [Immunefi](https://immunefi.com/)
- [SlowMist Zone](https://www.slowmist.io/)
- [Code4rena](https://code4rena.com/)

### Bug Bounty in Hackerone

- [Monero](https://hackerone.com/monero) *(All reports have been disclosed)*
- [Tron](https://hackerone.com/tronfoundation)
- [Hyperledger](https://hackerone.com/hyperledger)
- [Tendermint](https://hackerone.com/tendermint)
- [Coinbase](https://hackerone.com/coinbase)
- [BitMex](https://hackerone.com/bitmex)
- [Crypto.com](https://hackerone.com/crypto)
- [MyEtherWallet](https://hackerone.com/myetherwallet)
- [Blockchain](https://hackerone.com/blockchain)