Joran Honig

      • ⚔️ Quest - The Basics of DeFi
      • 🛣️ Path - The Ultimate Path to DeFi security research
      • Path Quest - A Crashcourse in Economics
      • Path Quest - The Attacker Mindset
      • 3 Activities to Make You a Better Bug Hunter
      • 3 Mistakes I Made When I Started Bounty Hunting
      • 3 Reasons Why You Should Publish Your Security Research
      • 3 strategies to get into hunting bugs in smart contracts
      • 3 Ways to Write a Proof of Concept
      • 4 Strategies for picking the perfect bounty hunting targets
      • A Perfect Balance Between Practice and Execution.
      • Becoming a web 3 security researcher: Balancing foundations and the attacker mindset.
      • Bounties & Two Sided Reputation
      • Decoding the Y Combinator: A Deep Dive into Recursion
      • Don't Ignore Oracle Extractable Value!
      • Game Theory - Exploiting Superior Knowledge
      • Getting familiar with systems thinking, modelling and cadCAD
      • Hunting For Bugs: Top Idea in Your Mind
      • Introduction into Mutation Testing
      • micro - Work on your tools
      • Moving to a digital garden
      • Mutation Testing for Smart Contracts - A step by step guide
      • Parse Solidity incrementally using tree-sitter
      • Properties vs Fuzz tests
      • Security Analysis - Diving into Dataflow Analysis and Reaching Definitions
      • Shift Left and DevSecOps - What does it even mean?
      • SirenMarkets V1 - Getting Free Leverage with a Block Stuffing Attack
      • Sleuthing Toolbox - Everything you need to reverse engineer web3 hacks!
      • Stealing all your secrets using IPFS Mounts
      • Ultimate list of Common DeFi Component Types
      • You Should Look for Game Theory Bugs
      • aeropress
      • Assurance Contract
      • Attacker Mindset
      • blind mempool injection
      • Bounty Hunting with Indicators
      • Bug Bounty Discussions - Moving the goalposts
      • Bug Hunting from the Terminal
      • Competitive Audit Economics
      • concentrated liquidity - sticky tick boundaries
      • cultivation
      • digital garden
      • Dominant Assurance Contract
      • Effort Budgeting
      • elo rating system
      • Flashbots
      • Flashbots Blind Backrunning
      • Flashbots Blind Frontrunning Attack
      • Flashbots Block Reward Sidechannel
      • Generation Effect
      • Goblins - Object Programming
      • halstead volume
      • Hanlon's razor
      • Hydroponics
      • Jubensha
      • Minimalistic Software
      • Myerson-Satterthwaite theorem
      • Offensive AI
      • ranking system
      • RLHF
      • Rogue public key attack
      • Signature Replay Attacks
      • Smart Contract Security and AI
      • solar punk
      • Structure and Interpretation of Computer Programs
      • trueskill
      • vim
      • Blockchain Bug Write-ups
    Home

    ❯

    Blockchain Bug Write-ups

    Blockchain Bug Write-ups

    Mar 04, 20241 min read

    I’ve aggregated a bunch of bug write-ups and post-mortems:

    2024

    • https://medium.com/immunefi/stacks-dos-bugfix-review-dc0f2a75b276
      • write-up quality: ⭐⭐ replicability: ⭐⭐⭐
      • tl;dr simple inappropriate error handling causing an unexpected exception in the vm

    2023

    • Post mortem: April 3rd, 2023 mev-boost relay incident and related timing issue - The Flashbots Ship
    • Vyper Nonreentrancy Lock Vulnerability Technical Post-Mortem Report - HackMD
    • Squashing a Pesky Bug in UniswapX :: Kebabsec
    • Rate manipulation in Balancer Boosted Pools — technical postmortem | by Juani
    • Ease - governance contract vuln
    • A thought experiment about empty ERC-4626 vaults that ended up making this white hat $33,500
    • A unique $100,000 bug in SiloFinance and Silo Finance Logic Error Bugfix Review
    • Halting and disabling the Cronos Gravity Bridge
    • Inside the Governance Hack of Tornado Cash
    • KyberSwap Hack Analysis and KyberSwap - REKT
    • ERC-4626 vault inflation attack
    • Euler Compromise Investigation Part 1 and Part 2
    • Vyper compiler bug involving incorrect success values
    • Saving $100M at risk in KyberSwap Elastic
    • Arbitrary Address Spoofing Attack: ERC2771Context Multicall Public Disclosure
    • The Billion Dollar Exploit: Collecting Validators Private Keys via Web2 Attacks

    📚 Resources

    • Open Zeppelin’s top 2023 bug writeups source
    • Blockthreat

    Graph View

    • 2024
    • 2023
    • 📚 Resources
    • GitHub