Blog
Web3 security, written by people who audit it
Audit case studies, protocol deep-dives, and security fundamentals. Every article ties back to a hands-on module you can rebuild yourself.
Web3 Foundations (57)
Address poisoning: the lookalike address that drains you
Address poisoning plants a lookalike address in your transaction history so you copy the wrong one. Here is how the $68M WBTC attack worked and how to never fall for it.
Approval phishing: how one signature drains your whole wallet
A security auditor explains approval phishing: how approve, increaseAllowance, and setApprovalForAll get abused, why the drain lands later, and how to revoke.
ClickFix explained: the fake CAPTCHA that hijacks your PC
A security auditor explains ClickFix: the fake 'verify you are human' prompt that copies a command to your clipboard and asks you to paste it into your terminal. Here's how to stop it.
The fake job crypto scam: how a take-home repo drains you
A security auditor breaks down the fake job crypto scam (aka Contagious Interview): the recruiter, the take-home repo, the npm install that fires a stealer, and how to stay safe.
How Web3 Users Actually Get Hacked (It's Not the Code)
The biggest crypto losses don't come from smart-contract bugs — they come from tricking a person into signing, running, or pasting something. Here's the human-layer playbook, attack by attack.
Permit phishing: how a gasless signature drains your wallet
A security auditor breaks down permit and signature phishing: how EIP-2612 permit and Permit2 turn a gasless sign-in into a full drain, and how to stay safe.
Pig butchering: how the slow-con investment scam works
Pig butchering is a long-con investment scam: a stranger warms you up for weeks, moves you to a fake trading platform showing fake gains, then blocks your withdrawal behind a fee. Here is the anatomy and the one tell that ends it.
Seed phrase phishing: how fake breach alerts steal wallets
Seed phrase phishing tricks you into typing your 12 or 24 recovery words into a fake site, app, email, or QR letter. Here is how each version works and the one rule that stops all of them.
Wallet drainers: how one signature empties your wallet
Wallet drainers are rented phishing kits that empty your wallet with a single malicious signature. Here is how drainer-as-a-service works and the setup that stops it.
Concentrated Liquidity Explained: How Uniswap v3 Made LPing a Job
What concentrated liquidity is, how Uniswap v3 ranges work, why out of range means zero fees and a fully converted position, and the honest trade: capital efficiency for management burden.
Crypto Airdrops and Points Explained: The Farming Meta From Both Sides
How crypto airdrops and points programs actually work: retro airdrops, farming, sybils, and why airdropped tokens sell off, read honestly from both the user's and the protocol's side.
Crypto Leverage: What 10x Really Means (and Why Liquidation Is Final)
Leverage means borrowed size on top of your own deposit. What 10x does to your risk, where the liquidation line sits, why the venue closes your position automatically, and why that sale is final.
Crypto Market Cycles Explained: Halvings, Alt Seasons, and Rotation
Money enters crypto in stages: Bitcoin first, then outward until alt season, then the retreat. How halvings, dominance, and narratives fit together, and where the pattern stops being reliable.
Money Legos: How DeFi Protocols Stack (and What Each Layer Risks)
Composability, or money legos, explained through one real stack: ETH staked for stETH, stETH as loan collateral, borrowed dollars providing liquidity. What each layer earns, promises, and who pays.
DeFi Governance Explained: What Token Votes Actually Control
The five levers DeFi token votes really control, fee switches, collateral listings, emissions, treasuries, and parameters, plus a thirty second test that tells a real decision from decoration.
DeFi Liquidations Explained: Health Factors, Bounty Bots, and Cascades
How DeFi liquidations actually work: the health factor on every loan, the bounty that makes strangers close failing positions in seconds, and why one red hour of forced selling feeds on itself.
Vaults, Aggregators, and Intents: DeFi's Convenience Layer Explained
Yield vaults, DEX aggregators, and intent-based trading explained: what each one automates, what it charges in fees and invisible spreads, and the three questions to ask before you delegate.
Looping, Delta-Neutral, and the Basis Trade, Explained Simply
The three yield strategies professional DeFi desks actually run, looping, delta-neutral, and the basis trade, taken apart: what each earns, who really pays it, and the exact step where each one burns.
How AMMs Work: The Formula That Replaced the Order Book
How automated market makers price trades with one formula: the balance scale behind Uniswap, why big trades cost more, and who quietly pays to keep a blind machine honest.
How Crypto Markets Work: Order Books, Spreads, Market Makers
What happens in the half second after you press buy: standing orders, the order book, spreads, market makers, slippage, and why nobody sets the price. The same machine runs Wall Street and Binance.
How DeFi Lending Works: Collateral, Utilization, and Rates Set by Code
How Aave-style lending markets size loans with collateral instead of credit scores, why the interest rate is a thermostat rather than a price list, and who actually pays whom in DeFi lending.
How to Analyze a DeFi Protocol in 20 Minutes: Docs, DefiLlama, Dune
A security auditor's four-stop route for reading any DeFi protocol cold: the docs, DefiLlama, Dune, and the token page. Twenty minutes to know what the machine is and who pays whom.
How to Get Into DeFi: Six Lanes and Your First 90 Days
Six realistic ways into DeFi, trader, LP, analyst, governance participant, builder, and allocator, with a concrete zero-risk first practice for each and honest guidance on where to start.
How to Read Crypto Charts: Candles, Volume, Depth, No Mysticism
Candles, volume, depth, and liquidity explained as gauges that describe the present, not the future. How to read a crypto chart like a pilot reads a cockpit, minus the mysticism.
TVL, APY, and FDV: How to Read DeFi Metrics Like an Analyst
What TVL, APY, volume, and FDV actually measure, the specific ways each number gets dressed up, and the three questions analysts ask before trusting any DeFi dashboard.
Impermanent Loss Explained: When LPing Beats Holding (and When Not)
What impermanent loss really is: how a liquidity pool rebalances through you, why the name lies twice, and the fees-minus-gap ledger that decides whether LPing beats just holding.
Liquid Staking Explained: stETH, LSTs, Restaking, and DeFi's Base Rate
What liquid staking is, how stETH pays you, why receipts can trade below the stake they represent, what restaking stacks on top, and why staking yield is the number every DeFi yield answers to.
Perpetual Futures Explained: Funding, Open Interest, and Why Perps Won
Perpetual futures drive most crypto trading volume. A plain-English guide to how perps work, why funding rates exist, who actually pays them, and what open interest really measures.
The 4 Types of Stablecoins (and What Actually Holds Each Peg)
Fiat backed, CDP, synthetic, and algorithmic stablecoins compared: what actually stands behind each design, who holds the peg day to day, and the three questions that sort any coin you meet.
ve-Tokenomics Explained: Locks, Gauges, Bribes, and the Curve Wars
How ve-tokenomics works: why protocols lock voters in, how gauge votes steer token emissions, why bribes are paid on public dashboards, and what the Curve wars proved about governance.
What Is a Perp DEX? Order Books, Vaults, and Who Takes the Other Side
How perp DEXs work, explained through one question: who takes the other side of your trade? Order book venues like dYdX and Hyperliquid vs vault models like GMX, and what each decides for you.
What Is Slippage in Crypto? Trading From Your Own Wallet, Explained
Slippage is the gap between the price you see and the price you get on a swap. What slippage tolerance actually controls, why failed swaps still cost gas, and who profits when you set it loose.
Where Does DeFi Yield Actually Come From? The Five Sources
Every DeFi yield flows from one of five sources: service fees, network issuance, counterparty losses, emissions, or subsidy. Learn to name who is paying before trusting any APY.
CEX vs DEX: What's the Difference and Which Should You Use?
CEX vs DEX explained in plain English. A security auditor breaks down where your money actually goes on each, why withdrawal is the moment of truth, and when to use which.
The 5 Most Common Crypto Scams (and How to Spot Them)
A security auditor breaks down the 5 most common crypto scams, the fixed anatomy of each, and the one shared trick under all of them so you can avoid them.
Crypto Assets Explained: Coins, Tokens, Stablecoins, and NFTs
The types of crypto assets explained simply. A security auditor breaks down coins vs tokens, stablecoins, governance tokens, and NFTs, so you can name any asset on sight.
Crypto Twitter Decoded: Culture, Slang, and How Narratives Move Money
Crypto slang and Crypto Twitter explained by a security auditor. Learn the words, how narratives move money before facts, how to spot a shill, and how the industry hires.
Who's Who in Crypto: The Players Behind Every Transaction
The crypto ecosystem explained in plain English. A security auditor maps who the major players are, what each does, and how one dollar travels through them.
How to Stay Safe in Crypto: Security Is a Decision, Not a Checklist
How to stay safe in crypto without a rulebook. A security auditor shows why safety is a judgment you make every time you sign, and the questions to ask first.
Crypto Wallets Explained: Keys, Seed Phrases, and Staying Safe
A security auditor explains how crypto wallets really work: a wallet holds keys, not coins, one seed phrase controls everything, and the safety rules that follow.
Where Is Crypto Heading? Institutions, Real-World Assets, and AI Agents
The future of crypto, explained without hype. A security auditor breaks down the three real currents moving Web3 and how to tell a durable shift from a passing narrative.
How Does a Blockchain Actually Work? A Plain-English Guide
How does blockchain work? A security auditor explains the shared ledger thousands of strangers keep honest, why cheating it is a losing trade, and what a block really is.
What Happens When You Send Crypto? Gas Fees and Transactions Explained
How do crypto transactions work? A security auditor explains what happens from tap to final, why gas fees exist and spike, and how to read a block explorer.
How to Earn in DeFi (and Spot Fake Yield Before It Takes Yours)
How to earn yield in DeFi explained plainly. A security auditor shows the honest ways money earns on-chain and the one question that exposes fake yield: who pays?
How to Break Into Web3: 5 Career Lanes for Beginners
How to get into Web3 as a beginner: the five career lanes (developer, auditor, founder, investor, community), the first free public move in each, and an honest fit test.
How to Research a Crypto Project (DYOR) in 10 Minutes
How to DYOR fast. A security auditor's ten-minute method to research any crypto project, the red flags each lens surfaces, and the disqualifiers that end your look early.
Layer 1 vs Layer 2: Why There Are So Many Blockchains
Layer 1 vs Layer 2 explained in plain English. Why so many blockchains exist, what a Layer 2 does for you, and why bridges are where the worst hacks happen.
Tokenomics Explained: How to Read a Token Before You Touch It
Tokenomics explained in plain English. A security auditor shows you how to read a token's supply, unlocks, and incentives to spot the patterns that quietly drain price.
What Are NFTs, Really? Digital Ownership Explained for Beginners
NFTs explained without the hype. A security auditor breaks down what an NFT actually is, why the 2021 mania happened, and how to tell a real use from noise.
What Are Stablecoins? How They Hold a Dollar (and How They Break)
Stablecoins explained by a security auditor: what holds a coin at one dollar, the three types, why one type died, and how a blockchain learns a real price.
What Is a DAO? On-Chain Governance Explained Simply
A DAO explained in plain English. A security auditor breaks down how strangers run a shared treasury, how a vote becomes an action, and where governance quietly fails.
What Is a Smart Contract? (And Why "Immutable" Doesn't Mean "Safe")
A smart contract is a vending machine that runs itself and holds real money. A security auditor explains how they work, why immutable isn't safe, and what an audit is.
What Is DeFi? How Decentralized Finance Actually Works
DeFi explained in plain English. A smart contract auditor breaks down how decentralized finance rebuilds bank functions with no company behind the counter.
What Is MEV? The Invisible Games Played on Your Trades
MEV explained for beginners. A security auditor shows what happens to your trade while it waits in public, who is watching it, and how to stop being easy prey.
What Is Web3? A Plain-English Guide for Complete Beginners
Web3 explained without the hype. A security auditor breaks down what Web3 actually is, how it differs from today's internet, and how to tell what's real from what's a scam.
Why Beginners Lose Money in Crypto (and How to Stop)
A security auditor explains why beginners lose money in crypto, the psychology behind buying high and selling low, and the boring habits that flip the odds.
Why Do Crypto Protocols Get Hacked? A Beginner's Explanation
Most crypto hacks aren't break-ins. A security auditor explains, in plain English, how protocols really lose money and how to read a project's security posture.
The Build (14)
The Case for Rebuilding Protocols Line by Line (Instead of Forking)
Forking a protocol ships code you don't understand. Rebuilding from scratch with a test suite as forcing function teaches what every defensive choice exists for.
Why Compound V2's Close Factor Caps Liquidations at 50%
Compound V2 caps single-liquidation seizure at 50% of borrower debt. Why partial liquidations beat one-shot total liquidations, and the trade-offs.
The Compound V2 Jump Rate Model: Why the Kink Is at 80% Utilization
Compound V2's interest rate curve is piecewise linear with a kink at 80% utilization. The math, the parameters, and the economic rationale for each piece.
Lazy Interest Accrual: How Compound V2 Scales to Millions of Borrowers
Compound V2 accrues interest in O(1) per market, no matter how many borrowers exist. The trick is a global borrowIndex plus per-account snapshots. Walking through the math and what forks get wrong.
accountLiquidity(): Where Compound V2 Audit Findings Cluster
Almost every critical bug in a Compound V2 fork lives in or around accountLiquidity(). Why this single function attracts oracle, exchange-rate, mantissa, and overflow risks all at once.
Why Compound V2's Oracle Returns Zero (and That's a Security Feature)
When the oracle returns zero, every borrow and liquidation in that market reverts. That is not a bug. It is the safest possible failure mode, and the alternative cost Mango $114M and Cream $130M.
How Uniswap V2's Protocol Fee Works (LP Dilution, Not Per-Swap)
Uniswap V2's protocol fee is 1/6th of K growth, paid as LP token dilution at the next mint or burn. Why this design saves gas, and the math that drives it.
UQ112x112: How Uniswap V2's TWAP Math Actually Works
Uniswap V2's UQ112x112 fixed-point format encodes prices as 224-bit values for the TWAP oracle. Why 112 integer + 112 fractional, and how the math preserves precision.
skim() and sync(): The Uniswap V2 Functions That Look Optional, Aren't
Why Uniswap V2 has skim() and sync() helpers, what donation attacks become possible without them, and why integrators reading reserves directly need to understand both functions.
Why Uniswap V2's Timestamp Wraps in 2106 (and Why It's a Feature)
Uniswap V2 packs block.timestamp into uint32, which wraps to zero on January 19, 2106. The TWAP oracle keeps working across the wrap because modular subtraction handles it for free.
Same Function, Opposite Arithmetic: Uniswap V2's _update()
Inside Uniswap V2's _update(), reserve writes must revert on overflow, but the price accumulator math must allow it. Why Solidity 0.8 makes this trickier than it looks.
How Uniswap V2 Saves 2100 Gas Per Swap with Storage Packing
Uniswap V2 packs reserve0, reserve1, and blockTimestampLast into a single 256-bit storage slot. The math, the tradeoffs, and why this is the most consequential gas optimization in DeFi.
Uniswap V2's 1000-Wei Minimum Liquidity Lock, Explained
Why Uniswap V2 burns 1000 wei of LP tokens forever on the first mint of any pair. The attack it prevents, the code that implements it, and what happens to forks that strip it.
The _mintFee() Ordering Bug in Uniswap V2 Forks
In Uniswap V2's mint() and burn(), _mintFee() must run before reading totalSupply. Reverse the order and you silently dilute the protocol fee recipient on every liquidity event.
Shadow Arena (8)
Flux Finance's KYC Signature Replay: EIP-712 Without a Nonce
Flux Finance's KYC verification uses EIP-712 signatures but omits the nonce. Once signed, the same KYC approval can be replayed indefinitely.
Canto v2's Oracle Mantissa Confusion: 1 vs 1e18
Canto v2's oracle uses a 1 mantissa where Compound V2 expects 1e18. The result: 18-decimal-place errors in liquidation math. A pattern that recurs in cross-chain forks.
How Basin's Pump-Encoding Code Produced Four Distinct Bug Classes
Basin's low-level bit-packing produced 4 documented bugs in Shadow Arena: off-by-one, slot confusion, bit-shift, and a missed update. One subsystem, four lessons.
Velodrome's Reward System: Three Permanent-Lock Paths in One Subsystem
Velodrome (Solidly fork on Optimism) has three documented permanent-lock bugs in its bribe-distribution code. Same subsystem, three different mechanisms. Every Solidly descendant inherits them.
33% of Bugs in 6 Real Audit Targets Are 'Missed State Updates'
Across 63 documented findings in Zealynx Academy's Shadow Arena, the dominant bug class isn't reentrancy or oracle manipulation. It's missed state updates in conditional paths.
Fee-on-Transfer Tokens Break 3 of 6 Shadow Arena Audit Targets
How fee-on-transfer tokens silently break accounting in DeFi protocols. Pattern, real findings from Basin and Velodrome, and the one-line fix most teams miss.
How Venus Inherited a 5x Interest Inflation Bug When Forking Compound to BSC
Compound V2 hardcodes blocksPerYear = 2,102,400 (15-second blocks). BSC has 3-second blocks. Forking the constant unchanged turns a 5% APR market into a 25% APR one. The Venus H-01 finding, walked through.
The Compound V2 Fork Donation Attack: 3 of 6 Shadow Arena Targets Have It
Three of six audit targets in the Zealynx Academy Shadow Arena are Compound V2 forks, and all three share the same cToken exchange-rate manipulation. Walking through the attack, the math, and why $7M of Hundred Finance proved the design is fragile under fork.
AI Auditor Builder (6)
Why Domain-Tuned AI Auditors Beat Generic Ones (DEX, Lending, Staking, Governance)
Generic AI auditors plateau in precision. Loading domain primers (DEX, lending, staking, governance) with category-specific exploits and checklists is what closes the gap.
The Multi-Mindset Pattern: Attacker, Accountant, Spec Auditor, Edge-Case Hunter
Running 4 specialized AI auditor roles in parallel surfaces bug classes that single-pass auditors miss. How to structure the prompts and synthesize the findings.
How Krait Achieves 100% Precision Across 50 Blind Code4rena Contests
The single biggest reason teams stop trusting AI security tools is false positives. Krait was built around eight kill gates that filter every candidate finding before it reaches the report.
The AI Auditor Arena: Benchmarking Against 118 Real Code4rena Findings
Most AI auditor benchmarks use toy code with planted bugs. The Arena uses 118 real Code4rena findings (41 High, 77 Medium) across 10 contests and 19,200 lines of Solidity. Submit your auditor and get a precision and recall score.
27 Open-Source AI Audit Tools, 7 Architectural Patterns, One Choice You Probably Haven't Made
AI smart contract auditing tools cluster into 7 architectural patterns. Each has a different failure mode. Most teams adopt one without knowing which they picked.
An AI Auditor Without Exploit Context Is a Security Guard Who's Never Seen a Break-In
Why generic AI security agents plateau and domain-tuned ones keep improving. The specific exploits that turn pattern matching into pattern recognition: DAO, Cream, Curve, Mango, Inverse, Bonq.
eMBA (8)
Progressive Decentralization: A Three-Stage Model for Web3 Founders
a16z's three-stage model adapted for crypto: PMF, community development, sufficient decentralization. When to move between stages and where teams get stuck.
55% of Web3 Teams Have No Incident Response Playbook (Here's Yours)
Most teams discover their IR gap mid-incident. A playbook turns chaos into checklists. The five sections every Web3 IR plan needs.
Security Budget by TVL Tier: What to Spend on Audits, Monitoring, and Bounties
Web3 security budget is not a fixed line item. It scales with TVL. A tiered framework from <$1M to $100M+ with allocation across pre-launch audit, monitoring, and bug bounty.
Terra/Luna's Death Spiral: $40B Destroyed by Mechanism Design, Not Code Bugs
Terra/Luna's collapse cost $40B. The bug wasn't in the code; it was in the mechanism. A case study in why design-level failures dwarf code bugs.
Token Price Is Not Revenue: A Web3 Founder's Mental Model
If your protocol's only business model is that the token appreciates, you don't have a business. How to reason about value capture before tokenomics.
The First Hire for a Web3 Founder Isn't a Community Manager. It's Operations.
Conventional wisdom says CM. Contrarian and correct says ops. Web3 founders are strong on code or vision and weak on the 80% of company-building that is neither. Plus: the 10-Day Rule for crypto hiring and Dragonfly's 2024-2025 comp data.
Monitoring Beats the First Audit: How Ronin Lost $624M Undetected for Six Days
Ronin Bridge was exploited and the loss went undetected for six days. With basic monitoring on cross-chain transfer volumes against a 24-hour rolling baseline, the alert fires within 90 minutes. Here's the budget allocation that follows.
The Audit Paradox: 91.96% of Hacked Smart Contracts Were Audited
AnChain.ai, Olympix, and Halborn data show audited contracts get hacked nearly as often as unaudited ones. Euler had 10 audits from 6 firms before losing $197M. Audits are necessary, but a strategy needs more.
Security Fundamentals (6)
Trust Assumptions in Smart Contract Audits: Fully vs Semi-Trusted Actors
Audit severity isn't a fixed property. It depends on whether the actor abusing the issue is fully trusted (governance multisig) or semi-trusted (admin, operator, oracle).
EVM Storage Layout: Why Slot Packing Matters for Both Gas and Security
EVM storage uses 32-byte slots. Slot packing saves gas. Storage collisions break upgradeable contracts. The mental model every Solidity developer needs.
Flash Loans and Security: What Changes When Capital Is Free
Flash loans amplify oracle manipulation, governance attacks, and accounting drift. Real exploits, defensive patterns, and what to check when auditing a protocol that allows them.
Why Public-Goods Funding Matters for Web3 Security
Open security tools, education platforms, audit infrastructure: under-funded by markets, over-relied-upon by the ecosystem. The funding mechanisms that work and the ones that don't.
Quadratic Funding Mechanics: How $5 from 100 Donors Beats $500 from 5
Quadratic funding's matching formula rewards breadth of support over size of donation. The math, the rationale, and why it matters for public goods funding in Web3.
Reentrancy Explained, 2026 Edition (After Curve, Cream, and DAO)
Reentrancy in 2026 is not just the DAO bug. Three flavors, three defenses, and why the Curve Vyper bug expanded the attack surface beyond what most auditors model.
Comparisons (3)
Code4rena vs Self-Directed Security Training: Which Path Is Right for You?
Audit contests and self-directed training are different learning modes, not substitutes. When to compete on Code4rena, when to grind in Shadow Arena, and why most pros do both.
Should You Fork Uniswap or Build From Scratch?
Forking gets you to market in days. Building from scratch teaches you what every line does. The decision framework for when each is right, with cautionary tales.
Zealynx Academy vs Cyfrin Updraft: Honest Side-by-Side
Two of the leading free Web3 security education platforms have very different teaching philosophies. Where each fits, what they share, and what's unique to each.