Concept Lab and security quizzes
Apply important concepts to realistic decisions. Test the reflex, see the explanation, and carry the method into your own work.
Concept Lab
Scenario-based practice for core Security, Builders, Founders, AI Security, and Resources concepts.
Account Abstraction
Follow one realistic Account Abstraction case from recognition through transfer.
Active Liquidity
Follow one realistic Active Liquidity case from recognition through transfer.
Address Mining
Follow one realistic Address Mining case from recognition through transfer.
Aderyn
Follow one realistic Aderyn case from recognition through transfer.
Agent Goal Hijack
Follow one realistic Agent Goal Hijack case from recognition through transfer.
Approval Bypass
Follow one realistic Approval Bypass case from recognition through transfer.
Asynchronous Settlement
Follow one realistic Asynchronous Settlement case from recognition through transfer.
Audit Decay
Follow one realistic Audit Decay case from recognition through transfer.
Audit Readiness
Follow one realistic Audit Readiness case from recognition through transfer.
Confirmation Fatigue
Follow one realistic Confirmation Fatigue case from recognition through transfer.
Formal Verification
Follow one realistic Formal Verification case from recognition through transfer.
Fuzzing
Follow one realistic Fuzzing case from recognition through transfer.
Incident Response
Follow one realistic Incident Response case from recognition through transfer.
Invariant Testing
Follow one realistic Invariant Testing case from recognition through transfer.
Invariant
Follow one realistic Invariant case from recognition through transfer.
Memory Poisoning
Follow one realistic Memory Poisoning case from recognition through transfer.
Reentrancy Attack
Follow one realistic Reentrancy Attack case from recognition through transfer.
Technical Due Diligence
Follow one realistic Technical Due Diligence case from recognition through transfer.
Timelock
Follow one realistic Timelock case from recognition through transfer.
Tool Poisoning Attack
Follow one realistic Tool Poisoning Attack case from recognition through transfer.
Shadow Audits
Full audit debriefs from live sessions. The real findings, the false positives that trap good auditors, and the method that separates them.
Spot the Bug
One real vulnerability at a time. Catch it before the reveal. New ones drop with the daily ZLX-Check.
Spot the Bug: the bridge replay trap
A bridge verifies a signed message and runs it. The signature is real, and that is the problem. Three questions on why a valid message can be replayed for a second payout.
Spot the Bug: first-depositor share inflation
A vault mints shares by dividing your deposit by its raw token balance. Anyone can send tokens straight to that balance. Three questions on the trap that leaves the next depositor with zero shares.
Spot the Bug: voting power you can rent
A governance contract reads voting power from your current token balance. Three questions on why a flash loan turns that read into a rented majority.
Spot the Bug: the Merkle proof that proves the wrong thing
An airdrop verifies a Merkle proof and pays the caller, but the leaf commits only to an amount. Three questions on why a valid proof can claim the wrong person's tokens, and be reused until the pool is empty.
Spot the Bug: spot price from reserves
A lending protocol reads its price straight from the AMM pool reserves. It compiles, it is live and on-chain, and it is still exploitable. Three questions on the spot-price trap.
Spot the Bug: the stale price trap
A price from Chainlink can still be wrong. Three questions on the freshness check a trusted feed does not do for you.
Spot the Bug: divide before multiply
A staking reward is computed as amount over total, times a rate. The algebra is right and small stakers still earn zero. Three questions on where the value leaks.
Spot the Bug: sends first, asks later
A vault withdraw transfers the funds, then subtracts the balance. Three questions on the ordering flaw that lets a receiver re-enter and drain.
Spot the Bug: the empty-address trap
A call to an address with no code does not fail. It succeeds and does nothing. Three questions on the trap a zero-address check does not catch.
Spot the Bug: the cliff that never held
A vesting function returns the linearly vested amount since the start. The formula is clean and it still pays out before the cliff. Three questions on the boundary a linear formula does not catch.