WEB3 BUG BOUNTY HUNTER GUIDE

Free guide by Techonquer

Web3 Bug Bounty Hunter Guide

A complete path from beginner to advanced: blockchain basics, Solidity, smart contract security, DeFi and oracle attacks, Foundry testing, proof of concept writing and a 90 day plan that ends at your first real bounty.

Techonquer live podcast on Web3 security with Manish Singh on 4 October at 7:30 PM
Upcoming free live podcast

Web3 Security: What actually happens behind the scenes?

What makes a Web3 application vulnerable? How do security researchers actually find bugs in smart contracts and Web3 applications? And can a beginner really get started with Web3 bug hunting? This Sunday we take these questions live with Manish Singh, Web3 Security Researcher and Bug Hunter.

Date: Sunday, 4 October Time: 7:30 PM IST Entry: Free Format: Live podcast with Q and A
What the session covers
  1. Web3 security and bug hunting as it actually works
  2. Real world vulnerabilities and the research behind them
  3. Smart contract security in depth
  4. AI and the future of security research
  5. How beginners can enter Web3 security

Bring your questions and ask them directly during the session. Livestream updates, reminders and access details are shared in the Techonquer WhatsApp community.

01 Web3 fundamentals

  • Blockchain
  • Bitcoin vs Ethereum
  • Ethereum Virtual Machine
  • Wallets
  • Private keys and seed phrases
  • Transactions
  • Blocks
  • Gas
  • Smart contracts
  • Tokens
  • ERC-20
  • ERC-721
  • ERC-1155
  • DeFi
  • DEX
  • DAO
  • NFT
  • Oracles
  • Bridges
  • Layer 1 and Layer 2
Goal: open any transaction on a block explorer and explain, in your own words, exactly what is happening.

02 Ethereum and EVM

  • EVM
  • EOAs and contract accounts
  • Storage
  • Memory
  • Calldata
  • Stack
  • Opcodes
  • Gas
  • Events
  • Function selectors
  • ABI
  • Contract deployment
Tools
  • Etherscan, Remix, MetaMask, Foundry, Hardhat
Basic flow
Wallet→Transaction→Smart contract→Function→State change→Event

03 Solidity

  • Variables
  • Functions
  • Visibility
  • Modifiers
  • Constructors
  • Events
  • Structs
  • Arrays
  • Mappings
  • Inheritance
  • Interfaces
  • Libraries
  • Errors
  • Payable functions
  • Ether transfers
Security focused concepts
msg.sender
msg.value
msg.data
tx.origin
block.timestamp
block.number
address(this)
Know the difference between these calls
  • call
  • delegatecall
  • staticcall
  • transfer
  • send

04 Smart contract security

Access control

  • Missing authorization
  • Incorrect role checks
  • Privilege escalation
  • Owner takeover
  • Admin function exposure
Ask three questions on every function: who can call it, who should be able to call it, and what happens if someone else calls it.

Reentrancy

Contract→External call→Attacker contract→Fallback or receive→Original function again
  • Classic reentrancy
  • Cross function reentrancy
  • Cross contract reentrancy
  • Read only reentrancy

Business logic

  • Incorrect accounting
  • Incorrect reward calculation
  • Double claiming
  • Incorrect withdrawal logic
  • Broken state transitions
  • Missing validation
  • Unexpected function combinations
Deposit→Reward→Claim→Withdraw

Test complete workflows, not only individual functions.

05 DeFi security

  • Lending
  • Borrowing
  • Staking
  • Yield farming
  • AMMs
  • Liquidity pools
  • Flash loans
  • Oracles
  • Liquidations
  • Collateral
  • Stablecoins
Core concepts
  • Price, liquidity, collateral, debt, shares, reserves and exchange rate

06 Price oracle security

  • Spot price
  • TWAP
  • Oracle providers
  • Stale prices
  • Incorrect decimals
  • Incorrect price feeds
  • Missing validation
Oracle price→Collateral value→Borrow limit→Loan

07 Flash loans

Borrow→Execute or manipulate→Profit→Repay
  • Price assumptions
  • Reserve calculations
  • Oracle dependencies
  • Share calculations
  • Liquidation logic

08 Token security

ERC-20
  • Mint authorization
  • Burn authorization
  • Transfer restrictions
  • Allowance issues
  • Decimal assumptions
  • Fee on transfer behaviour
  • Blacklist logic
  • Pause logic

Once ERC-20 is clear, move on to ERC-721 and ERC-1155.

09 Upgradeable contracts

  • Proxy patterns
  • Implementation contracts
  • Proxy admins
  • Upgrade authorization
  • Storage layout
  • Initializers
User→Proxy→Implementation
Ask: who controls the upgrade, can initialization happen again, is the implementation protected, and can storage collision occur?

10 Signature security

  • ecrecover
  • EIP-712
  • Nonces
  • Domain separators
  • Signature validation
  • Replay protection
Signature→Signer→Message→Nonce→Chain ID→Contract

11 Cross chain and bridge security

  • Lock and mint
  • Burn and release
  • Validators
  • Relayers
  • Message passing
  • Cross chain signatures
  • Proof verification
Ask: who validates the message, can it be replayed, can verification be bypassed, and can a fake message be accepted?

12 Foundry

forge init
forge build
forge test
forge test -vvvv
forge inspect
cast
anvil
  • Unit testing
  • Fuzz testing
  • Invariant testing
  • Fork testing
  • Mainnet forks
Source code→Build→Write test→Exploit PoC→Run test→Verify impact

13 Static analysis

  • Slither
  • Aderyn
  • Mythril
  • Semgrep
  • Foundry
  • Echidna
slither .

Always verify tool findings by hand. A tool gives you a shortlist, the proof is still your job.

14 Manual code review

Review the contract function by function and keep a table as you go.

FunctionWho can callState changedExternal callsRisk
deposit()Anyonebalances, totalSupplytoken.transferFromAccounting, fee on transfer tokens
withdraw()DepositorbalancesETH transferReentrancy, rounding
setOracle()OwneroracleNoneAccess control, price manipulation

Build a complete call flow map. Cross function and cross contract bugs only appear once you can see the whole flow.

15 Foundry testing

test/
    AccessControl.t.sol
    Reentrancy.t.sol
    Oracle.t.sol
    Accounting.t.sol
    Upgrade.t.sol
  • Normal user
  • Attacker
  • Admin
  • Zero address
  • Large values
  • Zero values
  • Repeated calls
  • Unexpected sequences

16 Fuzzing

// normal test
deposit(100)

// fuzz test
deposit(amount)
  • Integer edge cases
  • Rounding
  • Incorrect accounting
  • Unexpected state transitions

17 Invariant testing

An invariant is a condition that should never break.

Total assets >= Total liabilities
Total supply == Sum of user balances

When an invariant breaks, dig into the root cause. That is usually where the report worthy bug lives.

18 Bug bounty platforms

Immunefi

The largest Web3 bounties, mostly DeFi protocols.

Code4rena

Time boxed audit contests with judged findings.

Sherlock

Contests plus coverage based payouts.

Cantina

Competitions and private reviews.

HackenProof

Web3 and infrastructure programs.

HackerOne

Mostly Web2, with some Web3 programs.

Read the scope, rules, out of scope items, severity definitions and disclosure policy before you touch anything. Only test authorized targets.

19 Recon methodology

Program→Contracts→Addresses→Source code→Dependencies→Architecture→Attack surface
  • Contract addresses
  • Implementation addresses
  • Proxy information
  • Admin addresses
  • Oracle addresses
  • Token addresses
  • External protocols

20 Attack surface map

                   Protocol
                      |
       +--------------+--------------+
       |              |              |
    Lending         Oracle          Token
       |              |              |
    Borrow          Price         Transfer
       |              |              |
 Liquidation    Manipulation       Hooks

21 Read past Web3 reports

Root cause→Attack path→Exploit→Impact→Fix

Study public findings and audit reports. Do not copy reports, understand the reasoning behind them.

22 Vulnerability checklist

Access control

  • Missing authorization
  • Incorrect role
  • Privilege escalation

Reentrancy

  • External call
  • State update order
  • Cross function interaction

Accounting

  • Rounding
  • Share calculation
  • Balance calculation
  • Decimal mismatch

Oracle

  • Stale price
  • Manipulatable source
  • Incorrect decimals
  • Missing validation

Upgradeability

  • Initialization
  • Upgrade authorization
  • Storage layout

Signatures

  • Nonce
  • Replay
  • Domain separator
  • Chain ID

Business logic

  • Unexpected sequence
  • Double claim
  • Incorrect reward
  • Incorrect withdrawal

23 Proof of concept

Initial state→Attack setup→Exploit→State change→Impact
  • Reproducible
  • Minimal
  • Authorized
  • Clearly explained

24 Bug report structure

Title
Severity
Summary
Root cause
Attack scenario
Proof of concept
Impact
Affected contract
Affected function
Recommendation

Good title: Unauthorized withdrawal allows an attacker to drain user funds

Weak title: Critical bug in contract

25 Severity

  • Can an attacker steal funds?
  • Can an attacker freeze funds?
  • Can an attacker manipulate accounting?
  • Can an attacker bypass authorization?
  • Can an attacker affect protocol availability?

Back every severity claim with reproducible technical impact.

26 Daily practice

TimeWhat to do
1 hourLearn one vulnerability class
1 hourRead one real audit finding
2 hoursReview a smart contract
1 hourWrite Foundry tests
1 hourPractice on a CTF or an authorized lab
30 minutesWrite notes
Learn→Read→Code→Break→Explain

27 90 day roadmap

Day 1-15
Web3 fundamentals: blockchain, Ethereum, wallets, transactions, EVM, gas and Solidity basics
Day 16-30
Solidity security: access control, reentrancy, business logic, arithmetic, external calls and token security
Day 31-45
DeFi: AMMs, lending, oracles, flash loans, liquidations and accounting
Day 46-60
Tools: Foundry, Slither, Echidna, Hardhat, Remix and block explorers
Day 61-75
Real code review: review 5 to 10 protocols and write findings even if you never submit them
Day 76-90
Bug bounty: start with smaller scoped programs
Recon→Code review→Hypothesis→PoC→Impact→Report

28 Beginner practice stack

Install
  • VS Code
  • Remix
  • Foundry
  • Git
  • Node.js
  • Python
  • Slither
  • Anvil
Browser tools
  • Etherscan, DeFiLlama, Dune, Tenderly and OpenChain

29 The most important skill

Tools are not the main skill. Protocol understanding is.

Ask one question of every protocol: what assumption is this protocol making, and what happens if that assumption becomes false?
Input→Validation→Calculation→State change→External call→Output

Final roadmap

Web3 basics→Ethereum and EVM→Solidity→Contract security→DeFi→Foundry→Static analysis→Manual review→Fuzzing and invariants→Audit reports→CTFs and labs→Bounty programs→PoC→Report→Web3 bug bounty hunter
The Techonquer learning principle: do not just learn how smart contracts work. Learn how they fail.

What next?

The live podcast is on 4 October and reminders go out only in the WhatsApp community. Recordings land on YouTube.