Web3 Bug Bounty Hunter Guide
A complete path from beginner to advanced: blockchain basics, Solidity, smart contract security, DeFi and oracle attacks, Foundry testing, proof of concept writing and a 90 day plan that ends at your first real bounty.
Web3 Security: What actually happens behind the scenes?
What makes a Web3 application vulnerable? How do security researchers actually find bugs in smart contracts and Web3 applications? And can a beginner really get started with Web3 bug hunting? This Sunday we take these questions live with Manish Singh, Web3 Security Researcher and Bug Hunter.
- Web3 security and bug hunting as it actually works
- Real world vulnerabilities and the research behind them
- Smart contract security in depth
- AI and the future of security research
- How beginners can enter Web3 security
Bring your questions and ask them directly during the session. Livestream updates, reminders and access details are shared in the Techonquer WhatsApp community.
01 Web3 fundamentals
- Blockchain
- Bitcoin vs Ethereum
- Ethereum Virtual Machine
- Wallets
- Private keys and seed phrases
- Transactions
- Blocks
- Gas
- Smart contracts
- Tokens
- ERC-20
- ERC-721
- ERC-1155
- DeFi
- DEX
- DAO
- NFT
- Oracles
- Bridges
- Layer 1 and Layer 2
02 Ethereum and EVM
- EVM
- EOAs and contract accounts
- Storage
- Memory
- Calldata
- Stack
- Opcodes
- Gas
- Events
- Function selectors
- ABI
- Contract deployment
- Etherscan, Remix, MetaMask, Foundry, Hardhat
03 Solidity
- Variables
- Functions
- Visibility
- Modifiers
- Constructors
- Events
- Structs
- Arrays
- Mappings
- Inheritance
- Interfaces
- Libraries
- Errors
- Payable functions
- Ether transfers
msg.sender msg.value msg.data tx.origin block.timestamp block.number address(this)
calldelegatecallstaticcalltransfersend
04 Smart contract security
Access control
- Missing authorization
- Incorrect role checks
- Privilege escalation
- Owner takeover
- Admin function exposure
Reentrancy
- Classic reentrancy
- Cross function reentrancy
- Cross contract reentrancy
- Read only reentrancy
Business logic
- Incorrect accounting
- Incorrect reward calculation
- Double claiming
- Incorrect withdrawal logic
- Broken state transitions
- Missing validation
- Unexpected function combinations
Test complete workflows, not only individual functions.
05 DeFi security
- Lending
- Borrowing
- Staking
- Yield farming
- AMMs
- Liquidity pools
- Flash loans
- Oracles
- Liquidations
- Collateral
- Stablecoins
- Price, liquidity, collateral, debt, shares, reserves and exchange rate
06 Price oracle security
- Spot price
- TWAP
- Oracle providers
- Stale prices
- Incorrect decimals
- Incorrect price feeds
- Missing validation
07 Flash loans
- Price assumptions
- Reserve calculations
- Oracle dependencies
- Share calculations
- Liquidation logic
08 Token security
- Mint authorization
- Burn authorization
- Transfer restrictions
- Allowance issues
- Decimal assumptions
- Fee on transfer behaviour
- Blacklist logic
- Pause logic
Once ERC-20 is clear, move on to ERC-721 and ERC-1155.
09 Upgradeable contracts
- Proxy patterns
- Implementation contracts
- Proxy admins
- Upgrade authorization
- Storage layout
- Initializers
10 Signature security
- ecrecover
- EIP-712
- Nonces
- Domain separators
- Signature validation
- Replay protection
11 Cross chain and bridge security
- Lock and mint
- Burn and release
- Validators
- Relayers
- Message passing
- Cross chain signatures
- Proof verification
12 Foundry
forge init forge build forge test forge test -vvvv forge inspect cast anvil
- Unit testing
- Fuzz testing
- Invariant testing
- Fork testing
- Mainnet forks
13 Static analysis
- Slither
- Aderyn
- Mythril
- Semgrep
- Foundry
- Echidna
slither .
Always verify tool findings by hand. A tool gives you a shortlist, the proof is still your job.
14 Manual code review
Review the contract function by function and keep a table as you go.
| Function | Who can call | State changed | External calls | Risk |
|---|---|---|---|---|
| deposit() | Anyone | balances, totalSupply | token.transferFrom | Accounting, fee on transfer tokens |
| withdraw() | Depositor | balances | ETH transfer | Reentrancy, rounding |
| setOracle() | Owner | oracle | None | Access control, price manipulation |
Build a complete call flow map. Cross function and cross contract bugs only appear once you can see the whole flow.
15 Foundry testing
test/
AccessControl.t.sol
Reentrancy.t.sol
Oracle.t.sol
Accounting.t.sol
Upgrade.t.sol
- Normal user
- Attacker
- Admin
- Zero address
- Large values
- Zero values
- Repeated calls
- Unexpected sequences
16 Fuzzing
// normal test deposit(100) // fuzz test deposit(amount)
- Integer edge cases
- Rounding
- Incorrect accounting
- Unexpected state transitions
17 Invariant testing
An invariant is a condition that should never break.
Total assets >= Total liabilities Total supply == Sum of user balances
When an invariant breaks, dig into the root cause. That is usually where the report worthy bug lives.
18 Bug bounty platforms
Immunefi
The largest Web3 bounties, mostly DeFi protocols.
Code4rena
Time boxed audit contests with judged findings.
Sherlock
Contests plus coverage based payouts.
Cantina
Competitions and private reviews.
HackenProof
Web3 and infrastructure programs.
HackerOne
Mostly Web2, with some Web3 programs.
19 Recon methodology
- Contract addresses
- Implementation addresses
- Proxy information
- Admin addresses
- Oracle addresses
- Token addresses
- External protocols
20 Attack surface map
Protocol
|
+--------------+--------------+
| | |
Lending Oracle Token
| | |
Borrow Price Transfer
| | |
Liquidation Manipulation Hooks
21 Read past Web3 reports
Study public findings and audit reports. Do not copy reports, understand the reasoning behind them.
22 Vulnerability checklist
Access control
- Missing authorization
- Incorrect role
- Privilege escalation
Reentrancy
- External call
- State update order
- Cross function interaction
Accounting
- Rounding
- Share calculation
- Balance calculation
- Decimal mismatch
Oracle
- Stale price
- Manipulatable source
- Incorrect decimals
- Missing validation
Upgradeability
- Initialization
- Upgrade authorization
- Storage layout
Signatures
- Nonce
- Replay
- Domain separator
- Chain ID
Business logic
- Unexpected sequence
- Double claim
- Incorrect reward
- Incorrect withdrawal
23 Proof of concept
- Reproducible
- Minimal
- Authorized
- Clearly explained
24 Bug report structure
Title Severity Summary Root cause Attack scenario Proof of concept Impact Affected contract Affected function Recommendation
Good title: Unauthorized withdrawal allows an attacker to drain user funds
Weak title: Critical bug in contract
25 Severity
- Can an attacker steal funds?
- Can an attacker freeze funds?
- Can an attacker manipulate accounting?
- Can an attacker bypass authorization?
- Can an attacker affect protocol availability?
Back every severity claim with reproducible technical impact.
26 Daily practice
| Time | What to do |
|---|---|
| 1 hour | Learn one vulnerability class |
| 1 hour | Read one real audit finding |
| 2 hours | Review a smart contract |
| 1 hour | Write Foundry tests |
| 1 hour | Practice on a CTF or an authorized lab |
| 30 minutes | Write notes |
27 90 day roadmap
- Day 1-15
- Web3 fundamentals: blockchain, Ethereum, wallets, transactions, EVM, gas and Solidity basics
- Day 16-30
- Solidity security: access control, reentrancy, business logic, arithmetic, external calls and token security
- Day 31-45
- DeFi: AMMs, lending, oracles, flash loans, liquidations and accounting
- Day 46-60
- Tools: Foundry, Slither, Echidna, Hardhat, Remix and block explorers
- Day 61-75
- Real code review: review 5 to 10 protocols and write findings even if you never submit them
- Day 76-90
- Bug bounty: start with smaller scoped programs
28 Beginner practice stack
- VS Code
- Remix
- Foundry
- Git
- Node.js
- Python
- Slither
- Anvil
- Etherscan, DeFiLlama, Dune, Tenderly and OpenChain
29 The most important skill
Tools are not the main skill. Protocol understanding is.
Final roadmap
What next?
The live podcast is on 4 October and reminders go out only in the WhatsApp community. Recordings land on YouTube.