awesome-web3-security
github.com/fabionoth/awesome-web3-security ↗A curated list of awesome Web3 Security.
Use this list with your AI agent
Add the Context Awesome MCP server to Claude, Cursor, or any MCP client, then ask:
"Show me forensics resources from awesome-web3-security"
Installation instructions →What's inside
Tools
- abi-decompilerForensics
The purpose of abi-decompiler is to implement a simple tools to recover ABI of EVM smart contracts, including function names.
- BrownieSAST/DAST/Unity Test Analysis
Brownie is a Python-based development and testing framework for smart contracts targeting the Ethereum Virtual Machine.
- BSCheckTesting
Free Binance Smart Chain token analyzer
- ChainFuzzFuzzers
ChainFuzz requires a truffle project with correct migration files to fuzz a project.
- DeDaubForensics
The Dedaub decompiler takes Ethereum Virtual Machine (EVM) bytecode and produces more readable Solidity-like code.
- dethcodeOther tools
View source of deployed Ethereum smart contracts in VS Code
CTF
- blocksec-ctfs
A curated list of blockchain security Wargames, Challenges, and Capture the Flag (CTF) competitions and solution writeups.
- Capture the Ether
the game of Ethereum smart contract security
- ciphershastra
A place where you can enhance your Security Skills by solving and learning from CTF-like challenges.
- CryptoHack
A free, fun platform for learning modern cryptography
- Damn Vulnerable DeFi
The training ground for security researchers, developers and educators to dive into smart contract security.
- Hack the TON
Hack the TON is a TON based wargame inspired by The Ethernaut, played in the TON Virtual Machine.
Databases/Books and References
- Chainlist
Helping users connect to EVM powered networks
- REKT
Rekt News is a leading online platform offering timely and concise information on decentralized finance (DeFi), blockchain, and the cryptocurrency industry
- Smart Contract Security Chapter
Chapter 9 from Ethereum book.
Standards
- ERC 20
The ERC-20 introduces a standard for Fungible Tokens, in other words, they have a property that makes each Token be exactly the same (in type and value) as another Token.
- OWASP Smart Contract
The OWASP Smart Contract Top 10 is a standard awareness document that intends to provide Web3 developers and security teams with insight into the top 10 vulnerabilities found in smart contracts.
BugBounty
- Hacken Proof
Expert web3 bug bounty and crowdsourced audit platform
- Immunefi
Web3's bug bounty platform
Playgrounds
- Remix Ethereum
No more words. Everybody knows Remix
- Rust Playground
The Rust Playground
- TON Network Playground
TON Network IDE
Showing a sample of 49 resources. View the full list on GitHub →