1.0 KiB
1.0 KiB
Smart Contract Security Lab
This folder contains intentionally vulnerable contracts and tests that exploit them. The goal is to learn how bugs work so you can review and defend contracts more effectively.
Never deploy these contracts outside a local devnet.
Current Exercises
Reentrancy
Files:
src/security/VulnerableBank.soltest/security/Reentrancy.t.sol
The vulnerable contract sends ETH to the caller before updating internal
balances. The attacker contract re-enters withdraw from its receive
function and drains more ETH than it deposited.
Run:
./jeannie blockchain-test test/security/Reentrancy.t.sol -vv
Defensive fixes to practice:
- checks-effects-interactions
- reentrancy guards
- pull-payment patterns
- avoiding unnecessary raw calls
- invariant tests for total balances
Suggested Next Exercises
- bad access control
tx.originauthentication- signature replay without chain ID or nonce
- oracle price manipulation simulation
- unsafe upgradeable proxy ownership