Advanced

Protocol Security & Auditing — Hands-on lab

Learn how pros audit.

Developer Advanced
6/8 — Protocol Security & Auditing — Hands-on lab

Triage fastRun Slither for quick hits, then fuzz/invariant tests to catch deeper issues.

DocumentLog every finding with repro steps and proposed fixes.

Tighten scopeStart with a single contract; once clean, extend to integrations and upgrade paths.

slither . --filter-paths "node_modules|lib" --checklist
forge test --match-test invariant_ --gas-report
Steps
  1. Clone a vulnerable sample:(e.g., Not So Smart Contracts) and run Slither; note findings.
  2. Add CEI/nonReentrant fixes; rerun:Slither to confirm reductions.
  3. Write a fuzz test:For withdrawals vs balances; make it pass.
  4. Write an invariant test:That token.balanceOf(vault) == totalDeposits.
  5. Produce a short findings:Report with repro + fix notes.
← Previous section
Next section →