Advanced
Protocol Security & Auditing — Hands-on lab
Learn how pros audit.
Developer Advanced
6/8 — Protocol Security & Auditing — Hands-on lab
Triage fastRun Slither for quick hits, then fuzz/invariant tests to catch deeper issues.
DocumentLog every finding with repro steps and proposed fixes.
Tighten scopeStart with a single contract; once clean, extend to integrations and upgrade paths.
slither . --filter-paths "node_modules|lib" --checklist
forge test --match-test invariant_ --gas-report
Steps
- Clone a vulnerable sample:(e.g., Not So Smart Contracts) and run Slither; note findings.
- Add CEI/nonReentrant fixes; rerun:Slither to confirm reductions.
- Write a fuzz test:For withdrawals vs balances; make it pass.
- Write an invariant test:That token.balanceOf(vault) == totalDeposits.
- Produce a short findings:Report with repro + fix notes.