DeFi Security AllianceRequest an audit
Menu

DeFi Security Alliance Blog

Find an article for your task

21-40 of 80 articles.

Blog Articles

  • DeFi Security: Situation and Solution: Examples of DeFi Attacks Included

    cystack

    DeFi Security: Situation and Solution: Examples of DeFi Attacks Included

    When you land on this page, you might have already heard of or even been using Decentralized finance (DeFi) to keep your money. However, you may be concerned to know that this technology is also appealing to cyber criminals attempting to steal your assets. It was reported that 97% of cryptocurrency stolen in 2022's first quarter was from DeFi protocols.

  • Solana vulnerabilities: account checks, CPIs and arithmetic

    0xGuard

    Solana vulnerabilities: account checks, CPIs and arithmetic

    Solana security reviews must validate the accounts an instruction receives and the authority to use them. The program must enforce application rules, such as which vault belongs to a user, alongside memory safety and runtime checks.

  • Audit Builder

    DeFi Security Alliance

    Audit Builder

    In this sense, a report has to reflect best all the issues uncovered during the audit. DeFi Security Alliance has come up with a tool that helps simplify the compilation of this final audit report.

  • Top 10 Cybersecurity Companies in 2026

    Choosing a security firm

    Top 10 Cybersecurity Companies in 2026

    The top 10 cybersecurity companies below are ranked for one buyer: a team shipping a product that has smart contracts on one side and a web application, an API and a cloud account on the other. Each entry was checked on September 3, 2026 against the firm's own published material, and the three archives that sit on GitHub were counted through the API rather than estimated. One of the ten publishes price bands and lead times before the sales call, and the other nine quote on request.

    14 min read

  • Crypto Incident Response: A Protocol Team Playbook

    Operations

    Crypto Incident Response: A Protocol Team Playbook

    Start crypto incident response by assigning authority, preserving the first evidence and checking which containment actions the deployed system can execute. Our census of 84 public SEAL 911 log entries includes 10 takeover labels, making domain and account recovery relevant to the exercise as well as contract controls. Keep notification, containment and confirmed recovery as separate states.

    12 min read

  • Perpetual DEX Security: Liquidations, Funding, Oracles and ADL

    Verticals

    Perpetual DEX Security: Liquidations, Funding, Oracles and ADL

    A perpetual DEX security audit tests margin accounting, liquidation execution and who absorbs losses when normal settlement fails. Our snapshot resolved the margin rules for 177 Hyperliquid markets, including 34 with multiple tiers. Use that configuration inventory alongside a venue-specific loss model when commissioning the review.

    11 min read

  • RWA Token Security: ERC-3643 Controls, Custody and Holder Rights

    Verticals

    RWA Token Security: ERC-3643 Controls, Custody and Holder Rights

    A review of RWA token security depends on both implemented token controls and the evidence supporting the holder's asset claim. Our pinned T-REX reference scan found 14 direct role gates among 27 mutating declarations, plus batch paths that need separate interpretation. Use that distinction to scope identity, transfer and custody review.

    12 min read

  • A Developer's Guide: A Framework setup

    HASHEX

    A Developer's Guide: A Framework setup

    Developers often ask how to correctly, efficiently and securely set up a framework for developing smart contracts. This guide aims to help new developers do it quickly and conveniently.

  • How to Publish a Security Disclosure Policy a Whitehat Will Actually Use

    Disclosure and bounties

    How to Publish a Security Disclosure Policy a Whitehat Will Actually Use

    A security disclosure policy is the published set of rules that tells a researcher where to send a vulnerability report, what they may test and what happens next. On September 2, 2026, only 3 of the 30 largest DeFi protocols by TVL served a security.txt file, and one of those three met RFC 9116. This guide gives protocol teams the policy wording, the file, the SEAL Safe Harbor steps and the response deadlines, each tied to a published source or to the terms real adopters set.

    16 min read

  • ERC20 Token Audit: The Listing Packet and Free Self-Checks

    EVM patterns

    ERC20 Token Audit: The Listing Packet and Free Self-Checks

    Before listing, an issuer needs evidence for token behavior and the integrations that rely on it. An ERC20 token audit ties that evidence to a revision, current authority and the remaining compatibility limits.

    12 min read

  • Must-Check: The Complete Smart Contract Audit Checklist!

    CyStack

    Must-Check: The Complete Smart Contract Audit Checklist!

    Blockchain is supposed to be secure for all participants. However, it is not possible if the company does not strictly follow the smart contract audit checklist for blockchain readiness. Reports revealed that 5% of blockchain smart contracts were vulnerable to users' data leakage, information loss and funding lock.