DeFi Security AllianceRequest an audit
Menu

DeFi Security Alliance Blog

Find an article for your task

61-80 of 80 articles.

Blog Articles

  • Oracle Manipulation Attack: Spot, TWAP, Chainlink and Pull Oracles Compared

    Attack classes

    Oracle Manipulation Attack: Spot, TWAP, Chainlink and Pull Oracles Compared

    An oracle manipulation attack rarely breaks the oracle. It moves the venue the oracle reports, or reads a price the protocol should never have trusted, then borrows against the result. This comparison sizes spot reads, Uniswap TWAPs, Chainlink push feeds and pull oracles by what an attacker has to control, and carries our own survey of every Chainlink feed parameter published on four networks.

    16 min read

  • The Complete Guide to Smart Contract Auditing - Benefits and Risks

    SolidProof

    The Complete Guide to Smart Contract Auditing - Benefits and Risks

    Decentralized finance (DeFi) offers lucrative opportunities somewhat unavailable in the traditional centralized system. In this blockchain-based environment, almost anyone can use smart contracts to launch financial applications without a central authority's approval.

  • Security State Of DeFi And Risk Mitigation Ideas

    QuillAudits

    Security State Of DeFi And Risk Mitigation Ideas

    "DeFi," sounds like no alien term now. We are in a time where decentralized finance has engraved its significance as a blockchain-based alternative for financial systems and scaling its adoption rate at an incredible pace.

  • Tokenomics Audit: Report Scope and a Scan of 16 Firm Sites

    Personas and market

    Tokenomics Audit: Report Scope and a Scan of 16 Firm Sites

    A useful tokenomics audit tests economic assumptions and connects them to the rules a token actually enforces. Request reproducible scenarios and a findings report with explicit limits. Our scan found an explicit service offer on 1 of 16 readable member sites, showing why topic mentions need a closer check.

    12 min read

  • Securing the Future: Web3 Security and Auditing in the Age of Decentralized AI

    PaladinAI

    Securing the Future: Web3 Security and Auditing in the Age of Decentralized AI

    As the digital landscape evolves, the focus on Web3 technology and its integration with Artificial Intelligence (AI) is becoming increasingly prominent. This new era, marked by the decentralization of AI, is not just redefining our interaction with technology but also raising critical questions about security and auditing.

  • Web3 Security Engineer: Hiring Scope, Public Salaries and External Review

    Personas and market

    Web3 Security Engineer: Hiring Scope, Public Salaries and External Review

    Define the security decisions that need a permanent owner before choosing a job title. A Web3 security engineer, an audit manager and a security platform developer can have different responsibilities, so salary evidence must preserve role and location.

    12 min read

  • How to spot hidden mint functions

    SOLIDPROOF

    How to spot hidden mint functions

    A token can create unauthorized balances without exposing a function named mint. Follow every path that writes balances or changes the implementation, then test the accounting rules those paths must preserve.

  • How to build secure Smart Contracts with Rust on NEAR Protocol

    Blaze

    How to build secure Smart Contracts with Rust on NEAR Protocol

    Blockchain developers dream of creating smart contracts that do not fail. This requires secure and reliable programming. In this article, Blaize's experts share their secrets and tips to create secure smart contracts on NEAR Protocol with Rust.

  • Smart Contract Monitoring After Defender: What to Watch, Thresholds and the Alert-to-Pause Path

    Operations

    Smart Contract Monitoring After Defender: What to Watch, Thresholds and the Alert-to-Pause Path

    The job called smart contract monitoring starts once the audit is over: watching a live contract's events and storage slots for the changes that matter, then getting a person or a script to act on them. This guide names the events with their exact signatures, gives a procedure for deriving alert thresholds rather than copying someone else's, and walks the escalation path from a firing rule to a pause transaction. It also dates the end of OpenZeppelin Defender and measures how many alliance member firms publish a monitoring service at all.

    16 min read

  • Audit Report Explained: Scope, Severity and Status Fields

    Audit deliverables

    Audit Report Explained: Scope, Severity and Status Fields

    An audit report explained properly starts at the scope statement and the dates, not at the findings table. Everything below those pages is conditional on them: which files were read, in what window and under which severity rule the firm writes its labels. This guide walks a real published report end to end, and measures the severity and status vocabulary that member firm reports actually use.

    16 min read

  • Crypto Due Diligence Checklist: A Live Lido Protocol Walkthrough

    Personas and market

    Crypto Due Diligence Checklist: A Live Lido Protocol Walkthrough

    A crypto due diligence checklist should end in an evidence chain, not a row of green badges. We apply that standard to Lido on Ethereum by tracing two live proxies into verified implementations, matching the deployed scope to an audit commit and mapping privileged functions to their current control path. Our separate survey of 30 top total value locked records shows why the extra work matters: only 16 supplied an audit link, and a link alone says nothing about scope.

    12 min read

  • Importance of the security audit for DeFi projects

    DeFiMoon

    Importance of the security audit for DeFi projects

    A DeFi security audit adds independent review of a defined revision. Its value depends on the scope, the treatment of findings and evidence that the reviewed code matches the release. This guide explains how to check those links and reproduce a small synthetic example.

  • Crypto Bug Bounty Program: Scope, KYC, Vault Funding and Response

    Audit alternatives

    Crypto Bug Bounty Program: Scope, KYC, Vault Funding and Response

    A crypto bug bounty program needs clear scope, authorized testing conditions and an operational path from a valid report to remediation and payment. A maximum reward and a displayed vault balance describe different things; neither replaces the program terms.

    12 min read

  • Lending Protocol Audit: Collateral, Liquidation, Debt and Credit Scope

    Verticals

    Lending Protocol Audit: Collateral, Liquidation, Debt and Credit Scope

    A lending protocol audit follows borrowing limits, interest accounting and loss recovery through the actual loan model. We compared 28 Comet configuration files to show how a complete parameter inventory supports that scope. XRPL credit needs a different review because its documented lending model relies on off-chain underwriting.

    12 min read

  • Top 10 Solana Audit Companies in 2026

    Chains

    Top 10 Solana Audit Companies in 2026

    Choose Solana audit companies by the program they reviewed, the evidence they deliver and the changes they agree to recheck. These ten providers offer different starting points for application audits, token infrastructure and continuing security work. Our archive census found 14 Token2022-family files, including a commit attestation that explicitly is not a full audit report.

    14 min read