Skip to free scan

Security Reference

VULNERABILITY DATABASE

Reviewed smart contract vulnerability references covering mechanics, evidence, mitigations, and analysis limits.

New to a term? Browse the smart contract security glossary.

30

Published References

Critical Severity

CRITICAL

Access Control Vulnerability

Understand missing and incorrect smart contract authorization checks, how to review privileged paths, and how to test role boundaries.

CRITICAL

Cross-Chain Bridge Vulnerability

Review cross-chain message authentication, replay protection, finality, accounting, and operational trust boundaries.

CRITICAL

Delegatecall Injection

Understand untrusted delegatecall targets, proxy upgrade boundaries, storage hazards, and practical review and test guidance.

CRITICAL

Flash Loan Attack

Understand how atomic liquidity amplifies oracle, accounting, governance, and callback defects, with review and test guidance.

CRITICAL

Governance Attack

Understand governance capture, flash-loan voting, unsafe proposal execution, and the review and testing needed for on-chain governance systems.

CRITICAL

Oracle Manipulation

Understand unsafe price-feed consumption, stale and low-liquidity data, oracle trust assumptions, and practical review and mitigation techniques.

CRITICAL

Price Manipulation

Learn how attackers move on-chain reference markets, when the trade becomes profitable, and how to test and limit price-dependent protocol exposure.

CRITICAL

Proxy Storage Collision

Understand proxy and implementation storage clashes, upgrade layout drift, initializer risks, and the checks needed before an upgrade.

CRITICAL

Reentrancy Attack

Learn how reentrancy crosses functions and contracts, how to test callback paths, and how checks-effects-interactions and scoped guards reduce risk.

CRITICAL

Signature Replay Attack

Learn how valid signatures are replayed within or across contracts and chains, how EIP-712 domains help, and why nonces and deadlines are still required.

High Severity

HIGH

Centralization & Privileged-Role Risk

Assess smart contract admin powers, upgrade authority, key custody, delays, caps, and the limits of source-only centralization analysis.

HIGH

Denial of Service (DoS)

Review smart contract liveness failures caused by gas growth, external-call reverts, griefing, and unrecoverable state.

HIGH

ERC-4626 Inflation Attack

Understand first-depositor and donation attacks against tokenized vaults, rounding conditions, tests, and mitigation tradeoffs.

HIGH

Fee-on-Transfer & Rebasing Token Integration

Review accounting assumptions for fee-on-transfer, rebasing, and other non-standard ERC-20 tokens, with test and mitigation guidance.

HIGH

Front-Running (MEV)

Understand transaction-ordering risk, sandwich attacks, the conditions that make them profitable, and practical review and mitigation techniques.

HIGH

Insufficient Slippage Protection

Learn how weak swap bounds expose users and vaults to adverse execution, how to review integrations, and where minimum outputs and deadlines fall short.

HIGH

Integer Overflow & Underflow

Understand checked and unchecked Solidity arithmetic, unsafe downcasts, boundary testing, and practical overflow and underflow prevention.

HIGH

Business Logic Error

Learn how protocol assumptions and state transitions fail, how to define invariants, and how sequence-based testing finds exploitable logic errors.

HIGH

Precision Loss & Rounding Errors

Understand integer division, rounding direction, decimal scaling, share accounting, and tests that expose economically significant precision loss.

HIGH

Read-Only Reentrancy

Learn how callbacks expose inconsistent state through view functions, how integrations consume manipulated values, and how to review and mitigate the risk.

HIGH

Selfdestruct Abuse

Understand SELFDESTRUCT after EIP-6780, including forced Ether, same-transaction deletion, legacy assumptions, review methods, and safer contract design.

HIGH

Signature Malleability

Learn why two ECDSA encodings can recover the same Ethereum signer, when malleability becomes exploitable, and how canonical signatures and nonces prevent abuse.

HIGH

tx.origin Authentication Flaw

Learn why tx.origin is not spoofed but still unsafe for authorization, how a confused-deputy call chain works, and how to review immediate-caller controls.

HIGH

Unchecked Return Value

Learn how ignored low-level call and token return values create false-success state, how Solidity call semantics differ, and how to review and test them.

HIGH

Uninitialized Storage Pointer

Learn how uninitialized local storage references corrupted state in pre-0.5 Solidity, why modern compilers reject them, and how to review legacy deployments.

HIGH

Weak Randomness

Learn why public block fields are unsafe for many value-bearing outcomes, how PREVRANDAO differs, and what secure VRF and commit-reveal designs require.

Medium & Low Severity

Evaluate Repository Evidence

Run a Free Security Scan

These pages document vulnerability classes relevant to smart contract review. Detector coverage varies by language, repository, evidence, and scan type; a listing here is not a claim that every instance is automatically detectable.

START FREE SCAN →