Security Reference
VULNERABILITY DATABASE
Reviewed smart contract vulnerability references covering mechanics, evidence, mitigations, and analysis limits.
New to a term? Browse the smart contract security glossary.
30
Published References
Critical Severity
Access Control Vulnerability
Understand missing and incorrect smart contract authorization checks, how to review privileged paths, and how to test role boundaries.
Cross-Chain Bridge Vulnerability
Review cross-chain message authentication, replay protection, finality, accounting, and operational trust boundaries.
Delegatecall Injection
Understand untrusted delegatecall targets, proxy upgrade boundaries, storage hazards, and practical review and test guidance.
Flash Loan Attack
Understand how atomic liquidity amplifies oracle, accounting, governance, and callback defects, with review and test guidance.
Governance Attack
Understand governance capture, flash-loan voting, unsafe proposal execution, and the review and testing needed for on-chain governance systems.
Oracle Manipulation
Understand unsafe price-feed consumption, stale and low-liquidity data, oracle trust assumptions, and practical review and mitigation techniques.
Price Manipulation
Learn how attackers move on-chain reference markets, when the trade becomes profitable, and how to test and limit price-dependent protocol exposure.
Proxy Storage Collision
Understand proxy and implementation storage clashes, upgrade layout drift, initializer risks, and the checks needed before an upgrade.
Reentrancy Attack
Learn how reentrancy crosses functions and contracts, how to test callback paths, and how checks-effects-interactions and scoped guards reduce risk.
Signature Replay Attack
Learn how valid signatures are replayed within or across contracts and chains, how EIP-712 domains help, and why nonces and deadlines are still required.
High Severity
Centralization & Privileged-Role Risk
Assess smart contract admin powers, upgrade authority, key custody, delays, caps, and the limits of source-only centralization analysis.
Denial of Service (DoS)
Review smart contract liveness failures caused by gas growth, external-call reverts, griefing, and unrecoverable state.
ERC-4626 Inflation Attack
Understand first-depositor and donation attacks against tokenized vaults, rounding conditions, tests, and mitigation tradeoffs.
Fee-on-Transfer & Rebasing Token Integration
Review accounting assumptions for fee-on-transfer, rebasing, and other non-standard ERC-20 tokens, with test and mitigation guidance.
Front-Running (MEV)
Understand transaction-ordering risk, sandwich attacks, the conditions that make them profitable, and practical review and mitigation techniques.
Insufficient Slippage Protection
Learn how weak swap bounds expose users and vaults to adverse execution, how to review integrations, and where minimum outputs and deadlines fall short.
Integer Overflow & Underflow
Understand checked and unchecked Solidity arithmetic, unsafe downcasts, boundary testing, and practical overflow and underflow prevention.
Business Logic Error
Learn how protocol assumptions and state transitions fail, how to define invariants, and how sequence-based testing finds exploitable logic errors.
Precision Loss & Rounding Errors
Understand integer division, rounding direction, decimal scaling, share accounting, and tests that expose economically significant precision loss.
Read-Only Reentrancy
Learn how callbacks expose inconsistent state through view functions, how integrations consume manipulated values, and how to review and mitigate the risk.
Selfdestruct Abuse
Understand SELFDESTRUCT after EIP-6780, including forced Ether, same-transaction deletion, legacy assumptions, review methods, and safer contract design.
Signature Malleability
Learn why two ECDSA encodings can recover the same Ethereum signer, when malleability becomes exploitable, and how canonical signatures and nonces prevent abuse.
tx.origin Authentication Flaw
Learn why tx.origin is not spoofed but still unsafe for authorization, how a confused-deputy call chain works, and how to review immediate-caller controls.
Unchecked Return Value
Learn how ignored low-level call and token return values create false-success state, how Solidity call semantics differ, and how to review and test them.
Uninitialized Storage Pointer
Learn how uninitialized local storage references corrupted state in pre-0.5 Solidity, why modern compilers reject them, and how to review legacy deployments.
Weak Randomness
Learn why public block fields are unsafe for many value-bearing outcomes, how PREVRANDAO differs, and what secure VRF and commit-reveal designs require.
Medium & Low Severity
ERC-20 Approve Race Condition
Understand the ERC-20 allowance overwrite race, its transaction-ordering conditions, and safer approval and spending designs.
Forced Ether Sending
Understand how Ether can reach a contract without its receive logic and how to review exact-balance assumptions safely.
Gas Griefing
Learn how adversarial gas consumption can block progress, waste sponsored gas, or break calls, plus practical review, testing, and mitigation guidance.
Timestamp Dependence
Learn when block timestamps are safe for coarse scheduling, when they create exploitable assumptions, and how to test timing boundaries across EVM networks.
Evaluate Repository Evidence
Run a Free Security Scan
These pages document vulnerability classes relevant to smart contract review. Detector coverage varies by language, repository, evidence, and scan type; a listing here is not a claim that every instance is automatically detectable.
START FREE SCAN →