• This repository has been archived on 17/May/2024
  • Stars
    star
    410
  • Rank 105,468 (Top 3 %)
  • Language
    Solidity
  • License
    MIT License
  • Created over 2 years ago
  • Updated 6 months ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

Hardhat Security

This is a section of the Javascript Blockchain/Smart Contract FreeCodeCamp Course. This part of the course is to help users understand basic security and some fundamentals of auditing.

This repo has a few contracts with big flaws, see if you can see them, and see if the tools help you find them!

This repo has been updated for Sepolia over Goerli.

⌨️ (31:28:32) Lesson 18: Security & Auditing

Full Repo

This project is apart of the Hardhat FreeCodeCamp video.

What is an Audit?

An audit is a security focused code review for looking for issues with your code.

Help your auditors!

When writing good code, you 100% need to follow these before sending you code to an audit.

Tweet from legendary security expert Tincho

  • Add comments
    • This will help your auditors understand what you're doing.
  • Use natspec
    • Document your functions. DOCUMENT YOUR FUNCTIONS.
  • Test
    • If you don't have tests, and test coverage of all your functions and lines of code, you shouldn't go to audit. If your tests don't pass, don't go to audit.
  • Be ready to talk to your auditors
    • The more communication, the better.
  • Be prepared to give them plenty of time.
    • They literally pour themselves over your code.

"At this time, there are 0 good auditors that can get you an audit in under a week. If an auditor says they can do it in that time frame, they are either doing you a favor or they are shit. " - Patrick Collins, March 4th, 2022

Process

An auditors process looks like this:

  1. Run tests
  2. Read specs/docs
  3. Run fast tools (like slither, linters, static analysis, etc)
  4. Manual Analysis
  5. Run slow tools (like echidna, manticore, symbolic execution, MythX)
  6. Discuss (and repeat steps as needed)
  7. Write report (Example report)

Typically, you organize reports in a chart that looks like this:

impact image

Resources

These are some of the best places to learn even MORE about security:

PRs welcome to improve the list.

Tools

Games

Blogs

  • rekt
    • A blog that keeps up with all the "best" hacks in the industry.
  • Trail of bits blog
    • Learn from one of the best auditors in the space.
  • Openzeppelin Blog
    • Another blog of one of the best auditors in the space.

Audit Examples:

Articles

Getting Started

Requirements

  • Git
    • You'll know you did it right if you can run git --version and you see a response like git version x.x.x
  • Nodejs
    • You'll know you've installed nodejs right if you can run:
      • node --version and get an ouput like: vx.x.x
  • Yarn instead of npm
    • You'll know you've installed yarn right if you can run:
      • yarn --version and get an output like: x.x.x
      • You might need to install it with npm
  • Docker
    • You'll know you've installed docker right if you can run:
    • docker --version and get an ouput like Docker version xx.xx.xx, build xxxxx

Quickstart

git clone https://github.com/PatrickAlphaC/hardhat-security-fcc
cd hardhat-security-fcc
yarn set version 1.22.19   # can skip if your default version is already 1.x.x
yarn

(Yarn version 1 is recommended because auto-migration of this repo to yarn v2 doesn't go well. If your node version is incompatible with this, try node 16.19.1.) Then, go right into usage

No Typescript Support

Sorry! Feel free to make a PR if you'd like to see typescript here.

Optional Gitpod

If you can't or don't want to run and install locally, you can work with this repo in Gitpod. If you do this, you can skip the clone this repo part.

Open in Gitpod

Usage

Slither

Open the docker shell:

yarn toolbox

Then, run:

slither /src/contracts/ --solc-remaps @openzeppelin=/src/node_modules/@openzeppelin --exclude naming-convention,external-function,low-level-calls

To exit:

exit

Echidna

Open the docker shell:

yarn toolbox

Then, run this:

echidna-test /src/contracts/test/fuzzing/VaultFuzzTest.sol --contract VaultFuzzTest --config /src/contracts/test/fuzzing/config.yaml

To exit:

exit

Linting

To check linting / code formatting:

yarn lint

or, to fix:

yarn lint:fix

Formatting

yarn format

Thank you!

If you appreciated this, feel free to follow me or donate!

ETH/Polygon/Avalanche/etc Address: 0x9680201d9c93d65a3603d2088d125e955c73BD65

Patrick Collins Twitter Patrick Collins YouTube Patrick Collins Linkedin Patrick Collins Medium

More Repositories

1

nft-mix

Solidity
803
star
2

dungeons-and-dragons-nft

#chainlink #nft
JavaScript
603
star
3

all-on-chain-generated-nft

A repo for generating random NFTs with metadata 100% on chain!
JavaScript
356
star
4

dao-template

TypeScript
244
star
5

full-stack-web3-metamask-connectors

180
star
6

chainlink_defi

Build a defi yield farmable dApp. Get started here.
JavaScript
157
star
7

rwa-creator

Solidity
133
star
8

smart-contract-frameworks

A list of smart contract frameworks
C
119
star
9

hardhat-smartcontract-lottery-fcc

JavaScript
118
star
10

hardhat-nft-marketplace-fcc

JavaScript
114
star
11

hardhat-nft-fcc

JavaScript
101
star
12

simple-storage-fcc

Solidity
99
star
13

ethers-simple-storage-fcc

JavaScript
88
star
14

unstoppable-ui

JavaScript
87
star
15

async-python

Shows how to use async requests vs requests
Python
87
star
16

hardhat-fund-me-fcc

JavaScript
83
star
17

defi-stake-yield-brownie

Solidity
78
star
18

smartcontract-lottery

Solidity
75
star
19

PatrickAlphaC

75
star
20

hardhat-simple-storage-fcc

JavaScript
74
star
21

aave_brownie_py

Solidity
61
star
22

nextjs-smartcontract-lottery-fcc

JavaScript
60
star
23

foundry-play

Solidity
59
star
24

fund-me-fcc

Solidity
56
star
25

pokemon-nft

Pokémon NFTs
Solidity
54
star
26

defi-stake-yield-brownie-freecode

Solidity
53
star
27

simple_storage

Solidity
51
star
28

erc20-brownie

Solidity
50
star
29

fund_me

Solidity
48
star
30

storage-factory-fcc

Solidity
45
star
31

web3_py_simple_storage

Python
45
star
32

nextjs-nft-marketplace-moralis-fcc

JavaScript
44
star
33

lens-blog

A minimal example of using Lens Protocol to build a blog
JavaScript
39
star
34

nextjs-nft-marketplace-thegraph-fcc

JavaScript
39
star
35

hardhat-erc20-fcc

JavaScript
38
star
36

html-js-ethers-connect

JavaScript
37
star
37

nft-demo

Python
37
star
38

defi_py_mix

Solidity
36
star
39

storage_factory

Solidity
35
star
40

hardhat-defi-fcc

Solidity
35
star
41

aave_web3_py

web3.py way to interact with aave
Python
35
star
42

denver-security

Solidity
34
star
43

html-fund-me-fcc

JavaScript
32
star
44

graph-nft-marketplace-fcc

TypeScript
32
star
45

sc-language-comparison

Solidity
31
star
46

smartcontract-upgrades-example

JavaScript
28
star
47

foundry-smart-contract-lottery-f23

Solidity
27
star
48

nextjs-ethers-metamask-connect

JavaScript
26
star
49

brownie_fund_me

Solidity
25
star
50

weather-nft

chainlink weather nfts
Solidity
24
star
51

brownie_simple_storage

Python
23
star
52

chainlink-the-graph

JavaScript
22
star
53

flashloan-forta-py

Python
22
star
54

chainlink-hardhat

JavaScript
20
star
55

upgrades-mix

Solidity
19
star
56

multicall-js

JavaScript
19
star
57

signatureVerification

Solidity
18
star
58

openweathermap_cl_ea

JavaScript
17
star
59

denver-security-challenges

Solidity
17
star
60

multicall

Python
16
star
61

hardhat-upgrades-fcc

JavaScript
16
star
62

hardhat-dao-fcc

TypeScript
15
star
63

ai-stablecoin

Solidity
15
star
64

staking-ui-demo

JavaScript
15
star
65

decentralized-raffle

TypeScript
15
star
66

ipfs_cl_ea

IPFS Chainlink External Adapter
JavaScript
14
star
67

get-all-transactions

Python
14
star
68

hardhat-simple-storage

JavaScript
13
star
69

aave_brownie_py_freecode

Solidity
13
star
70

hardhat-events-logs

JavaScript
12
star
71

nextjs-moralis-metamask-connect

JavaScript
12
star
72

hardhat-metamorphic-upgrades-fcc

JavaScript
12
star
73

defi-dapp

TypeScript
12
star
74

battle-game

JavaScript
11
star
75

foundry-vyper

A package for deploying and compiling vyper code in foundry
Solidity
11
star
76

fuzzing-example

Solidity
10
star
77

vyper-chain-info

Python
10
star
78

vrf_pizza

lol
Solidity
10
star
79

dapptools-demo

Solidity
10
star
80

nextjs-web3-react-metamask-connect

JavaScript
10
star
81

eth-global-live-audit

Solidity
10
star
82

filecoin_cl_ea

JavaScript
9
star
83

puppy-raffle-smartcon

Solidity
9
star
84

ape-fund-me-v23

Python
8
star
85

erc20-brownie-py

Python
8
star
86

brownie-events-logs

Python
7
star
87

patrickalphac.com

TypeScript
7
star
88

send_blob

Python
7
star
89

unfinished-defi-workshop

JavaScript
6
star
90

vrf_pizza_front_end

lol
CSS
6
star
91

gcp-weather

Solidity
6
star
92

nextjs-web3modal-metamask-connect

JavaScript
6
star
93

smartcon-hacker-house-hunt-rules

6
star
94

hardhat-fund-me-forked-fcc

JavaScript
5
star
95

geo_db_brownie

Solidity
5
star
96

clever-lottery-web3

JavaScript
5
star
97

scavenger-hunt

TypeScript
5
star
98

nextjs-ethers-introduction-fcc

JavaScript
5
star
99

vheader

A tool for making perfect vyper headers, inspired by transmissions11
Rust
5
star
100

nextjs-usedapp-metamask-connect

JavaScript
5
star