Skip to content

For Aspiring Auditors

Build skill by pairing exploit history, ecosystem-specific testing, audit reports, and repeatable review artifacts. The goal is not to collect tools. The goal is to reason from code and state to exploitability, impact, and remediation.

30 / 60 / 90-day path

Window What to do Evidence to keep
30 days Read three public audit reports, reproduce two historical bugs, and set up Foundry plus one non-EVM test stack. Notes, fork tests, traces, failing tests, fixed tests.
60 days Build a review notebook with assets, actors, invariants, trust assumptions, privileged roles, and known unknowns. Threat model, invariant list, issue template, severity rubric.
90 days Review a small open-source protocol or toy scope and publish a responsible non-sensitive write-up. Report excerpt, PoC tests, remediation notes, reviewer feedback.

Must-read pages

Checklists to use first

First 10 resources

  1. OWASP SCSVS
  2. OWASP SCSTG
  3. Solodit
  4. DeFiHackLabs
  5. OpenZeppelin EIP-4337 audit
  6. Solana Program Security course
  7. Mollusk
  8. Anchor LiteSVM
  9. Tenderly docs
  10. BlockSec Phalcon simulator

Common failure

New auditors often jump from tool output to severity without proving the exploit path. Treat every tool result and AI suggestion as a hypothesis until a test, trace, invariant violation, or source-level argument proves it.

Educational resource only. Links and listings are not endorsements by Raiders0786, DigiBastion, maintainers, contributors, or this project. Verify third-party resources before relying on them. Not legal, financial, investment, compliance, or professional security advice. Read the full disclaimer.