Skip to content

Reports and Vulnerability Intelligence

Finding Search and Public Reports

Resource Tier Use
Solodit Must learn Search public contest and audit findings.
Code4rena Reports Use in real audits Public competitive audit findings.
Sherlock Audits Use in real audits Reports from Sherlock contests and audits.
Cantina Competitions Use in real audits Contest scopes and findings.
Spearbit Portfolio Use in real audits Public reports and specialty checklists.
OpenZeppelin Audit Reports Use in real audits Mature report format and remediation style.
Trail of Bits Publications Use in real audits Public reports and research.
ConsenSys Diligence Audits Use in real audits EVM audit reports and tooling references.
Pashov Audits Use in real audits Large public archive of independent audit reports.

Incident and Exploit Study

Resource Tier Use
DeFiHackLabs Must learn Reproduce exploits with runnable PoCs.
Rekt Must learn Incident narratives and loss context.
Immunefi Blog Use in real audits Vulnerability writeups and ecosystem loss reports.
ChainSecurity Blog Use in real audits Research and audit insights.
SlowMist Hacked Archive Use in real audits Incident database and trend tracking.
BlockSec Blog Use in real audits Exploit analysis and transaction traces.
DigiBastion Threat Intel Use in real audits Web3, DeFi, supply-chain, and OPSEC alert feed with subscriptions.
PeckShield Alerts Watchlist Fast incident signal; verify independently.

How to Study a Report

For each finding, extract:

  • root cause
  • impacted asset
  • missing invariant or authorization check
  • exploit preconditions
  • why tests missed it
  • fix pattern
  • monitoring rule that would detect exploitation
Educational resource only. Links and listings are not endorsements by Raiders0786, DigiBastion, maintainers, contributors, or this project. Verify third-party resources before relying on them. Not legal, financial, investment, compliance, or professional security advice. Read the full disclaimer.