In Web3 smart contract front end security is often overlooked and considered less important, due to the fact that it's "only" an interface to the contract. However this couldn't be further from the truth as classical web vulnerabilities are much more severe in the blockchain space. For example a Stored Cross-Site Scripting (XSS) vulnerability in a decentralised marketplace could lead to theft of funds from users wallets or improperly stored secrets (e.g. private keys) could lead to taking over control of the whole protocol. UI integration security is critical, as most of the time regular users will be using it instead of interacting directly with smart contracts. The two examples mentioned here are real cases identified by our consultants.
Smart Contract Audits
Security of smart contracts is a critical factor especially in the decentralized finance (DeFi) space. Once deployed on mainnet and real user funds starts flowing in and the total value locked (TVL) increases, the interest of black hats about the project also rises. An exploited vulnerability in a smart contract may result in catastrophic losses to the project users and its owners. It is important to incorporate security in the development lifecycle from the start.
REDTEAM.PL is experienced in conducting smart contract audits / security assessments mainly for Ethereum Virtual Machine (EVM) based chains (e.g. Ethereum, BNB Chain, Polygon or Avalanche to name a few) written in Solidity or Vyper. In addition we also have experience with Cairo (StarkNet) and Rust (Terra and Solana).
Exchange & Trading Platforms Security
If you are running a centralized crypto exchange or any kind of trading platform handling user funds it is critical to perform regular security assessments for both applications and network infrastructure. REDTEAM.PL has been providing penetration testing services to both crypto currency exchange sector as well as traditional finance for many years confirmed with references.
Blockchain forensics & Incident Response
In case a hack has already happened and funds were lost whether a smart contract has been exploited or private keys have been stolen we can aid the customer by performing an analysis of the incident. Using on-chain analysis we can track the funds flow and perform a post mortem analysis of an exploit in order to determine the root cause. We can also help in classic Digital Forensics & Incident Response (DFIR).
Managed Bug Bounty Programs
It is critical to get a smart contract audit, ideally from a few different vendors and not just to rely on one. Once the contract has been deployed on mainnet and getting significant user adoption the project owners should consider starting a bug bounty program in order to incentivise whitehat hackers from around the world to look at their code and responsibly disclose security issues before a blackhat finds it and steals the funds. Depending on the customer needs we can help with designing, setting up and maintaining a bug bounty program.
Projects & Companies Verification (OSINT)
Venture Capital Funds, Angel Investors, businesses or even individual investors that are looking into investment opportunities or partnerships should verify their contractors. Using Open Source Intelligence (OSINT) techniques and our technical expertise we can help perform risk assessment and identify potential red flags. Background checks of the team, business entities, analysis of the whitepaper and verification of the project claims. Checking blockchain data for connection with known scams or fraudulent sources of funds. Smart contracts analysis for potential risk factors e.g. rug pulls, low quality, copy/paste code is also performed.
Wallet Security Assessments
In case you are developing a crypto currency wallet whether in the form of a desktop, mobile, web application, hardware or a browser extension REDTEAM.PL can help you with assessing its security. We have a proven track record of identifying vulnerabilities in popular software including browsers from Google, Apple or Microsoft.