Skip to content
Breakpoint Labs
Authorised systems only. Breakpoint Labs works only on authorised scope, so rules of engagement are agreed in writing first.

Coverage note

Blockchain penetration testing for the whole application, not just the contract

Blockchain penetration testing looks at an application built on a chain from end to end. So it covers smart contracts, the web front end, key handling and the infrastructure around them.

  • Manual exploit chains
  • PTES and the OWASP testing guide
  • Authorised scope only
Blockchain penetration testing: agree the scope, test with authorisation and evidence and retest

Why blockchain penetration testing matters

Code on a public chain is visible to everyone and often cannot be changed after deployment. Therefore weaknesses are costly, and they must be found before launch.

Most incidents also involve ordinary systems. For example, a compromised front end or poorly protected keys, rather than the contract alone.

What blockchain penetration testing covers

The test covers each layer an attacker could use. For example, whether contract permissions match the design.

  • Smart contract logic and permissions
  • Web front end and its integrations
  • Key and wallet handling
  • Nodes and infrastructure
  • Admin and upgrade mechanisms

Blockchain penetration testing readiness check

Tick what is already true. Open items go into the written rules of engagement.

Your result appears here as you tick, so you can see what is still open.

Scoping blockchain penetration testing

Contract count drives effort. However, the surrounding systems often matter more.

QuestionEffect on scope
How many contracts?Each is reviewed
Upgradeable contracts?Admin paths are checked
Custodial keys?Key handling adds scope
Testnet available?Testing stays off mainnet

Authorisation and safety

Testing runs only under written rules of engagement, on a test network or fork. Also, no activity touches live funds or other users.

In addition, findings are shared privately before any public disclosure.

Evidence, fees and retest

Findings come with evidence and a fix. The OWASP Smart Contract Top 10 frames common contract issues.

Full engagements run from $35,000 to $120,000, while the floor is $25,000. Also, the bounded Attack Surface Diagnostic starts at $4,500. Moreover, its fee is credited in full against a full engagement commissioned within ninety days.

Also plan the launch carefully. Because fixes after deployment are hard, retest the final build that will actually ship. So the version tested and the version deployed match. In addition, monitor contracts after launch, because early unusual activity is often the first warning.

Blockchain penetration testing questions

Is blockchain penetration testing the same as a contract audit?

No. A contract review is part of it, alongside front end, keys and infrastructure.

Does blockchain penetration testing touch mainnet?

No. Testing runs on a test network or fork.

When should blockchain penetration testing happen?

Before launch, because deployed code is hard to change.

Who leads the work?

A senior penetration hacker.

Related guides

Send the brief for blockchain penetration testing

Describe the contracts, front end and key handling. The penetration hacker who would lead the work replies with a written scope and one fixed fee.

Send the brief