Coverage note
Blockchain penetration testing for the whole application, not just the contract
Blockchain penetration testing looks at an application built on a chain from end to end. So it covers smart contracts, the web front end, key handling and the infrastructure around them.
- Manual exploit chains
- PTES and the OWASP testing guide
- Authorised scope only
Why blockchain penetration testing matters
Code on a public chain is visible to everyone and often cannot be changed after deployment. Therefore weaknesses are costly, and they must be found before launch.
Most incidents also involve ordinary systems. For example, a compromised front end or poorly protected keys, rather than the contract alone.
What blockchain penetration testing covers
The test covers each layer an attacker could use. For example, whether contract permissions match the design.
- Smart contract logic and permissions
- Web front end and its integrations
- Key and wallet handling
- Nodes and infrastructure
- Admin and upgrade mechanisms
Blockchain penetration testing readiness check
Tick what is already true. Open items go into the written rules of engagement.
Your result appears here as you tick, so you can see what is still open.
Scoping blockchain penetration testing
Contract count drives effort. However, the surrounding systems often matter more.
| Question | Effect on scope |
|---|---|
| How many contracts? | Each is reviewed |
| Upgradeable contracts? | Admin paths are checked |
| Custodial keys? | Key handling adds scope |
| Testnet available? | Testing stays off mainnet |
Authorisation and safety
Testing runs only under written rules of engagement, on a test network or fork. Also, no activity touches live funds or other users.
In addition, findings are shared privately before any public disclosure.
Evidence, fees and retest
Findings come with evidence and a fix. The OWASP Smart Contract Top 10 frames common contract issues.
Full engagements run from $35,000 to $120,000, while the floor is $25,000. Also, the bounded Attack Surface Diagnostic starts at $4,500. Moreover, its fee is credited in full against a full engagement commissioned within ninety days.
Also plan the launch carefully. Because fixes after deployment are hard, retest the final build that will actually ship. So the version tested and the version deployed match. In addition, monitor contracts after launch, because early unusual activity is often the first warning.
Blockchain penetration testing questions
Is blockchain penetration testing the same as a contract audit?
No. A contract review is part of it, alongside front end, keys and infrastructure.
Does blockchain penetration testing touch mainnet?
No. Testing runs on a test network or fork.
When should blockchain penetration testing happen?
Before launch, because deployed code is hard to change.
Who leads the work?
A senior penetration hacker.
Related guides
Send the brief for blockchain penetration testing
Describe the contracts, front end and key handling. The penetration hacker who would lead the work replies with a written scope and one fixed fee.
Send the brief