2022 saw a massive increase in the number of developers participating across the blockchain development ecosystem, as well as pioneering protocols supporting the launch of novel technologies. With the rapid innovation came a deluge of new exploits, attack vectors, and hacking techniques that Web3 security teams must design for and defend against going forth.
OpenZeppelin and the greater community of Web3 security experts aim to document the security research from 2022 in order to enable the ecosystem at large to build safer decentralized technology.
As a result, we are announcing the Top 10 Blockchain Hacking Techniques of 2022 project, and are inviting community votes via the form below. This endeavor has the twofold purpose of surfacing new and practical security research while also providing a must-read top 10 of 2022 for every blockchain security researcher and Web3 security enthusiast. While projects like DASP Top 10 identify the most common vulnerability types, the Top 10 Blockchain Hacking Techniques project aims to identify the most novel, pervasive, and impactful vulnerability types, techniques, and methodologies of the previous year.
We would like to give credit to PortSwigger for leading the Top 10 Web Hacking Techniques project which we have “forked” to lead a similar initiative in the blockchain space.
Here’s the list of hacking techniques received during the submission phase. Feel free to review each before voting via the form below: