2026-08-11
OlderNew web3 security vulnerability disclosures and CVEs in the last 48 hours
Web3 Security Tools Overview
RESEARCH: New web3 security vulnerability disclosures and CVEs in the last 48 hours
Web3 Security Tools Overview
This repository curates a comprehensive list of essential tools for securing blockchain-based applications and investigating cryptocurrency-related activities. Below is an organized breakdown of the categories and specific tools mentioned, along with additional resources for deeper exploration.
Smart Contract Auditing Tools
These tools help developers identify and rectify security vulnerabilities in smart contracts before deployment.
Testing Frameworks:
- Foundry: A fast, robust framework for writing and testing Solidity smart contracts.
- Hardhat: A development environment to compile, test, and deploy Ethereum-based applications.
- Brownie: Python-based testing and deployment framework with a focus on simplicity.
- Truffle: A popular suite offering migrations, testing, asset compilation, and more.
Fuzzers:
- Echidna: Fuzzer for detecting vulnerabilities in smart contracts by exploring state transitions.
- Foundry Fuzz: Offers contract-level fuzzing capabilities within the Foundry environment.
- ChainFuzz: A tool designed to uncover runtime errors and security flaws via automated testing.
- Harvey & sFuzz: Specialized fuzzers targeting Solidity smart contracts.
Linters & Formatters:
- EthLint: Analyzes Solidity code for potential issues.
- Prettier + Solidity Plugin: Ensures consistent coding style and formatting.
- Solhint: Linter for enforcing best practices in Solidity development.
Blockchain Forensics Tools
These tools assist in tracking, analyzing, and investigating blockchain transactions to combat fraud and theft.
Blockchain Explorers:
- Etherscan, btc.com, Bscscan, Polygonscan: Platforms for querying transaction details on Ethereum, Bitcoin, Binance Smart Chain, and Polygon respectively.
- Universal Explorers like Blockchain.com & Blockchair.com: Aggregators providing insights across multiple blockchain networks.
Smart Contract Decompilers:
- Dedaub, Panoramix, abi-decompiler: Tools for reversing compiled Solidity contracts to their source code form.
Browser Extensions:
- Tenderly, MetaDock, Sentio, Blockchair, Impersonator: Extensions that enhance on-the-go analysis and monitoring of blockchain activities.
Rug Pull & Security Screening Tools
These tools are designed to detect suspicious token contracts and potential rug pulls before investment.
- Rug Pull Detectors:
- Rug Pull Finder, bscheck, rugscreen, QuillCheck, poocoin’s rugcheck, tokensniffer, rugpulldetector, rugdoc honeypot checker: Platforms offering real-time analysis of token contract safety.
Transaction Visualization & Analysis Tools
Tools that provide visual insights into blockchain transactions, aiding in front-running detection and transaction tracing.
Visualization Tools:
- MistTrack, ethtx.info, Front-running explorer, Phalcon BlockSec, Bitquery Explorer, Tx eth samczsun, Tenderly, Sentio, Socketscan: Offer graphical representations of transactions, gas usage, and potential attacks.
3D VR Blockchain Visualization:
- eigenphi.io, nansen.ai: Innovative platforms that provide immersive visualizations of blockchain data in three-dimensional space.
Miscellaneous Tools & Resources
Additional tools supporting various aspects of web3 security and development.
Wallet Security:
- Stelo Labs, BlowFish, Pocket Universe, Wallet Guard, Interlock, Revoke.cash, Novus, Web3 Antivirus, PeckShield Alert: Solutions focused on securing wallet interactions and preventing unauthorized access.
Officer CIA’s Investigation Tools List:
- A curated list of investigative tools from the Office of the Chief Archivist for blockchain forensics.
Toke Flow Visualizer & Analytical Tools:
- breadcrumbs.app, bloxy.info, ethtective.com: Platforms that visualize token flows and transaction patterns across networks.
Auditing Books, Guides, and Further References
Resources for learning about smart contract auditing best practices and staying updated on web3 security trends.
- Auditing Books & Guides:
- The Auditors Book, Solodit.xyz, Audit Hero, Solidity Attack Vectors, Audit Checklist, Awesome Solidity Gas Optimizations, Secureum Blogs, Diligence - Smart Contract Best Practices, Blockchain Hacking QuickStart Guide, How to Become a Smart Contract Auditor by Cmichel.
Additional GitHub Topics & Links
- GitHub Topics: Explore curated collections under web3-security.
- Web3 Security Tools Repository: Access the full list and contribute missing tools at Quillhash/Web3-Security-Tools.
- Suggested Sources for Claims:
These tools and resources collectively empower developers, security researchers, and blockchain enthusiasts to build more secure applications and effectively investigate suspicious activities on the blockchain.
Summary
Key Developments
Sources
- Quillhash/Web3-Security-Tools
- GitHub Advisory Database
- gmh5225/awesome-web3-security
- 0xMarcio/cve
- Tenable Newest CVEs
- sql3t0/cve-disclosures
- OpenCVE GitHub Vulnerabilities
- EthanKim88/ethan-cve-disclosures
- thecosmicexplorer/tools
- CVE‑2026‑40072 Detail - NVD
- Stealing Trust: Unraveling Blind Message Attacks in Web3 Authentication