finds.dev← search

// the find

crytic/building-secure-contracts

★ 2,481 · Solidity · AGPL-3.0 · updated Apr 2026

Guidelines and training material to write secure smart contracts

A training and reference repo from Trail of Bits covering smart contract security: high-level dev guidelines, an EVM reference, a cross-chain catalog of common vulnerability patterns, and hands-on exercises for their own tools (Echidna, Medusa, Slither, Manticore). It's aimed at smart contract developers and auditors who want structured material beyond scattered blog posts.

The 'not-so-smart-contracts' section covers vulnerability classes across nine chains (Solana, Algorand, Sui, TON, Substrate, Cosmos, Cairo, not just EVM), each with runnable broken code plus a fix, not just prose description. The Echidna/Manticore exercises ship template + solution files so you can self-check instead of just reading theory. CI actually runs the Echidna and Medusa workflows against the example contracts, so the fuzzing examples are verified to still work rather than rotting silently.

Slither and Medusa docs are git submodules pointing at separate repos, so cloning this alone gives you broken or empty directories unless you remember --recurse-submodules. AGPLv3 is an odd license choice for what is effectively documentation, and could make teams hesitant to lift code snippets into proprietary audit tooling. The EVM opcode and EIP/fork reference tables have no visible versioning against hardfork names, so there's no easy way to tell if a given page is current without cross-checking dates yourself.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →