// the find
crytic/building-secure-contracts
Guidelines and training material to write secure smart contracts
A training and reference repo from Trail of Bits covering smart contract security: high-level dev guidelines, an EVM reference, a cross-chain catalog of common vulnerability patterns, and hands-on exercises for their own tools (Echidna, Medusa, Slither, Manticore). It's aimed at smart contract developers and auditors who want structured material beyond scattered blog posts.
The 'not-so-smart-contracts' section covers vulnerability classes across nine chains (Solana, Algorand, Sui, TON, Substrate, Cosmos, Cairo, not just EVM), each with runnable broken code plus a fix, not just prose description. The Echidna/Manticore exercises ship template + solution files so you can self-check instead of just reading theory. CI actually runs the Echidna and Medusa workflows against the example contracts, so the fuzzing examples are verified to still work rather than rotting silently.
Slither and Medusa docs are git submodules pointing at separate repos, so cloning this alone gives you broken or empty directories unless you remember --recurse-submodules. AGPLv3 is an odd license choice for what is effectively documentation, and could make teams hesitant to lift code snippets into proprietary audit tooling. The EVM opcode and EIP/fork reference tables have no visible versioning against hardfork names, so there's no easy way to tell if a given page is current without cross-checking dates yourself.