← Index
Source: docs/zsub/hacking-instructions-summary.md (auto-generated by scripts/generate-docs-html.mjs — edit the .md, not this file)

Smart Contract Hacking Instructions — Summary

Two sets of CTF-style smart contract security exercises. Each .md defines an attacker scenario (Intro / Accounts / Tasks) on a target contract; the standard task structure is (1) exploit the vulnerability → (2) patch the contract → (3) sometimes propose alternate fixes. Each exercise has a paired .pdf.


Set 1 — Fundamentals

Core vulnerability classes. Start here if new to smart contract security.

Category What it teaches Exercises
Access Control Missing/incorrect permission checks (modifiers, owner roles, delegatecall to untrusted code) 1 (md / pdf) · 2 (md / pdf) · 3 (md / pdf) · 4 (md / pdf)
Arithmetic Overflows Integer over/underflow (pre-0.8 Solidity, unchecked blocks, casting bugs) 1 (md / pdf) · 2 (md / pdf) · 3 (md / pdf) · 4 (md / pdf)
ERC20 Token-spec edge cases — approval race, fee-on-transfer, missing return values 1 (md / pdf) · 2 (md / pdf)
ERC721 NFT-spec pitfalls — safeTransferFrom reentrancy hooks, ownership checks 1 (md / pdf) · 2 (md / pdf)
Randomness Vulnerabilities On-chain "randomness" using block.timestamp/blockhash is predictable 1 (md / pdf) · 2 (md / pdf)
Reentrancy Classic + cross-function + read-only reentrancy. Bank/EtherBank-style targets 1 (md / pdf) · 2 (md / pdf) · 3 (md / pdf) · 4 (md / pdf)
tx.origin Phishing Why tx.origin for auth is unsafe — attacker contract can impersonate user 1 (md / pdf)

Set 2 — DeFi & Advanced

Composability, oracles, MEV, governance — the categories that produce real-world losses.

Category What it teaches Exercises
DAO Attack Governance hijacking — token-borrow voting, proposal/queue/execute flaws 1 (md / pdf) · 2 (md / pdf) · 3 (md / pdf)
DEX AMM invariant violations — pool draining via reserve manipulation 1 (md / pdf) · 2 (md / pdf)
DoS (Denial of Service) Out-of-gas loops, blocked withdrawals, push-vs-pull payment patterns 1 (md / pdf) · 2 (md / pdf) · 3 (md / pdf) · 4 (md / pdf)
Flash Loan Attacks Using flash loans to drain pools (combined with reentrancy / price manipulation) 1 (md / pdf) · 2 (md / pdf)
Flash Loans Flash loan provider mechanics — fee accounting, repayment checks 1 (md / pdf) · 2 (md / pdf) · 3 (md / pdf)
Frontrunning Mempool MEV — sandwich, replay-with-higher-gas, commit-reveal as defense 1 (md / pdf) · 2 (md / pdf) · 3 (md / pdf)
Money Markets Lending protocol exploits — collateral pricing, liquidation manipulation 1 (md / pdf) · 2 (md / pdf)
Oracle Manipulation Spot-price oracle attacks (TWAP defense), off-chain oracle key/source hijack 1 (md / pdf) · 2 (md / pdf) · 3 (md / pdf)
Replay Attack Signature reuse across chains/contracts/nonces — EIP-712 domain separation 1 (md / pdf) · 2 (md / pdf) · 3 (md / pdf)
Sensitive On-Chain Data "Private" storage isn't private — slot reading, leaked secrets 1 (md / pdf) · 2 (md / pdf) · 3 (md / pdf)
Unchecked Returns call / send / low-level calls silently fail; missing success checks 1 (md / pdf) · 2 (md / pdf) · 3 (md / pdf)

Suggested Study Order

  1. Set 1 in listed order (Access Control → Reentrancy is the natural progression for breaking single contracts).
  2. Set 2 — Unchecked Returns / DoS / Sensitive Data before DeFi attacks (cheap fundamentals first).
  3. Set 2 — Oracle Manipulation → Flash Loans → Flash Loan Attacks → DEX → Money Markets (DeFi composability stack — these build on each other).
  4. Set 2 — Frontrunning, Replay, DAO as standalone categories.

Format Convention

Every exercise file follows:

Solutions are not included in this folder — these are practice prompts, not write-ups.