Banner Image

All Services

Programming & Development blockchain, nft, cryptocurrency, tokens

Web3 dApp Penetration Test

$165/hr Starting at $400

I perform Web3-specific dApp penetration tests covering the attack surfaces that smart contract audits and standard Web2 pen tests both miss — wallet connector security, EIP-712 signature handling, frontend injection to trigger malicious approvals, and off-chain API vulnerabilities.

Test coverage: wallet connector attack surface (phishing-resistant flow analysis, EIP-712 type hash validation, signature replay with missing nonces or domain separators); frontend XSS via injected content triggering malicious transaction popups; JSON-RPC endpoint CORS and authentication; backend API security (auth bypass, IDOR, rate limiting); IPFS metadata endpoint manipulation; transaction simulation bypass (showing safe simulation but executing malicious transaction); and off-chain component security (oracle relay, keeper, relayer authentication).

Deliverables: dApp pentest report with findings, PoC evidence where applicable, severity ratings, and remediation guidance specifically framed for Web3 application developers.

Requires: dApp URL, GitHub repo access, API documentation, and written authorisation. Testnet strongly preferred for active testing.

About

$165/hr Ongoing

Download Resume

I perform Web3-specific dApp penetration tests covering the attack surfaces that smart contract audits and standard Web2 pen tests both miss — wallet connector security, EIP-712 signature handling, frontend injection to trigger malicious approvals, and off-chain API vulnerabilities.

Test coverage: wallet connector attack surface (phishing-resistant flow analysis, EIP-712 type hash validation, signature replay with missing nonces or domain separators); frontend XSS via injected content triggering malicious transaction popups; JSON-RPC endpoint CORS and authentication; backend API security (auth bypass, IDOR, rate limiting); IPFS metadata endpoint manipulation; transaction simulation bypass (showing safe simulation but executing malicious transaction); and off-chain component security (oracle relay, keeper, relayer authentication).

Deliverables: dApp pentest report with findings, PoC evidence where applicable, severity ratings, and remediation guidance specifically framed for Web3 application developers.

Requires: dApp URL, GitHub repo access, API documentation, and written authorisation. Testnet strongly preferred for active testing.

Skills & Expertise

AltcoinAPI DevelopmentApp DevelopmentBinanceBitcoinBlockchainCardanoCryptocurrencyDAppDigital WalletDistributed Ledger TechnologyDogecoinEthereumInitial Coin OfferingMetaMaskNFTPenetration TestingSafety EngineeringSecurity ConsultingSmart ContractsSoftware TestingSolanaSolidityTokensWeb3

0 Reviews

This Freelancer has not received any feedback.