A structured checklist for reviewing EVM smart contracts. Built from notes across multiple audit engagements.
Work through each section during a review. Check items off as you verify them. Not every item applies to every contract — skip what is irrelevant but document why.
- Access Control
- Reentrancy
- Oracle & Price Feeds
- Flash Loan Risks
- Upgrade Patterns
- Token Integration
- Signatures & Replay Protection
PRs welcome. Each checklist item should have a one-line rationale and ideally a link to a real-world exploit that motivates it.
CC BY 4.0
Each checklist item links to a real incident where the pattern was exploited or nearly exploited. Some notable ones:
- Reentrancy: Curve pool read-only reentrancy (Jul 2023, ~$70M)
- Oracle: Mango Markets price manipulation (Oct 2022, $114M)
- Flash Loan: Euler Finance (Mar 2023, $197M)
- Access Control: Ronin Bridge (Mar 2022, $625M — compromised validator keys)
- Upgrades: Wormhole (Feb 2022, $320M — uninitialized implementation)
- Token: Fee-on-transfer handling failures across multiple DEX forks
- Signatures: Wintermute/Optimism 20M OP (multi-sig misconfiguration), Wormhole $320M (forged guardian signatures), permit front-running (industry-wide)
Work in progress. Adding more items as new audit patterns emerge.