Beginner Roadmap to Smart Contract Auditing

  Рет қаралды 36,582

Andy Li

Andy Li

Күн бұрын

Пікірлер: 188
@haruxe5140
@haruxe5140 2 жыл бұрын
This video couldn't come at a better time! Documentation is so limited in the auditing space, you are the goat Andy 🐐
@andyli
@andyli 2 жыл бұрын
thanks mate, appreciate it! 🐐
@udoma8
@udoma8 2 жыл бұрын
Yes, I agree with you. There is limited resources in the auditing space. Thanks Andy, will be looking forward to more crumbs from you.
@danielcawley1051
@danielcawley1051 2 жыл бұрын
hey im a 14 year old that is in tutorial hell right now, ive learned solidity + react js for 8 months now so after learning security (which I already know the basics of - e.g. reentrancy), I can make money :) Thank you so much for inspiring me, I really appreciate the work your put into these videos
@andyli
@andyli 2 жыл бұрын
It is amazing you are getting into this at 14 years old, THAT is inspiring
@danielcawley1051
@danielcawley1051 2 жыл бұрын
follow up, I've completed ethernaut and damn vulnerable defi and I'm just about to finish off completing secureum and then I'm gonna jump into it
@andyli
@andyli 2 жыл бұрын
Awesome, see you in the arena 🚀
@luigixb1
@luigixb1 2 жыл бұрын
@@danielcawley1051 Thats awesome man!
@danielcawley1051
@danielcawley1051 2 жыл бұрын
@@luigixb1 something even more awesome is that ive recently got my first payout and ive earned 91$, i just need to keep this up
@laiyintam6349
@laiyintam6349 2 жыл бұрын
5k bounty and 2 high severity on first 2 months, awesome!
@andyli
@andyli 2 жыл бұрын
Thanks!
@devotedros
@devotedros 8 ай бұрын
@laiyintam6349 Could u share ur discord ?
@devotedros
@devotedros 8 ай бұрын
@laiyintam6349 Could u share ur discord ?
@Studiom44
@Studiom44 2 жыл бұрын
Been searching high and low for the info you've shared here! Thank you so much!!!
@andyli
@andyli 2 жыл бұрын
Glad it was helpful!
@PaladinOfWeb3
@PaladinOfWeb3 2 жыл бұрын
Always wanted to find a way to link my cyberspace career and my cryptospace hobby, glad the algorithm made me pass through your channel.
@andyli
@andyli 2 жыл бұрын
hail to the algorithm
@baroonjha3160
@baroonjha3160 2 жыл бұрын
This is the video I'm awaiting for.Thanks Andy ,Great video .
@andyli
@andyli 2 жыл бұрын
Cheers!
@alaazingi5784
@alaazingi5784 Жыл бұрын
Hello Andy, I am 2nd year computer science student and learning solidity was a hobby for me that evolved into deep interest. Thank you for really educational videos they are helping me a lot to break into auditing.
@andyli
@andyli Жыл бұрын
awesome, glad to hear!
@natanaelconcha92
@natanaelconcha92 2 жыл бұрын
Been waiting on a video like this, it's fairly new so not many people talk about it
@andyli
@andyli 2 жыл бұрын
True
@maryonacross03
@maryonacross03 Жыл бұрын
selamlar sizin bu videonuz olmasaydı ilerlemem daha zor olacaktı herşey için teşekkürler.
@Rudra0x01
@Rudra0x01 8 ай бұрын
This is very helpful video, as this field are very limited of resources.
@tangflx
@tangflx 2 жыл бұрын
your video is gold! keep up the good work!
@andyli
@andyli 2 жыл бұрын
Thank you, appreciate it!
@tangflx
@tangflx 2 жыл бұрын
@@andyli I might kickstart bug bounty career bcoz of u. Thanks!!
@andyli
@andyli 2 жыл бұрын
Nice, good luck!
@mlntdtechbae
@mlntdtechbae 2 жыл бұрын
I'm so glad I decided to learn SM development & auditing! Currently learning via's Patrick's course. These kinds of rewards/payouts are very encouraging, lol.
@andyli
@andyli 2 жыл бұрын
Nice! Rewards did go down a by recently though
@mlntdtechbae
@mlntdtechbae 2 жыл бұрын
@@andyli Good to know. Only makes me want to learn faster, lol.
@Machinebrains2Mcd
@Machinebrains2Mcd Жыл бұрын
This is so amazingly put together will study your advice + opinions to gain better understanding solidity security audits grinding my way thanks Andy
@andyli
@andyli Жыл бұрын
Glad it was helpful!
@vomivore
@vomivore 2 жыл бұрын
Thanks for taking time to make this feedback!
@andyli
@andyli 2 жыл бұрын
no prob!
@matthewlee112
@matthewlee112 2 жыл бұрын
Fool, now I will be able to audit smart contracts too!
@andyli
@andyli 2 жыл бұрын
Yeah? But I have a 2 month head start 😈
@matthewlee112
@matthewlee112 2 жыл бұрын
@@andyli im gonna borrow the time stone
@erictee6950
@erictee6950 2 жыл бұрын
Keep it up Andy !
@andyli
@andyli 2 жыл бұрын
🙌
@morganweaver4230
@morganweaver4230 2 жыл бұрын
ABout to start an auditing fellowship, this is fantastic. Rally good specific resources and general commentary on the learning process in auditing--because security is a really complex and technical field in tech, let alone crypto.
@andyli
@andyli 2 жыл бұрын
Nice one, getting into a auditing fellowship. Which company was it?
@thomash5390
@thomash5390 2 жыл бұрын
Very cool - how did you find the fellowship?
@andyli
@andyli 2 жыл бұрын
It might be this yacademy.dev
@bobbychase5616
@bobbychase5616 2 жыл бұрын
such a banger video! so fun to watch the success from learning a new thing i wonder if the hassle of traditional bug bounty led you to crypto auditing or was it general interest. im still on my oscp journey so i hope this space isnt too crowded by the time i jump in. cheers!
@andyli
@andyli 2 жыл бұрын
Thanks! I stumbled onto this randomly when I saw a someone post about the Damn Vulnerable Defi CTF on twitter. I doubt it will be crowded anytime soon
@digitalchinmay263
@digitalchinmay263 2 жыл бұрын
How to actually write reports of low risk issues in code4rena submissions ?
@andyli
@andyli 2 жыл бұрын
have a look at the previous audit reports to get some ideas
@tangjunnz
@tangjunnz 2 жыл бұрын
thank you so much, awesome 👍👍
@andyli
@andyli 2 жыл бұрын
👍👍
@abdulhaqmohammed
@abdulhaqmohammed 2 жыл бұрын
This is the exact thing I was looking for. Thank you so much Andy👍
@andyli
@andyli 2 жыл бұрын
Glad it was helpful!
@rahulpujari5601
@rahulpujari5601 2 жыл бұрын
What a beautiful detailed roadmap! Thanks so much for sharing Andy 👌
@andyli
@andyli 2 жыл бұрын
Glad you enjoyed!
@ethisfreedom
@ethisfreedom Жыл бұрын
I hope it gets crowded! We need more security!
@MichelLedig
@MichelLedig 2 жыл бұрын
please keep going with the channel u are helping me build my journey so much. If karma exists this shit will go back twice to you Much love from Brasil!
@andyli
@andyli 2 жыл бұрын
💯 more to come!
@ashhadali7592
@ashhadali7592 2 жыл бұрын
incredible video i like it hope u create more on methodology
@andyli
@andyli 2 жыл бұрын
Thanks! I will think about how to create a video on methodology
@ashhadali7592
@ashhadali7592 2 жыл бұрын
@@andyli waiting create live auditing video also Thanks in advance u done great job
@PetritK10
@PetritK10 2 жыл бұрын
That's what I wanted for 2023 :D
@andyli
@andyli 2 жыл бұрын
😀
@ms-ej4gd
@ms-ej4gd Жыл бұрын
Best roadmap. Subscribed
@ayushmanthapa_onion
@ayushmanthapa_onion 2 жыл бұрын
this is great andy! thanks alot
@andyli
@andyli 2 жыл бұрын
🙏
@yufang173
@yufang173 2 жыл бұрын
Awesome, thanks!
@andyli
@andyli 2 жыл бұрын
👍
@garyb99
@garyb99 2 жыл бұрын
You have awesome content! Keep up the good work
@andyli
@andyli 2 жыл бұрын
Thanks!
@samratgupta8487
@samratgupta8487 2 жыл бұрын
Great video thanks😇
@andyli
@andyli 2 жыл бұрын
🙌
@jrsantos1737
@jrsantos1737 2 жыл бұрын
Oh man, i read the article of legendary auditor C.Michel, he says it will take years before reviews will become useful for newbies in coding. Ouch that hurts! Im currently on 3rd month of javascript study coming from accounting background. Somehow i touch the finance concepts of derivatives during college years, this might help me to shift to smart contract auditor. Wish me luck!
@andyli
@andyli 2 жыл бұрын
Yeah, finance concepts will help a lot. Good luck!
@devabdee
@devabdee 2 жыл бұрын
Thank you so much for creating this video.Really helpful. May God bless you. Also, Can you pls make a video on how to submit the findings? I actually didn't understood how submitting works. Do I need to make pull request or just copy and paste the part of the code before and after?One video on that would be really helpful. Thanks again
@andyli
@andyli 2 жыл бұрын
Have you registered to become a Warden yet? Once you get confirmed, you submit findings directly on the code4rena website.
@marquisebrown2397
@marquisebrown2397 2 жыл бұрын
Thank You, amazing video !
@andyli
@andyli 2 жыл бұрын
Thanks!
@marquisebrown2397
@marquisebrown2397 2 жыл бұрын
Once I finish Ethernaut do you think that’s enough info to get started on Code 4 Rena ?
@andyli
@andyli 2 жыл бұрын
@@marquisebrown2397 also read the secureum findings
@marquisebrown2397
@marquisebrown2397 2 жыл бұрын
@@andyli Thank you, do you know where I could get more than 1 Rinkeby test network ETH ?
@francoisguyot789
@francoisguyot789 2 жыл бұрын
Amazing content
@andyli
@andyli 2 жыл бұрын
Thanks!
@akshayaileni5258
@akshayaileni5258 2 ай бұрын
Any video how to do this whole process. Like spotting and reporting and stuff.
@lacag-lacag
@lacag-lacag 2 жыл бұрын
Thank u man been waiting this video alot but i wanna ask what kind of laptop do i need to participate the bugs is it ok 4GB ram
@andyli
@andyli 2 жыл бұрын
4GB is fine, you only need to browse GitHub and a text editor
@katelibra
@katelibra 2 жыл бұрын
Awesome 🤩
@andyli
@andyli 2 жыл бұрын
Thanks 🤗
@MartinMarchev
@MartinMarchev Жыл бұрын
Thanks for this amazing video! Both useful and inspiring!
@andyli
@andyli Жыл бұрын
Glad it was helpful!
@하동현-d5e
@하동현-d5e 2 жыл бұрын
Finally!
@andyli
@andyli 2 жыл бұрын
First comment 😊
@evmlionel
@evmlionel Жыл бұрын
Thanks for sharing! Since this space is so fast-paced, is there anything you would change for 2023?
@andyli
@andyli Жыл бұрын
Not really, the learning resources are the same. Perhaps learn Foundry instead of Hardhat
@internetkids5813
@internetkids5813 2 жыл бұрын
Great video
@andyli
@andyli 2 жыл бұрын
ty!
@S0L4RW4V3
@S0L4RW4V3 Жыл бұрын
I took about a year off from bug bounties after multiple dups @.@ or nothing for days like a big noob. Time really became precious after my former employer reduced by seniority & Tbh i was discoraged but knew that i just needed to improve so i began to study for htb's cpts. I will sit the exam soon and pass :D. After that my plan is to spam my application again.However, In the mean time , i wanted to reenter the bug bounty space. T.t i just miss "researching" lol and immunifi was an option. This is my first time hearing about code4rena and im excired to befome a warden. Lol sorry for the dump..mainly this is a thankyou for sharing
@andyli
@andyli Жыл бұрын
Nice, good luck hunting!
@adriapajaresaguilera572
@adriapajaresaguilera572 2 жыл бұрын
This is gold
@andyli
@andyli 2 жыл бұрын
thanks!
@dhom440
@dhom440 2 жыл бұрын
Many thanks for the video, I like your process 👍
@andyli
@andyli 2 жыл бұрын
Thank you! Cheers!
@apostle5135
@apostle5135 2 жыл бұрын
yay ! another video :D
@andyli
@andyli 2 жыл бұрын
:D
@lagrariscale8567
@lagrariscale8567 2 жыл бұрын
if i have no cyber security experience and i have little knowledge on solidity . is there any chance me finding bugs on code arena ?
@andyli
@andyli 2 жыл бұрын
it will just take you a bit longer to start finding bugs, start with the solidity tutorial
@ashhadali7592
@ashhadali7592 2 жыл бұрын
@@andyli how much solidity is need to find bugs
@nang88
@nang88 2 жыл бұрын
🐐 video
@andyli
@andyli 2 жыл бұрын
🙌
@James-li3ro
@James-li3ro 2 жыл бұрын
Im a web developer tryna break into security. would you suggest knowing about traditional pentesting before moving on to web3 security?
@andyli
@andyli 2 жыл бұрын
I don't think it is necessary, there are some concepts that help but I wouldn't consider them prerequisites
@James-li3ro
@James-li3ro 2 жыл бұрын
Thanks bro! Really thorough video. I appreciate your comment. Are you still working on traditional pentesting?
@andyli
@andyli 2 жыл бұрын
Yep, I only do bug bounties part time
@digitalchinmay263
@digitalchinmay263 2 жыл бұрын
Hey Andy, Can we get the notes of your secureum findings' classification. It will help us a lot.
@andyli
@andyli 2 жыл бұрын
github.com/andyfeili/SecureumFindings
@RJX_777
@RJX_777 7 ай бұрын
Hey Andy, is there a specific reason why you recommend doing CTF before learning solidity tutorial? Right now Im doing Solidity tutorial first, but it's not sticking very well and am confused by all the different little rules. Thinking about just jumping into CTF based on this video. Thanks
5 ай бұрын
Hey, how about you now? I learned solidity a few days ago and have the same question.
@EUU100
@EUU100 2 жыл бұрын
Thank you so much!
@andyli
@andyli 2 жыл бұрын
No problem!
@lllllIllIl.IIIlllIll
@lllllIllIl.IIIlllIll 6 ай бұрын
Ty for the video, is this still up to date?
@devadevans700
@devadevans700 2 жыл бұрын
Thank u😍
@andyli
@andyli 2 жыл бұрын
No problem!
@gideonnwankwo999
@gideonnwankwo999 Ай бұрын
see you at the arena..... noobie here
@mujtabaaltayib7417
@mujtabaaltayib7417 2 жыл бұрын
thank you so much
@andyli
@andyli 2 жыл бұрын
👍
@web3studynotes
@web3studynotes 2 жыл бұрын
Hello Andy, thank you for sharing this! Super helpful!! Do you currently provide any 1:1 consulting service on security contract audit?
@andyli
@andyli 2 жыл бұрын
Do you mean teaching or private audits?
@web3studynotes
@web3studynotes 2 жыл бұрын
@@andyli teaching. I am currently looking for help to break into web3 security space. Please let me know if you are available. Thanks!
@andyli
@andyli 2 жыл бұрын
Yeah can do. Feel free to reach out on twitter or any of the other social links on the channel
@TripleA679
@TripleA679 3 ай бұрын
Hi, is this roadmap still relevant now at 2024?.
@miraclemaxwell9988
@miraclemaxwell9988 11 ай бұрын
I’m learning ethical hacking can I combine with this?
@vns1111
@vns1111 2 жыл бұрын
hi andy is thier a way to remove swepper bot
@andyli
@andyli 2 жыл бұрын
Not sure what you mean by swepper bot
@RS-nc5qx
@RS-nc5qx Жыл бұрын
Is it best to go the developers route or cybersecurity for this? This is all a bit of everything.
@andyli
@andyli Жыл бұрын
You can learn this directly if it is what you want to do
@chibatomosuke5080
@chibatomosuke5080 2 жыл бұрын
Do you have link of this slide?
@andyli
@andyli 2 жыл бұрын
found it! docs.google.com/presentation/d/1Zx9DoS4wTAfu7d2WSSQHuVp3c1hwO3mOS3K76EbhIAE
@chibatomosuke5080
@chibatomosuke5080 2 жыл бұрын
@@andyli coool! You should add to description.Thanks!
@ashhadali7592
@ashhadali7592 2 жыл бұрын
will u create video how to perform auditing new in this field
@andyli
@andyli 2 жыл бұрын
go through the learning resources listed here and read past audit reports
@MrJCollector
@MrJCollector 2 жыл бұрын
Can i ask how do you join code4rena as a bug hunter?
@andyli
@andyli 2 жыл бұрын
fill out this form and join the Discord channel code4rena.com/warden-registration/
@niclans82
@niclans82 2 жыл бұрын
Hi Andy, your video pique my interest to learn about smart contract hacking /auditing. Do you think a total beginner in coding can follow through your guide and be good at this? Would it be possible?
@andyli
@andyli 2 жыл бұрын
Yeah it is possible. You will just need to spend more time on the Solidity tutorial - it is 32 hours long and assumes no prior knowledge.
@niclans82
@niclans82 2 жыл бұрын
@@andyli thanks a lot for your feedback Andy. Yeah, thinking of being good at understanding Solidity basics first before going further. My goal is to start as a smart contract developer and then gradually learning to be a smart contract auditor. I see many possibilities in Web3 and I hope to be ready to capilitalize once the bulls take over from the bear market.
@MrNike95
@MrNike95 Жыл бұрын
May i ask you that im on my journey for the oscp in 2023 is it worth it or should i focus on web3 security and start learning the fundamentals ? and What kinda job can i work after that .I watched some videos and it looks very interesting
@andyli
@andyli Жыл бұрын
You can work as a security engineer in web3, try some CFTs and see if you like this type of work.
@SKardasisLJC4E
@SKardasisLJC4E 2 жыл бұрын
Did you have to become a Solidity developer first, in order to be able to find bugs?
@andyli
@andyli 2 жыл бұрын
not necessarily, I am not a Solidity developer
@SKardasisLJC4E
@SKardasisLJC4E 2 жыл бұрын
@@andyli Thanks Andy. This actually gives me hope.
@0xfoster958
@0xfoster958 2 жыл бұрын
Hey Andy, do you take students or are you open to mentoring?
@andyli
@andyli 2 жыл бұрын
Open to exploring taking students or mentoring. Reach out on discord or twitter
@keccak32
@keccak32 2 жыл бұрын
hey Andy! I am just starting. Is this Roadmap relevant for now or any updates?
@andyli
@andyli 2 жыл бұрын
Yep still relevant, thinking of doing an updated version though
@keccak32
@keccak32 2 жыл бұрын
@@andyli Do it please
@liongames7078
@liongames7078 2 жыл бұрын
Do you need a computer science knowledge and be really good at math
@andyli
@andyli 2 жыл бұрын
Programming knowledge and math helps.
@dishalroy5948
@dishalroy5948 2 жыл бұрын
How much time it takes to complete all the topics
@andyli
@andyli 2 жыл бұрын
took me about 5-6 months
@madhuvarun2790
@madhuvarun2790 Жыл бұрын
What is QA?
@andyli
@andyli Жыл бұрын
Quality assurance or low severity issues
@castmate8778
@castmate8778 6 ай бұрын
Is this still effective in 2024? 😢
@MoKamal1490
@MoKamal1490 5 ай бұрын
+1
@steveaxel6333
@steveaxel6333 2 жыл бұрын
nice
@andyli
@andyli 2 жыл бұрын
Cheers
@saikatkarmakar955
@saikatkarmakar955 2 жыл бұрын
capture the ether is not working anymore
@andyli
@andyli 2 жыл бұрын
ah might be because Rinkeby testnet is deprecated
@patricksfeir6947
@patricksfeir6947 2 жыл бұрын
I think it's extremely hard to get a job as an entry level smart contract auditor, they all go for seniors.
@andyli
@andyli 2 жыл бұрын
Some firms are hiring juniors, but you're right it is generally harder to get junior positions in any industry due to more competition
@theviperxxsy1041
@theviperxxsy1041 Жыл бұрын
smart contract Auditor is hard job in the world and very very difficult
@andyli
@andyli Жыл бұрын
yeah difficult but worth it
@jd-yf6he
@jd-yf6he 2 жыл бұрын
Hey buddy, do u have a discord or telegram group ?
@andyli
@andyli 2 жыл бұрын
There is a discord link on the channel description
@dixiegolden3681
@dixiegolden3681 2 жыл бұрын
Great video! Thank you man
@andyli
@andyli 2 жыл бұрын
thanks!
Too Late to Learn Web3 Security
19:00
Andy Li
Рет қаралды 12 М.
First Month as a Smart Contract Auditor
8:46
Andy Li
Рет қаралды 14 М.
Sigma girl VS Sigma Error girl 2  #shorts #sigma
0:27
Jin and Hattie
Рет қаралды 124 МЛН
Жездуха 42-серия
29:26
Million Show
Рет қаралды 2,6 МЛН
#behindthescenes @CrissaJackson
0:11
Happy Kelli
Рет қаралды 27 МЛН
How to become the #1 Auditor in Web3
8:11
Patrick Collins
Рет қаралды 23 М.
My Smart Contract Audit Process (Part 1)
17:06
Jackson Kelley
Рет қаралды 9 М.
Advanced Smart Contract Hacking
35:17
RSA Conference
Рет қаралды 57 М.
Complete Smart Contract Auditing System
24:52
Owen Thurm
Рет қаралды 6 М.
BHIS | Getting Started in Blockchain Security and Smart Contract Auditing | Beau Bullock
1:51:51
Black Hills Information Security
Рет қаралды 32 М.
$300k / year salary - How to become a smart contract auditor?
8:51
Sigma girl VS Sigma Error girl 2  #shorts #sigma
0:27
Jin and Hattie
Рет қаралды 124 МЛН