Beginner Roadmap to Smart Contract Auditing

  Рет қаралды 34,442

Andy Li

Andy Li

Күн бұрын

Пікірлер: 181
@haruxe5140
@haruxe5140 2 жыл бұрын
This video couldn't come at a better time! Documentation is so limited in the auditing space, you are the goat Andy 🐐
@andyli
@andyli 2 жыл бұрын
thanks mate, appreciate it! 🐐
@udoma8
@udoma8 2 жыл бұрын
Yes, I agree with you. There is limited resources in the auditing space. Thanks Andy, will be looking forward to more crumbs from you.
@laiyintam6349
@laiyintam6349 2 жыл бұрын
5k bounty and 2 high severity on first 2 months, awesome!
@andyli
@andyli 2 жыл бұрын
Thanks!
@devotedros
@devotedros 4 ай бұрын
@laiyintam6349 Could u share ur discord ?
@devotedros
@devotedros 4 ай бұрын
@laiyintam6349 Could u share ur discord ?
@danielcawley1051
@danielcawley1051 2 жыл бұрын
hey im a 14 year old that is in tutorial hell right now, ive learned solidity + react js for 8 months now so after learning security (which I already know the basics of - e.g. reentrancy), I can make money :) Thank you so much for inspiring me, I really appreciate the work your put into these videos
@andyli
@andyli 2 жыл бұрын
It is amazing you are getting into this at 14 years old, THAT is inspiring
@danielcawley1051
@danielcawley1051 2 жыл бұрын
follow up, I've completed ethernaut and damn vulnerable defi and I'm just about to finish off completing secureum and then I'm gonna jump into it
@andyli
@andyli 2 жыл бұрын
Awesome, see you in the arena 🚀
@luigixb1
@luigixb1 Жыл бұрын
@@danielcawley1051 Thats awesome man!
@danielcawley1051
@danielcawley1051 Жыл бұрын
@@luigixb1 something even more awesome is that ive recently got my first payout and ive earned 91$, i just need to keep this up
@lacag-lacag
@lacag-lacag 2 жыл бұрын
Thank u man been waiting this video alot but i wanna ask what kind of laptop do i need to participate the bugs is it ok 4GB ram
@andyli
@andyli 2 жыл бұрын
4GB is fine, you only need to browse GitHub and a text editor
@888rjx
@888rjx 4 ай бұрын
Hey Andy, is there a specific reason why you recommend doing CTF before learning solidity tutorial? Right now Im doing Solidity tutorial first, but it's not sticking very well and am confused by all the different little rules. Thinking about just jumping into CTF based on this video. Thanks
Ай бұрын
Hey, how about you now? I learned solidity a few days ago and have the same question.
@baroonjha3160
@baroonjha3160 2 жыл бұрын
This is the video I'm awaiting for.Thanks Andy ,Great video .
@andyli
@andyli 2 жыл бұрын
Cheers!
@digitalchinmay263
@digitalchinmay263 2 жыл бұрын
How to actually write reports of low risk issues in code4rena submissions ?
@andyli
@andyli 2 жыл бұрын
have a look at the previous audit reports to get some ideas
@Studiom44
@Studiom44 2 жыл бұрын
Been searching high and low for the info you've shared here! Thank you so much!!!
@andyli
@andyli 2 жыл бұрын
Glad it was helpful!
@bobbychase5616
@bobbychase5616 2 жыл бұрын
such a banger video! so fun to watch the success from learning a new thing i wonder if the hassle of traditional bug bounty led you to crypto auditing or was it general interest. im still on my oscp journey so i hope this space isnt too crowded by the time i jump in. cheers!
@andyli
@andyli 2 жыл бұрын
Thanks! I stumbled onto this randomly when I saw a someone post about the Damn Vulnerable Defi CTF on twitter. I doubt it will be crowded anytime soon
@lagrariscale8567
@lagrariscale8567 2 жыл бұрын
if i have no cyber security experience and i have little knowledge on solidity . is there any chance me finding bugs on code arena ?
@andyli
@andyli 2 жыл бұрын
it will just take you a bit longer to start finding bugs, start with the solidity tutorial
@ashhadali7592
@ashhadali7592 2 жыл бұрын
@@andyli how much solidity is need to find bugs
@natanaelconcha92
@natanaelconcha92 2 жыл бұрын
Been waiting on a video like this, it's fairly new so not many people talk about it
@andyli
@andyli 2 жыл бұрын
True
@tangjunnz
@tangjunnz 2 жыл бұрын
thank you so much, awesome 👍👍
@andyli
@andyli 2 жыл бұрын
👍👍
@matthewlee112
@matthewlee112 2 жыл бұрын
Fool, now I will be able to audit smart contracts too!
@andyli
@andyli 2 жыл бұрын
Yeah? But I have a 2 month head start 😈
@matthewlee112
@matthewlee112 2 жыл бұрын
@@andyli im gonna borrow the time stone
@maryonacross03
@maryonacross03 10 ай бұрын
selamlar sizin bu videonuz olmasaydı ilerlemem daha zor olacaktı herşey için teşekkürler.
@tangflx
@tangflx 2 жыл бұрын
your video is gold! keep up the good work!
@andyli
@andyli 2 жыл бұрын
Thank you, appreciate it!
@tangflx
@tangflx 2 жыл бұрын
@@andyli I might kickstart bug bounty career bcoz of u. Thanks!!
@andyli
@andyli 2 жыл бұрын
Nice, good luck!
@James-li3ro
@James-li3ro 2 жыл бұрын
Im a web developer tryna break into security. would you suggest knowing about traditional pentesting before moving on to web3 security?
@andyli
@andyli 2 жыл бұрын
I don't think it is necessary, there are some concepts that help but I wouldn't consider them prerequisites
@James-li3ro
@James-li3ro 2 жыл бұрын
Thanks bro! Really thorough video. I appreciate your comment. Are you still working on traditional pentesting?
@andyli
@andyli 2 жыл бұрын
Yep, I only do bug bounties part time
@samratgupta8487
@samratgupta8487 2 жыл бұрын
Great video thanks😇
@andyli
@andyli 2 жыл бұрын
🙌
@PaladinOfWeb3
@PaladinOfWeb3 Жыл бұрын
Always wanted to find a way to link my cyberspace career and my cryptospace hobby, glad the algorithm made me pass through your channel.
@andyli
@andyli Жыл бұрын
hail to the algorithm
@liongames7078
@liongames7078 2 жыл бұрын
Do you need a computer science knowledge and be really good at math
@andyli
@andyli 2 жыл бұрын
Programming knowledge and math helps.
@devabdee
@devabdee 2 жыл бұрын
Thank you so much for creating this video.Really helpful. May God bless you. Also, Can you pls make a video on how to submit the findings? I actually didn't understood how submitting works. Do I need to make pull request or just copy and paste the part of the code before and after?One video on that would be really helpful. Thanks again
@andyli
@andyli 2 жыл бұрын
Have you registered to become a Warden yet? Once you get confirmed, you submit findings directly on the code4rena website.
@miraclemaxwell9988
@miraclemaxwell9988 7 ай бұрын
I’m learning ethical hacking can I combine with this?
@erictee6950
@erictee6950 2 жыл бұрын
Keep it up Andy !
@andyli
@andyli 2 жыл бұрын
🙌
@evmlionel
@evmlionel Жыл бұрын
Thanks for sharing! Since this space is so fast-paced, is there anything you would change for 2023?
@andyli
@andyli Жыл бұрын
Not really, the learning resources are the same. Perhaps learn Foundry instead of Hardhat
@-rk2cyfgfg
@-rk2cyfgfg 2 ай бұрын
Ty for the video, is this still up to date?
@하동현-d5e
@하동현-d5e 2 жыл бұрын
Finally!
@andyli
@andyli 2 жыл бұрын
First comment 😊
@katelibra
@katelibra 2 жыл бұрын
Awesome 🤩
@andyli
@andyli 2 жыл бұрын
Thanks 🤗
@mlntdtechbae
@mlntdtechbae 2 жыл бұрын
I'm so glad I decided to learn SM development & auditing! Currently learning via's Patrick's course. These kinds of rewards/payouts are very encouraging, lol.
@andyli
@andyli 2 жыл бұрын
Nice! Rewards did go down a by recently though
@mlntdtechbae
@mlntdtechbae 2 жыл бұрын
@@andyli Good to know. Only makes me want to learn faster, lol.
@yufang173
@yufang173 2 жыл бұрын
Awesome, thanks!
@andyli
@andyli 2 жыл бұрын
👍
@ayushmanthapa_onion
@ayushmanthapa_onion 2 жыл бұрын
this is great andy! thanks alot
@andyli
@andyli 2 жыл бұрын
🙏
@alaazingi5784
@alaazingi5784 Жыл бұрын
Hello Andy, I am 2nd year computer science student and learning solidity was a hobby for me that evolved into deep interest. Thank you for really educational videos they are helping me a lot to break into auditing.
@andyli
@andyli Жыл бұрын
awesome, glad to hear!
@francoisguyot789
@francoisguyot789 2 жыл бұрын
Amazing content
@andyli
@andyli 2 жыл бұрын
Thanks!
@Machinebrains2Mcd
@Machinebrains2Mcd Жыл бұрын
This is so amazingly put together will study your advice + opinions to gain better understanding solidity security audits grinding my way thanks Andy
@andyli
@andyli Жыл бұрын
Glad it was helpful!
@nang88
@nang88 2 жыл бұрын
🐐 video
@andyli
@andyli 2 жыл бұрын
🙌
@castmate8778
@castmate8778 2 ай бұрын
Is this still effective in 2024? 😢
@MoKamal1490
@MoKamal1490 Ай бұрын
+1
@digitalchinmay263
@digitalchinmay263 2 жыл бұрын
Hey Andy, Can we get the notes of your secureum findings' classification. It will help us a lot.
@andyli
@andyli 2 жыл бұрын
github.com/andyfeili/SecureumFindings
@internetkids5813
@internetkids5813 2 жыл бұрын
Great video
@andyli
@andyli 2 жыл бұрын
ty!
@MrJCollector
@MrJCollector 2 жыл бұрын
Can i ask how do you join code4rena as a bug hunter?
@andyli
@andyli 2 жыл бұрын
fill out this form and join the Discord channel code4rena.com/warden-registration/
@Rudra0x01
@Rudra0x01 4 ай бұрын
This is very helpful video, as this field are very limited of resources.
@S0L4RW4V3
@S0L4RW4V3 Жыл бұрын
I took about a year off from bug bounties after multiple dups @.@ or nothing for days like a big noob. Time really became precious after my former employer reduced by seniority & Tbh i was discoraged but knew that i just needed to improve so i began to study for htb's cpts. I will sit the exam soon and pass :D. After that my plan is to spam my application again.However, In the mean time , i wanted to reenter the bug bounty space. T.t i just miss "researching" lol and immunifi was an option. This is my first time hearing about code4rena and im excired to befome a warden. Lol sorry for the dump..mainly this is a thankyou for sharing
@andyli
@andyli Жыл бұрын
Nice, good luck hunting!
@vns1111
@vns1111 2 жыл бұрын
hi andy is thier a way to remove swepper bot
@andyli
@andyli 2 жыл бұрын
Not sure what you mean by swepper bot
@adriapajaresaguilera572
@adriapajaresaguilera572 2 жыл бұрын
This is gold
@andyli
@andyli 2 жыл бұрын
thanks!
@devadevans700
@devadevans700 2 жыл бұрын
Thank u😍
@andyli
@andyli 2 жыл бұрын
No problem!
@MrNike95
@MrNike95 Жыл бұрын
May i ask you that im on my journey for the oscp in 2023 is it worth it or should i focus on web3 security and start learning the fundamentals ? and What kinda job can i work after that .I watched some videos and it looks very interesting
@andyli
@andyli Жыл бұрын
You can work as a security engineer in web3, try some CFTs and see if you like this type of work.
@theviperxxsy1041
@theviperxxsy1041 Жыл бұрын
smart contract Auditor is hard job in the world and very very difficult
@andyli
@andyli Жыл бұрын
yeah difficult but worth it
@MichelLedig
@MichelLedig Жыл бұрын
please keep going with the channel u are helping me build my journey so much. If karma exists this shit will go back twice to you Much love from Brasil!
@andyli
@andyli Жыл бұрын
💯 more to come!
@ashhadali7592
@ashhadali7592 2 жыл бұрын
incredible video i like it hope u create more on methodology
@andyli
@andyli 2 жыл бұрын
Thanks! I will think about how to create a video on methodology
@ashhadali7592
@ashhadali7592 2 жыл бұрын
@@andyli waiting create live auditing video also Thanks in advance u done great job
@jrsantos1737
@jrsantos1737 2 жыл бұрын
Oh man, i read the article of legendary auditor C.Michel, he says it will take years before reviews will become useful for newbies in coding. Ouch that hurts! Im currently on 3rd month of javascript study coming from accounting background. Somehow i touch the finance concepts of derivatives during college years, this might help me to shift to smart contract auditor. Wish me luck!
@andyli
@andyli 2 жыл бұрын
Yeah, finance concepts will help a lot. Good luck!
@garyb99
@garyb99 2 жыл бұрын
You have awesome content! Keep up the good work
@andyli
@andyli 2 жыл бұрын
Thanks!
@abdulhaqmohammed
@abdulhaqmohammed Жыл бұрын
This is the exact thing I was looking for. Thank you so much Andy👍
@andyli
@andyli Жыл бұрын
Glad it was helpful!
@RS-nc5qx
@RS-nc5qx Жыл бұрын
Is it best to go the developers route or cybersecurity for this? This is all a bit of everything.
@andyli
@andyli Жыл бұрын
You can learn this directly if it is what you want to do
@apostle5135
@apostle5135 2 жыл бұрын
yay ! another video :D
@andyli
@andyli 2 жыл бұрын
:D
@chibatomosuke5080
@chibatomosuke5080 2 жыл бұрын
Do you have link of this slide?
@andyli
@andyli 2 жыл бұрын
found it! docs.google.com/presentation/d/1Zx9DoS4wTAfu7d2WSSQHuVp3c1hwO3mOS3K76EbhIAE
@chibatomosuke5080
@chibatomosuke5080 2 жыл бұрын
@@andyli coool! You should add to description.Thanks!
@ms-ej4gd
@ms-ej4gd Жыл бұрын
Best roadmap. Subscribed
@keccak32
@keccak32 Жыл бұрын
hey Andy! I am just starting. Is this Roadmap relevant for now or any updates?
@andyli
@andyli Жыл бұрын
Yep still relevant, thinking of doing an updated version though
@keccak32
@keccak32 Жыл бұрын
@@andyli Do it please
@marquisebrown2397
@marquisebrown2397 2 жыл бұрын
Thank You, amazing video !
@andyli
@andyli 2 жыл бұрын
Thanks!
@marquisebrown2397
@marquisebrown2397 2 жыл бұрын
Once I finish Ethernaut do you think that’s enough info to get started on Code 4 Rena ?
@andyli
@andyli 2 жыл бұрын
@@marquisebrown2397 also read the secureum findings
@marquisebrown2397
@marquisebrown2397 2 жыл бұрын
@@andyli Thank you, do you know where I could get more than 1 Rinkeby test network ETH ?
@patricksfeir6947
@patricksfeir6947 2 жыл бұрын
I think it's extremely hard to get a job as an entry level smart contract auditor, they all go for seniors.
@andyli
@andyli 2 жыл бұрын
Some firms are hiring juniors, but you're right it is generally harder to get junior positions in any industry due to more competition
@ashhadali7592
@ashhadali7592 2 жыл бұрын
will u create video how to perform auditing new in this field
@andyli
@andyli 2 жыл бұрын
go through the learning resources listed here and read past audit reports
@web3studynotes
@web3studynotes Жыл бұрын
Hello Andy, thank you for sharing this! Super helpful!! Do you currently provide any 1:1 consulting service on security contract audit?
@andyli
@andyli Жыл бұрын
Do you mean teaching or private audits?
@web3studynotes
@web3studynotes Жыл бұрын
@@andyli teaching. I am currently looking for help to break into web3 security space. Please let me know if you are available. Thanks!
@andyli
@andyli Жыл бұрын
Yeah can do. Feel free to reach out on twitter or any of the other social links on the channel
@dhom440
@dhom440 2 жыл бұрын
Many thanks for the video, I like your process 👍
@andyli
@andyli 2 жыл бұрын
Thank you! Cheers!
@niclans82
@niclans82 2 жыл бұрын
Hi Andy, your video pique my interest to learn about smart contract hacking /auditing. Do you think a total beginner in coding can follow through your guide and be good at this? Would it be possible?
@andyli
@andyli 2 жыл бұрын
Yeah it is possible. You will just need to spend more time on the Solidity tutorial - it is 32 hours long and assumes no prior knowledge.
@niclans82
@niclans82 2 жыл бұрын
@@andyli thanks a lot for your feedback Andy. Yeah, thinking of being good at understanding Solidity basics first before going further. My goal is to start as a smart contract developer and then gradually learning to be a smart contract auditor. I see many possibilities in Web3 and I hope to be ready to capilitalize once the bulls take over from the bear market.
@MartinMarchev
@MartinMarchev Жыл бұрын
Thanks for this amazing video! Both useful and inspiring!
@andyli
@andyli Жыл бұрын
Glad it was helpful!
@saikatkarmakar955
@saikatkarmakar955 Жыл бұрын
capture the ether is not working anymore
@andyli
@andyli Жыл бұрын
ah might be because Rinkeby testnet is deprecated
@dishalroy5948
@dishalroy5948 Жыл бұрын
How much time it takes to complete all the topics
@andyli
@andyli Жыл бұрын
took me about 5-6 months
@PetritK10
@PetritK10 2 жыл бұрын
That's what I wanted for 2023 :D
@andyli
@andyli 2 жыл бұрын
😀
@vomivore
@vomivore 2 жыл бұрын
Thanks for taking time to make this feedback!
@andyli
@andyli 2 жыл бұрын
no prob!
@SKardasisLJC4E
@SKardasisLJC4E 2 жыл бұрын
Did you have to become a Solidity developer first, in order to be able to find bugs?
@andyli
@andyli 2 жыл бұрын
not necessarily, I am not a Solidity developer
@SKardasisLJC4E
@SKardasisLJC4E 2 жыл бұрын
@@andyli Thanks Andy. This actually gives me hope.
@dixiegolden3681
@dixiegolden3681 Жыл бұрын
Great video! Thank you man
@andyli
@andyli Жыл бұрын
thanks!
@morganweaver4230
@morganweaver4230 2 жыл бұрын
ABout to start an auditing fellowship, this is fantastic. Rally good specific resources and general commentary on the learning process in auditing--because security is a really complex and technical field in tech, let alone crypto.
@andyli
@andyli 2 жыл бұрын
Nice one, getting into a auditing fellowship. Which company was it?
@thomash5390
@thomash5390 2 жыл бұрын
Very cool - how did you find the fellowship?
@andyli
@andyli 2 жыл бұрын
It might be this yacademy.dev
@steveaxel6333
@steveaxel6333 Жыл бұрын
nice
@andyli
@andyli Жыл бұрын
Cheers
@madhuvarun2790
@madhuvarun2790 Жыл бұрын
What is QA?
@andyli
@andyli Жыл бұрын
Quality assurance or low severity issues
@mujtabaaltayib7417
@mujtabaaltayib7417 2 жыл бұрын
thank you so much
@andyli
@andyli 2 жыл бұрын
👍
@EUU100
@EUU100 2 жыл бұрын
Thank you so much!
@andyli
@andyli 2 жыл бұрын
No problem!
@rahulpujari5601
@rahulpujari5601 Жыл бұрын
What a beautiful detailed roadmap! Thanks so much for sharing Andy 👌
@andyli
@andyli Жыл бұрын
Glad you enjoyed!
@ethisfreedom
@ethisfreedom Жыл бұрын
I hope it gets crowded! We need more security!
@jd-yf6he
@jd-yf6he 2 жыл бұрын
Hey buddy, do u have a discord or telegram group ?
@andyli
@andyli 2 жыл бұрын
There is a discord link on the channel description
@0xfoster958
@0xfoster958 Жыл бұрын
Hey Andy, do you take students or are you open to mentoring?
@andyli
@andyli Жыл бұрын
Open to exploring taking students or mentoring. Reach out on discord or twitter
Too Late to Learn Web3 Security
19:00
Andy Li
Рет қаралды 11 М.
Learn from Reading Audit Reports (Sturdy Report)
18:15
Andy Li
Рет қаралды 5 М.
Cute
00:16
Oyuncak Avı
Рет қаралды 12 МЛН
4 Tips to Land Your First Job as a Smart Contract Auditor
11:42
JohnnyTime
Рет қаралды 1,1 М.
How to HACK a smart contract
30:47
Timegame
Рет қаралды 11 М.
What is Blockchain
13:58
zlotolow
Рет қаралды 3,2 МЛН
Best Smart Contract Auditor Courses in 2024
12:10
JohnnyTime
Рет қаралды 2,9 М.
Zach Obront: Winning Audit Contests & Crushing Bug Bounties
56:59
Can You Make YouTube From Scratch Using Only Bash?
17:51
Complete Smart Contract Auditing System
24:52
Owen Thurm
Рет қаралды 5 М.