Defensive dApp Workshop
Learn to exploit and defend decentralised applications and smart contracts — hands-on, instructor-led, and modelled on real incidents.
About the Workshop
In this attack and defence workshop, we look at vulnerabilities of decentralised apps and what makes them unique among software vulnerabilities. With beginners in mind, we go under the hood of each vulnerability, understand its internal workings, and find the root cause of the flaw.
What you will learn
We have hand picked security vulnerabilities from both Web2 and Web3 domains. We then attack dApp in a simulated environment and learn how to exploit each vulnerability.
With these insights, we then explore modern defensive design patterns to understand how they protect dApps.
We learn advanced techniques to hunt hard-to-find security bugs and then go one step further to build property-based fuzzers protecting our dApp against possible future security bugs.
At a glance
- For: Blockchain engineers, Software engineers, Test engineers, DevOps engineers, Tech leads, Code reviewers, and Penetration testers
- Languages: Solidity, Python, JavaScript, TypeScript (other languages on request)
- Duration: 4 half-days
- Delivery: Live online led by Dr. Pedram Hayati
Workshop Modules
A subset of topics is selected based on participants’ skill level and the available class time.
Module 1: Introduction
We have learnt software security the wrong way, let's redefine it.
Why we have so many vulnerabilities
Web2 vs Web3 vulnerabilities
Why post-release patching is dangerous
What is Defensive Design and Programming
Five phases of identifying and exploiting a vulnerable program
Module 2: Rapid Threat Modelling
Build a rapid, effective and actionable threat model early during development
Identify security design issues during stand-ups
Trust boundary analysis
Five + three threat actors
Discover threats
Common insecure assumptions in our programs that are exploited
Rapid Threat Modelling
STRIDE
SecDim's Threat Thinking Matrix
Build a threat model in an attack and defence game
Hack your own app exploitation lab
Module 3: Hunt for security bugs
Hunt for dApp security bugs at run-time using new fuzzing techniques
Write security unit tests in brownie
Property-based testing using Hypothesis
Coverage guided fuzzing
Fuzzing vs testing
Property-based fuzzing
Symbolic execution
Swarm fuzzing
Stateful fuzzing
Module 4: Follow defensive design patterns
Learn three core defensive design patterns to address the insecure anti-patterns:
Transaction order dependency
Call before state change
Unlimited gas usage
Insufficient data validation
Lack of data recognition
Overlooking an untrusted entry point
Security by coding conventions
Module 5: Attack and defend dApps
Learn advanced exploitation techniques to attack dApp security vulnerabilities and then apply defensive design patterns to eliminate the security bugs
Reentrancy
Denial of Service
Block stuffing
Front running
Numeric overflow
Numeric imprecision
Visual Spoofing
Unicode Vulnerabilities
Time Of Check Time Of Use (race condition)
What is included?
- Step-by-step delivery by a highly qualified instructor
- Large collection of self-paced git-based labs
- Access to an exclusive support forum
- Certificate of completion
- Full access to workshop content
A Three-Month Pathway, Not a One-Off
We forget almost 60% of newly acquired information within a week. You get a practice schedule and mentorship during a three-month pathway, so secure software engineering becomes your habit.

Reserve Your Seat Today
Our workshops are offered only a few times a year — don't miss out. Get in touch with our team to reserve your seat and confirm workshop details.