Superteam Earn
Guvenkaya

1

Abhishek

Web2 Security Issues In Web3 Systems Article

by Guvenkaya

|
Redacted
|
5,000USDC

Total Prizes

3,000

USDC

1st

1,500

USDC

2nd

500

USDC

3rd

24

SUBMISSIONS

Syncing...

REMAINING

REDACTED TRACK

This is a track for the Redacted hackathon, hosted exclusively on Superteam Earn.

View All Tracks
Redacted Listing Banner

Introduction

Many web3 projects do not pay enough attention to web2 security and fall victim to simple hacks through web2 components. As an example, several weeks ago time.fun was ethically hacked through their web2 components. The purpose of this bounty is to bring attention to this problem and highlight current trends, some common web2 security issues, which can be exploited in web3 scenarios, and a general conclusion on what we can do better as an industry.

Process

Refer to the process below on what you should do. For additional details refer to the Deliverables section

  1. Pick 2 web2 security vulnerabilities, which could be exploited in web3 scenarios in off-chain components (relayers, signers, any other backend etc).

  2. Do a research into them

  3. Prepare one big lab or two small labs for the web2 security vulnerabilities you picked.

  4. Write a long-form research article to highlight the importance of paying attention to web2 security in web3, which goes over

    1. Current trend (maybe you can refer to some other real-world incidents)

    2. Explaining 2 security vulnerabilities you picked and possible remediations.

    3. Conclusion and what we as an industry can do better in general to protect against web2 security issues in web3

Deliverables

  1. The long-form research article posted on a blogging site (e.g. Medium, Substack, Notion, etc.) that is publicly viewable upon deadline, which covers:

  • The current trend of web3 projects not paying enough attention to web2 security. You can highlight some real-world incidents

  • 2 web2 security vulnerabilities and their exploitability in web3 scenarios in off-chain components with possible remediations. You should refer to the labs you prepared as an example and optionally other real-world hacks to prove a point.

  • Conclusion and general practical recommendations to the industry on how we can get better protection against web2 security issues.

  1. One big lab or two small labs on web2 security vulnerabilities you picked. The code has to be uploaded to Github, Gitlab, Bitbucket, or any other version control system of your choice. It has to be publicly viewable upon the deadline

Judging Criteria:

  1. Realism: whether the examples you showed are realistic.

  2. Accuracy: factual accuracy of the information and the relevance of the data used

  3. Resources: inclusion of resources to support your claims

  4. Writing Style: quality, readability and engagement level of your content

  5. Rich Media & Presentation: use of data dashboards, original charts, etc.

  6. Reproducibility: ease of launching labs and reproducing issues

  7. Brownie points for tweeting about the bounty/your submission and tagging @guvenkaya_sec, @timurguvenkaya, @heliuslabs and @SuperteamEarn in your tweet.

Submission Requirements:

Please review the reasons why your submission will get rejected either through an article or a lab

Article:

  • If it is not written in English.

  • If any of the vulnerabilities you picked can be only exploited through phishing. For example, exploiting dev devices to inject malicious code on the frontend

  • If any of the vulnerabilities you picked refer to a supply chain attack. For example, finding a bug in a dependency used by many projects and by doing that harming the main project. We want to focus on direct exploitation.

  • If any of the examples do not showcase vulnerability in the web3 scenario. For example, simply SQL injection in an isolated backend does not count if it does not interact with blockchain or smart contracts and SQL injection does not lead to any loss of funds or reliability of the whole web3 system.

  • If any of the examples refer to the exploitation through leaked credentials

  • If the contents of the submission are less than 1,000 words

  • If it is found to be plagiarized or stolen

  • If it fails to include and cite proper references

  • Your submission is not publicly viewable on and after the submission deadline. Submissions of private links will not be eligible.

Lab(s):

  • If it does not have a README or it is not written in English.

  • If it lacks any guidelines to launch a lab and steps to reproduce issues

  • If it is found to be plagiarized or stolen

  • If it fails to include and cite proper references in the code or README

  • Your submission is not publicly viewable on and after the submission deadline. Submissions of private links will not be eligible.

Prizes Details:

The total prize for this bounty is 5,000 USDC, and it will be distributed based on the judges' decision as:

🥇1st Place - $3,000 USDC

🥈2nd Place - $1,500 USDC

🥉3rd Place - $500 USDC

Resources

SKILLS NEEDED

Content

Blockchain

Backend

CONTACT

Reach outif you have any questions about this initialBounty