WEB3 PENTESTING

Pentesting for the Web2 attack surfaces inside Web3 apps.

We offer white-box and black-box testing based on each project’s needs. Our research examines the large, underexplored Web2 attack surfaces that remain in many Web3 applications.

$36.82B+ On-chain TVL secured$1.00B+ Vulnerabilities patched120+ Projects audited

WHAT WE TEST

Where our pentesting research has gone

Our research covers the Web2 layers that sit around on-chain code: authentication, sandboxes, and app backends.

White-box and black-box testing

We offer both approaches and choose based on each project’s needs.

Web2 attack surfaces

Our research examines the large, underexplored Web2 attack surfaces that remain in many Web3 applications.

Authentication research

Our post “Subverting Web2 authentication in Web3” covers OAuth logic exploits and Supabase misconfigurations.

Sandbox research

We’ve done extensive research into MetaMask’s Snaps sandboxing environment, published on our blog.

RESEARCH-DRIVEN TESTING

Testing shaped by published research

  • White-box or black-box testing, chosen based on your project’s needs.
  • Our research on Web2 bugs in Web3 apps is public in “Web2 bug repellant instructions” on our blog.
  • Our research into MetaMask’s Snaps sandboxing environment found a property spoofing vulnerability in the Snaps sandboxing layer.

CLIENT FEEDBACK

In a client’s words

“Their website says protecting Blockchain ideas, but their command of JavaScript is impressive. If you've got something that you think would be "too hard for pentesters to understand" - these folks will surprise you. They're not your average pentester.”
Zbigniew TenerowiczMetaMask

OUR PROCESS

Steps from our auditing process

  1. 01

    Initial discussion

    We’ll discuss your goals, timeline, and security needs to see whether we’re a fit.

  2. 02

    Info gathering

    We’ll send an MNDA and look at repositories within scope to understand the details of your project and requests.

  3. 03

    Report delivery

    At completion, we will send you a report with our findings and suggestions for fixes.

PENTESTING FAQS

Frequently asked questions

What pentesting does OtterSec offer?

We offer white-box and black-box testing based on each project’s needs. Our research examines the large, underexplored Web2 attack surfaces that remain in many Web3 applications, and we’ve done extensive research into MetaMask’s Snaps sandboxing environment.

REQUEST A PENTEST

Put white-box and black-box testing on your app

We work with leading teams across multiple blockchains. Put the same collaborative approach to work on your application.

Get an audit