Smart Contract Security
Alchemy University
Alchemy's free web3 education platform organizes courses and coding projects into learning roadmaps, including one on smart contract security. Content is project-based, so learners write and test Solidity rather than only reading about vulnerabilities.
More resources on Blockchain Security
Mastering Bitcoin: Programming the Open Blockchain (First Edition)
Technical book by Andreas Antonopoulos on how Bitcoin works internally: keys and addresses, wallets, transaction structure and scripts, the peer-to-peer network, the blockchain data structure, mining and proof-of-work consensus. Readers can follow Bitcoin's protocol at code level and reason about its security properties.
The Complete Security Guide to keep you, your computer, and your crypto safe
A comprehensive, community-vetted guide from the r/CryptoCurrency subreddit covering a broad range of security measures for protecting cryptocurrency assets, personal computers, and online activities. It's an excellent resource for understanding general crypto security best practices.
OWASP Foundation
Nonprofit foundation publishing open web application security standards and guides, including the OWASP Top Ten, the Application Security Verification Standard, the Web Security Testing Guide and the Cheat Sheet Series, used to identify, test for and prevent common web vulnerabilities.
Blockchain Security
This course introduces blockchain security, including a description of how the blockchain works at each level of the blockchain ecosystem. The instructor begins with the building blocks that create the structure of blockchain, the cryptography that it uses for security, and the role of hash functions in the blockchain and how they can be attacked. In the next module, the instructor describes what blockchain consensus is, why it’s needed, its underlying theory (Byzantine Fault Tolerance and Security via Scarcity), some of the common consensus algorithms, and the security issues inherent to each variant. The course progresses with a module that describes how blocks are created, the nodes and network that make up the blockchain ecosystem, and examples of various attacks that can be made on their security. Next the focus is on smart contracts and how their security can be compromised with vulnerabilities created by common programming errors during contract development, including in Ethereum, the most commonly used smart contract platform. Finally, the course wraps up with discussions of distributed ledger architectures that are alternatives to blockchain, second-level blockchain protocols, and advanced cryptography in blockchain.
CertiK Security Blog
Posts from a smart contract auditing firm analyzing exploits, formal verification techniques, and recurring vulnerability classes across DeFi protocols. Useful for seeing how real incidents unfold on-chain and which code patterns auditors flag most often.
ConsenSys Diligence
Audit practice publishing its Ethereum smart contract best practices guide, public audit reports, and security tooling. Working through the known attacks and recommendations sections gives a concrete checklist for reviewing Solidity code before deployment.