Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 2 min read

The honest pre-mainnet security checklist for small protocols

Most "security checklists" are 80 items long and read like a compliance form. This one is short on purpose: these are the checks that actually catch loss of funds in small protocols before mainnet. For each, the failure

Most "security checklists" are 80 items long and read like a compliance form. This one is short on purpose: these are the checks that actually catch loss of funds in small protocols before mainnet. For each, the failure mode it prevents.

Go through it honestly. A "no" isn't a shame β€” it's a to-do before you ship.

Access control

  • [ ] Every privileged function (mint, pause, setFee, setOracle, upgrade, sweep, initialize) is protected by a modifier or role. Prevents: anyone calling your admin functions.
  • [ ] Privileged roles sit behind a multisig or timelock, not a single hot EOA. Prevents: one leaked key draining everything.
  • [ ] initialize() on upgradeable contracts can't be front-run and can't be called twice. Prevents: attacker becoming owner.
  • [ ] No tx.origin for authorization β€” use msg.sender. Prevents: phishing-based auth bypass.

Oracles & pricing

  • [ ] Price reads check staleness (updatedAt) and deviation bounds. Prevents: acting on a frozen or manipulated price.
  • [ ] You don't price off a spot AMM reserve that can be flash-loan-manipulated. Prevents: flash-loan price attacks.
  • [ ] No read-only reentrancy on prices you consume from Curve/Balancer-style pools. Prevents: manipulated mid-tx views.

Reentrancy & external calls

  • [ ] Checks-Effects-Interactions: state updated before any external call. Prevents: the whole reentrancy family.
  • [ ] Guards on every function touching shared state, not just withdraw. Prevents: cross-function reentrancy.
  • [ ] Low-level call/delegatecall/send return values are checked. Prevents: silent failures treated as success.

Vault / share math (if ERC-4626 or similar)

  • [ ] Protected against first-depositor inflation (virtual shares / dead shares). Prevents: the empty-vault attack that robs your first user.
  • [ ] Rounding always favors the vault, never the withdrawer. Prevents: slow drain via rounding.
  • [ ] totalAssets is not derived from raw balanceOf(address(this)). Prevents: donation-based accounting manipulation.

Tokens

  • [ ] Handles fee-on-transfer / rebasing tokens β€” or explicitly documents it doesn't support them. Prevents: accounting drift.
  • [ ] Uses SafeERC20 for tokens with non-standard returns (USDT-style). Prevents: transfers that "fail open."
  • [ ] Aware of callback tokens (ERC-777/677/1363) as reentrancy vectors. Prevents: hook-based re-entry.

Upgrades & storage

  • [ ] If upgradeable: storage layout is append-only; no reordered/removed slots. Prevents: storage collisions corrupting state.
  • [ ] Upgrades are gated behind governance/timelock. Prevents: instant malicious upgrade.

Testing & process

  • [ ] Invariant/fuzz tests on core economic properties (solvency, fund conservation, exchange rate). Prevents: whole classes of edge cases.
  • [ ] A security scan in CI on every PR, so no diff merges unreviewed. Prevents: the "quick change after the audit" incident.
  • [ ] Someone other than the author has read the money-moving paths. Prevents: author blind spots.

Automate the first pass

You can knock out a big chunk of this list automatically. OpenClaw Audit is a free scanner with detectors for access control, oracle staleness, reentrancy, unchecked calls, tx.origin, first-depositor inflation, fee-on-transfer and more β€” calibrated to stay quiet on clean code:

# .github/workflows/security.yml β€” a scan on every PR
name: security
on: [push, pull_request]
permissions: { contents: read, pull-requests: write }
jobs:
  audit:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: juan23z/openclaw-audit@v1

Findings are heuristic candidates β€” verify before acting. Automation covers the mechanical checks so your (or a reviewer's) attention goes to the judgment calls.

Want a human to run this checklist against your contracts before mainnet? A hand-verified Quick Scan is $49 (one contract, 48h, and if it's not useful you don't pay). Interactive version of this checklist: juan23z.github.io/checklist.html.

πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.