The honest pre-mainnet security checklist for small protocols
Most "security checklists" are 80 items long and read like a compliance form. This one is short on purpose: these are the checks that actually catch loss of funds in small protocols before mainnet. For each, the failure
Most "security checklists" are 80 items long and read like a compliance form. This one is short on purpose: these are the checks that actually catch loss of funds in small protocols before mainnet. For each, the failure mode it prevents.
Go through it honestly. A "no" isn't a shame β it's a to-do before you ship.
Access control
- [ ] Every privileged function (
mint,pause,setFee,setOracle,upgrade,sweep,initialize) is protected by a modifier or role. Prevents: anyone calling your admin functions. - [ ] Privileged roles sit behind a multisig or timelock, not a single hot EOA. Prevents: one leaked key draining everything.
- [ ]
initialize()on upgradeable contracts can't be front-run and can't be called twice. Prevents: attacker becoming owner. - [ ] No
tx.originfor authorization β usemsg.sender. Prevents: phishing-based auth bypass.
Oracles & pricing
- [ ] Price reads check staleness (
updatedAt) and deviation bounds. Prevents: acting on a frozen or manipulated price. - [ ] You don't price off a spot AMM reserve that can be flash-loan-manipulated. Prevents: flash-loan price attacks.
- [ ] No read-only reentrancy on prices you consume from Curve/Balancer-style pools. Prevents: manipulated mid-tx views.
Reentrancy & external calls
- [ ] Checks-Effects-Interactions: state updated before any external call. Prevents: the whole reentrancy family.
- [ ] Guards on every function touching shared state, not just
withdraw. Prevents: cross-function reentrancy. - [ ] Low-level
call/delegatecall/sendreturn values are checked. Prevents: silent failures treated as success.
Vault / share math (if ERC-4626 or similar)
- [ ] Protected against first-depositor inflation (virtual shares / dead shares). Prevents: the empty-vault attack that robs your first user.
- [ ] Rounding always favors the vault, never the withdrawer. Prevents: slow drain via rounding.
- [ ]
totalAssetsis not derived from rawbalanceOf(address(this)). Prevents: donation-based accounting manipulation.
Tokens
- [ ] Handles fee-on-transfer / rebasing tokens β or explicitly documents it doesn't support them. Prevents: accounting drift.
- [ ] Uses SafeERC20 for tokens with non-standard returns (USDT-style). Prevents: transfers that "fail open."
- [ ] Aware of callback tokens (ERC-777/677/1363) as reentrancy vectors. Prevents: hook-based re-entry.
Upgrades & storage
- [ ] If upgradeable: storage layout is append-only; no reordered/removed slots. Prevents: storage collisions corrupting state.
- [ ] Upgrades are gated behind governance/timelock. Prevents: instant malicious upgrade.
Testing & process
- [ ] Invariant/fuzz tests on core economic properties (solvency, fund conservation, exchange rate). Prevents: whole classes of edge cases.
- [ ] A security scan in CI on every PR, so no diff merges unreviewed. Prevents: the "quick change after the audit" incident.
- [ ] Someone other than the author has read the money-moving paths. Prevents: author blind spots.
Automate the first pass
You can knock out a big chunk of this list automatically. OpenClaw Audit is a free scanner with detectors for access control, oracle staleness, reentrancy, unchecked calls, tx.origin, first-depositor inflation, fee-on-transfer and more β calibrated to stay quiet on clean code:
# .github/workflows/security.yml β a scan on every PR
name: security
on: [push, pull_request]
permissions: { contents: read, pull-requests: write }
jobs:
audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: juan23z/openclaw-audit@v1
Findings are heuristic candidates β verify before acting. Automation covers the mechanical checks so your (or a reviewer's) attention goes to the judgment calls.
Want a human to run this checklist against your contracts before mainnet? A hand-verified Quick Scan is $49 (one contract, 48h, and if it's not useful you don't pay). Interactive version of this checklist: juan23z.github.io/checklist.html.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.