Securing Blockchain Applications: Practical Examples

Marco Morana, Harpreet Singh, Francesco Piccoli · 2025

This chapter provides practical guidance for blockchain security practitioners, focusing on smart contract auditing and securing decentralized applications (DApps) through real-world examples and security audits. It begins with a DApp creation example, covering smart contract deployment, AWS integration, and frontend security reviews. The DApp development section walks readers through building a secure DApp on AWS, integrating smart contracts with AWS Lambda, API Gateway, and IPFS, serving as a foundation for threat modeling and security testing. A core focus is smart contract security auditing, analyzing common vulnerabilities such as reentrancy, integer overflows, denial-of-service attacks, and access control flaws through real-world code examples. It explores blockchain node software, wallet security, and DApp auditing, emphasizing manual code reviews, automated security tools, and best practices for remediation. The chapter concludes with best practices for consolidating security findings, coordinating with development teams, and responsible disclosure, equipping developers, security engineers, and architects with practical tools to audit and secure blockchain applications effectively.

Read the paper · More papers on PaperTik