Skip to main content
日本語

Smart contract pre-procurement security checklist

40 items you can use in an internal review before a formal audit.

Available in Japanese only: this checklist is currently published in Japanese only. The overview below is in English, but the full 40-item checklist with commentary has not yet been translated.

This resource brings together, in a 40-item checklist, the security points a company should check internally before placing a smart contract development order, across four areas: design, tokenomics, infrastructure/operations, and audit/legal. It works backward from past hacking incidents in DeFi, NFTs, and RWA.

Each item includes commentary on background, what to check, and recommended countermeasures, so that even a point that is hard to judge from the title alone becomes understandable.

How this resource is organized

Section 2: Design-layer checks (10 items)

Points to confirm at the smart contract design stage — upgrade approach, access control, and function visibility, focused on the parts that are hard to fix once deployed.

Section 3: Tokenomics-design checks (10 items)

Points around token economics, liquidity, oracle references, and governance — the structures attackers exploit for economic gain.

Section 4: Infrastructure & operations checks (10 items)

Points around key management, multi-sig, the frontend, and monitoring — the operational foundation outside the contract itself.

Section 5: Audit & legal checks (10 items)

Points around third-party audits, bounty programs, and regulatory/legal compliance.

How to use the scoring sheet

32+ items marked Yes
You are ready to engage an audit firm and place an order — proceed to a formal audit request.
24–31 items marked Yes
The main issues are covered — organize the remaining unconfirmed items internally before considering an order.
Fewer than 24 items marked Yes
Design-stage organization is still incomplete — internal discussion or consulting to structure the issues is recommended.

Design lessons from past incidents

Each item in this checklist is worked backward from a real hacking incident. Representative cases and the checklist items they map to:

IncidentAttack vector
Ronin Bridge (2022, ~$600M)Private-key leak, a flawed multi-sig threshold design
Wormhole Bridge (2022, ~$320M)A flaw in signature-verification logic
BadgerDAO (2021, ~$120M)Frontend tampering
Euler Finance (2023, ~$200M)A flash loan combined with a logic flaw
Mango Markets (2022, ~$110M)Oracle price manipulation
Beanstalk Farms (2022, ~$180M)Governance combined with a flash loan
Nomad Bridge (2022, ~$190M)An initialization flaw during an upgrade

Talk to Netsujo

This checklist can be used entirely on your own, or with Netsujo's pre-procurement internal review support. If many items are "Not yet confirmed" and you are not sure where to start, a free 30-minute first consultation can help work through the issues together. Our standard scope of support includes: