The 10 Most Common Vulnerabilities Found in Audit Contests by Jack Sanford | Devcon SEA
Thu, Oct 2, 2025, 12:00 AM
This lightning talk offers a quick survival guide for DApp developers and security experts, highlighting the most common vulnerabilities found in audit contests. As these contests are often the final step before mainnet, the identified vulnerabilities have typically been overlooked by multiple developers and auditors. The session includes a link to a guide on fixing each vulnerability and a 2-minute Q&A to explore any of the 10 vulnerabilities in more detail and discuss why they are often missed Speaker(s): Jack Sanford Skill level: Intermediate Track: Security Keywords: Security, Auditing, audit, contest Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/
Speakers
Jack Sanford is the CEO and co-founder of Sherlock. Sherlock is one of the leading audit contest providers in the crypto space, having provided security solutions for the Ethereum Foundation, Optimism, MakerDAO, and many others. Sherlock also provides bug bounties and smart contract coverage to further invest in the success of customers. Previously, Jack worked at Citadel and Morgan Stanley.