Web & DApp Penetration Testing

Job ID: 39915922

Budget: $250 – $750 USD

I will hand over a curated list of live targets—a traditional, login-based crypto portal plus several production DApps—and I need you to treat them as a black box. Your mission is to uncover anything that would let an attacker compromise user accounts, escalate to admin, or in the blockchain layer, drain funds or seize control of the underlying smart contracts.

You may use your preferred toolset (Burp Suite, OWASP ZAP, Metasploit, Hardhat, Foundry, MythX, etc.) as long as every finding is validated and reproducible from an external attacker’s perspective. I’m interested not only in classic web issues (injection, XSS, auth bypass, RCE) but also in logic flaws and creative DeFi attacks that can slip past automated scanners.

Deliverables
• A concise executive summary followed by a detailed technical report
• Step-by-step reproduction of each exploit with screenshots, payloads or scripts
• Working proof-of-concepts for every confirmed foothold or fund-drain scenario
• Clear severity rating and remediation guidance for each issue

The engagement is strictly black-box: you receive only the URLs and whatever on-chain information is publicly visible. No intrusive testing on other domains, no social engineering, and no denial-of-service attempts—stay within scope and local regulations. If you’re confident in both modern web exploitation and smart-contract assessments, let’s discuss timelines and get started.