Shift / 03 — On-Chain Systems

Decentralized code with immutable impacts.

Web3 relies on code to move and manage real value on an immutable ledger. If something goes wrong, there is little or no recourse. This shift covers Web3 use cases, security risks, and best practices.

Web3 inherits classical and emerging security risks and applies them to an immutable ledger.

Web3 systems are vulnerable to many of the same security threats as classical IT (access management, data manipulation, etc.). It's also impacted by other shifts as quantum computing threatens its underlying security model and AI agents are entrusted with wallets. When attacks occur on-chain, there's no clawback and no way to erase the effects.

COMMON BUGSReentrancy, oracle manipulation, access control
AT RISKBridges, contracts holding real value, on-chain agent wallets
FIRST STEPUnderstand top vulnerability patterns and design errors

Reports first, then a course — keep the briefing on hand.

01

Reports

Start free, with email — upgradeable to a paid Extended Edition with additional operational details and special reports.

Browse Web3 reports →
02

Courses

On-chain security courses detail top security risks and teach key skills for auditing Web3 security.

Browse Web3 courses →
03

Briefing

Board-ready material describing Web3 use cases and risks without the hype.

View the briefing kit →