OWASP SCS Handbooks¶
About the series¶
The security handbook series extends the OWASP Smart Contract Security Project beyond contract code into the surrounding people, process, application, and infrastructure layers. It complements SCSVS, SCSTG, SCWE, the Smart Contract Top 10, and the SCS Checklist without replacing those resources.
Field Manuals for Whole-Stack Web3 Security
These eleven handbooks are practical field manuals for developers, auditors, security engineers, incident responders, infrastructure and DevOps teams, product and UX practitioners, hiring teams, project leaders, and operators. Together they cover contract-adjacent, application, identity, people, supply-chain, infrastructure, response, forensics, and operational layers so Web3 security is treated as a complete system, not only as Solidity code.
Supporting Ethereum's Trillion Dollar Security Vision
This whole-stack approach supports the direction of the Ethereum Foundation's Trillion Dollar Security (1TS) initiative, which is strengthening UX, smart contracts, infrastructure, incident response, and the wider ecosystem so Ethereum can safely support global-scale onchain value.
Powered by an Ethereum Foundation ESP Grant
OWASP SCS is powered by an Ethereum Foundation Ecosystem Support Program (ESP) grant, helping translate that ambition into open technical awareness, actionable standards, and freely available security field manuals for the ecosystem.
Handbook 01
CDN and Front-End Supply Chain Security
Handbook 02
DNS and Hosting Security
Handbook 03
Employee Lifecycle Security
Handbook 04
EVM Forensics and DeFi Recovery
Handbook 05
Hiring, Remote Work, and Insider Threat
Handbook 06
Incident Response
Handbook 07
Infrastructure Security
Handbook 08
SDK Security Testing
Handbook 09
UX Security
Handbook 10
Web3 Attack Vectors Mapping
Handbook 11
Web3 Operational Security