Appendix C: References and Further Reading¶
This appendix collects every external source cited across the UX Security Handbook, grouped by category for easy lookup.
Standards and Frameworks¶
- MITRE AADAPT Framework
- MITRE ATT&CK
- MITRE AADAPT public matrix repository, GitHub
- NIST SP 800-218, Secure Software Development Framework (SSDF)
- EIP-20: Token Standard
- EIP-712: Typed Structured Data Hashing and Signing
- EIP-2612: Permit Extension for EIP-20
- ERC-4337: Account Abstraction
- EIP-7702: Set EOA Account Code
- ERC-7730: Clear Signing Format
- OWASP Software Assurance Maturity Model (SAMM)
- OWASP Smart Contract Security (SCS), including SCSTG, SCSVS, and SCWE
- OWASP Smart Contract Top 10: 2026
- OWASP Web3 Attack Vectors Top 15
- ISO 9241-11: Ergonomics of Human-System Interaction
- W3C Web Content Accessibility Guidelines (WCAG) 2.2
Incidents and Case Studies¶
- Bybit background, Wikipedia
- Curve Finance loses $570k due to DNS compromise, CryptoTimes
- FBI Internet Crime Complaint Center (IC3), PSA250226 - TraderTraitor advisory
- Scam Sniffer 2025 phishing report
- Sygnia investigation into the Bybit hack
Tools and Documentation¶
- Blockaid
- Cantina
- Code4rena
- Immunefi
- Permit2 overview, Uniswap developer documentation
- Permit2 overview, Uniswap contracts documentation
- Permit2 contract and documentation, GitHub
- Reown documentation
- WalletConnect Verify API documentation
- Revoke.cash
- Ledger, Clear Signing
Further Reading¶
- Ethereum Foundation, Pectra roadmap
- Deceptive Design taxonomy
- Nielsen Norman Group, "10 Usability Heuristics for User Interface Design"
- Nielsen Norman Group, "How to Rate the Severity of Usability Problems"
- Nielsen Norman Group, "Usability Testing 101"
- Crying Wolf: An Empirical Study of SSL Warning Effectiveness, USENIX Security 2009