Skip to Content
Blockchain Application Security
book

Blockchain Application Security

by Marco Morana, Harpreet Singh, Francesco Piccoli
September 2025
Intermediate to advanced
640 pages
19h 47m
English
Wiley
Content preview from Blockchain Application Security

Appendix CMapping of Threat Scenarios to Exploitable Attack Paths

Threat scenario (TS)Attack vectorCWEEntry pointDerived attack scenario
TS1: mobile or browser client/UIExploiting improper authentication via stolen session tokensCWE-287 (improper authentication)Mobile or browser clientAn attacker uses stolen session tokens obtained through phishing to impersonate legitimate users, allowing unauthorized access and fraudulent transactions.
TS2: digital wallet/smart contractsReusing valid transactions to perform replay attacksCWE-326 (inadequate encryption strength)Digital wallet APIThe attacker intercepts and replays previously signed wallet transactions due to weak encryption, leading to duplicate payments or withdrawals.
TS3: distributed digital identity system/trust boundaryManipulating identity data transmitted between the dApp and identity systemCWE-345 (insufficient verification of data authenticity)Identity validation APIThe attacker tampers with transmitted identity payloads, corrupting user data or enabling fraudulent access by impersonating a legitimate user.
TS4: dApp frontend and componentsInjecting malicious scripts into input fieldsCWE-79 (cross-site scripting)dApp frontendMalicious scripts injected into input fields execute in the victim’s browser, allowing the attacker to steal session tokens and execute unauthorized transactions.
TS5: dApp middleware (JSON-RPC)Exploiting deserialization vulnerabilities to inject malicious payloadsCWE-502 (deserialization of untrusted ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Mastering Blockchain

Mastering Blockchain

Lorne Lantz, Daniel Cawrey
Microservices Security in Action

Microservices Security in Action

Prabath Siriwardena, Wajjakkara Kankanamge Anthony Nuwan Dias

Publisher Resources

ISBN: 9781119551034