September 2025
Intermediate to advanced
640 pages
19h 47m
English
| Threat scenario (TS) | Attack vector | CWE | Entry point | Derived attack scenario |
|---|---|---|---|---|
| TS1: mobile or browser client/UI | Exploiting improper authentication via stolen session tokens | CWE-287 (improper authentication) | Mobile or browser client | An attacker uses stolen session tokens obtained through phishing to impersonate legitimate users, allowing unauthorized access and fraudulent transactions. |
| TS2: digital wallet/smart contracts | Reusing valid transactions to perform replay attacks | CWE-326 (inadequate encryption strength) | Digital wallet API | The attacker intercepts and replays previously signed wallet transactions due to weak encryption, leading to duplicate payments or withdrawals. |
| TS3: distributed digital identity system/trust boundary | Manipulating identity data transmitted between the dApp and identity system | CWE-345 (insufficient verification of data authenticity) | Identity validation API | The attacker tampers with transmitted identity payloads, corrupting user data or enabling fraudulent access by impersonating a legitimate user. |
| TS4: dApp frontend and components | Injecting malicious scripts into input fields | CWE-79 (cross-site scripting) | dApp frontend | Malicious scripts injected into input fields execute in the victim’s browser, allowing the attacker to steal session tokens and execute unauthorized transactions. |
| TS5: dApp middleware (JSON-RPC) | Exploiting deserialization vulnerabilities to inject malicious payloads | CWE-502 (deserialization of untrusted ... |
Read now
Unlock full access