ABOUT TRACEFI
Built to learn Web3 security deeply — and share the journey.
TraceFi is my personal Web3 security learning system. I study real implementations, incidents, and security write-ups, then turn what I learn into structured lessons and hands-on Foundry Labs that others can explore too.
01 / MOTIVE
Why I built TraceFi
Reading a security report alone is not enough for me. I want to understand the implementation, reproduce the behavior, identify the broken invariant and its Root Cause, and rebuild the lesson as something executable.
TraceFi grew from that process: a personal system for turning genuine study into structured Learn content, implementation-first explanations, practical Foundry Labs, and reflection and verification exercises.
02 / LEARNING PIPELINE
How I learn
- 01Study implementation
- 02Read the write-up or incident
- 03Reproduce the behavior
- 04Identify the Root Cause
- 05Build the Learn
- 06Build the Lab
- 07Review and publish
03 / OPERATING PRINCIPLES
Learning principles
Implementation first
Every Learn has a Lab
Root Cause before exploit memorization
Evidence-backed claims
Protected solutions remain private
Uncertainty is labelled honestly
Learn deeply before publishing
04 / INDEPENDENT
An independent project
TraceFi is an independent personal project. Its first purpose is to help me become a stronger smart-contract security researcher.
Publishing the resulting lessons and Labs also allows auditors, bounty hunters, researchers, and developers to learn from the same process. TraceFi is not an audit firm, a university, or a guarantee of security.
05 / SCOPE
Current focus
Future direction — not current coverage
Cosmos, Solana, Polkadot/Substrate, Move ecosystems, validator security, and broader distributed-system failures may become future areas of study.
06 / PUBLIC CHANNELS
Follow the work
An independent, implementation-first Web3 security learning project.