Near Learn

Make it safe · Advanced

Security pitfalls

Most NEAR contract exploits are not exotic. They come from a handful of patterns that behave differently from the EVM: cross-contract calls that are asynchronous and never roll back the caller, callbacks that anyone can call, access keys that can act without a wallet prompt, storage that the contract pays for, and gas limits that turn a growing loop into a dead feature.

Each lesson shows the bug as real near-sdk 5.x Rust, explains why NEAR’s execution model allows it, and gives the fixed version. Where there is an EVM analog — tx.origin, reentrancy, payable — it is shown side by side, so Solidity developers can map what they already know.

The module ends with a one-page review checklist and a sandbox test you can adapt to check failure paths before you deploy.

12 lessons~80 min36 quiz questionsFree · no sign-up

What you’ll learn

  • Write cross-contract calls whose callbacks restore state when the call fails
  • Close the double-spend window between a call and its callback
  • Lock callbacks down with #[private] and keep them panic-free
  • Authorize with the predecessor, not the signer, and require 1 yoctoNEAR for sensitive actions
  • Audit access keys and decide who can upgrade a contract
  • Handle deposits, refunds and failed transfers without stranding funds
  • Defend against storage cost attacks and unbounded iteration
  • Migrate state safely when the contract layout changes

Lessons