ZeroDay Dev
教育
免費 · App內購買 · 專為 iPad 設計。尚未針對 macOS 驗證。
Learn to break things—before attackers do.
ZeroDay Dev teaches secure coding and blockchain security through 4,000+ hands-on challenges. Learn from 120+ real-world exploits: Beanstalk, Indexed Finance, bZx, VeilCash, Sigma.Money, Bybit, and more. Each exploit is linked to verified incident records so you learn from actual on-chain events, not hypotheticals.
Practice — Build exploit intuition without reading docs. Tap vulnerable lines, drag tokens into code, get instant feedback. Filter by domain (Exploits, Solidity, Rust, DeFi, Solana) or difficulty.
Exercises — Full code challenges with reference solutions. Deeper dives when you're ready.
Exam — Prepare for real security assessments. Timed tests across domains with performance tracking. Memory-match decks for opcodes, EIPs, and security terms.
Deep Dive Hub — Curated learning tracks for Web2, Web3, Rust, ZK Proofs, and Trading. Recommended tracks driven by your weak areas. Build your own from bookmarks or missed questions.
Streaks & XP — Stay consistent and level up. Daily streaks, badges, and progression keep you coming back.
Offline-first — Learn on the subway, no Wi‑Fi needed. All content lives on your device. No account required—start immediately.
Covers reentrancy, oracle manipulation, flash loans, proxy races, ZK trusted setup, and more. Rust, Solidity, DeFi, Solana & cybersecurity.
更多 - Prompt Library: the Helpful Prompts area is now the Prompt Library, with your own saved prompts pinned to the top and a dedicated My Prompts shortcut on the Home screen.
- Prompt chaining: combine several prompts into one and copy them together, with a quick in-app tip so the feature is easy to find.
- Build and the Rust journey: the Rust journey now has its own filter chips at the top, the catalog is cleaner, and your Build progress (tier, solved, streak) now lives in the Stats screen.
- Build reminders: set custom practice reminders by time and by days of the week.
- New real world exploit breakdowns: GnosisPay Delay module, Gravity Bridge, and Alephium TokenBridge, plus Zcash and Sui incidents.
- New hands on labs: PGP privacy training, API security in Rust, and Linux security tracks covering filesystem permissions and systemd privilege escalation.
- New Hyperliquid deep dive, smarter next best lesson recommendations, and a smoother Deep Dive flow.
- Updated AI reference with a refreshed model landscape including the latest providers and models.
- Fixes: lock screen widget text alignment and Deep Dive dismissal.
2.0.2 6月7日
General updates.
- Breaking incidents notifications
- Deep Dives for PoW, PoS, Solana Staking, ZCash
- Extending Glossary Terms
2.0.1 5月28日
> Breaking incidents, improved — Better live/recent incident discovery, clearer briefings, and easier rediscovery from the archive.
> Completed deep dives show as finished challenges and appear in your progress history.
> Three Home Screen widgets — Glossary, Exploits, and Checklist widgets now cover more of the app, with better layouts, rotation controls, and deep links.
> Chain Guide upgrades — Sort chains faster, scan updated details, and get clearer context around decentralization, privacy, and centralized-exchange risk.
> Build lab polish — A cleaner lesson layout gets you to the code faster while keeping the guided context close by.
> More current reference material — Refreshed glossary, reference, and exploit content make the app feel more useful as a daily study and security reference.
2.0 5月21日
- Build is now our in-app coding lab, with guided Rust lessons, a more visible entry point in Practice, and direct handoff from related exercises into matching Build lessons.
- Added new real-world exploit and CVE content, including PAN-OS User-ID Authentication Portal (CVE-2026-0300), cPanel & WHM (CVE-2026-41940), TanStack npm Supply Chain, Ivanti Endpoint Manager Mobile (CVE-2026-6973), Grok Bankrbot Morse-Code Prompt Injection, TrustedVolumes RFQ Proxy Drain, and 1inch Fusion V1 Settlement.
- Expanded exploit browsing and study coverage, so newer incidents are searchable, browsable, and tied into the real-world incident catalog more cleanly.
- Widgets now cover three experiences: Glossary, Exploits, and Checklist Progress.
- Updated widget functionality with manual rotation, a new Every 15 minutes rotation option, improved compact layouts, better deep links, and more reliable shared rotation state.
- Improved glossary and reference content, including new glossary terms and stronger deep links from widgets into full in-app content.
- Added more checklist and sharing polish, including hint-level share/copy support and better widget syncing for checklist progress.
- Refreshed references and learning content across chains, wallets, and security material so more of the catalog feels current and easier to browse.
1.9 5月14日
• Glossary widgets — Review rotating security and developer terms from your Home Screen or Lock Screen.
• New real-world incident lessons — Added KelpDAO rsETH Bridge and Litecoin MWEB reorg exercises.
• Widget customization — Choose a domain, rotation cadence, text size, color, and minimal just-text presentation.
1.8 4月28日
Memory exam card polish, plus new incident packs for Rhea Finance, Hyperbridge, Fortinet EMS, and wolfSSL (CVE-2026-5194). Expanded exercises, glossary entries, Solana material, Solidity EVM crypto snippets, and ZK proof content.
1.7 4月18日
Deep Dive polish — Faster navigation, a new favorites shelf, smoother customization, and added contract links and papers.
Practice filters — Hide and reorder chips so it is easier to focus on the topics you want.
More real-world learning — New exploit content, glossary links, and refreshed security packs.
1.6 4月9日
• **Operator profile** — Pick your callsign in onboarding. It appears in scenarios, War Rooms, and Stats.
• **Deep Dive Hub** — Home is now a launchpad. Curated tracks for Web2, Web3, Rust, ZK, and Trading. Recommended row based on your weak areas. Build your own from bookmarks or missed questions.
• **Memory-match exam** — New exam mode: flip cards and match terms across Opcodes, EIPs, Security Terms, DeFi, and more.
• **Glossary test** — Test yourself on term definitions in any domain directly from the Exam tab.
• **Safety checklists** — OpSec, Wallet & Web3, Protocol Reading, and Emergency Response checklists on Home.
• **Starred exploits** — Favorite incidents in Real World Exploits and jump back with a starred-only filter.
1.5 4月1日
More real-world exploit exercises — New and refined incident-linked drills: USR, CoW-Swap, Solv, DBXen, Venus, and Aave CAPO.
Learning UX — ML, ZK Proofs, and Dev Concepts subdomain chips.
1.4 3月31日
Free to download. Unlock all content with a one-time $4.99 purchase. Try Rust, Solidity, Exploits, and DeFi for free—no account required.
• Ops & War Rooms — Consequence-based narrative sessions: Thriller mode (limited lives, story-driven) and War Room (real-incident timeline simulations). Earn scenario badges.
• Bitcoin domain — First-class domain with subdomain filters: Basics, Script, Consensus, Lightning & L2.
• Protocol Patterns — DeFi architecture reference in More tab. Practice patterns with tagged questions.
• EIP Atlas — Searchable standards (ERC-20/721/4626, ERC-4337, EIP-712, etc.). "Practice this EIP" routes to tagged questions.
• Real World Exploits browse — Searchable incidents list. Tap row → detail → practice with full incident sessions.
• Solidity antipatterns — Dedicated snippet set, EIP antipatterns field.
• Trading Strategies subdomain chips — Arbitrage, Market Making, MEV, Execution, Risk Management.
• Web2 exploits — Log4Shell, Heartbleed, SolarWinds, buffer overflows, path traversal, SSRF.
• Cryptography subdomain — New Cybersecurity chip for crypto-focused practice.
• Assembly / Yul — Solidity subdomain for inline assembly questions.
• Rust Performance — New subdomain chip and gap-fill content.
1.3 3月24日
Free to download. Unlock all content with a one-time $4.99 purchase. Try Rust, Solidity, Exploits, and DeFi for free - no account required.
• Subdomain filters - Filter by topics like Reentrancy, Oracle, and Basics in Rust, Solidity, DeFi, and Exploits.
• New questions & real exploits - Aave + CoW Swap (~$50M), Aave wstETH CAPO (~$26M), Cetus Protocol ($223M, Sui), KiloEx oracle, and more. "In the wild" callouts link each exploit to verified incidents.
• Spaced repetition - Questions you miss are resurfaced at intervals to strengthen weak areas.
• Premium onboarding - Premium users can select ZK Proofs during onboarding.
1.2 3月18日
• On-chain feedback — Submit feedback via WalletConnect (Base or Ethereum). View your feedback on block explorers.
• Stats badges — See all tier badges (Pro, Expert, Zero Day Master), domain certifications, and achievements with lock/unlock state.
• Lightning Round — Now interactive-only (tap, swipe, drag, match) with up to 50 questions per run.
• New content — 9 new domains (cybersecurity, DeFi, trading, ZK proofs, and more) plus Snowden, Wireshark, and trading questions.
• Bookmarks — Quick "Practice bookmarked" flow from saved questions.
• UX hints — Code wrap and Glossary tips when you need them.
1.1 3月16日
- Prompt Library: the Helpful Prompts area is now the Prompt Library, with your own saved prompts pinned to the top and a dedicated My Prompts shortcut on the Home screen.
- Prompt chaining: combine several prompts into one and copy them together, with a quick in-app tip so the feature is easy to find.
- Build and the Rust journey: the Rust journey now has its own filter chips at the top, the catalog is cleaner, and your Build progress (tier, solved, streak) now lives in the Stats screen.
- Build reminders: set custom practice reminders by time and by days of the week.
- New real world exploit breakdowns: GnosisPay Delay module, Gravity Bridge, and Alephium TokenBridge, plus Zcash and Sui incidents.
- New hands on labs: PGP privacy training, API security in Rust, and Linux security tracks covering filesystem permissions and systemd privilege escalation.
- New Hyperliquid deep dive, smarter next best lesson recommendations, and a smoother Deep Dive flow.
- Updated AI reference with a refreshed model landscape including the latest providers and models.
- Fixes: lock screen widget text alignment and Deep Dive dismissal.
更多 版本 2.0.2 6月7日
不收集資料 開發者不會從這個 App 收集任何資料。