Capability

API security testing for Web3 infrastructure

How RedTeam's Surface Engine discovers, maps, and continuously tests your API attack surface: endpoints, RPC nodes, subdomains, cloud services, and frontends.

Primary phrase: API security testing

Your smart contract is only as secure as the API that fronts it. Most Web3 exploits do not break the contract; they break the API layer, the RPC proxy, the indexers, or the frontend that talks to it. Veritas RedTeam's Surface Engine continuously tests that layer the way a real attacker would.

What the Surface Engine discovers

Before testing, RedTeam maps your full attack surface. This is not a one-time scan; the surface is re-walked on every loop because infrastructure changes between deploys.

  • Subdomains: brute-forced from certificate transparency logs, DNS records, and wordlists.
  • API endpoints: discovered from OpenAPI specs, route enumeration, and traffic analysis.
  • RPC nodes: detected by probing common RPC paths and chain-specific patterns.
  • Cloud assets: S3 buckets, CDN origins, and exposed storage endpoints.
  • Frontend assets: JavaScript bundles analyzed for hardcoded endpoints and API keys.

How API penetration testing works

Once the surface is mapped, RedTeam stages proof-of-impact payloads against each endpoint. Every test is gated by your rules of engagement: read-only by default, active exploitation only in authorized scopes.

  • Input fuzzing: invalid types, oversized payloads, and edge-case values sent to every parameter.
  • Auth bypass: token replay, role escalation, and IDOR attempts on authenticated endpoints.
  • Injection: SQL, NoSQL, command, and template injection probes.
  • Rate-limit testing: brute-force and credential-stuffing viability checks on auth endpoints.
  • CORS abuse: origin reflection and credential leakage tests.
  • GraphQL introspection and query-depth attacks on GraphQL endpoints.

Attack surface management, continuously

Attack surface management is not a quarterly report. It is a live graph of every reachable asset, updated after every deploy. RedTeam fuses discovered endpoints, live findings, and code-level vulnerabilities into a single Neo4j attack graph so you see:

  • Which endpoints are reachable from the public internet without authentication.
  • Which API findings chain with smart-contract findings to form a full exploit path.
  • Which assets changed since the last scan (new endpoints, removed services, exposed keys).
  • Which findings are new, which are persistent, and which were fixed and regressed.

A finding on its own is a line item. A finding chained with three others is an exploit path. The attack graph shows the path, not just the line items.

Cloud security testing

RedTeam tests the cloud layer around your contracts: the API gateway, the lambda functions, the IAM roles, the storage buckets. Common findings include:

  • Publicly readable S3 buckets containing deployment artifacts or user data.
  • IAM roles with overly broad permissions (e.g., wildcard s3:GetObject).
  • API gateway endpoints missing auth or rate limiting.
  • Lambda functions exposing environment variables (including private keys) in error responses.

How to get started

RedTeam's API security testing runs continuously against your staging and production infrastructure. To scope a scan for your protocol:

  • Define your scope: which domains, API endpoints, and RPC nodes to test.
  • Set rules of engagement: read-only by default, active exploitation only where authorized.
  • Reserve a scan slot for a time-boxed deep test, or enable continuous monitoring.

Reserve a scoped scan or join the waitlist to get started.

Learn more about Veritas Protocol or explore the full RedTeam capabilities.

Ready to put RedTeam on the wire?

Join the early-access cohort or reserve a scoped scan slot for your protocol.