{"repo":"onchainattack/oak","free":true,"listed":false,"github":"https://github.com/onchainattack/oak","clone":"git clone https://github.com/onchainattack/oak.git","description":"Open vendor-neutral taxonomy of on-chain adversary tactics and techniques across token launches, smart-contract exploits, bridges, custody, laundering - with mitigations, software, threat actors, and worked examples.","language":"TeX","stars":17,"topics":["adversary-tactics","attack-framework","blockchain-security","bridge-security","crypto-security","defi-security","drainer-detection","knowledge-base","onchain-security","rug-pull-detection"],"license":null,"category":"productivity","readme_excerpt":"OAK — OnChain Attack Knowledge A common language for on-chain adversary behavior. OAK is an open, vendor-neutral knowledge base of adversary Tactics and Techniques observed against on-chain assets — tokens, liquidity, custody, and the wallets and protocols that interact with them. The threat surface is fundamentally different from traditional IT infosec: public-ledger finality, anonymous adversaries, money-and-laundering as the primary objective, smart-contract code as the attack surface, no patchable endpoints. OAK exists because crypto needs vocabulary built for crypto's threat model, not borrowed from elsewhere. Current state: see STATS.md for live counts (auto-generated on every build). Schema versioning + content-snapshot model: see VERSIONING.md . Coverage gaps and contributor backlog: see BACKLOG.md . Open structural questions: see TAXONOMY-AUDIT.md . Why OAK exists On-chain attackers reuse a small, finite set of Tactics — but the security, research, and on-chain-monitoring communities lack a shared vocabulary to describe them. Investigators, vendors, and risk teams each use their own terminology; coverage claims are not comparable across products; and academic findings rarely transfer cleanly to operational defense. OAK provides a stable identifier system ( OAK-Tn for Tactics, OAK-Tn.NNN for Techniques) so that: - Investigators can attribute findings unambiguously. - Vendors can map their detectors to specific Techniques and publish honest coverage matrices. - Risk te","default_branch":null,"files":null,"tree":[],"storefront":"/r/onchainattack","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/onchainattack/oak/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}