BlockSec Research published a material on blockchain penetration testing and its boundaries. In the source, this approach is described as testing a live system from an attacker's perspective—searching for paths that can be exploited.

A key distinction is drawn between testing a live system, code auditing, and bug bounty programs. The source does not report on a specific attack, a found error, or an affected project.

The practical implication of the topic is to separate code verification from the verification of behavior in an already live system. However, the available material is presented only as a brief synopsis of metadata, so details of the methodology and results require further confirmation.