DeFi Security: With So Many Hacks, Will It Ever Be Safe? - Ep.170
Unchained5 Touko 2020

DeFi Security: With So Many Hacks, Will It Ever Be Safe? - Ep.170

Dan Guido, cofounder and CEO of Trail of Bits, and Taylor Monahan, founder and CEO of MyCrypto, discuss all the recent hacks in DeFi, how it can be made more safely and who is responsible. We tackle: the Hegic security incident: whose responsibility it was to make sure the contract was secure — the auditor (Trail of Bits) or the team (Hegic) — what Trail of Bits was saying in its audit summary, and how to read between the lines of an audit summary how long an audit should be upgradeability: particularly around when more advanced technology and contracts interface with older technology/contracts centralization vs. decentralization: whether contracts can be made safely while maintaining adhering to the principle of decentralization, why Taylor would prioritize centralization and security, and how teams can create different levels of risk for users bug bounties: why asking what amount they should be is the wrong question the security threats posed by oracles and what a checklist for DeFi teams might look like Thank you to our sponsors! Crypto.com: https://crypto.com Kraken: https://www.kraken.com Stellar: https://www.stellar.org Episode links: Dan Guido: https://twitter.com/dguido Trail of Bits: https://www.trailofbits.com Taylor Monahan: https://twitter.com/tayvano_ MyCrypto: https://mycrypto.com Initial tweet by Hegic calling the security issue a typo: https://twitter.com/HegicOptions/status/1253937104666742787?s=20 Hegic tweet saying, “It’s not a security issue”: https://twitter.com/HegicOptions/status/1253954145113038849?s=20 Trail of Bits saying it will no longer work with Hegic: https://twitter.com/dguido/status/1254260725431894020?s=20 Taylor breaks down the audit summary: https://twitter.com/MyCrypto/status/1254058121342803968?s=20 Molly Wintermute’s Medium post on requesting a week audit vs. three-day review: https://medium.com/@molly.wintermute/post-mortem-hegic-unlock-function-bug-or-three-defi-development-mistakesthat-i-feel-sorry-about-5a23a7197bce Unconfirmed episode with Haseeb Qureshi on the Lendf.me attack: https://unchainedpodcast.com/haseeb-qureshi-on-the-unbelievable-story-of-the-25-million-lendf-me-hack/ Unchained interview showing Matt Luongo's approach to kill switches and upgradeability with tBTC: https://unchainedpodcast.com/tbtc-what-happens-when-the-most-liquid-crypto-asset-hits-defi/ Discussion of the bZx attacks on Unchained: https://unchainedpodcast.com/the-bzx-attacks-unethical-or-illegal-2-experts-weigh-in/ Issue with Curve contract: https://blog.curve.fi/vulnerability-disclosure/ Compound bug bounty program: https://compound.finance/docs/security#bug-bounty Taylor on “upgradeability makes things more insecure”: https://twitter.com/tayvano_/status/1222564979657723904?s=20 Synthetix oracle incident, allowing a bot to profit $1 billion: https://unchainedpodcast.com/how-synthetix-became-the-second-largest-defi-platform/ Taylor’s tips on how to get more ROI on an audit: https://twitter.com/MyCrypto/status/1254061500244713474?s=20 Tips to follow before getting an audit: https://blog.openzeppelin.com/follow-this-quality-checklist-before-an-audit-8cc6a0e44845/ Resources for security in DeFi: crytic/building-secure-contractsGuidelines and training material to write secure smart contracts - crytic/building-secure-contractsgithub.com https://consensys.github.io/smart-contract-best-practices/ https://forum.openzeppelin.com https://swcregistry.io https://diligence.consensys.net/blog/2020/03/new-offering-1-day-security-reviews/ Learn more about your ad choices. Visit megaphone.fm/adchoices

Jaksot(1101)

Bitcoin DeFi Has Been Elusive. Can Mysten Labs Bring $1.4 Trillion Onchain?

Bitcoin DeFi Has Been Elusive. Can Mysten Labs Bring $1.4 Trillion Onchain?

Adeniyi Abiodun, co-founder and CPO of Mysten Labs,  walks through how Hashi works and how it differs from the competition. Can it succeed where others have failed? Nexo is the premier digital wealth...

20 Maalis 30min

Uneasy Money: Should DeFi Frontends Block High Slippage Swaps?

Uneasy Money: Should DeFi Frontends Block High Slippage Swaps?

The crew unpacks the significance of the Trade[XYZ] S&P 500 license, why Vanity Fair's recent crypto piece is so controversial and whether the EF is returning to “communism.” Thank you to our sponsor...

20 Maalis 1h 15min

DEX in the City: Why the Binance Case Against the WSJ ‘Is Probably Not a Winner’

DEX in the City: Why the Binance Case Against the WSJ ‘Is Probably Not a Winner’

The crew unpacks the Binance case against the Wall Street Journal. Is the lawsuit just for optics? Plus, why crypto can't turn a blind eye to one Aave user's $50 million loss. Nexo is the premier dig...

19 Maalis 52min

The Top Things Investors Need to Know Before Buying Crypto Tokens

The Top Things Investors Need to Know Before Buying Crypto Tokens

Across Protocol wants to retire its token in exchange for equity. Is the DAO model structurally broken? Thank you to our sponsor! Adaptive Security With Across Protocol proposing to retire i...

19 Maalis 1h 8min

The Chopping Block: The Ethereum Foundation Manifesto + Who Really Runs Crypto?

The Chopping Block: The Ethereum Foundation Manifesto + Who Really Runs Crypto?

Crypto insiders debate the Ethereum Foundation’s new “CROPS” mandate: is the EF losing touch with builders, why does Solana keep pulling startups away, and what will it actually take for Ethereum to s...

19 Maalis 1h 11min

Bits + Bips: Bitcoin Hits $75K as It Starts Catching Up to Gold

Bits + Bips: Bitcoin Hits $75K as It Starts Catching Up to Gold

Ram is bearish on equities, oil is keeping the Fed frozen, and Bitcoin is holding up anyway. The hosts debate whether crypto has bottomed or whether worse is still ahead. --- Thanks to our sponsor, ...

18 Maalis 1h 2min

Bits + Bips: Bitcoin Finally Acted Like a Hedge. Will It Last?

Bits + Bips: Bitcoin Finally Acted Like a Hedge. Will It Last?

For the first time in a geopolitical crisis, bitcoin held its ground while safe havens faltered. But can it keep holding if the VIX moves from yellow to red? --- Bits + Bips is spreading its wings ...

16 Maalis 48min

Is the DeFi Mullet Strategy the Best Way to Bring Finance Onchain?

Is the DeFi Mullet Strategy the Best Way to Bring Finance Onchain?

Sid Powell and Paul Frambot on why Apollo, Cantor, and Coinbase are quietly building their financial products on DeFi rails, and what it means for lending.  Nexo is the premier digital wealth platfor...

13 Maalis 1h 13min

Suosittua kategoriassa Politiikka ja uutiset

uutiscast
aikalisa
ootsa-kuullut-tasta-2
rss-ootsa-kuullut-tasta
politiikan-puskaradio
tervo-halme
rss-vaalirankkurit-podcast
rss-podme-livebox
rss-asiastudio
otetaan-yhdet
viisupodi
et-sa-noin-voi-sanoo-esittaa
rikosmyytit
the-ulkopolitist
rss-tasta-on-kyse-ivan-puopolo-verkkouutiset
aihe
radio-antro
rss-hyvaa-huomenta-bryssel
rss-merja-mahkan-rahat
rss-girls-finish-f1rst