DeFi Security: With So Many Hacks, Will It Ever Be Safe? - Ep.170
Unchained5 Touko 2020

DeFi Security: With So Many Hacks, Will It Ever Be Safe? - Ep.170

Dan Guido, cofounder and CEO of Trail of Bits, and Taylor Monahan, founder and CEO of MyCrypto, discuss all the recent hacks in DeFi, how it can be made more safely and who is responsible. We tackle: the Hegic security incident: whose responsibility it was to make sure the contract was secure — the auditor (Trail of Bits) or the team (Hegic) — what Trail of Bits was saying in its audit summary, and how to read between the lines of an audit summary how long an audit should be upgradeability: particularly around when more advanced technology and contracts interface with older technology/contracts centralization vs. decentralization: whether contracts can be made safely while maintaining adhering to the principle of decentralization, why Taylor would prioritize centralization and security, and how teams can create different levels of risk for users bug bounties: why asking what amount they should be is the wrong question the security threats posed by oracles and what a checklist for DeFi teams might look like Thank you to our sponsors! Crypto.com: https://crypto.com Kraken: https://www.kraken.com Stellar: https://www.stellar.org Episode links: Dan Guido: https://twitter.com/dguido Trail of Bits: https://www.trailofbits.com Taylor Monahan: https://twitter.com/tayvano_ MyCrypto: https://mycrypto.com Initial tweet by Hegic calling the security issue a typo: https://twitter.com/HegicOptions/status/1253937104666742787?s=20 Hegic tweet saying, “It’s not a security issue”: https://twitter.com/HegicOptions/status/1253954145113038849?s=20 Trail of Bits saying it will no longer work with Hegic: https://twitter.com/dguido/status/1254260725431894020?s=20 Taylor breaks down the audit summary: https://twitter.com/MyCrypto/status/1254058121342803968?s=20 Molly Wintermute’s Medium post on requesting a week audit vs. three-day review: https://medium.com/@molly.wintermute/post-mortem-hegic-unlock-function-bug-or-three-defi-development-mistakesthat-i-feel-sorry-about-5a23a7197bce Unconfirmed episode with Haseeb Qureshi on the Lendf.me attack: https://unchainedpodcast.com/haseeb-qureshi-on-the-unbelievable-story-of-the-25-million-lendf-me-hack/ Unchained interview showing Matt Luongo's approach to kill switches and upgradeability with tBTC: https://unchainedpodcast.com/tbtc-what-happens-when-the-most-liquid-crypto-asset-hits-defi/ Discussion of the bZx attacks on Unchained: https://unchainedpodcast.com/the-bzx-attacks-unethical-or-illegal-2-experts-weigh-in/ Issue with Curve contract: https://blog.curve.fi/vulnerability-disclosure/ Compound bug bounty program: https://compound.finance/docs/security#bug-bounty Taylor on “upgradeability makes things more insecure”: https://twitter.com/tayvano_/status/1222564979657723904?s=20 Synthetix oracle incident, allowing a bot to profit $1 billion: https://unchainedpodcast.com/how-synthetix-became-the-second-largest-defi-platform/ Taylor’s tips on how to get more ROI on an audit: https://twitter.com/MyCrypto/status/1254061500244713474?s=20 Tips to follow before getting an audit: https://blog.openzeppelin.com/follow-this-quality-checklist-before-an-audit-8cc6a0e44845/ Resources for security in DeFi: crytic/building-secure-contractsGuidelines and training material to write secure smart contracts - crytic/building-secure-contractsgithub.com https://consensys.github.io/smart-contract-best-practices/ https://forum.openzeppelin.com https://swcregistry.io https://diligence.consensys.net/blog/2020/03/new-offering-1-day-security-reviews/ Learn more about your ad choices. Visit megaphone.fm/adchoices

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(1148)

DEX in the City: KelpDAO vs. LayerZero: Who Is Liable When a DeFi Protocol Is Hacked?

DEX in the City: KelpDAO vs. LayerZero: Who Is Liable When a DeFi Protocol Is Hacked?

A $300M bridge exploit is forcing the question DeFi has been avoiding: when users lose money, who is actually responsible — the protocol, the infrastructure provider, or both? Thanks to our sponsor...

24 Huhti 47min

The Chopping Block: Kelp DAO Hack Fallout, DeFi Socialized Losses & Arbitrum’s “Reverse Hack”

The Chopping Block: Kelp DAO Hack Fallout, DeFi Socialized Losses & Arbitrum’s “Reverse Hack”

The Chopping Block crew and guest Monet Supply break down the $200M Kelp DAO bridge exploit, finger-pointing between LayerZero, Kelp DAO, and Aave, the wild “reverse hack” Arbitrum bailout, and what i...

23 Huhti 1h 1min

Is Canton Permissionless? CEO Says Yes, but SuperValidators Need Approval

Is Canton Permissionless? CEO Says Yes, but SuperValidators Need Approval

Digital Asset’s CEO faces pointed questions about Canton’s core claims and admits something surprising about the network’s architecture. ======================================================== As B...

22 Huhti 1h 26min

Strategy's Preferred Stock Is Now a Stablecoin. And DeFi Has a Security Problem.

Strategy's Preferred Stock Is Now a Stablecoin. And DeFi Has a Security Problem.

The $290 million Kelp DAO hack, attributed to North Korea's Lazarus Group, has DeFi TVL down $13 billion in 48 hours. Do DeFi's foundational assumptions need to change? --- Heads up! If you haven’t...

22 Huhti 1h

Bits + Bips: Why Josh Lim Is Optimistic on the Dynamics He's Seeing in Bitcoin

Bits + Bips: Why Josh Lim Is Optimistic on the Dynamics He's Seeing in Bitcoin

Bitcoin's spot-led rally looks healthy on the surface. But derivatives say conviction is thin. Josh Lim from FalconX on what the market structure is actually telling you right now. --- Thank you to ...

19 Huhti 44min

The Chopping Block: Quantum FUD, Circle vs. Tether & WLFI Drama

The Chopping Block: Quantum FUD, Circle vs. Tether & WLFI Drama

Quantum computing risk, USDC vs. Tether drama after the Drift hack, and World Liberty Financial’s governance circus take center stage as Haseeb, Tom, Tarun, and special guest Joshua Lim dissect market...

19 Huhti 1h 20min

How the DOJ and SEC Cases Against BitClout's Nader Al-Naji Collapsed

How the DOJ and SEC Cases Against BitClout's Nader Al-Naji Collapsed

Debanked 12 times. Walked through an airport in handcuffs. Every charge eventually gone. Nader Al-Naji on the defense strategy that convinced both agencies to back off. ==============================...

18 Huhti 1h 20min

Uneasy Money: BIP-361 Wants to Freeze Satoshi's Coins. What Happens If It Passes?

Uneasy Money: BIP-361 Wants to Freeze Satoshi's Coins. What Happens If It Passes?

A Bitcoin developer just proposed freezing wallets that don't upgrade for quantum resistance. Including Satoshi's. Thank you to our sponsors!⁠⁠⁠⁠⁠⁠⁠⁠⁠ Nexo Nexo is the premier digital wealth pl...

18 Huhti 1h 16min

Suosittua kategoriassa Politiikka ja uutiset

uutiscast
aikalisa
politiikan-puskaradio
viisupodi
rss-ootsa-kuullut-tasta
tervo-halme
ootsa-kuullut-tasta-2
rss-podme-livebox
rss-asiastudio
rss-pinnalla
rikosmyytit
otetaan-yhdet
the-ulkopolitist
linda-maria
et-sa-noin-voi-sanoo-esittaa
rss-mina-ukkola
rss-kaikki-uusiksi
rss-ulkopoditiikkaa
aihe
rss-raha-talous-ja-politiikka