DeFi Security: With So Many Hacks, Will It Ever Be Safe? - Ep.170
Unchained5 Touko 2020

DeFi Security: With So Many Hacks, Will It Ever Be Safe? - Ep.170

Dan Guido, cofounder and CEO of Trail of Bits, and Taylor Monahan, founder and CEO of MyCrypto, discuss all the recent hacks in DeFi, how it can be made more safely and who is responsible. We tackle: the Hegic security incident: whose responsibility it was to make sure the contract was secure — the auditor (Trail of Bits) or the team (Hegic) — what Trail of Bits was saying in its audit summary, and how to read between the lines of an audit summary how long an audit should be upgradeability: particularly around when more advanced technology and contracts interface with older technology/contracts centralization vs. decentralization: whether contracts can be made safely while maintaining adhering to the principle of decentralization, why Taylor would prioritize centralization and security, and how teams can create different levels of risk for users bug bounties: why asking what amount they should be is the wrong question the security threats posed by oracles and what a checklist for DeFi teams might look like Thank you to our sponsors! Crypto.com: https://crypto.com Kraken: https://www.kraken.com Stellar: https://www.stellar.org Episode links: Dan Guido: https://twitter.com/dguido Trail of Bits: https://www.trailofbits.com Taylor Monahan: https://twitter.com/tayvano_ MyCrypto: https://mycrypto.com Initial tweet by Hegic calling the security issue a typo: https://twitter.com/HegicOptions/status/1253937104666742787?s=20 Hegic tweet saying, “It’s not a security issue”: https://twitter.com/HegicOptions/status/1253954145113038849?s=20 Trail of Bits saying it will no longer work with Hegic: https://twitter.com/dguido/status/1254260725431894020?s=20 Taylor breaks down the audit summary: https://twitter.com/MyCrypto/status/1254058121342803968?s=20 Molly Wintermute’s Medium post on requesting a week audit vs. three-day review: https://medium.com/@molly.wintermute/post-mortem-hegic-unlock-function-bug-or-three-defi-development-mistakesthat-i-feel-sorry-about-5a23a7197bce Unconfirmed episode with Haseeb Qureshi on the Lendf.me attack: https://unchainedpodcast.com/haseeb-qureshi-on-the-unbelievable-story-of-the-25-million-lendf-me-hack/ Unchained interview showing Matt Luongo's approach to kill switches and upgradeability with tBTC: https://unchainedpodcast.com/tbtc-what-happens-when-the-most-liquid-crypto-asset-hits-defi/ Discussion of the bZx attacks on Unchained: https://unchainedpodcast.com/the-bzx-attacks-unethical-or-illegal-2-experts-weigh-in/ Issue with Curve contract: https://blog.curve.fi/vulnerability-disclosure/ Compound bug bounty program: https://compound.finance/docs/security#bug-bounty Taylor on “upgradeability makes things more insecure”: https://twitter.com/tayvano_/status/1222564979657723904?s=20 Synthetix oracle incident, allowing a bot to profit $1 billion: https://unchainedpodcast.com/how-synthetix-became-the-second-largest-defi-platform/ Taylor’s tips on how to get more ROI on an audit: https://twitter.com/MyCrypto/status/1254061500244713474?s=20 Tips to follow before getting an audit: https://blog.openzeppelin.com/follow-this-quality-checklist-before-an-audit-8cc6a0e44845/ Resources for security in DeFi: crytic/building-secure-contractsGuidelines and training material to write secure smart contracts - crytic/building-secure-contractsgithub.com https://consensys.github.io/smart-contract-best-practices/ https://forum.openzeppelin.com https://swcregistry.io https://diligence.consensys.net/blog/2020/03/new-offering-1-day-security-reviews/ Learn more about your ad choices. Visit megaphone.fm/adchoices

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(1148)

How 'Booth Babes' at Crypto Conferences Could Lead to Big Hacks Like Drift's

How 'Booth Babes' at Crypto Conferences Could Lead to Big Hacks Like Drift's

The Drift hack wasn't a one-off exploit. It was a patient operation spanning months, with nation-state actors working the conference circuit. Then Circle let the hackers take the money. Bitcoin’s app...

8 Huhti 1h 10min

Bits + Bips: $285M Hack, Iran's Crypto War Machine & the Token Fundamentals Crisis

Bits + Bips: $285M Hack, Iran's Crypto War Machine & the Token Fundamentals Crisis

A nation state hacked a startup and won. The hosts debate who's liable, what's fixable, and what isn't. --- Thank you to our sponsors: Bitcoin’s application layer, Citrea, launched its mainnet, exp...

7 Huhti 59min

How Bitcoin Is Both a Risk Asset and a Hedge Against Debasement

How Bitcoin Is Both a Risk Asset and a Hedge Against Debasement

Charles Schwab’s chief crypto strategist breaks down why traditional finance valuation frameworks, not narratives, are finally taking hold in digital assets. --- Multichain Advisors is an emerging t...

6 Huhti 45min

How State-Sponsored Hackers Like DPRK Drain DeFi Protocols: Uneasy Money

How State-Sponsored Hackers Like DPRK Drain DeFi Protocols: Uneasy Money

The Drift Protocol is down $285 million and Circle has the power to freeze the funds — but won’t. Kain, Taylor, and Luca explain why. Thank you to our sponsors! ⁠⁠⁠⁠⁠⁠⁠Fuse: The Energy Network...

6 Huhti 1h 16min

The Chopping Block: Is Canton a Real Blockchain? Ethereum’s Cypherpunk Dilemma, AI Security Chaos

The Chopping Block: Is Canton a Real Blockchain? Ethereum’s Cypherpunk Dilemma, AI Security Chaos

The Chopping Block crew and Wintermute’s Evgeny Gaevoy debate whether Canton is truly permissionless, if Ethereum Foundation should double down on cypherpunk ideals or embrace institutions, and how AI...

5 Huhti 56min

Do Centralized Real World Assets on DeFi Break Ethereum? - Bits + Bips

Do Centralized Real World Assets on DeFi Break Ethereum? - Bits + Bips

When do oil prices force a ceasefire? Why is crypto holding firm while equities crack? And does Canton or Ethereum win the institutional race? --- Thank you to our sponsor: ⁠⁠⁠Nexo⁠⁠⁠ — the premier...

5 Huhti 1h 4min

How Bitcoin Is Both a Risk Asset and a Hedge Against Debasement

How Bitcoin Is Both a Risk Asset and a Hedge Against Debasement

Charles Schwab’s chief crypto strategist breaks down why traditional finance valuation frameworks, not narratives, are finally taking hold in digital assets. --- Multichain Advisors is an emerging t...

5 Huhti 46min

How Solana's Largest Perp DEX Was Exploited for $285 Million

How Solana's Largest Perp DEX Was Exploited for $285 Million

Chaos Labs' Omer Goldberg unpacks the $285 million Drift Protocol exploit. Did the perp DEX fail to implement best practices? Sponsored by ⁠Nexo⁠: A crypto lending and borrowing platform that lets ...

4 Huhti 38min

Suosittua kategoriassa Politiikka ja uutiset

uutiscast
aikalisa
politiikan-puskaradio
viisupodi
rss-ootsa-kuullut-tasta
tervo-halme
ootsa-kuullut-tasta-2
rss-podme-livebox
rss-asiastudio
rss-pinnalla
rikosmyytit
otetaan-yhdet
the-ulkopolitist
linda-maria
et-sa-noin-voi-sanoo-esittaa
rss-mina-ukkola
rss-kaikki-uusiksi
rss-ulkopoditiikkaa
aihe
rss-raha-talous-ja-politiikka