DeFi Security: With So Many Hacks, Will It Ever Be Safe? - Ep.170
Unchained5 Mai 2020

DeFi Security: With So Many Hacks, Will It Ever Be Safe? - Ep.170

Dan Guido, cofounder and CEO of Trail of Bits, and Taylor Monahan, founder and CEO of MyCrypto, discuss all the recent hacks in DeFi, how it can be made more safely and who is responsible. We tackle: the Hegic security incident: whose responsibility it was to make sure the contract was secure — the auditor (Trail of Bits) or the team (Hegic) — what Trail of Bits was saying in its audit summary, and how to read between the lines of an audit summary how long an audit should be upgradeability: particularly around when more advanced technology and contracts interface with older technology/contracts centralization vs. decentralization: whether contracts can be made safely while maintaining adhering to the principle of decentralization, why Taylor would prioritize centralization and security, and how teams can create different levels of risk for users bug bounties: why asking what amount they should be is the wrong question the security threats posed by oracles and what a checklist for DeFi teams might look like Thank you to our sponsors! Crypto.com: https://crypto.com Kraken: https://www.kraken.com Stellar: https://www.stellar.org Episode links: Dan Guido: https://twitter.com/dguido Trail of Bits: https://www.trailofbits.com Taylor Monahan: https://twitter.com/tayvano_ MyCrypto: https://mycrypto.com Initial tweet by Hegic calling the security issue a typo: https://twitter.com/HegicOptions/status/1253937104666742787?s=20 Hegic tweet saying, “It’s not a security issue”: https://twitter.com/HegicOptions/status/1253954145113038849?s=20 Trail of Bits saying it will no longer work with Hegic: https://twitter.com/dguido/status/1254260725431894020?s=20 Taylor breaks down the audit summary: https://twitter.com/MyCrypto/status/1254058121342803968?s=20 Molly Wintermute’s Medium post on requesting a week audit vs. three-day review: https://medium.com/@molly.wintermute/post-mortem-hegic-unlock-function-bug-or-three-defi-development-mistakesthat-i-feel-sorry-about-5a23a7197bce Unconfirmed episode with Haseeb Qureshi on the Lendf.me attack: https://unchainedpodcast.com/haseeb-qureshi-on-the-unbelievable-story-of-the-25-million-lendf-me-hack/ Unchained interview showing Matt Luongo's approach to kill switches and upgradeability with tBTC: https://unchainedpodcast.com/tbtc-what-happens-when-the-most-liquid-crypto-asset-hits-defi/ Discussion of the bZx attacks on Unchained: https://unchainedpodcast.com/the-bzx-attacks-unethical-or-illegal-2-experts-weigh-in/ Issue with Curve contract: https://blog.curve.fi/vulnerability-disclosure/ Compound bug bounty program: https://compound.finance/docs/security#bug-bounty Taylor on “upgradeability makes things more insecure”: https://twitter.com/tayvano_/status/1222564979657723904?s=20 Synthetix oracle incident, allowing a bot to profit $1 billion: https://unchainedpodcast.com/how-synthetix-became-the-second-largest-defi-platform/ Taylor’s tips on how to get more ROI on an audit: https://twitter.com/MyCrypto/status/1254061500244713474?s=20 Tips to follow before getting an audit: https://blog.openzeppelin.com/follow-this-quality-checklist-before-an-audit-8cc6a0e44845/ Resources for security in DeFi: crytic/building-secure-contractsGuidelines and training material to write secure smart contracts - crytic/building-secure-contractsgithub.com https://consensys.github.io/smart-contract-best-practices/ https://forum.openzeppelin.com https://swcregistry.io https://diligence.consensys.net/blog/2020/03/new-offering-1-day-security-reviews/ Learn more about your ad choices. Visit megaphone.fm/adchoices

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(1147)

Uneasy Money: Who Owns Stolen Crypto? The $71M Fight Testing DeFi Limits

Uneasy Money: Who Owns Stolen Crypto? The $71M Fight Testing DeFi Limits

A legal battle over frozen KelpDAO hack funds is forcing DeFi to answer questions it has long avoided. Thank you to our sponsors!⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ Coinbase One: Get 20% off the first year of your ...

9 Mai 1h 14min

Coinbase's Chief Policy Officer on Why He Believes the Clarity Act Will Pass

Coinbase's Chief Policy Officer on Why He Believes the Clarity Act Will Pass

Coinbase's chief policy officer explains why the bank lobby failed to kill stablecoin rewards — and what 'workable compromise' actually means for crypto users. =======================================...

8 Mai 34min

DEX in the City: With the Stablecoin Yield Compromise, Can the Clarity Act Get Passed?

DEX in the City: With the Stablecoin Yield Compromise, Can the Clarity Act Get Passed?

Seven lawsuits blame OpenAI for enabling a mass shooting. Could the same legal theory come for DeFi? Thanks to our sponsor! Coinbase One Get 20% off the first year of your Coinbase One annual pla...

8 Mai 39min

A16z Crypto Raised $2.2 Billion for Fund 5. Here's How They Plan to Deploy It

A16z Crypto Raised $2.2 Billion for Fund 5. Here's How They Plan to Deploy It

From AI agents as economic actors to quantum threats and prediction market regulation, Ali Yahya of a16z lays out the investment thesis behind a16z crypto's fifth fund. ==============================...

7 Mai 55min

Why Wrapped Energy or Compute Will Be the New Store of Value: Bits + Bips

Why Wrapped Energy or Compute Will Be the New Store of Value: Bits + Bips

Missiles in the Strait of Hormuz. Brent jumps 5%. Bitcoin breaks through $80. The Bits + Bips crew reads the geopolitical tape — and explains why crypto is shrugging it off. --- Thank you to our spo...

7 Mai 1h

Ben Fielding: Gensyn, Decentralized AI, and the Prediction Market That Settles Itself: Bits + Bips

Ben Fielding: Gensyn, Decentralized AI, and the Prediction Market That Settles Itself: Bits + Bips

A prediction market trades on outcomes. An information market trades on knowledge. Fielding makes the case for the latter. --- Heads up! If you haven’t yet, be sure to subscribe to Bits + Bips, sin...

3 Mai 50min

After April's $606 Million in DeFi Hacks, What's the Fair Value Yield Rate?

After April's $606 Million in DeFi Hacks, What's the Fair Value Yield Rate?

$606 million in DeFi exploits in one month. Two of the space's sharpest risk thinkers debate whether lenders are being paid anywhere close to enough. =================================================...

3 Mai 1h 6min

Pump.fun’s $370M Burn Was a Mistake, Says Luca Netz: Uneasy Money

Pump.fun’s $370M Burn Was a Mistake, Says Luca Netz: Uneasy Money

Pump.fun set fire to $370 million in tokens. Luca lays out the airdrop math that says they should have done the opposite. Thank you to our sponsors!⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ MultiChain Advisors is an emerging...

1 Mai 1h 14min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
forklart
aftenpodden-usa
popradet
stopp-verden
fotballpodden-2
nokon-ma-ga
det-store-bildet
dine-penger-pengeradet
rss-gukild-johaug
hanna-de-heldige
rss-espen-lee-usensurert
lydartikler-fra-aftenposten
rss-ness
aftenbla-bla
rss-dannet-uten-piano
e24-podden
rss-utenrikskomiteen-med-bogen-og-grasvik
rss-gilbrantsuvatne