DeFi Security: With So Many Hacks, Will It Ever Be Safe? - Ep.170
Unchained5 Mai 2020

DeFi Security: With So Many Hacks, Will It Ever Be Safe? - Ep.170

Dan Guido, cofounder and CEO of Trail of Bits, and Taylor Monahan, founder and CEO of MyCrypto, discuss all the recent hacks in DeFi, how it can be made more safely and who is responsible. We tackle: the Hegic security incident: whose responsibility it was to make sure the contract was secure — the auditor (Trail of Bits) or the team (Hegic) — what Trail of Bits was saying in its audit summary, and how to read between the lines of an audit summary how long an audit should be upgradeability: particularly around when more advanced technology and contracts interface with older technology/contracts centralization vs. decentralization: whether contracts can be made safely while maintaining adhering to the principle of decentralization, why Taylor would prioritize centralization and security, and how teams can create different levels of risk for users bug bounties: why asking what amount they should be is the wrong question the security threats posed by oracles and what a checklist for DeFi teams might look like Thank you to our sponsors! Crypto.com: https://crypto.com Kraken: https://www.kraken.com Stellar: https://www.stellar.org Episode links: Dan Guido: https://twitter.com/dguido Trail of Bits: https://www.trailofbits.com Taylor Monahan: https://twitter.com/tayvano_ MyCrypto: https://mycrypto.com Initial tweet by Hegic calling the security issue a typo: https://twitter.com/HegicOptions/status/1253937104666742787?s=20 Hegic tweet saying, “It’s not a security issue”: https://twitter.com/HegicOptions/status/1253954145113038849?s=20 Trail of Bits saying it will no longer work with Hegic: https://twitter.com/dguido/status/1254260725431894020?s=20 Taylor breaks down the audit summary: https://twitter.com/MyCrypto/status/1254058121342803968?s=20 Molly Wintermute’s Medium post on requesting a week audit vs. three-day review: https://medium.com/@molly.wintermute/post-mortem-hegic-unlock-function-bug-or-three-defi-development-mistakesthat-i-feel-sorry-about-5a23a7197bce Unconfirmed episode with Haseeb Qureshi on the Lendf.me attack: https://unchainedpodcast.com/haseeb-qureshi-on-the-unbelievable-story-of-the-25-million-lendf-me-hack/ Unchained interview showing Matt Luongo's approach to kill switches and upgradeability with tBTC: https://unchainedpodcast.com/tbtc-what-happens-when-the-most-liquid-crypto-asset-hits-defi/ Discussion of the bZx attacks on Unchained: https://unchainedpodcast.com/the-bzx-attacks-unethical-or-illegal-2-experts-weigh-in/ Issue with Curve contract: https://blog.curve.fi/vulnerability-disclosure/ Compound bug bounty program: https://compound.finance/docs/security#bug-bounty Taylor on “upgradeability makes things more insecure”: https://twitter.com/tayvano_/status/1222564979657723904?s=20 Synthetix oracle incident, allowing a bot to profit $1 billion: https://unchainedpodcast.com/how-synthetix-became-the-second-largest-defi-platform/ Taylor’s tips on how to get more ROI on an audit: https://twitter.com/MyCrypto/status/1254061500244713474?s=20 Tips to follow before getting an audit: https://blog.openzeppelin.com/follow-this-quality-checklist-before-an-audit-8cc6a0e44845/ Resources for security in DeFi: crytic/building-secure-contractsGuidelines and training material to write secure smart contracts - crytic/building-secure-contractsgithub.com https://consensys.github.io/smart-contract-best-practices/ https://forum.openzeppelin.com https://swcregistry.io https://diligence.consensys.net/blog/2020/03/new-offering-1-day-security-reviews/ Learn more about your ad choices. Visit megaphone.fm/adchoices

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(1233)

Inside the Coldcard Hack That Drained Over $100 Million in Bitcoin: Uneasy Money

Inside the Coldcard Hack That Drained Over $100 Million in Bitcoin: Uneasy Money

A hardware wallet's 5-year-old randomness bug just let hackers drain over $100 million in Bitcoin. How many more waves are coming? Plus, Ethereum's fight over cutting ETH issuance. ==================...

7 Aug 1h 6min

The Chopping Block: ColdCard's $100M RNG Hack, AI-Powered Security & Ethereum's Staking Yield Taper

The Chopping Block: ColdCard's $100M RNG Hack, AI-Powered Security & Ethereum's Staking Yield Taper

This week we dissect ColdCard's ~$100M RNG exploit that Claude Code cracked in 8 minutes, debate whether AI just killed open-source security and Bitcoin maximalism, tear apart Ethereum's EIP-8361 stak...

6 Aug 1h 3min

DEX in the City: How Claude's Red-Teaming Agents Escaped a Test Without Realizing It

DEX in the City: How Claude's Red-Teaming Agents Escaped a Test Without Realizing It

Anthropic's AI agents escaped a hacking test and still think they're inside it. Katherine, Jessi, and Vy Le on who's liable when a model breaks free, plus the $100M Coldcard hack and Kalshi's court lo...

6 Aug 49min

Is Any Cold Wallet Safe? Inside the Coldcard Hack's Wave Three

Is Any Cold Wallet Safe? Inside the Coldcard Hack's Wave Three

📢 Bits + Bips has its own channel now — full episodes here: https://www.youtube.com/@Bitsandbips A firmware bug quietly introduced into Coldcard hardware wallets in 2021 has let attackers drain a...

4 Aug 18min

Should Tokenized Stock Only Come From Issuers? Yes, Says Carlos Domingo

Should Tokenized Stock Only Come From Issuers? Yes, Says Carlos Domingo

Wall Street's transfer agents want issuers, not outside platforms, to control tokenized stock. Securitize's CEO says the alternative invites insider trading. =========================================...

4 Aug 59min

Meta Fell 10%. Microsoft Didn't Blink.

Meta Fell 10%. Microsoft Didn't Blink.

📢 Bits + Bips has its own channel now — full episodes here: https://www.youtube.com/@Bitsandbips Meta and Microsoft reported earnings on the same night, and investors sent their stocks in opposit...

31 Jul 10min

Zcash, Ethereum, Aztec, Canton and More: Which Chain Will Win the Privacy Race?

Zcash, Ethereum, Aztec, Canton and More: Which Chain Will Win the Privacy Race?

Privacy is having a moment in crypto. As competition heats up, the pitfalls of the technology around the quantum threat, regulatory risk and more make the trajectory hard to predict. A counterfeit...

31 Jul 1h 3min

Should Crypto Tokens Come With Investor Rights? - Uneasy Money

Should Crypto Tokens Come With Investor Rights? - Uneasy Money

BitMEX shut down without an angry tweet. Offchain Labs CEO Steven Goldfeder joins Kain and Taylor on why dead tokens never get that mercy. Plus, Kyle Samani's Multicoin blowup. ======================...

31 Jul 1h 11min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
forklart
popradet
stopp-verden
rss-gukild-johaug
fotballpodden-2
nokon-ma-ga
hanna-de-heldige
det-store-bildet
rss-ness
dine-penger-pengeradet
rss-penger-polser-og-politikk
aftenbla-bla
e24-podden
aftenpodden-usa
lydartikler-fra-aftenposten
frokostshowet-pa-p5
unitedno
rss-utenrikskomiteen-med-bogen-og-grasvik