DeFi Security: With So Many Hacks, Will It Ever Be Safe? - Ep.170
Unchained5 Mai 2020

DeFi Security: With So Many Hacks, Will It Ever Be Safe? - Ep.170

Dan Guido, cofounder and CEO of Trail of Bits, and Taylor Monahan, founder and CEO of MyCrypto, discuss all the recent hacks in DeFi, how it can be made more safely and who is responsible. We tackle: the Hegic security incident: whose responsibility it was to make sure the contract was secure — the auditor (Trail of Bits) or the team (Hegic) — what Trail of Bits was saying in its audit summary, and how to read between the lines of an audit summary how long an audit should be upgradeability: particularly around when more advanced technology and contracts interface with older technology/contracts centralization vs. decentralization: whether contracts can be made safely while maintaining adhering to the principle of decentralization, why Taylor would prioritize centralization and security, and how teams can create different levels of risk for users bug bounties: why asking what amount they should be is the wrong question the security threats posed by oracles and what a checklist for DeFi teams might look like Thank you to our sponsors! Crypto.com: https://crypto.com Kraken: https://www.kraken.com Stellar: https://www.stellar.org Episode links: Dan Guido: https://twitter.com/dguido Trail of Bits: https://www.trailofbits.com Taylor Monahan: https://twitter.com/tayvano_ MyCrypto: https://mycrypto.com Initial tweet by Hegic calling the security issue a typo: https://twitter.com/HegicOptions/status/1253937104666742787?s=20 Hegic tweet saying, “It’s not a security issue”: https://twitter.com/HegicOptions/status/1253954145113038849?s=20 Trail of Bits saying it will no longer work with Hegic: https://twitter.com/dguido/status/1254260725431894020?s=20 Taylor breaks down the audit summary: https://twitter.com/MyCrypto/status/1254058121342803968?s=20 Molly Wintermute’s Medium post on requesting a week audit vs. three-day review: https://medium.com/@molly.wintermute/post-mortem-hegic-unlock-function-bug-or-three-defi-development-mistakesthat-i-feel-sorry-about-5a23a7197bce Unconfirmed episode with Haseeb Qureshi on the Lendf.me attack: https://unchainedpodcast.com/haseeb-qureshi-on-the-unbelievable-story-of-the-25-million-lendf-me-hack/ Unchained interview showing Matt Luongo's approach to kill switches and upgradeability with tBTC: https://unchainedpodcast.com/tbtc-what-happens-when-the-most-liquid-crypto-asset-hits-defi/ Discussion of the bZx attacks on Unchained: https://unchainedpodcast.com/the-bzx-attacks-unethical-or-illegal-2-experts-weigh-in/ Issue with Curve contract: https://blog.curve.fi/vulnerability-disclosure/ Compound bug bounty program: https://compound.finance/docs/security#bug-bounty Taylor on “upgradeability makes things more insecure”: https://twitter.com/tayvano_/status/1222564979657723904?s=20 Synthetix oracle incident, allowing a bot to profit $1 billion: https://unchainedpodcast.com/how-synthetix-became-the-second-largest-defi-platform/ Taylor’s tips on how to get more ROI on an audit: https://twitter.com/MyCrypto/status/1254061500244713474?s=20 Tips to follow before getting an audit: https://blog.openzeppelin.com/follow-this-quality-checklist-before-an-audit-8cc6a0e44845/ Resources for security in DeFi: crytic/building-secure-contractsGuidelines and training material to write secure smart contracts - crytic/building-secure-contractsgithub.com https://consensys.github.io/smart-contract-best-practices/ https://forum.openzeppelin.com https://swcregistry.io https://diligence.consensys.net/blog/2020/03/new-offering-1-day-security-reviews/ Learn more about your ad choices. Visit megaphone.fm/adchoices

Episoder(1094)

Gold to $12,000 or “Sell Gold Today”? – Bits + Bips

Gold to $12,000 or “Sell Gold Today”? – Bits + Bips

Crypto taxes stressing you out? You don’t have to figure it out alone. We’ve partnered with Crypto Tax Girl, a crypto-focused tax firm that’s been helping investors since 2017, to give readers $100 o...

28 Jan 1h 6min

Bits + Bips: Why Gold Still Dominates — And What Bitcoin Must Prove

Bits + Bips: Why Gold Still Dominates — And What Bitcoin Must Prove

Gold is hitting new highs. Bitcoin is struggling to keep up. And once again, the “digital gold” narrative is being put to the test.On today’s episode of Bits + Bips: The Interview, host Steve Ehrlich ...

24 Jan 48min

Uneasy Money: Why Crypto Still Can't Overcome Its ICO Struggles

Uneasy Money: Why Crypto Still Can't Overcome Its ICO Struggles

Thank you to our sponsors! Fuse: The Energy Network MultiChain Advisors Trove Markets crashed at launch after a hyped ICO. X has pulled the plug on the InfoFi meta. Farcaster has been absorbed. In...

23 Jan 1h 17min

The Chopping Block: Crypto Clarity Act Drama + Stablecoin Yield Wars + Developer Liability Fights

The Chopping Block: Crypto Clarity Act Drama + Stablecoin Yield Wars + Developer Liability Fights

This week the boys break down the Crypto Clarity Act's dramatic Senate markup with Coin Center's Peter Van Valkenburgh, covering developer liability concerns, tokenized securities language controversy...

22 Jan 55min

DEX in the City: When NYSE Goes Onchain, What Happens to Financial Intermediaries?

DEX in the City: When NYSE Goes Onchain, What Happens to Financial Intermediaries?

Thanks to Mantle for supporting the pod—and launching the Global Hackathon 2025 with $150k in prizes, VC mentorship, and access to 7M+ Bybit users. Your next big idea could go live here The New York...

22 Jan 53min

How Nansen’s New Trading Agent Makes It Easier to Follow the Smart Money Onchain

How Nansen’s New Trading Agent Makes It Easier to Follow the Smart Money Onchain

Thank you to our sponsor, Walrus! Crypto intelligence platform Nansen has rolled out an AI trading agent, aiming to let users complete the full trading lifecycle—from discovery to execution—within a ...

21 Jan 1h 4min

Why Bitcoin Isn't Acting as Digital Gold & International Stocks Are Winning - Bits + Bips

Why Bitcoin Isn't Acting as Digital Gold & International Stocks Are Winning - Bits + Bips

This episode is brought to you by Uniswap! Are you a builder who needs to add on-chain trading to your product? The Uniswap Trading API from Uniswap Labs offers plug-and-play access to some of the d...

21 Jan 1h 8min

Bits + Bips: Why Grayscale Sees ATHs Before Q3, With ETH Outperforming

Bits + Bips: Why Grayscale Sees ATHs Before Q3, With ETH Outperforming

Thank you to our sponsor, Walrus! Walrus is where the world’s data becomes reliable, valuable, and governable. Geopolitical tensions are rising. Crypto legislation is stalled. And pressure on the Fe...

19 Jan 47min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
aftenpodden-usa
stopp-verden
forklart
i-retten
popradet
lydartikler-fra-aftenposten
fotballpodden-2
rss-gukild-johaug
det-store-bildet
dine-penger-pengeradet
rss-ness
nokon-ma-ga
hanna-de-heldige
aftenbla-bla
frokostshowet-pa-p5
rss-dannet-uten-piano
grasoner-den-nye-kalde-krigen
e24-podden