DeFi Security: With So Many Hacks, Will It Ever Be Safe? - Ep.170
Unchained5 Maj 2020

DeFi Security: With So Many Hacks, Will It Ever Be Safe? - Ep.170

Dan Guido, cofounder and CEO of Trail of Bits, and Taylor Monahan, founder and CEO of MyCrypto, discuss all the recent hacks in DeFi, how it can be made more safely and who is responsible. We tackle: the Hegic security incident: whose responsibility it was to make sure the contract was secure — the auditor (Trail of Bits) or the team (Hegic) — what Trail of Bits was saying in its audit summary, and how to read between the lines of an audit summary how long an audit should be upgradeability: particularly around when more advanced technology and contracts interface with older technology/contracts centralization vs. decentralization: whether contracts can be made safely while maintaining adhering to the principle of decentralization, why Taylor would prioritize centralization and security, and how teams can create different levels of risk for users bug bounties: why asking what amount they should be is the wrong question the security threats posed by oracles and what a checklist for DeFi teams might look like Thank you to our sponsors! Crypto.com: https://crypto.com Kraken: https://www.kraken.com Stellar: https://www.stellar.org Episode links: Dan Guido: https://twitter.com/dguido Trail of Bits: https://www.trailofbits.com Taylor Monahan: https://twitter.com/tayvano_ MyCrypto: https://mycrypto.com Initial tweet by Hegic calling the security issue a typo: https://twitter.com/HegicOptions/status/1253937104666742787?s=20 Hegic tweet saying, “It’s not a security issue”: https://twitter.com/HegicOptions/status/1253954145113038849?s=20 Trail of Bits saying it will no longer work with Hegic: https://twitter.com/dguido/status/1254260725431894020?s=20 Taylor breaks down the audit summary: https://twitter.com/MyCrypto/status/1254058121342803968?s=20 Molly Wintermute’s Medium post on requesting a week audit vs. three-day review: https://medium.com/@molly.wintermute/post-mortem-hegic-unlock-function-bug-or-three-defi-development-mistakesthat-i-feel-sorry-about-5a23a7197bce Unconfirmed episode with Haseeb Qureshi on the Lendf.me attack: https://unchainedpodcast.com/haseeb-qureshi-on-the-unbelievable-story-of-the-25-million-lendf-me-hack/ Unchained interview showing Matt Luongo's approach to kill switches and upgradeability with tBTC: https://unchainedpodcast.com/tbtc-what-happens-when-the-most-liquid-crypto-asset-hits-defi/ Discussion of the bZx attacks on Unchained: https://unchainedpodcast.com/the-bzx-attacks-unethical-or-illegal-2-experts-weigh-in/ Issue with Curve contract: https://blog.curve.fi/vulnerability-disclosure/ Compound bug bounty program: https://compound.finance/docs/security#bug-bounty Taylor on “upgradeability makes things more insecure”: https://twitter.com/tayvano_/status/1222564979657723904?s=20 Synthetix oracle incident, allowing a bot to profit $1 billion: https://unchainedpodcast.com/how-synthetix-became-the-second-largest-defi-platform/ Taylor’s tips on how to get more ROI on an audit: https://twitter.com/MyCrypto/status/1254061500244713474?s=20 Tips to follow before getting an audit: https://blog.openzeppelin.com/follow-this-quality-checklist-before-an-audit-8cc6a0e44845/ Resources for security in DeFi: crytic/building-secure-contractsGuidelines and training material to write secure smart contracts - crytic/building-secure-contractsgithub.com https://consensys.github.io/smart-contract-best-practices/ https://forum.openzeppelin.com https://swcregistry.io https://diligence.consensys.net/blog/2020/03/new-offering-1-day-security-reviews/ Learn more about your ad choices. Visit megaphone.fm/adchoices

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(1148)

Pump.fun’s $370M Burn Was a Mistake, Says Luca Netz: Uneasy Money

Pump.fun’s $370M Burn Was a Mistake, Says Luca Netz: Uneasy Money

Pump.fun set fire to $370 million in tokens. Luca lays out the airdrop math that says they should have done the opposite. Thank you to our sponsors!⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ MultiChain Advisors is an emerging...

1 Maj 1h 14min

The Chopping Block: Defi United’s “Bailout,” MegaETH’s KPI Vesting, and Prediction Market Chaos

The Chopping Block: Defi United’s “Bailout,” MegaETH’s KPI Vesting, and Prediction Market Chaos

Is the era of protocol bailouts upon us? The Chopping Block crew and MegaETH's Shuyao Kong debate Defi United’s community-funded rescue, the KPI vesting experiment shaking up token launches, whether D...

30 Apr 1h

How Microsoft Won the OpenAI Fight as Markets Rally on Iran

How Microsoft Won the OpenAI Fight as Markets Rally on Iran

One side wins the OpenAI-Microsoft divorce, Ram calls a 19% earnings growth year 'bananas,' and Chris wants the US to hack back against DeFi exploiters. Here is the full rundown. --- Heads up! If y...

29 Apr 57min

How Microsoft Won in Its Revised Deal With OpenAI

How Microsoft Won in Its Revised Deal With OpenAI

Microsoft restructured its agreement with OpenAI, and Ram Ahluwalia has a clear verdict: Microsoft won.  In this segment from Bits + Bips, Ram explains the three things Microsoft secured from the new...

29 Apr 3min

How Morpho Survived a $300M DeFi Hack With Only $1M Exposure

How Morpho Survived a $300M DeFi Hack With Only $1M Exposure

People think of Aave and Morpho as competitors. But Morpho only lost $1 million when North Korea drained $300M from a DeFi protocol. The architecture explains why. ===================================...

29 Apr 37min

Bits + Bips: How the Kelp rsETH Hack Left Aave With $193M in Bad Debt

Bits + Bips: How the Kelp rsETH Hack Left Aave With $193M in Bad Debt

Luke Leasure and Shaunda Devens of Blockworks Research explain how three compounding failures, Kelp's one-of-one bridge signer, Layer Zero's permissive default settings, and Aave's failure to flag it ...

28 Apr 9min

Arbitrum Froze $70M From North Korea? Griff Green on the Decision + Miguel Morel on the Hack

Arbitrum Froze $70M From North Korea? Griff Green on the Decision + Miguel Morel on the Hack

KelpDAO’s hackers left telltale signs pointing to one culprit, North Korea. Then, in a surprise move, the Arbitrum Security Council decided to fight back. ============================================...

26 Apr 1h 7min

Did Arbitrum Violate DRPK's Property Rights? No, Because It Wasn't Their Property

Did Arbitrum Violate DRPK's Property Rights? No, Because It Wasn't Their Property

The $300M KelpDAO exploit became a watershed moment for DeFi, and the Arbitrum Security Council voted froze $70M worth of stolen funds. Is this a slippery slope or learning from history? Thank you...

24 Apr 1h 20min

Populärt inom Politik & nyheter

aftonbladet-krim
p3-krim
aftonbladet-daily
politiken
motiv
rss-krimstad
flashback-forever
svenska-fall
spar
rss-sanning-konsekvens
rss-krimreportrarna
rss-vad-fan-hande
kungligt
rss-aftonbladet-krim
rss-frandfors-horna
rss-flodet
blenda-2
olyckan-inifran
svd-ledarredaktionen
krimmagasinet