DeFi Security: With So Many Hacks, Will It Ever Be Safe? - Ep.170
Unchained5 Maj 2020

DeFi Security: With So Many Hacks, Will It Ever Be Safe? - Ep.170

Dan Guido, cofounder and CEO of Trail of Bits, and Taylor Monahan, founder and CEO of MyCrypto, discuss all the recent hacks in DeFi, how it can be made more safely and who is responsible. We tackle: the Hegic security incident: whose responsibility it was to make sure the contract was secure — the auditor (Trail of Bits) or the team (Hegic) — what Trail of Bits was saying in its audit summary, and how to read between the lines of an audit summary how long an audit should be upgradeability: particularly around when more advanced technology and contracts interface with older technology/contracts centralization vs. decentralization: whether contracts can be made safely while maintaining adhering to the principle of decentralization, why Taylor would prioritize centralization and security, and how teams can create different levels of risk for users bug bounties: why asking what amount they should be is the wrong question the security threats posed by oracles and what a checklist for DeFi teams might look like Thank you to our sponsors! Crypto.com: https://crypto.com Kraken: https://www.kraken.com Stellar: https://www.stellar.org Episode links: Dan Guido: https://twitter.com/dguido Trail of Bits: https://www.trailofbits.com Taylor Monahan: https://twitter.com/tayvano_ MyCrypto: https://mycrypto.com Initial tweet by Hegic calling the security issue a typo: https://twitter.com/HegicOptions/status/1253937104666742787?s=20 Hegic tweet saying, “It’s not a security issue”: https://twitter.com/HegicOptions/status/1253954145113038849?s=20 Trail of Bits saying it will no longer work with Hegic: https://twitter.com/dguido/status/1254260725431894020?s=20 Taylor breaks down the audit summary: https://twitter.com/MyCrypto/status/1254058121342803968?s=20 Molly Wintermute’s Medium post on requesting a week audit vs. three-day review: https://medium.com/@molly.wintermute/post-mortem-hegic-unlock-function-bug-or-three-defi-development-mistakesthat-i-feel-sorry-about-5a23a7197bce Unconfirmed episode with Haseeb Qureshi on the Lendf.me attack: https://unchainedpodcast.com/haseeb-qureshi-on-the-unbelievable-story-of-the-25-million-lendf-me-hack/ Unchained interview showing Matt Luongo's approach to kill switches and upgradeability with tBTC: https://unchainedpodcast.com/tbtc-what-happens-when-the-most-liquid-crypto-asset-hits-defi/ Discussion of the bZx attacks on Unchained: https://unchainedpodcast.com/the-bzx-attacks-unethical-or-illegal-2-experts-weigh-in/ Issue with Curve contract: https://blog.curve.fi/vulnerability-disclosure/ Compound bug bounty program: https://compound.finance/docs/security#bug-bounty Taylor on “upgradeability makes things more insecure”: https://twitter.com/tayvano_/status/1222564979657723904?s=20 Synthetix oracle incident, allowing a bot to profit $1 billion: https://unchainedpodcast.com/how-synthetix-became-the-second-largest-defi-platform/ Taylor’s tips on how to get more ROI on an audit: https://twitter.com/MyCrypto/status/1254061500244713474?s=20 Tips to follow before getting an audit: https://blog.openzeppelin.com/follow-this-quality-checklist-before-an-audit-8cc6a0e44845/ Resources for security in DeFi: crytic/building-secure-contractsGuidelines and training material to write secure smart contracts - crytic/building-secure-contractsgithub.com https://consensys.github.io/smart-contract-best-practices/ https://forum.openzeppelin.com https://swcregistry.io https://diligence.consensys.net/blog/2020/03/new-offering-1-day-security-reviews/ Learn more about your ad choices. Visit megaphone.fm/adchoices

Avsnitt(1101)

Bits + Bips: Why Gold Still Dominates — And What Bitcoin Must Prove

Bits + Bips: Why Gold Still Dominates — And What Bitcoin Must Prove

Gold is hitting new highs. Bitcoin is struggling to keep up. And once again, the “digital gold” narrative is being put to the test.On today’s episode of Bits + Bips: The Interview, host Steve Ehrlich ...

24 Jan 48min

Uneasy Money: Why Crypto Still Can't Overcome Its ICO Struggles

Uneasy Money: Why Crypto Still Can't Overcome Its ICO Struggles

Thank you to our sponsors! Fuse: The Energy Network MultiChain Advisors Trove Markets crashed at launch after a hyped ICO. X has pulled the plug on the InfoFi meta. Farcaster has been absorbed. In...

23 Jan 1h 17min

The Chopping Block: Crypto Clarity Act Drama + Stablecoin Yield Wars + Developer Liability Fights

The Chopping Block: Crypto Clarity Act Drama + Stablecoin Yield Wars + Developer Liability Fights

This week the boys break down the Crypto Clarity Act's dramatic Senate markup with Coin Center's Peter Van Valkenburgh, covering developer liability concerns, tokenized securities language controversy...

22 Jan 55min

DEX in the City: When NYSE Goes Onchain, What Happens to Financial Intermediaries?

DEX in the City: When NYSE Goes Onchain, What Happens to Financial Intermediaries?

Thanks to Mantle for supporting the pod—and launching the Global Hackathon 2025 with $150k in prizes, VC mentorship, and access to 7M+ Bybit users. Your next big idea could go live here The New York...

22 Jan 53min

How Nansen’s New Trading Agent Makes It Easier to Follow the Smart Money Onchain

How Nansen’s New Trading Agent Makes It Easier to Follow the Smart Money Onchain

Thank you to our sponsor, Walrus! Crypto intelligence platform Nansen has rolled out an AI trading agent, aiming to let users complete the full trading lifecycle—from discovery to execution—within a ...

21 Jan 1h 4min

Why Bitcoin Isn't Acting as Digital Gold & International Stocks Are Winning - Bits + Bips

Why Bitcoin Isn't Acting as Digital Gold & International Stocks Are Winning - Bits + Bips

This episode is brought to you by Uniswap! Are you a builder who needs to add on-chain trading to your product? The Uniswap Trading API from Uniswap Labs offers plug-and-play access to some of the d...

21 Jan 1h 8min

Bits + Bips: Why Grayscale Sees ATHs Before Q3, With ETH Outperforming

Bits + Bips: Why Grayscale Sees ATHs Before Q3, With ETH Outperforming

Thank you to our sponsor, Walrus! Walrus is where the world’s data becomes reliable, valuable, and governable. Geopolitical tensions are rising. Crypto legislation is stalled. And pressure on the Fe...

19 Jan 47min

Q-Day Is Imminent. Can Bitcoin Survive the Quantum Threat?

Q-Day Is Imminent. Can Bitcoin Survive the Quantum Threat?

Thank you to our sponsors! Walrus Post-quantum era focused blockchain builder Project Eleven has just raised $20 million from the industry's heavy hitters as concerns over Bitcoin's quantum readines...

18 Jan 40min

Populärt inom Politik & nyheter

aftonbladet-krim
svenska-fall
p3-krim
rss-krimstad
spar
fordomspodden
flashback-forever
rss-sanning-konsekvens
aftonbladet-daily
rss-vad-fan-hande
motiv
rss-expressen-dok
rss-frandfors-horna
dagens-eko
rss-krimreportrarna
politiken
blenda-2
rss-aftonbladet-krim
rss-flodet
olyckan-inifran