Replies: 15 comments 2 replies
-
Note to self I just remembered I'm connected with the guy who made the world's first hack for pacemakers - career white hat. I think he can do a white box test easily. |
Beta Was this translation helpful? Give feedback.
-
Hardhat security Slither Analyzer to avoid security issues and vulnerabilities Solhint to follow the best programming rules |
Beta Was this translation helpful? Give feedback.
-
https://twitter.com/drdr_zz/status/1564920740721426433?s=21&t=ohJwYahWyq9Mbv6zXkNO6w |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
I was looking at the CI of other projects and realized that we can probably just use the same configs. |
Beta Was this translation helpful? Give feedback.
-
I accidentally disabled lavamoat on the core dollar contracts at some point while converting this into a monorepo. We should definitely re-add to the whole project.
|
Beta Was this translation helpful? Give feedback.
-
Since DNS hijacking is on the rise (we've seen it recently with the curve.fi UI being compromised) an idea would be to have a badge on the UI that does an ajax request to get the commit hash of the current instance ( This would require a compromise of all UI deployments simultaneously to thwart this detection. If there's any difference then we can get the user's attention and explain that something is fishy and to be aware of any new approvals! |
Beta Was this translation helpful? Give feedback.
-
Automated threat detection and killswitch transaction can be signed and deployed by the platform frontrunning suspicious transactions in the mempool. Not entirely sure how they guarantee a frontrun but worth exploring. I already reached out to sales to learn more. |
Beta Was this translation helpful? Give feedback.
-
Certora - formal verification tool |
Beta Was this translation helpful? Give feedback.
-
|
Beta Was this translation helpful? Give feedback.
-
More for economic security but we should consider a Gauntlet subscription to run real time simulations on our inflows (collateral) and outflows (uAD) in order to simulate and prevent bank runs. I'm not entirely sure if their platform supports our type of setup (we don't have the concept of liquidations) but its worth speaking with their team on this. |
Beta Was this translation helpful? Give feedback.
-
I converted one of the lists in one of the images I posted earlier and I think we should consider all of these options to add to our CI potentially? I didn't actually realize how many tools are out there. I think we should try and stick with the top/most popular ones.
NoticeWe should first research the tool to see what its about, then check if its relevant to our project. The possibilities per row could be
|
Beta Was this translation helpful? Give feedback.
-
https://twitter.com/1nf0s3cpt/status/1583011233363824640?s=46&t=Pl2ZJVPiATpTDi6ulNNMXw 📑 Root cause analysis from past DeFi incidents. Hope this stuff can help devs to avoid the same mistakes as much as possible. Now covered 95 incidents. #DeFi #Web3 |
Beta Was this translation helpful? Give feedback.
-
https://twitter.com/storming0x/status/1509769575021178886?t=aP4CHqGHvi6cn0gbOeqfRw |
Beta Was this translation helpful? Give feedback.
-
ongoing security hygiene suggestions
hiring
spec design
code reviews
testing
fuzzing
<- we are here #120formal verification
key management
external reviews
security assessment
bug bounty program
incident handling
List of known attack vectors
Beta Was this translation helpful? Give feedback.
All reactions