Security

191 bookmarks
Custom sorting
pashov on X
pashov on X
Proxy Checklist
·twitter.com·
pashov on X
Typical vulnerabilities in AMM protocols
Typical vulnerabilities in AMM protocols
This article discusses the fundamental security aspects of the AMM (automatic market maker) protocols.
·blog.decurity.io·
Typical vulnerabilities in AMM protocols
Oracles, Entropy & Chainlink VRF Secure Integration Tips
Oracles, Entropy & Chainlink VRF Secure Integration Tips
In this article, we present tips that we have acquired over the years of auditing similar integrations. We also intend to discuss the…
VRF
·blog.pessimistic.io·
Oracles, Entropy & Chainlink VRF Secure Integration Tips
Tal – Medium
Tal – Medium
Read writing from Tal on Medium. researcher @ smlXL. Every day, Tal and thousands of other voices read, write, and share important stories on Medium.
·medium.com·
Tal – Medium
How To Effectively Learn Smart-Contract Auditing
How To Effectively Learn Smart-Contract Auditing
https://twitter.com/DevDacianHow to cultivate a growth mindset, overcome fears, and adopt winning strategies for successful audits. Explore a range of audit ...
·youtube.com·
How To Effectively Learn Smart-Contract Auditing
Vyper Nonreentrancy Lock Vulnerability Technical Post-Mortem Report - HackMD
Vyper Nonreentrancy Lock Vulnerability Technical Post-Mortem Report - HackMD
On the 30th of July, 2023, multiple Curve.Fi liquidity pools were exploited as a result of a latent vulnerability in the Vyper compiler, specifically in versions 0.2.15, 0.2.16, and 0.3.0. While bug was identified and patched by the v0.3.1 release, the impact to protocols using the vulnerable compilers was not realized at the time and they were not explicitly notified. The vulnerability itself was an improperly implemented re-entrancy guard that could be bypassed under certain conditions which we will delve into in this report.
·hackmd.io·
Vyper Nonreentrancy Lock Vulnerability Technical Post-Mortem Report - HackMD
Dedaub on Twitter
Dedaub on Twitter
“Watchdog analyses operate on the actual bytecode of contracts (via decompilation as seen here) As a result, compiler bugs can also be caught by these analyses Yesterday's @CurveFinance hack could have been prevented had a cross-reentrancy analysis on this codebase been run”
·twitter.com·
Dedaub on Twitter
🎤 Demystifying EVM Opcodes
🎤 Demystifying EVM Opcodes
Join Gilbert G of Macro for a talk titled, "Demystifying EVM Opcodes." This workshop is part of ETHNewYork 2022, a three-day in person hackathon that will fe...
·youtube.com·
🎤 Demystifying EVM Opcodes
Solidity Internals
Solidity Internals
A bunch of notes for beginners learning solidity
·0xpranay.github.io·
Solidity Internals
How To Consume Chainlink Price Feeds Safely
How To Consume Chainlink Price Feeds Safely
Chainlink price feeds are reliable, but it is crucial to have circuit breakers to prevent any issues from a single source. Using a single entity is not ideal from a decentralization perspective as well, and it is better to have backup plans in case of system failure. Many developers were
·0xmacro.com·
How To Consume Chainlink Price Feeds Safely
The math behind Defi is not as hard as you think
The math behind Defi is not as hard as you think
I was never a good student at math. Math made me uncomfortable. But investing in Defi gets me to re-study it. And this time, I found its…
·cryptocutie.medium.com·
The math behind Defi is not as hard as you think
Numerical Analysis
Numerical Analysis
This article is an overview of Kurt Barry's seminar at Spearbit on performing numerical analysis on DeFi projects to identify vulnerabilities. Spearbit is a decentralized and industry-leading blockchain security services firm pairing protocols with top security researchers with deep subject matter e
·paragraph.xyz·
Numerical Analysis
MEV-PACK
MEV-PACK
MEV / Sandwich / Front-run & Back-run:
·graph.org·
MEV-PACK
0xcacti/awesome-oracle-manipulation: Awesome list of all things oracle manipulation. Creating to help spread a better understanding of oracles and oracle manipulation.
0xcacti/awesome-oracle-manipulation: Awesome list of all things oracle manipulation. Creating to help spread a better understanding of oracles and oracle manipulation.
Awesome list of all things oracle manipulation. Creating to help spread a better understanding of oracles and oracle manipulation. - 0xcacti/awesome-oracle-manipulation: Awesome list of all things ...
·github.com·
0xcacti/awesome-oracle-manipulation: Awesome list of all things oracle manipulation. Creating to help spread a better understanding of oracles and oracle manipulation.
Ethereum Smart Contract Auditor's 2022 Rewind • Ventral Digital
Ethereum Smart Contract Auditor's 2022 Rewind • Ventral Digital
This article is the result of reviewing the technical details from many of this year's Smart Contract Vulnerabilities and Exploits in and around the Ethereum ecosystem.
·ventral.digital·
Ethereum Smart Contract Auditor's 2022 Rewind • Ventral Digital
Kristian Apostolov on Twitter
Kristian Apostolov on Twitter
“Here is how you can get an easy H/M on @code4rena or @sherlockdefi. A 🧵 about the CREATE2 optcode👇”
·twitter.com·
Kristian Apostolov on Twitter
bloqarl on Twitter
bloqarl on Twitter
“1/9:🔒✨Attention auditors! Don't overlook this crucial step in upgradable contracts. Discover why reviewing constructors and initialize functions is crucial You can use your Solidity contracts with OpenZeppelin Upgrades without modifications... Wait, without any modification?”
·twitter.com·
bloqarl on Twitter