a codebase doesnt suddenly become "unaudited" because 20 lines changed but the real question is: what security assumptions did those 20 lines invalidate?
Some teams assume a code change means starting the audit over. Full repo, from scratch.
The problem is that this gets applied unconditionally, whether or not the change actually calls for it. A client recently asked us on an intro call: when we change the code, we need to re-audit the whole repo, correct? The answer was no, not necessarily. It depends on what changed and what that change actually touches.
That distinction is the entire argument for our service called “continuous security”, so it is worth being precise about it. A single-line change to an isolated helper function does not put your treasury logic back in question. A change to a shared state variable, an access control check, or anything else the rest of the system depends on might reach further than it looks, but it will rarely require a full re-audit.
A one-time audit answers that question once, on one commit hash. It cannot tell you anything about the pull request you merge six weeks later. Continuous Security answers it perpetually.
We plug into your development process and review pull requests before they merge, tracing each change out to what it actually affects instead of defaulting to the whole repo out of habit. Findings come with severity rankings, and we work through them with your team before the next cycle opens.
The result is that you stop paying for a rule of thumb and start paying for the scope the change actually requires.
More of our clients are making this same switch, for the same reason. It ends up costing much less compared to a full re-audit. We will always be truthful and tell you what your code actually needs.
@AdevarLabs the interesting part is that diff size and security impact are barely correlated
a tiny change to authorization, shared state, accounting, or a CPI boundary can have a huge blast radius
a much larger isolated change might have almost none
that's why scope should follow impact
interesting rustls bug from this week:
EncryptedExtensions could be accepted in plaintext when packed in the same record as ServerHello
the transcript is still authenticated, so its not a handshake bypass. its basically the TLS state machine accepting a message across an encryption-level boundary it shouldn't cross
nice example of memory-safe code still having protocol-level bugs
the project gets more hidden and "niche" findings. the auditor time is not spent on reporting the same bugs over and over again and can really focus on the particular bussiness logic and not-obvious corner cases
another reason why that's a good practice for both parties this time is that the audit quality is way better if the code does not have obvious bugs. so the auditor focuses on the most important and more creative findings
@banescusebi a nice and simple threat modeling session can come in handy for a lot of the projects which chose to go for option 1. So if you're a founder not looking for an audit for whichever reason, but still care about security, work as hard as you can with AI but you MUST do this session
ISO 27001 and SOC 2 miss stuff that may get protocols rekt: multisig ops, treasury flows, onchain incident response
Been saying that since 2023 https://t.co/CRoJmsIyQM
@_SEAL_Org certifications are built for those gaps
Glad to be one of the firms helping close them 🫡
this one was in a fix review. those are so important as the instinct is to allocate all effort and attention to the before fix, however regressions are more and more frequent especially now when a lot of the code being ai written in all fields
Any user could impersonate another account and trade both sides of a position they never opened, zero signatures required from the victim.
In a recent audit, we found a bug where two round trips moved a test account's balance from $1M to $800K. Full breakdown 👇
We are sorry for the issues you may have experienced with Grok following an outage at our Memphis compute center this morning. We’d also like to apologize to our impacted compute partners.
All systems have now been restored and are functioning nominally.
You don’t need a bridge anymore.
Introducing Universal Deposit.
Send a token from any supported chain and receive USDC in your Solana wallet.
Universal Deposit handles the routing, bridging, and swapping automatically:
- Send funds from the wallet you already use
- Deposit from Ethereum, Base, Arbitrum and Sui
- No bridge apps, network switching and extra transactions
- Flat $0.30 fee, whether you send $100 or $10M
The most seamless cross-chain transfer experience is here.
All roads lead to Solana
Audit Completed for @atomicvaults
Atomic Vault System is a non-custodial vault for automated DeFi strategies on Solana and we have recently completed a smart contract audit for such.
Grateful to work with the team and help them Ship Safely. 🚀 Public report & testimonial below🧵:
We're selling ad space on the Solana logo.
9 spots, with 100% of proceeds donated to Nepal flood relief. Win and your logo or artwork sits on our PFP and pinned post for a week.
24 hours to bid and donate: https://t.co/Y76WemJtVX
Powered by @mallowdotart