After intensive research on web3security compiled a playlist of publicly available videos for learning Smart Contract Auditing & Development and more.
https://t.co/DFRwndK16D
Thrilled to be awarded an Ecosystem Support Program @EF_ESP grant for https://t.co/YfWoBgN7hP
We're developing a public good security platform that offers a centralized hub for real-time security tools, actionable checklists for personal privacy and protection, threat intelligence, and supply chain monitoring.
Here's why this matters... 🧵
North Korean hackers AGAIN⚠️
✍️In this article, the SlowMist Security Team analyzes the #Bybit hacker's attack techniques and fund movements @MistTrack_io , while also raising some questions. (We also look forward to the official disclosure of more investigation results.)
Dive in here⬇️
https://t.co/OimyTImgMV
Recently, I received an invitation for interview on @Upwork regarding a job post:
https://t.co/JTms4NocPf
As mentioned in the job post, it's an ongoing project. So, as usual, the client sent me the repo of the project:
https://t.co/EnyrU1gmME
And, sent me a screen-recording (https://t.co/hiMWkR54BH) pointing-out to the bug/issue in the existing project, and asked me whether I'm also facing the same after running the project locally.
As, you can see, the repo doesn't look suspicious at all (especially in the eyes of regular devs). So, I cloned the repo and started executing it locally. Once, it started running on localhost, it was opening like a normal Next.js app on browser. Trust me, everything was completely unsuspicious.
However, here comes the twist, all of a sudden, it started asking for permissions of accessing browser cache, notes, reminders and what not. And to be very honest, i denied all of them as it started looking a lot suspicious all of a sudden. And I closed and deleted the project completely. Suddenly checked my bank accounts and all using my phone via dedicated banking apps (as I never access any of my bank account via browser or laptop).
But then, when I checked my Metamask, all of my funds on all the mainnet accounts were gone. Luckily, I was/am not holding any crypto for investment purposes or so, whatever was there of around $60 was for various testing purposes, mainly in Polygon MATIC. These were the transactions that happened:
https://t.co/jir1SizoDo
https://t.co/XEgm2hQ9Dg
Funny enough, in the second transaction, you guys can see the scammer has spent around $4 in transaction fees to transfer $1 worth of Ethereum. Clearly, not an expert scammer for sure!
So, the entire motive to quote this incident is to alert all of my fellow #developers and advice them to be safe in terms of never executing any project/code provided by any stranger no matter how safe it looks.
I would also like to encourage the #web3security experts like @RealJohnnyTime, @pashov, @PatrickAlphaC, @bytes032, @0xOwenThurm, etc. to even push harder in spreading more & more awareness regarding the best practices and measures to take, and how to safeguard ourselves against such out-of-bounds & out-of-leagues #scams.
It's finally here! 2 Hours of pure Web3 Security content that will help you level up your skills! ⭐️
Join me & @ProgrammerSmart as we dive into the Ethereum Credit Guild Contest on code4rena!
🔍 Teamwork, Protocols, Bugs, and more!
Watch the full recorded live stream: https://t.co/wNljlKIRLH
🔍 What's Covered:
- How we worked as a team
- Productive sessions, brainstorming, and idea sharing
- Ethereum Credit Guild Protocol Overview
- Bugs that we found and bugs that the Smart Contract Hacking course students found
And much more!
⏱️Timestamps
00:00:00 Intro
00:04:40 How Taz and I Worked Together
00:11:27 How We "Cheated"
00:12:23 A Tip for New Contests
00:14:15 Our Meetings and Diagrams
00:17:00 Auditing Contests Tip
00:18:27 Smart Contract Programmer Contests Tips
00:18:52 Promodoro for Auditing
00:20:20 Ethereum Credit Guild Overview
00:23:50 Lending Terms Explained
00:30:30 Credit Token and Guild Token
00:32:40 Governance: Lending Term On-boarding
36:00 Governance: Veto
00:37:50 Governance: Lending Term Off-boarding
00:42:19 Ethereum Credit Guild Tokenomics
00:47:43 Liquidations and AuctionHouse
00:54:44 Staking, Rewards, and Slashing
01:04:05 Finding 1: Transfer to Self to Claim Extra Credit
01:09:25 Finding 2-3: NotifyPnl Frontrunning
01:10:19 Attacker Mindset Brainstorming
01:11:40 Finding 2-3: NotifyPnl Frontrunning (Continue)
01:15:40 Tips to Write a Good PoC
01:23:16 Finding 4: Incorrect Profit Index Init
01:25:30 How to Get Better in Auditing Contests
01:27:08 Finding 4: Incorrect Profit Index Init (Continue)
01:31:23 Finding 5: Credit Multiplier Cross-Contract Issue
01:39:41 Students Findings
01:53:16 Summary
Awesome On-Chain Investigations HandBook 💎
Disclaimer: All information (tools, links, articles, text, images, etc.) is provided for educational purposes only! All information is also based on data from public sources. You are solely responsible for your actions, not the author! Follow InfoSec and OpSec guidelines and perform all of your research on a separate, secure device!
Check out more tools here ⬇️
�� https://t.co/Qza38k3nqL
Here we discuss how one can investigate crypto hacks and security incidents, and collect all the possible tools and manuals! PRs are welcome!
De-mixing @TornadoCash (by @flipsidecrypto and @AMLBotHQ & @PureFi_Protocol ) ⬇️
• https://t.co/3OZomRIpCb
Also (including @RAILGUN_Project de-mixers), check out awesome tools by @0xKoda ⬇️
• https://t.co/CBsLMFEEQ4
• https://t.co/l1DbVYFY2D
• https://t.co/Jv6LVEHib7
• https://t.co/VFWRECWjZ3
• https://t.co/3pcE4tubmV
• https://t.co/EIeXVPpjgO
How I investigate crypto hacks and security incidents: A-Z ⬇️
• https://t.co/dNutNgQzyg
• https://t.co/YY4KVep2bo
• https://t.co/X7vlnY9cHF
Cracking crypto criminals: how to build a career in crypto Forensics in 2023 and find your dream web3 job by @CryptoJobsList & @shivamchhuneja ⬇️
• https://t.co/4PeLBt9Mzs
We need also to check out this address via https://t.co/tiZqT6QcGq + reverse check ⬇️
• https://t.co/ysdf6GyGKi
• https://t.co/n3WUb1NRxG
• https://t.co/KQAsn1g6W1
Important tools: @MetaSleuth / @Phalcon_xyz / @SlowMist_Team / @AMLBotHQ / @MaltegoHQ / @AppBreadcrumbs / @ethtective / @oxt_btc / @ArkhamIntel
My own articles on topic ⬇️
• Attacks via a Representative Sample : Myths and Reality: https://t.co/uBNmCgEK6C
• 100 BTC deadman drops: Silk Road: https://t.co/H5zUGwxGs0
• Ethereum Alarm Clock Exploit: Final Thoughts: https://t.co/7mloI3vXks
• Navigation page: https://t.co/bzhXKyAkqH
Also check out my 3 articles about OSINT - visit my mirror blog: https://t.co/Xkp4wIeqT5 and scroll down!
Stay safe!
SMART CONTRACT SECURITY AND AUDITING FULL COURSE IS NOW OPEN TO EVERYONE ON CYFRIN UPDRAFT
🎊🎊🎊🎊🎊🎊🎊🎊🎊🎊🎊🎊🎊🎊
In just 22 hours, the top web3 experts walk you through 5 increasingly difficult audits to drill security power into you.
Here's what you need to know👇
At this point I've worked with dozens of Smart Contract Auditors and seen exactly who performs and why...
Here are the 7 skills I observed that set the difference between auditors who earn $43 in contests and those who earn $23,058.
THREAD
New hack analysis video just landed. In this episode I go deep into Kyber hack - definitely one of the most complicated hacks I've seen.
https://t.co/ksRbus9T7w
This time I added some additional context around the hack. I hope you like it 🙏
1/ Finished a preliminary deep dive into the Kyber exploit, and think I now have a pretty good understanding of what happened.
This is easily the most complex and carefully engineered smart contract exploit I've ever seen...
Sherlock is extremely disappointed to see the @KyberNetwork exploit and is engaged fully in assisting Kyber.
The hack is one of the most complex exploits ever seen in DeFi but this does not absolve Sherlock from responsibility.[1]
For background, the Kyber team stands out as a team that has done an exceptional job when it comes to security this year, including:
- Paying $1M to whitehat @1_00_proof for finding a very complex bug (which is related to the current exploit)[2]
- A @1_00_proof fix review for the $1M bug
- A @chain_security audit in May[3]
- A Sherlock audit in August/September[4]
- A $200k bug bounty program EVEN AFTER paying $1M for the bug bounty earlier this year[5]
Kyber's audit results at Sherlock were also extremely impressive.
There were only 2 Medium findings across the 16-day audit. The audit had one of the lowest issue counts of any audit Sherlock has completed this year.
@IAm0x52 led the KyberSwap audit. @IAm0x52 is widely regarded as one of the top security experts in crypto[6] and Sherlock continues to stand by their expertise.
207 other auditors signed up and spent some amount of time on the KyberSwap audit contest.
If ANY ONE of these auditors had found this exploit in the 16-day Sherlock audit contest, they would have made $37,681. No questions asked, paid immediately to their wallet address.
But nobody found it.
Unfortunately, Kyber did not sign up for exploit coverage from Sherlock, so Kyber won't be eligible for a payout from Sherlock's coverage protocol.
But to be clear, Sherlock's maximum payout would have been in the low single-digit millions. This would not have made much of a dent in the $54.7M lost in the exploit[7].
Sherlock stands by the level of security in the KyberSwap codebase as a whole. Sherlock also stands by the expertise of @IAm0x52 and the quality of the audit Sherlock provided. And Sherlock is open to providing coverage to Kyber in the future once the fix for this exploit is fully reviewed.
The scariest part of this exploit is that it isn't clear what could have been done better to prevent it outside of throwing significantly more money at the problem. There's no "smoking gun" or obvious negligence that led to it[8].
Based on the complexity, it almost certainly required weeks' worth of research to find, and likely longer to plan the attack.
It seems that Sherlock's approach ($37,681 reward and 16 days) was not enough to incentivize research this deep. Nor was the traditional audit approach by Chainsecurity. Nor was the prospect of a $200,000 bug bounty payout.
What's clear is that whitehats are not being incentivized enough compared to blackhats when it comes to finding these bugs.
Changing this equation will require improvements from protocol teams, traditional auditors, audit contest providers, bug bounty providers, security bootcamps, and whitehats themselves.
The success of crypto as an industry is at stake, so these improvements must be made. Sherlock will strive to do its part.
In the meantime, Sherlock continues to stand by the Kyber team and deeply regrets that this event has occurred.
References:
[1]: https://t.co/qyhLrKofvP
[2]: https://t.co/lHd5DNSILg
[3]: https://t.co/icuJylzxrD
[4]: https://t.co/fkxz2NUuU7
[5]: https://t.co/fzHDjtDanM
[6]: https://t.co/aUOc8rvgFC
[7]: https://t.co/cQW7PsQjPi
[8]: https://t.co/qyhLrKofvP
Let's talk about DAO & Governance Attacks...
(Over $200,000,000 stolen)
There are 4️⃣ common ways in which DAOs get hacked.
If you master these, you'll know exactly what to look for when auditing DAO & Governance systems.👇
Everything you need to become a skilled Web3 Security Researcher.
→ 12 MORE hours of the free @intogateway Web3 Security Course ←
Totaling 23+ hours of EVERYTHING Web3 Security + curated projects & assignments to solidify the knowledge.
Here's everything in Part 2️⃣ 🧵
📢📢📢 Exciting news! I’ve embarked on a mission to create a comprehensive collection of web3 security vulnerabilities in smart contracts, blockchains, and zero knowledge.
We’ve already documented around 300 vulnerabilities! Now, with the sponsorship of @hexens, we’re making the “Vulnerability Wikipedia” a reality. It’s all about community power. We want it to be community-driven. This project is set to become the go-to resource for web3 security, containing articles on every known vulnerability in the space!
But, we can’t do it alone, so I’m calling on security alphas and popular educators in the space like @officer_secret@PatrickAlphaC@RealJohnnyTime@0xOwenThurm@cmichelio@bytes032 @tom_eth_dev @0xKaden@chrisdior777@ddimitrovv22 .... to join us in this community-driven initiative.
Let’s build a Wikipedia of web3 security vulnerabilities, making it easy to learn and a valuable resource for all.
Please share, tag, and be active! If you know someone who would love to contribute, tag them! If you have questions, don’t hesitate to DM me. And if you’re tight on time, no worries – we’ve got it covered, and we’ll always credit the original authors in our resources.
Let’s work together for a safer web3! 🚀🫡
Example article: 👇
Session 1/8 of the 'Intro to Web3 Security' course being hosted by SolidityATL through @KittLabs kicked off this week.
Participating in this course also gives students access to join our web3 security research teams that participate in both public and private web3 security reviews.
The course is 100% free and virtual as we are looking to upskill web3 developers and security researchers. You can sign up here: https://t.co/Cl4euXo9gZ