🧵 Introducing Fullstack Audits
1/
99% of “audits” in web3 only check smart contracts.
But attackers don’t respect boundaries.
And that’s why “audited” projects still get hacked. 👇
One of the biggest mistakes smart contract engineers make when building off-chain systems:
ATOMICITY, assuming the EVM's failure model still applies.
While reviewing a Polymarket-based Telegram bot, I uncovered a flaw that enabled dual redemption because of exactly this mistake 🧵:
Great to see web3 teams like @ValkyriSecurity working on protecting infra side. Many projects centralize their on-chain program behind a unique (or few) private keys, thinking this is sufficient. But it is definitely not.
Just dropped an article covering a security issue which could have let any user post under different user’s blog.
We have now stopped working on SocialFi hacking campaign and managed to find few instances which could have leaked private key through infrastructure takeover and admin takeover based bugs.
Well, all this requires severe attention towards. With security posture like this web3 social will never thrive and recent stats already showed their survival interest.
Thanks for reading 🙏
🚨Top 10 Ways Soroban Contracts Get Hacked
A practical, real-world breakdown of common vulnerabilities on Soroban contracts with code examples. If you’re building on @StellarOrg or auditing Soroban contracts, this is a must-read. 👇
https://t.co/ntO3E8Y33w