Wave's mission is to protect the open digital landscape. A Wave security audit will help to improve your overall security posture, enabling your users to safely use your application. Request an audit today 👇https://t.co/LMSQRAcrBf
kendrick's new album had so much energy 💯
anyone else find the secret track on disc one where he talks how stoked he is to properly configure his Ethereum validator client on startup with an address to accept tx tips on the execution layer?? GO OFF KING
1/ The @BeanstalkFarms was exploited in a flurry of txs (https://t.co/PMsdP5dnJG and https://t.co/wyHe3ARZgU),
leading to the gain of $80+M for the hacker (The protocol loss may be larger), including 24,830 ETH and 36M BEAN.
⚠️ A new scam is making the rounds that goes to a fake version of the popular contract-revoking site @RevokeCash.
Like most scams, it imparts a sense of fear/urgency to get you to approve a contract that you shouldn’t - and then steals your funds.
1/🧵
https://t.co/aKHXgC15ou
- Include mechanisms in smart contracts that mitigate transaction-ordering dependence and front-running attacks. Ex: commit-reveal strategies, gas limit checks, counters, etc.
- Consider the implications surrounding thinly traded illiquid assets that are used as collateral.
6/6
The Inverse Finance hack - an exploit totaling $15M.
Incredibly sophisticated hack; a combination of oracle price manipulation, front-running, distraction, and tumbling.
Here’s a high-level debrief on how they did it... a thread:👇🏼
1/6
Takeaways:
- Validation mechanisms; time is crucial in this hack. Validation checks within the oracle protocol should be altered to ensure that the window for determining the average price of an asset over a period of time is long enough.
5/6
Something interesting to note: As blockchains start to modularize, the line between L1s will blur, especially once ZK bridges become the norm. The chains with the most robust security and consensus layers will likely hold the majority of future infrastructure.
@danielvf A great example of why smart contract states should never rely on ambiguous values such as address balance, timestamp, block hash, etc. Contract balances can be manipulated with pre-sent ether and self-destruct methods.
after a few months of hard work @OpenZeppelin Contracts for Cairo v0.1.0 is finally out 🥲⚡️
start developing apps for zero knowledge rollups today with this tutorial: write, deploy, and interact with your own ERC20 on StarkNet
https://t.co/9T0daTB4wG
@WhaleCoinTalk Incredibly sophisticated hack; a combination of oracle price manipulation, front-running, "bot distraction", and tumbling. All of which were used to manipulate a thinly traded, illiquid asset.
Today, bored ape holder "s27" lost their bubble gum ape and matching mutants ($567k at current floors) in an instant. This is a thread on how it happened, and how to prevent something similar from happening to you. 1/🧵
3d / Mitigate these attacks by marking untrusted functions, progressing contract state prior to external calls, and checking return values (i.e. require, assert). In more complex scenarios, consider using a mutex to lock state progression.