Unpopular opinion: most web3 projects don't get hacked because of bad code. They get hacked because of bad processes.
No security culture from day 1
Rushing audits to hit launch dates
Treating security as a checkbox, not a culture
The biggest Web3 vulnerability I see isn't bad code. It's flawed business logic.
Automated scanners won't save you from an attacker "legally" draining your protocol due to a poorly designed reward mechanism or oracle dependency.
Think like an attacker from day one.
@mert Facts, happens way more than ppl realize. Ever play around with stealth addresses or tx relayers to break the link? Curious how folks handle this in practice.
@Al_Qa_qa @vquelque @trailofbits Mark Files is clutch for big repos, fr. Havenβt tried WeAudit yet, looks clean though. Gonna give it a spin next round. Thanks for sharing!
@philogy @PatrickAlphaC Lol fr, on-chain sleuthing always wild. Kinda hilarious how transparent everything is. Aztec privacy features gonna be clutch if this keeps up. Did he actually ape tho or just rumors?