As institutions move onchain, counterparty and transaction screening are essential to their security and compliance.
Forta Firewall delivers that, powered by the FORT token.
Learn more 👉 https://t.co/kW67C4seya
$351 million walked out of Bitget. Almost none of it was frozen by the asset issuers.
Our August piece on why issuers need to automate that decision is becoming increasingly relevant.
👇
https://t.co/4LwSu1zh6j
Bad look for Circle.
The Bitget hacker stole $350M today, and a part of these funds was in USDC.
Circle had the possibility to freeze these funds as USDC is centralized, but it chose to do nothing.
That says a lot about how much Circle cares about saving user funds.
$RWC drained for ~$109K on BSC 🚨
Attacks this size never make the headlines, which is exactly why they keep working. Nobody builds monitoring for the $100K case, and the $100K case runs every week.
Forta flagged it.
👇
Congratulations to the @OpenZeppelin team.
Over the past 11 years, OZ has played a fundamental role in making crypto safer, more resilient, and ready for adoption by the global financial system.
Excited to see what this talented team will do next, now with the scale and reach of S&P Global behind them.
👇
Today we are announcing that S&P Global has entered an agreement to acquire OpenZeppelin.
Onchain finance is growing from an emerging market into core financial infrastructure, and the standards and rails our team and community built are becoming the rails of global finance. OpenZeppelin smart contracts facilitated over $37 trillion in value transferred, with the vast majority of the largest DeFi protocols, blockchain networks, stablecoins and tokenized funds relying on them.
With S&P Global, we expect to accelerate the impact of onchain finance, backed by more than a century of trust in global markets, benchmarks, and risk frameworks.
To our clients and to all the users of OpenZeppelin open source tools:
• OpenZeppelin Contracts and all our open source applications and tools remain open source, free, and publicly maintained on GitHub. Building open source standards stays a core priority.
• Audits, engineering work, and ecosystem programs continue with the same team, brand, quality, and customer experience, with what will be the added benefit of S&P Global's research capacity, market data, and institutional reach.
For the last decade, OpenZeppelin has set the security standard for onchain finance. Today begins a new chapter for that mission, together with one of the most trusted names in global markets.
Read the full announcement: https://t.co/lxBUWkWVUK
You're asking the right question. Alerts are public and timestamped, so the latency is measurable rather than something we assert.
Worth separating two things though: detection tells you it happened, enforcement stops it. On chains running Firewall the transaction is rejected before execution, so latency stops being the variable.
Справжні гроші виходять onchain. Разом з ними — і справжні ризики.
З 2021 року Forta — це рівень безпеки та управління ризиками, який тримає їх під контролем.
Дізнайтеся, як Forta вирішує питання ризиків onchain
👇
💸 ~$346K taken from @flamincome 🚨
The vault counted tokens anyone could send it as its own, then priced them with Curve's virtual price, which assumes a balanced pool. It wasn't. Share price inflated, redeemed against real aUSDT.
Forta flagged it.
👇
~65 people lost ~$47K yesterday to an approval they forgot they'd granted 🚨
The BonfireSwap router let anyone move tokens out of any address that had approved it. $BONFIRE, BNB Chain.
Approvals don't expire. Forta flagged it. Go revoke what you're not using.
👇
Who actually bears the loss when an asset fails?
If USDe went to zero, USDT depositors on Aave v3 could lose up to 20% despite having zero direct USDe exposure.
This is what DeFi contagion looks like, mapped and quantified by Forta in real time.
👇
In onchain finance, direct exposure is only part of the risk.
If USDe were compromised, USDT suppliers on Aave v3 with zero USDe direct exposure could still face losses of up to 20%.
Forta maps and quantifies how contagion travels through DeFi in real-time.
👇
https://t.co/yJafl8LKWY
In onchain finance, direct exposure is only part of the risk.
If USDe were compromised, USDT suppliers on Aave v3 with zero USDe direct exposure could still face losses of up to 20%.
Forta maps and quantifies how contagion travels through DeFi in real-time.
👇
https://t.co/yJafl8LKWY
OFAC just designated Xinbi Guarantee, a scam-center marketplace that moved $24B+ since 2022.
52 TRON addresses added to the SDN list.
All 52 are now in Forta Firewall. Chains running Firewall reject transactions touching them before execution.
https://t.co/g37fMWkIni
Tokenization 1.0, 2.0, 3.0. Everyone is somewhere on that curve, and almost nobody is standing still.
Laeeq Shabir, Partner at @htdgtl, closing out the roundtable on where institutions actually are today.
Cyber is having a moment
Across 21 major software companies, including Apple, AWS, Microsoft, and Google:
- Reported critical vulnerabilities never cleared 100 per month in four years
- Since spring they've jumped to over 600 per month
Charts of the Week: https://t.co/4dgNGwG5Nx
Blocking potentially bad things before they happen or reacting and mitigating as quickly as possible if something is to arise.
John Neufeld of @OpenZeppelin on why real time monitoring belongs in the security lifecycle, not just the audit.
If risk, compliance, legal, product, and tech are The Avengers, then AI is the Age of Ultron moment.
How does this change how businesses actually operate?
Not every exploit is clever. Sometimes a function is just missing a caller check 🚨
GebProxyActions quitSystem had none. Misconfigured SAFEs sat callable by anyone until someone finally called.
Firewall flagged it.
👇
A question worth sitting with: do risk, compliance, legal, product and engineering eventually collapse into one team around the systems that write the code?
Rohan Ranadive, @WisdomTreePrime, at Forta roundtable.
An old @Balancer V1 pool was drained through a rounding error 🚨
The attacker pushed WBTC reserves down to dust, then minted 4,408 BPT paying 1 satoshi at a time.
Forta flagged it.
Everything gets tokenized eventually. The interesting question is what happens to risk when it does.
@ajbeal, Head of Institutional Strategy at @fortanetwork.
~$162K drained from @enjin ⛑️
A storage slot collision via DELEGATECALL handed the attacker manager rights over the proxy.
Flagged in real time by Forta.
Regulators worldwide are working the same problem: how do you open up a technology that lowers costs and widens access, without leaving consumers exposed?
@johndneufeld, General Counsel at @OpenZeppelin.