1/ The testing framework that powers our continuous frontend monitoring is officially open-source! GuardianTest is an advanced E2E testing framework for developers working on EVM-compatible chains
GuardianTest is more powerful and less brittle than any other framework available
Another frontend hack.
Last few weeks there’s been:
@fraxfinance@Balancer@TraderJoe_xyz@SpookySwap
If you’re a protocol dev, contact us. We’ll monitor your frontend and detect hacks so you can keep your users safe.
The Spooky team is currently investigating a frontend vulnerability on our domain 😿
Please do not execute any transactions on the DEX! 🚨
We'll keep our community updated here, on Discord and Telegram when the issue has been resolved 💜
@0xmurloc Re #2, we should chat. We can continuously monitor your frontend to make sure it creates the correct smart contract interactions for users.
Then we alert you immediately if there’s an issue.
There have been several frontend attacks to very reputable projects the last few weeks. @fraxfinance@Balancer and now @TraderJoe_xyz
Let us help you monitor your frontend to detect and mitigate these attacks before users are impacted.
🚨 Further Update: Frontend Restored 👍
Following investigation and removal of the vulnerable 3rd party analytics code, the frontend has now been restored and it is marked safe to use for all activities such as trading, liquidity, staking, lending and more.
There are no other integrations or 3rd party solutions on the Trader Joe DEX.
___________________________
🚨 Are you impacted?
You are at risk if you used the Front End of the DEX to perform a transaction on any chain, after the time of 18:34 GMT on the 17th.
🚨 Your steps to take
If you think this may be applicable to you, please immediately take precautionary measures to check and remove approval of a malicious contract: 0xd8ea07f43bc5045ec49ab52a3da2d0bf533581bf.
To do this, you can follow the steps in the below quote retweet, or join the Trader Joe Discord for guided support. Please note If you open a Support ticket there may be a delayed response, but every ticket will be answered and all details recorded.
___________________________
🚨 Confirm Our Contracts
When performing transactions on the DEX you will only be asked to execute transactions again our verified and safe contract addresses that can be found in the deployment page of our Developer documents: https://t.co/IN7oGxm0mv
@samkazemian Our frontend security monitoring tool detects these types of attacks.
We make sure your live UI is creating the correct smart contract interactions.
Would love to chat w the @fraxfinance team ab how we can help you monitor going forward. 🫡
Sad to see the recent frontend attacks of @Balancer and @fraxfinance and the impact to those affected.
GuardianUI is purpose-built to help you detect frontend attacks before they harm your users.
DM us if you’re building on @0xPolygonLabs @optimismFND @arbitrum or @ethereum
We've talked to 100s of protocols. Many say the same thing:
They want to increase test coverage but their teams are stretched thin.
That's why we offer 'test writing as a service'. We'll write your e2e tests for you as a standalone service.
Sign up 👉 https://t.co/S9HBZrPJFS
We've talked to 100s of protocols. Many say the same thing:
They want to increase test coverage but their teams are stretched thin.
That's why we offer 'test writing as a service'. We'll write your e2e tests for you as a standalone service.
Sign up 👉 https://t.co/S9HBZrPJFS
3/3
Want to write your own tests?
You can install GuardianTest for free and use it now (it's open source!): https://t.co/OKzXdk76Lj
Want us to write your tests and/or monitor your tests in prod? Fill out this form for a 2 week free trial!
https://t.co/Z08SrtHA4V
1/3 Writing e2e tests is hard in web3...but it doesn't have to be!
This is how @SushiSwap can write an e2e test to confirm swapping eth to usdc from the sushi UI interacts with the correct sushiswap router.
2/3 This test runs through the entire user flow in a chrome browser -> connects a wallet w mocked balances and approvals -> and performs the swap txn on @SushiSwap's dapp .
5/ Here's everything you need to get started 🙏
- Install GuardianTest: https://t.co/OKzXdk76Lj
- Third web test code: https://t.co/pAgzAMoLkb
- Docs: https://t.co/45r7ATo36m
- Community: https://t.co/gMdPUw3Uc3
1/ Are you using the @thirdweb tech stack to build your dApp?
Here's how you can continuously simulate user interactions with your dApp to make sure it’s working properly👇
https://t.co/y8bk0NSmeE
6/ These tests can also be monitored in production to detect any issues that might cause users to get rugged when interacting with your dapp (e.g. frontend attack).
Learn more: https://t.co/q8Zomu1OcA
Free trial: https://t.co/Z08SrtHA4V