#Cosmwasm and #EVM smart contracts are quite different! Not just the language (#Rust Vs #Solidity) but the rest of the tech too! How do auditing skills transfer between them? 🧵
1/21
ZKsyncs Atlas stack means it is processing 10x the number of TPS of US credit cards, in a process that is:
-sub-1 second finality
-cryptographically provable
-0.06% the cost of an average interchange fee
-possible in private environments
Hei @MetanaHQ ! I was reading your article on delegatecall, https://t.co/i4On6VJC3c, and I noticed an interesting behavior in the example you shared.
A short thread on why storage layouts really matter when using delegatecall! 🧵👇
As part of @zksync Trust & Safety initiative, @the_matter_labs Red Team reviewed the new features of @zkemail . Read the audit report: https://t.co/2ki6uQY9hb and dive into the most critical issues in our blog post: https://t.co/HW5RipH0sR cc @portport255@gluk64@anthonykrose
First audit report by @the_matter_labs 🥳 Our goal is to help decentralized applications built on ZKsync.
If you need an audit, contact [email protected] 🫡
Recently, I was reading about @immunefi bug fixes and decided to collect the last 2 years' findings in one place and open-source it. As imo, these are the best resources to learn security. No rocket science here, just gathered and documented it on GitHub. Sharing it here, maybe you'll find it interesting 🫡
https://t.co/r08gjN7WNC
We have just published our audit report of @ApolloDAO's @osmosis Fixed Width Range Vault @CosmWasm smart contracts. Read all about our findings and recommendations here: https://t.co/X5BlO73jIk
Not sure which platform you should deploy your new #defi protocol on? Read Eduard Kotysh's guide on #security considerations to be aware of when choosing a blockchain.
https://t.co/fwrqcfnfOK
One of the latest audits that I took part in while I was (almost) full-time at @SecurityOak .
I will keep working on @CosmWasm audits from time to time though :)
I disagree that Software Engineers should be accountable. Everyone writes bad code. Some more than others.
If that bad code can be easily released to cause havoc in the real world, the problem is the management and processes that enabled it. Hold the company and its management responsible.
All programmers that I know wish they could spend more time on tests, have better QA processes, have good practices like canary deployments, etc. We have to actually force ourselves to release code we don't think is good enough because management is standing there tapping their foot and pointing at their watch.
The problem at Crowdstrike isn't the engineer that messed up, because all of their engineers will mess up sooner or later. The problem is the poor processes they have in place, a lack of sensible precautions like canary deployments and sufficient automated and manual testing. The fault lies 100% with management, and I hope they are held accountable in the lawsuits that follow.
But watch them pay themselves hefty bonuses while they shift the blame to the people at the bottom of the hierarchy who didn't have responsibility or a say in the matter.