8/ See also our previous thread on the capability pattern down below.
Do follow us at @move_sec for more news on move security. Also give the auditors at @sharkteamorg a follow for the excellent article!
https://t.co/702bBJS82h
Move Security: The Capability Pattern
In smart contracts, correct access control is of utmost importance. The Capability pattern is a powerful tool that allows for controlled authorization of specific actions.
Let's go through the example on https://t.co/iKLcs2cmo3
🧵👇
📘Technical Comparison between @SuiNetwork and @Aptos_Network Implementations
Recently, with the upcoming launch of the Sui mainnet, discussions surrounding #Aptos and #Sui have been increasing,
Learn more:https://t.co/BGju0m5G4l
#SharkTeam
7/ Low-level security: Both Aptos and Sui handle integer overflows at the language level, but do not test for overflow in bit ops. Meanwhile, access control in Move is achieved through design patterns such as AdminCap, but the Aptos and Sui differ in implementation specifics.
3/ (And let's be real here, both the claimed 11k single-send of #SuiNetwork and the claimed 20k transactions on #Aptos are miles ahead of most other chains!)
1/ So on the whole 300k tps thing by #SuiNetwork: I agree that the way it's presented is a bit annoying. That being said, there are real use-cases for these batch sends they're using (think NFT mints, whose volume has brought down Solana for example).
For Web3 to grow and build mainstream trust, there is an urgent need for verifiable, real-world benchmarks.
A solution: Aptos has put forth the first fully-reproducible performance benchmark test.
Learn more and join the industry-wide conversation to establish consensus 👇🧵
2/ Tps is not the only end-all measure of performance. Different chains can have different specializations, like parallelizability & batch send throughput vs raw single-account-locking throughput -- think GPU vs CPU.
The future is multi-chain, as they say.
This is why "audit stamp" companies are such a problem, both in traditional and web3 security. High-cost audits may have a higher initial investment, but they're the ones that find the actual bugs.
Don't fall for cheap audit providers that more or less only run automated tools.
The zkSync-based Merlin DEX was exploited today for over $1.1M. Certified by CertiK, which oversees 70% of all audits, the question arises: Can we trust audits?
It's time to research cases of audited protocol hacks and see if safety is ever guaranteed ↓
Bookmark & RT
🧵 1/11
8/ Most importantly, security is paramount for Mole. The protocol has been audited by @MoveBit_, a leading auditor in move security. No major bugs were found (a rare occurence!).
Audit report: https://t.co/HGn3dLFYHA
1/ Quick highlight on #Aptos & #SuiNetwork project @moledefi, a DeFi protocol offering savings, leveraged yield farms, and funds. Here's what you need to know about its three core products and what its devs are doing about security.
7/ Mole says its intelligent algorithms automatically calculate the best leveraged rate and borrowing interests to maximize investing returns. The platform also adjusts positions based on market volatility.