We decided to test @xyz_remedy glider tool and found a critical vulnerability in a privacy protocol.
Tldr: Broken Groth16 deployment leads to proof forgery, allowing to withdraw full TVL.
Read more below 👇
@akyra_0 I agree in that case (and assuming there is real activity) its not impossible. Visa is currently valued at 600B, so half of that is realistic.
This is the reason we have also been focusing on securing canton apps lately 🫡
We just published the most dense article on:
☣️Radiant Capital hack (Lazarus: malicious PDF)
☣️Bybit Hack (Lazarus: npm compromise)
☣️KelpDAO Hack (Lazarus: compromise + DOS)
Every developer or Auditor should read it.
Read the full article 👇
DAML bugs ≠ Solidity bugs.
Found a strong resource covering 8 Daml-specific vulns, how the threat model differs from Solidity and what builders/auditors should watch for.
Must read for anyone interested in Canton’s smart contract language.👇
https://t.co/0ELu1Mu6yS
Don’t use or put money in platforms that don’t have a clear way for white hats to report bugs
Simple as that
There should be a defillama to easily check this
Roughly 1/3 of exploited funds in web3 between 2021–2026 were caused by private key compromises.
And in recent months, this trend has only accelerated.
Here’s how to prevent it 👇