• bitcoinBitcoin (BTC) $ 67,937.00
  • ethereumEthereum (ETH) $ 3,255.79
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 579.21
  • solanaSolana (SOL) $ 182.81
  • usd-coinUSDC (USDC) $ 1.00
  • xrpXRP (XRP) $ 0.596586
  • staked-etherLido Staked Ether (STETH) $ 3,253.92
  • dogecoinDogecoin (DOGE) $ 0.134113
  • the-open-networkToncoin (TON) $ 6.70
  • cardanoCardano (ADA) $ 0.416048
  • tronTRON (TRX) $ 0.137305
  • avalanche-2Avalanche (AVAX) $ 28.75
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 67,769.00
  • shiba-inuShiba Inu (SHIB) $ 0.000017
  • chainlinkChainlink (LINK) $ 13.54
  • polkadotPolkadot (DOT) $ 5.84
  • bitcoin-cashBitcoin Cash (BCH) $ 378.91
  • nearNEAR Protocol (NEAR) $ 5.68
  • uniswapUniswap (UNI) $ 7.65
  • leo-tokenLEO Token (LEO) $ 5.83
  • litecoinLitecoin (LTC) $ 71.34
  • daiDai (DAI) $ 1.00
  • pepePepe (PEPE) $ 0.000012
  • wrapped-eethWrapped eETH (WEETH) $ 3,397.24
  • matic-networkPolygon (MATIC) $ 0.513500
  • internet-computerInternet Computer (ICP) $ 10.10
  • kaspaKaspa (KAS) $ 0.182082
  • ethereum-classicEthereum Classic (ETC) $ 22.84
  • aptosAptos (APT) $ 7.02
  • ethena-usdeEthena USDe (USDE) $ 0.999502
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 1.27
  • stellarStellar (XLM) $ 0.102505
  • moneroMonero (XMR) $ 162.71
  • blockstackStacks (STX) $ 1.87
  • mantleMantle (MNT) $ 0.844441
  • filecoinFilecoin (FIL) $ 4.60
  • dogwifcoindogwifhat (WIF) $ 2.61
  • render-tokenRender (RENDER) $ 6.60
  • injective-protocolInjective (INJ) $ 25.60
  • bittensorBittensor (TAO) $ 346.96
  • okbOKB (OKB) $ 41.14
  • hedera-hashgraphHedera (HBAR) $ 0.068693
  • crypto-com-chainCronos (CRO) $ 0.091435
  • makerMaker (MKR) $ 2,630.76
  • immutable-xImmutable (IMX) $ 1.58
  • arbitrumArbitrum (ARB) $ 0.725812
  • cosmosCosmos Hub (ATOM) $ 6.17
  • vechainVeChain (VET) $ 0.028670
  • first-digital-usdFirst Digital USD (FDUSD) $ 1.00
  • bonkBonk (BONK) $ 0.000029
  • arweaveArweave (AR) $ 30.37
  • suiSui (SUI) $ 0.780935
  • optimismOptimism (OP) $ 1.72
  • the-graphThe Graph (GRT) $ 0.200292
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,644.75
  • flokiFLOKI (FLOKI) $ 0.000180
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,301.65
  • thorchainTHORChain (RUNE) $ 4.71
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,379.31
  • bitget-tokenBitget Token (BGB) $ 1.12
  • theta-tokenTheta Network (THETA) $ 1.50
  • whitebitWhiteBIT Coin (WBT) $ 10.10
  • notcoinNotcoin (NOT) $ 0.014208
  • aaveAave (AAVE) $ 97.74
  • jupiter-exchange-solanaJupiter (JUP) $ 1.07
  • ondo-financeOndo (ONDO) $ 0.993788
  • pyth-networkPyth Network (PYTH) $ 0.390247
  • jasmycoinJasmyCoin (JASMY) $ 0.029075
  • lido-daoLido DAO (LDO) $ 1.56
  • fantomFantom (FTM) $ 0.460109
  • based-brettBrett (BRETT) $ 0.129174
  • coredaoorgCore (CORE) $ 1.38
  • celestiaCelestia (TIA) $ 5.97
  • algorandAlgorand (ALGO) $ 0.142995
  • sei-networkSei (SEI) $ 0.368890
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,250.01
  • quant-networkQuant (QNT) $ 72.69
  • flowFlow (FLOW) $ 0.667616
  • gatechain-tokenGate (GT) $ 7.65
  • mantra-daoMANTRA (OM) $ 1.19
  • msolMarinade Staked SOL (MSOL) $ 219.56
  • kucoin-sharesKuCoin (KCS) $ 9.70
  • popcatPopcat (POPCAT) $ 0.940814
  • beam-2Beam (BEAM) $ 0.018231
  • elrond-erd-2MultiversX (EGLD) $ 33.31
  • axie-infinityAxie Infinity (AXS) $ 6.06
  • bitcoin-svBitcoin SV (BSV) $ 45.36
  • heliumHelium (HNT) $ 5.30
  • galaGALA (GALA) $ 0.023595
  • ethereum-name-serviceEthereum Name Service (ENS) $ 26.52
  • bittorrentBitTorrent (BTT) $ 0.00000090
  • eosEOS (EOS) $ 0.577759
  • flare-networksFlare (FLR) $ 0.019335
  • tokenize-xchangeTokenize Xchange (TKX) $ 10.38
  • neoNEO (NEO) $ 11.69
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,313.39
  • ordinalsORDI (ORDI) $ 38.63
  • akash-networkAkash Network (AKT) $ 3.30
  • dydx-chaindYdX (DYDX) $ 1.29
  • raptoreumRaptoreum (RTM) $ 0.000862
  • raptoreumRaptoreum (RTM) $ 0.000862
  • peri-financePERI Finance (PERI) $ 0.279208
  • peri-financePERI Finance (PERI) $ 0.279208
  • chumbai-valleyChumbi Valley (CHMB) $ 0.000193
  • chumbai-valleyChumbi Valley (CHMB) $ 0.000193
  • alfALF (ALF) $ 0.000038
  • alfALF (ALF) $ 0.000038
  • paramParam (PARAM) $ 0.014492
  • paramParam (PARAM) $ 0.014492
  • mirror-protocolMirror Protocol (MIR) $ 0.023945
  • mirror-protocolMirror Protocol (MIR) $ 0.023945
  • edgevana-staked-solEdgevana Staked SOL (EDGESOL) $ 205.47
  • edgevana-staked-solEdgevana Staked SOL (EDGESOL) $ 205.47
  • soraSora (XOR) $ 0.000013
  • soraSora (XOR) $ 0.000013
  • daggerDagger (XDAG) $ 0.002987
  • daggerDagger (XDAG) $ 0.002987
  • bumperBumper (BUMP) $ 0.019046
  • bumperBumper (BUMP) $ 0.019046
  • ashswapAshSwap (ASH) $ 0.012757
  • ashswapAshSwap (ASH) $ 0.012757
  • dxdaoDXdao (DXD) $ 158.12
  • dxdaoDXdao (DXD) $ 158.12
  • electronicguldenElectronic Gulden (EFL) $ 0.176725
  • electronicguldenElectronic Gulden (EFL) $ 0.176725
  • hex-orange-addressHex Orange Address (HOA) $ 0.024673
  • hex-orange-addressHex Orange Address (HOA) $ 0.024673
  • alpha-fiAlpha Fi (ALPHA) $ 1.82
  • alpha-fiAlpha Fi (ALPHA) $ 1.82
  • tenet-1b000f7b-59cb-4e06-89ce-d62b32d362b9TENET (TENET) $ 0.008762
  • tenet-1b000f7b-59cb-4e06-89ce-d62b32d362b9TENET (TENET) $ 0.008762
  • rebel-botsRebel Bots (RBLS) $ 0.012957
  • rebel-botsRebel Bots (RBLS) $ 0.012957
  • rubicRubic (RBC) $ 0.021164
  • rubicRubic (RBC) $ 0.021164
  • onomy-protocolOnomy Protocol (NOM) $ 0.041353
  • onomy-protocolOnomy Protocol (NOM) $ 0.041353
  • sphynx-labs-bae5b42e-5e37-4607-8691-b56d3a5f344cSphynx Labs (SPHYNX) $ 0.002453
  • sphynx-labs-bae5b42e-5e37-4607-8691-b56d3a5f344cSphynx Labs (SPHYNX) $ 0.002453
  • boosted-lusdBoosted LUSD (BLUSD) $ 1.27
  • boosted-lusdBoosted LUSD (BLUSD) $ 1.27
  • bonsai3Bonsai3 (SEED) $ 0.006923
  • bonsai3Bonsai3 (SEED) $ 0.006923
  • liquiddriverLiquidDriver (LQDR) $ 0.359334
  • liquiddriverLiquidDriver (LQDR) $ 0.359334
  • ebtceBTC (EBTC) $ 66,972.00
  • ebtceBTC (EBTC) $ 66,972.00
  • gameswap-orgGameswap (GSWAP) $ 0.415416
  • gameswap-orgGameswap (GSWAP) $ 0.415416
  • wozxEfforce (WOZX) $ 0.005840
  • wozxEfforce (WOZX) $ 0.005840
  • rebootReboot (GG) $ 0.022092
  • rebootReboot (GG) $ 0.022092
  • crowny-tokenCrowny (CRWNY) $ 0.005174
  • crowny-tokenCrowny (CRWNY) $ 0.005174
  • soyjak-2Soyjak (SOY) $ 0.003702
  • soyjak-2Soyjak (SOY) $ 0.003702
  • nav-coinNavcoin (NAV) $ 0.047053
  • nav-coinNavcoin (NAV) $ 0.047053
  • klevaKLEVA (KLEVA) $ 0.065822
  • klevaKLEVA (KLEVA) $ 0.065822
  • wombat-exchangeWombat Exchange (WOM) $ 0.016501
  • wombat-exchangeWombat Exchange (WOM) $ 0.016501
  • quiddQuidd (QUIDD) $ 0.013872
  • quiddQuidd (QUIDD) $ 0.013872
  • ispolinkIspolink (ISP) $ 0.001196
  • ispolinkIspolink (ISP) $ 0.001196
  • 0chainZus (ZCN) $ 0.074297
  • 0chainZus (ZCN) $ 0.074297
  • aminoAmino ($AMO) $ 0.000130
  • aminoAmino ($AMO) $ 0.000130
  • frok-aiFrok.ai (FROK) $ 0.037372
  • frok-aiFrok.ai (FROK) $ 0.037372
  • xfundxFUND (XFUND) $ 358.54
  • xfundxFUND (XFUND) $ 358.54
  • pepe-0x69-on-basePEPE 0x69 ON BASE (PEPE) $ 0.00000001
  • pepe-0x69-on-basePEPE 0x69 ON BASE (PEPE) $ 0.00000001
  • zeek-coinZeek Coin (MEOW) $ 0.000004
  • zeek-coinZeek Coin (MEOW) $ 0.000004
  • suiswapSuiswap (SSWP) $ 0.000356
  • suiswapSuiswap (SSWP) $ 0.000356
  • carloCarlo (CARLO) $ 0.003553
  • carloCarlo (CARLO) $ 0.003553
  • safemarsSafemars (SAFEMARS) $ 0.00000001
  • safemarsSafemars (SAFEMARS) $ 0.00000001
  • wesenditWeSendit (WSI) $ 0.010080
  • wesenditWeSendit (WSI) $ 0.010080
  • plebbitPlebbit (PLEB) $ 0.000002
  • plebbitPlebbit (PLEB) $ 0.000002
  • gami-worldGAMI World (GAMI) $ 0.081967
  • gami-worldGAMI World (GAMI) $ 0.081967
  • lucroLucro (LCR) $ 0.000035
  • lucroLucro (LCR) $ 0.000035
  • pantherPanther Protocol (ZKP) $ 0.010464
  • pantherPanther Protocol (ZKP) $ 0.010464
  • polka-cityPolkacity (POLC) $ 0.008542
  • polka-cityPolkacity (POLC) $ 0.008542
  • kira-the-injective-catKira the Injective Cat (KIRA) $ 0.000051
  • kira-the-injective-catKira the Injective Cat (KIRA) $ 0.000051
  • bmxBMX (BMX) $ 1.28
  • bmxBMX (BMX) $ 1.28
  • hacashHacash (HAC) $ 3.93
  • hacashHacash (HAC) $ 3.93
  • mind-languageMind (MND) $ 0.036080
  • mind-languageMind (MND) $ 0.036080
  • omni-2Omni (OMNI) $ 0.003478
  • omni-2Omni (OMNI) $ 0.003478
  • pktPKT (PKT) $ 0.000789
  • pktPKT (PKT) $ 0.000789
  • rainbow-token-2Rainbow Token (RBW) $ 0.013834
  • rainbow-token-2Rainbow Token (RBW) $ 0.013834
  • crypteriumCrypterium (CRPT) $ 0.040998
  • crypteriumCrypterium (CRPT) $ 0.040998
  • cerebrum-daoCerebrum DAO (NEURON) $ 0.000253
  • cerebrum-daoCerebrum DAO (NEURON) $ 0.000253
  • velhallaScarQuest (SCAR) $ 0.001437
  • velhallaScarQuest (SCAR) $ 0.001437
  • label-foundationLABEL AI (LBL) $ 0.002996
  • label-foundationLABEL AI (LBL) $ 0.002996
  • silk-bcec1136-561c-4706-a42c-8b67d0d7f7d2Silk (SILK) $ 1.14
  • silk-bcec1136-561c-4706-a42c-8b67d0d7f7d2Silk (SILK) $ 1.14
  • taboo-tokenTaboo (TABOO) $ 0.000349
  • taboo-tokenTaboo (TABOO) $ 0.000349
  • baby-grokBaby Grok (BABYGROK) $ 0.00
  • baby-grokBaby Grok (BABYGROK) $ 0.00
  • 0-knowledge-network0 Knowledge Network (0KN) $ 0.000425
  • 0-knowledge-network0 Knowledge Network (0KN) $ 0.000425
  • spheroid-universeSpheroid Universe (SPH) $ 0.001514
  • spheroid-universeSpheroid Universe (SPH) $ 0.001514
  • ca-htbCoupon Assets (CA) $ 0.273075
  • ca-htbCoupon Assets (CA) $ 0.273075
  • veloce-vextVeloce (VEXT) $ 0.019155
  • veloce-vextVeloce (VEXT) $ 0.019155
  • wecoinWECOIN (WECO) $ 0.000369
  • wecoinWECOIN (WECO) $ 0.000369
  • delta-exchange-tokenDelta Exchange (DETO) $ 0.035704
  • delta-exchange-tokenDelta Exchange (DETO) $ 0.035704
  • spacefalconSpaceFalcon (FCON) $ 0.000194
  • spacefalconSpaceFalcon (FCON) $ 0.000194
  • gainsGains (GAINS) $ 0.062661
  • gainsGains (GAINS) $ 0.062661
  • pizabrcPIZA (Ordinals) (PIZA) $ 0.159759
  • pizabrcPIZA (Ordinals) (PIZA) $ 0.159759
  • vesper-financeVesper Finance (VSP) $ 0.393517
  • vesper-financeVesper Finance (VSP) $ 0.393517
  • metalcoreMetalCore (MCG) $ 0.005387
  • metalcoreMetalCore (MCG) $ 0.005387
  • adamant-messengerADAMANT Messenger (ADM) $ 0.029731
  • adamant-messengerADAMANT Messenger (ADM) $ 0.029731
  • linqLinq (LINQ) $ 0.033362
  • linqLinq (LINQ) $ 0.033362
  • mimo-parallel-governance-tokenMimo Governance (MIMO) $ 0.006304
  • mimo-parallel-governance-tokenMimo Governance (MIMO) $ 0.006304
  • send-token/send (SEND) $ 0.000127
  • send-token/send (SEND) $ 0.000127
  • umbrella-networkUmbrella Network (UMB) $ 0.008566
  • umbrella-networkUmbrella Network (UMB) $ 0.008566
  • not-financial-adviceNot Financial Advice (NFAI) $ 0.039079
  • not-financial-adviceNot Financial Advice (NFAI) $ 0.039079
  • tokencardMonolith (TKN) $ 0.091313
  • tokencardMonolith (TKN) $ 0.091313
  • carbon-creditCarbon Credit (CCT) $ 0.178055
  • carbon-creditCarbon Credit (CCT) $ 0.178055
  • merchant-tokenMerchant (MTO) $ 0.055684
  • merchant-tokenMerchant (MTO) $ 0.055684
  • metavault-tradeMetavault Trade (MVX) $ 1.31
  • metavault-tradeMetavault Trade (MVX) $ 1.31
  • parexParex (PRX) $ 0.251986
  • parexParex (PRX) $ 0.251986
  • solbankSolbank (SB) $ 196.72
  • solbankSolbank (SB) $ 196.72
  • zambesigoldZambesiGold (ZGD) $ 0.078010
  • zambesigoldZambesiGold (ZGD) $ 0.078010
  • pepe-solPepe (SOL) (PEPE) $ 0.003267
  • pepe-solPepe (SOL) (PEPE) $ 0.003267
  • my-lovely-coinMy Lovely Coin (MLC) $ 0.158554
  • my-lovely-coinMy Lovely Coin (MLC) $ 0.158554
  • safe-dealSafeDeal (SFD) $ 0.133729
  • safe-dealSafeDeal (SFD) $ 0.133729
  • hydranetHydranet (HDN) $ 0.020256
  • hydranetHydranet (HDN) $ 0.020256
  • romeRome (ROME) $ 14.33
  • romeRome (ROME) $ 14.33
  • mintoMinto (BTCMT) $ 0.559509
  • mintoMinto (BTCMT) $ 0.559509
  • metronomeMetronome (MET) $ 0.523552
  • metronomeMetronome (MET) $ 0.523552
  • chimaeraXAYA (WCHI) $ 0.056244
  • chimaeraXAYA (WCHI) $ 0.056244
  • particlParticl (PART) $ 0.227386
  • particlParticl (PART) $ 0.227386
  • ramses-exchangeRamses Exchange (RAM) $ 0.025029
  • ramses-exchangeRamses Exchange (RAM) $ 0.025029
  • stimaSTIMA (STIMA) $ 1.01
  • stimaSTIMA (STIMA) $ 1.01
  • hamiHAMI ($HAMI) $ 0.003211
  • hamiHAMI ($HAMI) $ 0.003211
  • social-good-projectSocialGood (SG) $ 0.135266
  • social-good-projectSocialGood (SG) $ 0.135266

Latest DeFi exploits show audits are no guarantee

0 101

Latest DeFi exploits show audits are no guarantee

  blockworks.co 8 h

Latest DeFi exploits show audits are no guarantee

Two recent catastrophic exploits of two DeFi protocols differed in many ways, yet shared one commonality — both were audited multiple times.

Raft Finance, a stablecoin provider inspired by Liquity but backed by staked ether, fell victim to an infinite mint bug two weeks ago. KyperSwap saw its liquidity pools drained on Nov. 23.

The Raft team’s post-mortem analysis of the incident pointed out that, “the exploited Raft smart contracts were audited by Trail of Bits and Hats Finance. Unfortunately, the vulnerabilities that led to the incident were not detected in these audits.”

Kyber Network similarly flagged its platform’s audits from vaunted security experts, including 100proof, ChainSecurity and participants in an audit competition organized by Sherlock.

7/ Security measures we’ve taken include internal smart contract checks, & audits by 100proof (whitehacker), ChainSecurity, & community developers via Sherlock’s audit competition. We encouraged further checks on the smart contracts through our Bug Bounty Program with Immunefi.

— Kyber Network (@KyberNetwork) November 24, 2023

Raft procured even more audits by Curious Apple and Aviggiano throughout 2023, indicating ongoing security evaluations and improvements​​ that have led onlookers to question the assumption that an audited protocol is necessarily safe.

What’s needed is a “paradigm shift” in how blockchain projects tackle threats in the face of examples like these, says Halborn’s chief operating officer Dave Schwed, highlighting “sophisticated manipulation of smart contract functions.”

“It highlights the importance of projects taking a proactive and layered approach to security, beyond just relying on external audits,” Schwed told Blockworks.

Other smart contract specialists, including Yearn Finance security researcher Storming0x, concur. They said on X that it’s “a waste for a project to get an audit” absent attention to other best practices.

IMO is a waste for a project to get an audit without good testing, coverage, fuzzing and at least 1 good peer review.

Why? Because a good auditor will find most evident high issues at surface given the small amount time but not have time to go in depth.

7/ pic.twitter.com/t64H0RVtC2

— Storm Blessed 0x (@storming0x) November 14, 2023

It is also difficult for ordinary users to tell whether an audit covers the final code in production.

The Devil vulnerability is in the details

Theoretically, a user could compare the audited code with the current published version, Schwed noted.

“Most audit reports show, or should show, a hash of the repo of the code that was audited,” he said. “There should be some automated mechanism to compare the code audited and the code in production enhancing transparency and trust.”

Michael Lewellen, head of solutions architecture at Open Zeppelin, noted that “change management” — ensuring the production version matches the audited one — was not an issue in Raft’s case. However, he does see a tendency for some development teams to ignore the advice of their auditors.

“Trail of Bits, despite missing the bug itself, did note in their report that the Raft codebase could have made improvements to their testing and verification,” Lewellen told Blockwoks.

“These recommendations should not be taken lightly by projects that might otherwise assume the audit report gives them the all-clear to launch without making improvements to other parts of their security stack,” he added.

Making users partly whole

After receiving feedback that it was unfair to exclude those who sold their R following the depeg event, Raft retracted its initial recovery plan.

A revised “recovery plan” was published Friday, giving victims until the end of March 2024, recoup a portion of their losses.

“After substantial feedback from the Raft community, the Raft Recovery Plan has been finalized, resulting in a 42% recovery rate. This guide is for all the affected users who were included in the Raft Recovery Plan to claim their DAI,” the plan said.

For Kyber the scale of the loss was significantly greater — some $48 million. The road to recovery is still unclear.

9/ We are grateful for the overwhelming support from those who have offered assistance in aiding in the investigation. Our heartfelt appreciation goes out to our users & partners who believe in our product & mission. Updates will be provided as the situation unfolds.

— Kyber Network (@KyberNetwork) November 24, 2023

The KyberSwap exploit, noted for its unusual sophistication, has left DeFi users wondering about the level of yield that justifies their risk-taking.

Source

Leave A Reply

Your email address will not be published.