This tweet did not age well. The guy who wrote this? His buggy code was committed into Mirror Protocol in June 2021, creating a hole that allowed an attacker to drain $88m from users just a few months later. https://github.com/Mirror-Protocol/mirror-contracts/commit/56c79bafa7b2f7693653d5144e2e3aab93673695#diff-61e7453301fdb7fea66099c942a799658950c63013da0257f88b9541d30a877fR182 …https://twitter.com/csanti_95/status/1492130389254893574 …
-
Show this thread
-
Replying to @FatManTerra
We’re really calling devs out directly for incidents and vulnerabilities now?
3 replies 0 retweets 10 likes -
This Tweet is unavailable.
-
Replying to @FatManTerra
You obviously have no grasp on what goes into building DeFi or crypto-native projects. I don’t know a single dev who hasn’t had one vuln slip through.
1 reply 0 retweets 0 likes -
Replying to @0xacme @FatManTerra
It may be caught during an audit / etc, but it reflects on the organization and it’s practices, not the individual. No dev should have the keys to the kingdom, hence you don’t blame the dev for a mistake that made it into prod.
2 replies 0 retweets 1 like -
Replying to @0xacme
Do devs in your project slip in fixes without disclosing to users that a bug existed, had been patched, and probably caused millions in losses? Is that normal in the industry?
2 replies 0 retweets 3 likes -
Replying to @FatManTerra
I mean we’ve had our share of bugs which are disclosed the vast majority of the time, but it’s definitely a different world in on-chain gaming w/ much less at stake. Mistakes happen, even with great testing practices, reviews and audits.
1 reply 0 retweets 1 like -
Replying to @0xacme @FatManTerra
I’ve been fortunate enough to have caught mistakes in DeFi work before shipping though, bur I honestly count that as luck.
1 reply 0 retweets 1 like -
Replying to @0xacme
Look. I see where you're coming from. But please don't tell me you would, in good conscience, smuggle in a fix without disclosing it, and then watch in the Discord as people complain about millions being missing while being completely radio silent about the fix you put in.
1 reply 0 retweets 1 like -
Replying to @FatManTerra
I get that, this is a totally different topic though. You can’t quite blame a dev for things not being disclosed, which is not what your original post was saying. I totally agree though, vulnerability patches should be reported and incidents should have timely post mortems.
1 reply 0 retweets 0 likes
The only reason I'm calling him out this way is because he tried to cover it up undetected - if they were different people this tweet wouldn't exist
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
