We will shortly disclose a security issue that could potentially cause exchanges a loss of funds. In order to receive advance notice prior to disclosure, please add your name to the following list via pull request, or by DM’ing @trailofbits or @levelk_io:https://github.com/trailofbits/blockchain-security-contacts …
-
-
Ability to patch = ability to exploit. No? Scenario: DEX common construct has exploit allows stealing user funds. You disclose exploit to exchange first, friend of owner exploits it to steal user funds before said user has awareness or able to personally mitigate.
-
Thanks for your perspective, however, we see no better way to release this information than a staged process that attempts to maximize patching and minimize harm. You can choose a different process when you find the bug.
- 2 more replies
New conversation -
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Smart man. Respect.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
