I love @compoundfinance as a concept and as a product.
But this code https://etherscan.io/address/0x3d9819210a31b4961b30ef54be2aed79b9c9cd3b#code … controlling soon $100M scares the shit out of me.
Many thousand lines of code, assembly use, literally 6 open "todo's".
-
Show this thread
-
Replying to @koeppelmann @compoundfinance
Martin, Gnosis contracts also use many lines of code, inline assembly and, occasionally, comments. I've love to walk you through our code, as we've done with our auditors:
@trailofbits and @Certora1. Excited to discuss and answer any questions you have.2 replies 0 retweets 6 likes -
Replying to @justHGH @koeppelmann and
We want to know what
@trailofbits found, and how you fixed them1 reply 0 retweets 1 like -
Zaki Manian Retweeted Jessy Irwin ✨
Talk to
@trailofbits about publishing executive summaries from your audits.@jessysaurusrex Our head of security has a great thread on audit best practices.https://twitter.com/jessysaurusrex/status/1154145643146825728?s=20 …Zaki Manian added,
1 reply 0 retweets 3 likes -
ameen.eth 👹is out of melee range Retweeted 🤖 Leshner
Code https://twitter.com/rleshner/status/1154821526048264192?s=19 … Trail of Bits Audit (can't find Centora Report) https://www.reddit.com/r/ethereum/comments/buvfhl/im_worried_about_the_security_of_compound_v2/epix8pw?utm_medium=android_app&utm_source=share …
ameen.eth 👹is out of melee range added,
1 reply 0 retweets 1 like -
I put the final report for our Compound v2 review on our publications repo just now. The final report has one extra week compared to the one linked on Reddit. https://github.com/trailofbits/publications/blob/master/reviews/compound-2.pdf …
2 replies 1 retweet 5 likes
Similar the thread from @jessysaurusrex, I would strongly caution that many people misread the outcome of security reviews. They are primarily intended for the product's own engineering team and half the purpose is education.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.