I love @compoundfinance as a concept and as a product.
But this code https://etherscan.io/address/0x3d9819210a31b4961b30ef54be2aed79b9c9cd3b#code … controlling soon $100M scares the shit out of me.
Many thousand lines of code, assembly use, literally 6 open "todo's".
-
Show this thread
-
Replying to @koeppelmann @compoundfinance
Martin, Gnosis contracts also use many lines of code, inline assembly and, occasionally, comments. I've love to walk you through our code, as we've done with our auditors:
@trailofbits and @Certora1. Excited to discuss and answer any questions you have.2 replies 0 retweets 6 likes -
Replying to @justHGH @koeppelmann and
We want to know what
@trailofbits found, and how you fixed them1 reply 0 retweets 1 like -
Zaki Manian Retweeted Jessy Irwin ✨
Talk to
@trailofbits about publishing executive summaries from your audits.@jessysaurusrex Our head of security has a great thread on audit best practices.https://twitter.com/jessysaurusrex/status/1154145643146825728?s=20 …Zaki Manian added,
1 reply 0 retweets 3 likes -
ameen.eth 👹is out of melee range Retweeted 🤖 Leshner
Code https://twitter.com/rleshner/status/1154821526048264192?s=19 … Trail of Bits Audit (can't find Centora Report) https://www.reddit.com/r/ethereum/comments/buvfhl/im_worried_about_the_security_of_compound_v2/epix8pw?utm_medium=android_app&utm_source=share …
ameen.eth 👹is out of melee range added,
1 reply 0 retweets 1 like -
I put the final report for our Compound v2 review on our publications repo just now. The final report has one extra week compared to the one linked on Reddit. https://github.com/trailofbits/publications/blob/master/reviews/compound-2.pdf …
2 replies 1 retweet 5 likes -
Thank you. Can you also confirm that the code that you audited is the code verified on etherscan? The GitHub commit hashes from your audit report are for a private repo.
1 reply 0 retweets 4 likes
As the report says, we reviewed their code for 8 person-weeks as of the date indicated. We worked with their team to understand and address risk, and helped educate their team about security.
-
-
Understood
0 replies 0 retweets 0 likesThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.