My take: smart-contract auditing is simply way too expensive and it's a problem.
As it's a reputation-based market, reputable firms in the space charge A LOT with no risk attached except "our reputation is on the line"
Less #DeFi exploits requires cheaper audits.https://twitter.com/CamiRusso/status/1251921338455019521 …
-
Show this thread
-
-
Replying to @AdamDraper
In my book, firms with the highest reputation in the space are
@OpenZeppelin,@ConsenSysAudits@chain_security@trailofbits... I probably forget some1 reply 1 retweet 4 likes -
Replying to @thibauld @AdamDraper and
Please consider some of our free resources: - Building Secure Contracts https://github.com/crytic/building-secure-contracts … -
@CryticCI - Ethereum Office Hours https://calendar.google.com/calendar/embed?src=trailofbits.com_56jstkqe74aj76vv83q7h041q4%40group.calendar.google.com&ctz=America%2FNew_York … - Projects from 1 day https://github.com/trailofbits/publications/blob/master/reviews/Assurance%20Practice%20Overview.pdf … - So, so many public reports and presentations https://github.com/trailofbits/publications/blob/master/reviews/Assurance%20Practice%20Overview.pdf …1 reply 1 retweet 3 likes
In particular, we host a free 1hr videoconference every other week (Ethereum office hours) to help others understand security risks and make progress with best practices. DM me, we're happy to help anyone get started.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
DeFi exploits:
June 2019: Synthetix 37m sETH
Feb. 2020: bZx $900k
Mar 2020: iEarn ~$280k
April 2020: LendfMe $25m
It's not just one project's problem. DeFi needs better security standards or we'll continue seeing the downside of that composability double-edged sword.