We're hired to provide industry-best advice @trailofbits, and that's exactly what we provided to @HegicOptions. How, then, were bugs found in their code mere hours after they deployed it to mainnet? (1/n) https://twitter.com/HegicOptions/status/1253937104666742787 …
-
-
It was more than just security experts who understood this about
@HegicOptions. It was obvious that further work was needed to non-experts too. “It's OK we have no tests because the auditors will catch all the bugs” said no one ever https://twitter.com/BlockEnthusiast/status/1254132916675907584 …https://twitter.com/hitchcott/status/1253982497446166528 …Show this thread -
We know there are roadblocks to interpreting our results by non-experts. For example, we purposefully avoid subjective opinions in our reports, preferring objective facts to maintain our integrity and independence.https://twitter.com/HeidyKhlaaf/status/1254121886902083584 …
Show this thread -
Further, it's possible for clients to simply ignore what we document in reports.
@trailofbits does not have any authority over our clients, we simply provide them advice. https://twitter.com/HeidyKhlaaf/status/1254122500407152640 …https://twitter.com/spencecoin/status/1254116602720608258 …Show this thread -
How will we improve after this incident? 1st, we will no longer work with
@HegicOptions. Their behavior has been deeply irresponsible. They ignored our advice and recklessly put user funds at risk. This hurts the entire DeFi community.Show this thread -
2nd, we will keep services from
@trailofbits accessible for those with lower or limited financial resources. Security assistance is essential for smaller projects, and we'll continue to help those that need it with shorter project sizes.Show this thread -
3rd, we'll add structure to our summary reports to help readers better evaluate the current state and maturity of the project while remaining objective. It's unfortunate so few people look beyond our reports so we'll provide stats and info about the code in them.
Show this thread -
cc
@defiprime@lalleclausen@tzhen@drVillo@preston_vanloon@hitchcott@intocryptoast@quentinc137@Fiskantes@ck_SNARKs@nicksdjohnson@ChainLinkGod@hosseeb@IamNomad@JTremback Thanks for your earlier comments! We're open to hearing your opinions about how we can improve.Show this thread
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.