Vulnerability Detection with Automatic Semantical Oracles
Finding Permission Bugs in Smart Contracts with Role Mining Access Control
AChecker: Statically Detecting Smart Contract Access Control Vulnerabilities Access Control
@EthSecurity1
Finding Permission Bugs in Smart Contracts with Role Mining Access Control
AChecker: Statically Detecting Smart Contract Access Control Vulnerabilities Access Control
@EthSecurity1
Last week, Shido Global was exploited on BSC through a flash loan attack, allowing the attacker to steal around 977 WBNB from the pool. https://explorer.phalcon.xyz/tx/bsc/0x72f8dd2bcfe2c9fbf0d933678170417802ac8a0d8995ff9a56bfbabe3aa712d6I
@EthSecurity1
@EthSecurity1
🔥4😢1
Mastering Fuzzing
https://github.com/Elpacos/mastering-fuzzing
It provides several practical examples of fuzzing using both Echidna & Foundry, two popular property based testing tools @EthSecurity1
https://github.com/Elpacos/mastering-fuzzing
It provides several practical examples of fuzzing using both Echidna & Foundry, two popular property based testing tools @EthSecurity1
GitHub
GitHub - Elpacos/mastering-fuzzing: Practical fuzzing examples for the mastering fuzzing talk
Practical fuzzing examples for the mastering fuzzing talk - Elpacos/mastering-fuzzing
❤3
These results are from a 1-hour long bot-race & not a full-fledged audit.
Wake up to the reality anon, ChatGPT & bots will soon eradicate the lower rungs of bugs from any codebase.
Only the auditors that dare to dive deep will survive this battlefield.
https://gist.github.com/liveactionllama/27513952718ec3cbcf9de0fda7fef49c
@Ethsecurity1
Wake up to the reality anon, ChatGPT & bots will soon eradicate the lower rungs of bugs from any codebase.
Only the auditors that dare to dive deep will survive this battlefield.
https://gist.github.com/liveactionllama/27513952718ec3cbcf9de0fda7fef49c
@Ethsecurity1
Gist
Winning bot race submission
Winning bot race submission. GitHub Gist: instantly share code, notes, and snippets.
❤5
This POC shows you how to perform view-only reentrancy
Just copy paste the code into your tests as an integration test
For Auditors: Apply the check to test if an oracle is safe or not (test against all uses, see sturdy) https://github.com/sherlock-audit/2022-12-sentiment-judging/issues/7
@EthSecurity1
Just copy paste the code into your tests as an integration test
For Auditors: Apply the check to test if an oracle is safe or not (test against all uses, see sturdy) https://github.com/sherlock-audit/2022-12-sentiment-judging/issues/7
@EthSecurity1
GitHub
GalloDaSballo - H-01 wstETH-ETH Curve LP Token Price can be manipulated to Cause Unexpected Liquidations · Issue #7 · sherlock…
GalloDaSballo high H-01 wstETH-ETH Curve LP Token Price can be manipulated to Cause Unexpected Liquidations Summary The wsteETH-ETH LP token is priced via it's virtual_price Through what Chaina...
❤2
poly chain hack https://dedaub.com/blog/poly-chain-hack-postmortem
security alerts channel because of twitter restriction https://news.1rj.ru/str/web3_security_alerts @EthSecurity1
security alerts channel because of twitter restriction https://news.1rj.ru/str/web3_security_alerts @EthSecurity1
Dedaub
Poly Network Hack Postmortem
Poly Network Hack | GPTPoly Network's $34b notional hack on July 2, 2023, was due to misused private keys, not a smart contract bug.
❤2
EthSecurity
Vulnerability Detection with Automatic Semantical Oracles Finding Permission Bugs in Smart Contracts with Role Mining Access Control AChecker: Statically Detecting Smart Contract Access Control Vulnerabilities Access Control @EthSecurity1
Vulnerability Detection with Automatic Semantical Oracles
Towards Automated Verification of Smart Contract Fairness Fairness Property
Clockwork Finance: Automated Analysis of Economic Security in Smart Contracts @EthSecurity1
Towards Automated Verification of Smart Contract Fairness Fairness Property
Clockwork Finance: Automated Analysis of Economic Security in Smart Contracts @EthSecurity1
❤3👍3
common Smart contract vulnerabilities by Raiders
https://blog.web3sec.news/posts/common-smart-contract-vulnerabilities-audit-checklist/
https://crosschainriskframework.github.io
Crosschain Risk Framework @EthSecurity1
https://blog.web3sec.news/posts/common-smart-contract-vulnerabilities-audit-checklist/
https://crosschainriskframework.github.io
Crosschain Risk Framework @EthSecurity1
❤6👍1
How to diff contracts against Etherscan verified code https://blog.theredguild.org/how-to-diff-smart-contracts-etherscan/
https://github.com/lidofinance/diffyscan
@EthSecurity1
https://github.com/lidofinance/diffyscan
@EthSecurity1
The Red Guild
How to diff contracts against Etherscan verified code
How to compare smart contracts in GitHub against verified code in Etherscan using Diffyscan.
🔥6
The zero-knowledge attack of the year might just have happened, or how Nova got broken @EthSecurity1
www.zksecurity.xyz
The zero-knowledge attack of the year might just have happened, or how Nova got broken - ZKSECURITY
Last week, a strange paper (by Wilson Nguyen et al.) came out: Revisiting the Nova Proof System on a Cycle of Curves. Its benign noscript might have escaped the attention of many, but within its pages lied one of the most impressive and devastating attack on…
Forwarded from Rektoff
Gm Rektoffians!
We’ve prepared an alpha-only web3 security telegram pack so you can always stay up to date with market trends, cool articles and useful groups 👥
Add it with the following link:
https://news.1rj.ru/str/addlist/b0NZzSm3Q9gxYTMy
And feel free to share your gem channels under this post in case we missed something.
Stay Rektoff😀
We’ve prepared an alpha-only web3 security telegram pack so you can always stay up to date with market trends, cool articles and useful groups 👥
Add it with the following link:
https://news.1rj.ru/str/addlist/b0NZzSm3Q9gxYTMy
And feel free to share your gem channels under this post in case we missed something.
Stay Rektoff
Please open Telegram to view this post
VIEW IN TELEGRAM
🫡5
BrutePrint: Expose Smartphone Fingerprint Authentication to Brute-force Attack.
2 Hours Web3 Smart Contract Security Interview with Dravee.
@EthSecurity1
2 Hours Web3 Smart Contract Security Interview with Dravee.
@EthSecurity1
YouTube
2 Hours Web3 Smart Contract Security Interview with Dravee
Join the Blockchain Security Academy,
GET 100$ Discount on the Smart Contract Hacking Course:
https://johnnytime.xyz/smart-contract-hacker
An awesome interview with our special guest, Dravee. In this interview, we'll delve deep into Dravee's experiences…
GET 100$ Discount on the Smart Contract Hacking Course:
https://johnnytime.xyz/smart-contract-hacker
An awesome interview with our special guest, Dravee. In this interview, we'll delve deep into Dravee's experiences…
❤3
still stuck using csv? well there’s a new tool for anyone that enjoys rust, parquet, or crypto data…
❄️🧊cryo🧊❄️
you can use cryo to easily extract:
- blocks
- txs
- logs
- call traces
- slot traces
- balance traces
- nonce traces
- code traces
- vm traces
cryo can extract all historical uniswap trades with this command:
cryo logs --topic0 0xc42079f94a6350d7e6235f29174924f928cc2ac818eb64fed8004e115fbcca67
@EthSecurity1
❄️🧊cryo🧊❄️
you can use cryo to easily extract:
- blocks
- txs
- logs
- call traces
- slot traces
- balance traces
- nonce traces
- code traces
- vm traces
cryo can extract all historical uniswap trades with this command:
cryo logs --topic0 0xc42079f94a6350d7e6235f29174924f928cc2ac818eb64fed8004e115fbcca67
@EthSecurity1
GitHub
GitHub - paradigmxyz/cryo: cryo is the easiest way to extract blockchain data to parquet, csv, json, or python dataframes
cryo is the easiest way to extract blockchain data to parquet, csv, json, or python dataframes - paradigmxyz/cryo
🔥6👍2
Patch Thursday — Security risks due to exchange rate manipulation of ibToken
From Exploit to Recovery: Unraveling DeFi Incidents with Spreek
Secrets of Successful Bug Hunting: Insights from Pro Whitehats and Immunefi with Mackenzie
@EthSecurity1
From Exploit to Recovery: Unraveling DeFi Incidents with Spreek
Secrets of Successful Bug Hunting: Insights from Pro Whitehats and Immunefi with Mackenzie
@EthSecurity1
Medium
Patch Thursday — Security risks due to exchange rate manipulation of ibToken
This article introduces the concept and principles of ibToken and sheds light on the security risks of ibToken exchange rate manipulation.
🔥2
Guide To Advanced Calldata | Everything You Need To Know
Behind the Scenes of Smart Contract Security Reviews - Engn33r
smart contract audit tools
@EthSecurity1
Behind the Scenes of Smart Contract Security Reviews - Engn33r
smart contract audit tools
@EthSecurity1
YouTube
Guide To Advanced Calldata | Everything You Need To Know
Are you a security researcher looking to join a world-class team? Apply to open positions at Guardian here: https://guardianaudits.com
Interested in getting hands-on training to become an expert security researcher in a matter of months?
Get the guide to…
Interested in getting hands-on training to become an expert security researcher in a matter of months?
Get the guide to…
👍7
Differential Fuzzing On Solidity Fixed-Point Libraries link
Pre-deployment Analysis of Smart Contracts -- A Survey link
With Trail to Follow: Measurements of Real-world Non-fungible Token Phishing Attacks on Ethereum. link
@EthSecurity1
Pre-deployment Analysis of Smart Contracts -- A Survey link
With Trail to Follow: Measurements of Real-world Non-fungible Token Phishing Attacks on Ethereum. link
@EthSecurity1
ventraldigital
Fuzzing Vyper Contracts Using Foundry • Ventral Digital
Ventral Digital LLC is a research and consultancy firm specializing in Information Security and Privacy.
👍3
Arbiter - EVM logic simulator for security and performance testing @EthSecurity1
YouTube
Arbiter - EVM logic simulator for security and performance testing
Arbiter is a tool build by Primitivefinance in order to rigorously test the performance and security of their own protocol. Arbiter is pure Rust. It uses a Rust-based EVM called revm in order to run smart contracts directly (revm is used inside of the Anvil…
👍4❤2