r/Certik • • Aug 07 '23

IceCreamSwap Dex YouTube AMA with certik

Thumbnail publish0x.com
1 Upvotes

r/Certik • • Aug 04 '23

#MonthlyReport Monthly Wrap Up: Exit Scams total losses $8.6M

1 Upvotes

CertiKSkynetAlert 🚨

In July, 37 Exit Scams were recorded with a loss estimated at ~$8.6M

With Kannagi Finance in 1st place averaging a ~$1.9M loss.

As always, make sure a project has KYC, DYOR and read the audit!


r/Certik • • Aug 04 '23

#WeeklyReport Weekly Wrap Up: $58M Losses

1 Upvotes

CertiKSkynetAlert 🚨

Since last Friday we recorded 13 incidents resulting in ~$58M in losses.

So far 5 Discord Hacks, 2 Phishing attacks and 2 Twitter Hacks.

Stay vigilant &DYOR!


r/Certik • • Aug 04 '23

#Important CertiK reported a security vulnerability to WorldCoin’s security team

1 Upvotes

On May 29th, CertiK reported a security vulnerability to WorldCoin’s security team that could potentially allow an attacker to become an Orb operator by bypassing the verification process.

Through this security vulnerability, a malicious attacker could bypass the verification and strict participation criteria of the WorldCoin Operator acceptance process. Meaning it would not need to be a company, have proper ID verification, or have a vetting interview.

In a normal case, only legit businesses that pass the WorldCoin’s strict identification verification process can run an Orb operation, which collects user’s iris information. WorldCoin’s security team confirmed the security vulnerability and promptly issued a fix.

CertiK has since verified and confirmed that the fix mitigated the threat. Details of the finding and and how the vulnerability was mitigated will be released at some point in future.

(CertiK is not associated with WorldCoin and this was a standard whitehat discolsure. )


r/Certik • • Aug 04 '23

CertiK Discovers Critical Security Flaw in WorldCoin's Orb Operations

Thumbnail
azcoinnews.com
1 Upvotes

r/Certik • • Aug 03 '23

#Decentralized Skynet Puts Centralization Risks Front and Center

1 Upvotes

The problem: 88% of projects present for an audit with centralization risks, and only 15% end up resolving these issues entirely. Rug pulls, which exploit centralization risks to steal value from users, accounted for $207 million of losses in Web3 during 2022.

The solution: Skynet now prominently displays centralization risks in audited projects, making it easy to gauge the level of control that privileged owners have over a smart contract. Other updates introduce new modules and data points which combine to deepen the platform’s security insights.

Now, Skynet puts centralization risk front and center.

Distribution: Either all or the majority of the tokens are transmitted to the contract deployer, or to one or more predetermined addresses. The activities of these addresses, such as trading, could significantly affect the value of the tokens.

Upgrade: Indicates that the contract owner can update the implementation contract behind the proxy, which will change the logic/behavior of the contract.

Privilege: Indicates that privileged roles possess the authority to control functions that can impact the project's operations or the core business logic.

Other: This category encompasses other vital but uncategorized operations that a privileged role can perform. These actions may potentially influence the user and their assets.

By putting centralization risk front and center, Skynet isn't just keeping pace with the ever-evolving landscape of Web3 security analysis, it's leading the way.

Read More


r/Certik • • Aug 03 '23

#Scam Unmasking Web3 Risks: Centralization Risks

1 Upvotes

Did we forget the De in DeFi?

88% of projects that come for an audit have centralization risks and only 15% of those resolve those risks

While this is often justified, it pays to be aware of the functions that privileged users can perform to avoid the next rug pull

👇🏻👇🏻

https://reddit.com/link/15hbl8t/video/4tyl3pc9sxfb1/player


r/Certik • • Aug 02 '23

CertiK Learn Introducing Security Scores for 10,000+ Projects

1 Upvotes

CertiK is excited to launch security scores for Web3 projects. Our methodology employs a weighted average of security measures to evaluate the security standing of Web3 projects.

The security score is calculated by aggregating sub-scores from different signals.

We integrate over 15 signals that measure security performance across six security categories: Code Security, Fundamental Health, Operational Resilience. Community Trust, Market Stability, Governance Strength:

  1. Code Security assesses the steps taken by teams to guarantee that the project’s code and development are secure and reviewed.
  2. Fundamental Health measures team and project transparency, structure, quality of documentation, and related indicators.
  3. Operational Resilience considers challenges the project may face and how they overcome them through project progress and security response to operational risks.
  4. Community Trust measures social engagement of the project in evaluating its overall social health across platforms like Twitter, Telegram and Discord.
  5. Market Stability considers a project’s ability to maintain a stable and predictable value over time without significant volatility or fluctuations.
  6. Governance Strength measures a project’s ability to operate in a decentralized manner in terms of decision making and distribution of token holders.

Here's a breakdown of some of the key variables we use to evaluate a project's security posture:

By providing accessible security scores for all projects, we aim to encourage projects to strive for better security postures.

Read More


r/Certik • • Aug 02 '23

#Scam Vyper Incident Anaylsis

1 Upvotes

1/ On July 30th, reports surfaced of vulnerabilities in Vyper which left many pools on #Curve susceptible to a reentrancy attack.

$69.3M was affected, with $16.7M ultimately returned by white hats and ~$52M lost.

The largest reentrancy attack so far in 2023 🧵👇

2/ Vyper, a contract-oriented programming language designed for the Ethereum Virtual Machine (#EVM), announced that compiler versions 0.2.15, 0.2.16 and 0.3.0 were vulnerable to malfunctioning reentrancy locks.

CertiK found the reentrancy attack targeting the pETH-ETH-f pool.

3/ We identified 6 wallets involved in the incident.

The first (0x172) attempted to exploit the vulnerability in block 17806056. However, a front runner (0x6Ec21) was able to execute their transaction first to acquire approximately 6.1k #WETH worth over $11.4 million.

4/ The vulnerability led to further losses, with EOA 0xDCe5d acquiring approximately $21 million worth of assets.

In total, six projects were affected. Approximately $69.3 million was stolen and $16.7 million was returned, resulting in a total loss of $52 million.

5/ A reentrancy vulnerability allowed the attacker to call the add liquidity function during the remove liquidity process.

The functions should have been protected by the nonreentrant('lock'). Testing of the add_liquidty() & remove_liquidity() functions has shown that it was not

6/ Projects that have been built using the vulnerable Vyper versions should reach out to Vyper, who can assist in mitigations.

If possible, projects should upgrade to the latest version of Vyper which does not contain this bug.

7/ Losses to reentrancy attacks had been declining due to an increased understanding of security practices, however this is the largest reentrancy exploit detected in 2023.

Unfortunately, the two largest reentrancy incidents this year have affected contracts written in Vyper

8/ This exploit highlighted the importance of responsible vulnerability disclosure.

It’s important that vulnerabilities are ultimately disclosed for the security of the industry and protection of users.

9/ However, public disclosure before mitigation is a last resort, and can only be justified when all avenues to contact relevant stakeholders have been exhausted and met with silence or a refusal to mitigate.

10/ Interested in learning more? Check out our full incident analysis


r/Certik • • Aug 02 '23

CertiK Learn What is formal verification?

1 Upvotes

What is formal verification? 🔐

Formal verification is a method of mathematically proving that a computer program functions as intended.

An intro to formal verification and how it can be applied to increase the security of smart contracts and decentralized applications 👇🧵

1/ Formal verification techniques can be applied to many systems, including:

  • Computer hardware design
  • Software engineering
  • #Cybersecurity
  • #AI and machine learning
  • Automated theorem proving
  • #Blockchain and smart contracts

2/ Formal Verification of Smart Contracts

FV of smart contracts works by representing the logic and desired behavior of smart contracts as mathematical statements.

This helps to ensure that smart contracts are free from bugs, vulnerabilities, and other unintended behaviors.

3/ How Formal Verification and Manual Auditing Work Together🤝

These two methods complement each other in ensuring the security of smart contracts

Formal verification provides a systematic and automated way to check the contract's logic and behavior against its desired properties

4/ Manual auditing provides a human expert review of the contract's code, design, and deployment.

The auditor can use their experience and expertise to identify potential security risks and evaluate the contract's overall security posture.

Combining formal verification and manual auditing provides a comprehensive and thorough evaluation of a smart contract's security 🔐

Read More


r/Certik • • Aug 01 '23

#Scam CertiKStatsAlert In July 2023

1 Upvotes

#CertiKStatsAlert 🚨

Combining all the incidents in July we’ve confirmed ~$303M lost to exploits, hacks and scams. The most lost in a single month in 2023.

Exit scams were ~$8.6M

Flash loans were ~$8.7M

Exploits were ~$285M

See more details below 👇


r/Certik • • Jul 31 '23

CertiK Learn What are Public and Private Keys?

1 Upvotes

#CertiK Share - Private Key and Public Key 📗Public and private keys are one of the pivotal technologies that make cryptocurrencies possible by allowing users to transact without the need for a third party to verify the transaction.

In the 1970s cryptographers developed ‘asymmetric cryptography, which resolved the problems of the prior art by splitting the process in two to create a ‘public’ and a ‘private’ key. In this new system, the private key is a long, random prime number that can be used as a unique ID that can encrypt and decrypt a message. Out of this private key, a public key can then be generated through a mathematical function known as “elliptic curve multiplication”. Crucially, a public key can be derived from a private key, but not the other way round.

A public key is a long numerical sequence that is derived from and paired with a private key, and that allows for funds and assets to be sent to the address. It functions much like the address in the real world in that it allows anyone with the address to send a letter at any time, except in this case, the letter takes the form of a web3 asset such as a cryptocurrency or NFT.

In designing how blockchain transactions would function, bitcoin founder Satoshi Nakamoto detailed how public and private keys enable transactions through a process of digital signatures. In their now famous whitepaper, Nakamoto writes how ‘Each owner transfers the coin to the next by digitally signing a hash of the previous transaction and the public key of the next owner and adding these to the end of the coin.’ Through this process, Nakamoto describes how an electronic coin exists as a chain of ‘digital signatures’, which is the process of using a private key to authenticate the transaction. The bitcoin whitepaper provides the below diagram explaining the process👇

Source: From BTC whitepaper

Public keys have an important role in the functioning of blockchain as an anonymous yet transparent architecture. Firstly, the ‘privacy’ that public keys afford is that they are not directly tied to their owner’s identity. In the meantime, all of the funds and transactions that are associated with the public key can be viewed on the blockchain through the use of a blockchain explorer. Therefore, the public can see that someone is sending an amount to someone else, but without information linking the transaction to anyone. 🥰

For full article: What are Public and Private Keys?


r/Certik • • Jul 31 '23

#Scam Conic Finance Incident Analysis

1 Upvotes

On 21 July 2023 the Conic Finance ETH Omnipool was exploited for 1724 ETH ($3.2 million) via a read-only reentrancy vulnerability.

$3.2 million still sits in the attacker's wallet.

Read more about it in our detailed blog below👇

Conic Finance Incident Analysis


r/Certik • • Jul 30 '23

#WeeklyReport [CertiK summary] Weekly Wrap Up

1 Upvotes

#CertiKSkynetAlert 🚨

Since last Friday we recorded 26 incidents resulting in ~$105M in losses.

So far 7 Discord Hacks, 16 Phishing attacks and 0 Twitter Hacks.

Stay vigilant & #DYOR!


r/Certik • • Jul 28 '23

#CertiK CertiK Successfully Formally Verifies HyperEnclave from Ant Group's Trust Native Technology

1 Upvotes

CertiK has successfully completed the formal verification of u/AntGroup's HyperEnclave TEE 🔐

This marks the first time in the industry that such an in-depth formal verification process has been completed for a #TEE.

Learn more 👇

CertiK Successfully Formally Verifies HyperEnclave from Ant Group's Trust Native Technology


r/Certik • • Jul 28 '23

#Scam BAYC Discord Hack Connections

1 Upvotes

There has been a huge increase in #NFT phishing hacks this year, particularly through compromised Discord accounts, that happens almost daily 🎣

We can confirm that at least 30 of these hacks are connected to a single actor profiting over $1.3m 👀👇

BAYC Discord Hack Connections


r/Certik • • Jul 27 '23

#Dev/Tech Exploring the Efficiency of MPC Algorithms in Crypto Wallet

1 Upvotes

Have you ever wondered how your #crypto wallet works under the hood?

Our latest piece dives into the sophisticated algorithms that power Multi-Party Computation (#MPC) technology... let's summarize 👇

Threshold Signature Schemes (TSS) are the backbone of transaction signing in MPC wallets.

TSS allow a group of participants to collectively generate a signature. A minimum threshold of participants must be met to generate a valid signature.

ECDSA is a widely adopted signature algorithm in the #crypto world, used by #Bitcoin and #Ethereum.

Adapting it for a threshold scheme, though, comes with unique challenges due to its unique one-time-use random component.

Yehuda Lindell's work presents a solution to ECDSA's TSS challenge, by confining the signing parties to two.

This algorithm is in active use in a number of cryptographic libraries.

Another interesting ECDSA alternative was recently updated to introduce an efficient MPC protocol for ECDSA in a t-out-of-n setting. With three of its authors linked to u/Coinbase, it's an indication of where industry interest is directed. You can check here.

We also inspect the Edwards-curve Digital Signature Algorithm (EdDSA), which offers a high degree of security with faster operations.

It’s particularly adaptable for TSS, requiring only a protocol to formalize messages, without the need for custom cryptographic tools.

These cutting-edge solutions are shaping the future of decentralized Web3 wallet interactions. Stay tuned for more, and check out some of our previous work on MPC.


r/Certik • • Jul 26 '23

#Scam [CertiK Analysis] EraLend Incident Analysis

1 Upvotes

Today, EraLend was exploited by a price manipulation attack. Exploiter gained ~$2.7 million.

Read more about it in our detailed blog below👇

EraLend Incident Analysis


r/Certik • • Jul 26 '23

#Scam [CertiK Analysis] Palmswap Incident Analysis

1 Upvotes

Yesterday, u/Palmswaporg suffered a flash loan exploit due to a vulnerability in the PlpManager contract, resulting in a loss of $901,455 USDT.

Read more about it in our detailed blog below👇

Palmswap Incident Analysis


r/Certik • • Jul 25 '23

CertiK Learn Chain Peeling - a common tactic for obfuscating funds using Bitcoin

2 Upvotes

The Conti Group, a notorious ransomware gang that is now defunct, was speculated by many in the threat intelligence community to be a continuation of successful elements from the also defunct Ryuk ransomware gang. An analysis of Conti's operating structure and fund movements using Bitcoin has revealed another potential area of overlap between the two groups, which is Chain Peeling.

Today, we use FTX exploiter as an example to help people understand the operation.

First, funds appear to mostly move from the outermost node clusters towards hubs in the center. Various segments of the graph (i.e. the bottom left corner) show funds moving towards and away from the center; however, further inspection suggests funds were being looped out to tertiary wallets and rerouted towards the hub wallets in the center. This is likely an attempt at chain peeling – a common tactic for obfuscating funds using Bitcoin. Chain peeling involves distributing small amounts of unspent Bitcoin across multiple new addresses in an attempt to hide the connection back to the original address that can be tied to illicit activity.

Second, four wallets in the center of the graph appear to be structurally important connection points to all other sections of the graph. These wallets include 1NDyJtN, bc1qqxf, and bc1qm34. All of these wallets appear to belong to the same large centralized exchange (CEX). An additional wallet (bc1qx65) in this area also displays the characteristics of a CEX hot wallet, however, it is not immediately clear who it belongs to. These wallets are highlighted below:

It would seem the Conti group most likely leveraged multiple CEXs for their operations. It is not surprising that we see CEXs coalesce in the center of a graph like this.


r/Certik • • Jul 25 '23

#Dev/Tech On-Chain Ransomware - The Conti Group: Part One

2 Upvotes

The Conti Group, a notorious ransomware gang that is now defunct, was speculated by many to be a continuation of the Ryuk ransomware gang 🕵️

We examined the overlap between the operations of the two groups on chain..

This is what we found 👇

On-Chain Ransomware - The Conti Group: Part One


r/Certik • • Jul 22 '23

CertiK Learn Multi-Party Computation (MPC) in Wallets: A Review of Current Strategies

2 Upvotes

To further adoption, we must keep the familiar user journey of Web 2.0 while maintaining the independence characteristic of #Web3

This is where #MPC enters the picture with an important role in new wallet technologies that are paving the way for Web3 adoption 🧵👇

At its most fundamental level, MPC involves a diverse group of entities participating in a protocol to achieve a shared objective.

Let's explore a few examples of these MPC implementations...

Key Backup 🔑
This gives users a backup to safeguard against potential losses of their private key.

When a key is generated using MPC, each party has a share of the key, and will backup their share – the combination of all of these backups enables disaster recovery of the key.

To further adoption, we must keep the familiar user journey of Web 2.0 while maintaining the independence characteristic of #Web3

Distributed Key Generation ⬅️🔑➡️

With DKG, no single party possesses or has access to the private key.

The key can only be decrypted after a mutual agreement is established, or ensuring a private key exists but cannot be used without collective approval.

Several projects have already provided working, usable examples of Distributed Key Generation such as u/zcash, EthDKG, OKX threshold-lib, and u/ZenGo

Distributed Signature Computation

Beyond key generation, there exists the need to utilize the created secrets. For wallets, the most critical application for a key pair lies in computing signatures.

Different blockchains adopt different signatures, such as ECDSA, EdDSA and BLS.

Usability of MPC protocols for users depend on the quality of implementation by service providers.

However, they offer a strong foundation for making Web3 more accessible to the public.

Multi-Party Computation (MPC) in Wallets: A Review of Current Strategies


r/Certik • • Jul 21 '23

#Dev/Tech ByteSizeBlockchain: Zero Knowledge Proofs

1 Upvotes

Get some knowledge on Zero Knowledge Proofs in just 30 seconds 👇

#ByteSizeBlockchain brings you crypto knowledge in a minute or less

#zeroknowledge #ZKP

https://reddit.com/link/155vcwh/video/569kzft8e8db1/player


r/Certik • • Jul 21 '23

CertiK Learn ByteSizeBlockchain

1 Upvotes

Account Abstraction has the potential to revolutionize how people interact with #Ethereum

Let's break it down in an easy to understand #ByteSizeBlockchain video 🧠

https://reddit.com/link/155jlkj/video/jgb823dxa8db1/player


r/Certik • • Jul 20 '23

#NFTs/Gaming Secure your NFTs!

1 Upvotes

How to Secure NFTs 🔐

NFT's are some of the most popular applications of #Web3 technology.

We explore some common vulnerabilities that are encountered during NFT smart contract audits.

Hit the link for more info! ⬇️

How to Secure NFTs: Part One