Ultimate magazine theme for WordPress.

Recent DeFi exploits show that audits are not a guarantee

Two recent catastrophic attacks on two DeFi protocols were different in many ways, but had one thing in common: both were subject to multiple audits.

Raft Finance, a stablecoin provider inspired by Liquity but backed by Staked Ether, fell victim to an Infinite Mint bug two weeks ago. KyperSwap experienced a depletion of its liquidity pools on November 23rd.

The post-mortem analysis of the incident by the Raft team noted that “the exploited Raft smart contracts were audited by Trail of Bits and Hats Finance.” Unfortunately, the vulnerabilities that led to the incident were found in these Audits not discovered.”

Kyber Network similarly noted its platform’s audits by respected security experts, including 100proof, ChainSecurity, and participants in an audit competition organized by Sherlock.

Raft had even more audits conducted by Curious Apple and Aviggiano throughout 2023, indicating ongoing security assessments and improvements that have led observers to question the assumption that an audited protocol is necessarily secure.

Read more: Raft Finance Releases User Rescue Plan After Strange Exploit

What is needed is a “paradigm shift” in the way blockchain projects deal with threats in light of such examples, says Dave Schwed, Halborn’s chief operating officer, highlighting the “sophisticated manipulation of smart contract functions.”

“It highlights the importance of projects taking a proactive and layered approach to security and not relying solely on external audits,” Schwed told Blockworks.

Other smart contract specialists, including security researcher Storming0x of Yearn Finance, agree. They said up

It is also difficult for regular users to see whether an audit covers the final code in production.

The devil’s weak point is in the details

In theory, a user could compare the reviewed code with the currently released version, Schwed noted.

“Most audit reports show, or should show, a hash of the repository of the code being audited,” he said. “There should be an automated mechanism to compare the tested code and the code in production to increase transparency and trust.”

Michael Lewellen, head of solution architecture at Open Zeppelin, noted that “change management” – ensuring that the production version matches the tested version – was not an issue in Raft’s case. However, he sees a tendency among some development teams to ignore the advice of their auditors.

“Although Trail of Bits overlooked the flaw itself, it noted in its report that the Raft codebase could have improved its testing and verification,” Lewellen told Blockwoks.

“These recommendations should not be taken lightly by projects that might otherwise assume that the audit report gives them the all-clear to launch without making improvements to other parts of their security package,” he added.

Make user partially complete

After receiving feedback that it was unfair to exclude those who sold their R after the Depeg incident, Raft withdrew its original recovery plan.

A revised “recovery plan” was released on Friday, giving victims until the end of March 2024 to recoup some of their losses.

“After extensive feedback from the Raft community, the Raft recovery plan was finalized, resulting in a 42% recovery rate. This guide is intended for all affected users enrolled in the Raft Recovery Plan to claim their DAI,” the plan states.

For Kyber, the magnitude of the loss was significantly larger – about $48 million. The path to recovery is still unclear.

The KyberSwap exploit, known for its unusual sophistication, has left DeFi users wondering what the return could be that could justify their risk appetite.

Don’t miss the next big story – sign up for our free daily newsletter.

Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers

Comments are closed.

%d bloggers like this: