#defi

92 posts · Last used 9d

In an upgradeable proxy, the funds live in the proxy and the logic is swappable. Own the pointer, own everything. This issue covers delegatecall storage collisions (Audius), uninitialized implementations (Wormhole's other bug), UUPS selfdestruct bricking (Parity froze 513k ETH), and the 2025 mempool bots front-running initialize() on fresh proxies. Plus slither-check-upgradeability to catch it. https://www.kayssel.com/newsletter/issue-61/ #InfoSec #CyberSecurity #Web3 #SmartContracts #BugBounty #DeFi
1
1
0
0
де в нас безпечно це складне питання. по факту, CeFi дає зручність, але я тримаю на біржах лише те, що готова втратити завтра. DeFi теж не панацея, але свої ключі це свій ризик, без посередника який може заморозити акаунт. для мене особисто баланс такий: левова частка в холодному гаманці, на біржі тільки робочий капітал для P2P і швидких угод. ліквідність пули на стабільних парах дають відсоток, але я туди не кладу більше ніж можу пережити. ну а військові облігації це взагалі окрема історія, не інвестиція, а внесок. з CeFi в 2026 головний ризик не злом, а регуляторка, яка може вдарити коли не чекаєш. #крипта #deFi #інвестиції
0
0
0
0
Attackers drained $20M+ from protocols built around Uniswap v4 hooks. The two largest were Cork (~$12M) and Bunni ($8.4M). Neither came from bugs in the PoolManager, Uniswap v4's central contract. The failures came from application and hook code. We analyzed dozens of audit findings to isolate seven ways hooks break, and created a checklist for keeping these bugs out of production. https://blog.trailofbits.com/2026/07/30/building-secure-uniswap-v4-hooks/#infosec #DeFi #smartcontracts
2
0
1
0