Investment

As faith in audits falter, the DeFi community ponders security alternatives

img-ads

As the attacks launched against popular decentralized finance (DeFi) protocols grow ever-more complex, the efficacy of audits from major security companies have in turn come under scrutiny — and some members of the DeFi community have already begun building homegrown alternatives.

“I think that now, after all the hacks we’ve had, we basically understand that if you have two audits, three audits, it doesn’t mean you’re safe,” said the co-founder of DeFi Italy Emiliano Bonassi in an interview with Cointelegraph. “This does not mean that audits have no value in this moment, but they are not silver bullets.”

This new reality is what pushed Bonassi to form ReviewsDAO. A simple forum for connecting security experts and projects looking for an extra set of eyes, in the three days since its launch ReviewsDAO has already attracted four volunteer reviewers (including Bonassi), and has matched two reviewers with a project.

Bonassi and ReviewsDAO aren’t alone, either. Code 423n4 is another project aiming to jumpstart a security movement within the ecosystem, leveraging an gamified, experimental twist on bug bounties. And likewise Immunefi, another DeFi bounty platform that launched in December last year, is overhauling the security disclosure model by pushing for upwards of 10% of vulnerable funds as a reward. 

Immunefi’s model in particular has already made waves, successfully netting a whitehat a $1.5 million reward.

Three new projects emerging in just two months, and each with their own incentive model — it’s an industry-wide effort Stani Kulechov, the founder of DeFi lending platform Aave, believes will be key to the health and security of the space moving forward.

“Auditors are not here to guarantee the security of a protocol, merely they help to spot something that the team itself wasn’t aware of. Eventually it’s about peer review and we need to find as a community incentives to empower more security experts into the space.”

“No silver bullets”

Bonassi should be a familiar name to anyone who has kept up with the recent spate of exploits. The Italian developer is one of the half-dozen or so white-hat hackers who frequently convene in the wake of an attack in an effort to replicate the exploit and help projects patch the vulnerabilities

Ask just about any DeFi founder about Bonassi and his fellow post-exploit “war room” whitehats, and they’ll be quick to sing their praises.

“The DeFi community is blessed to have whitehats such as Samczsun and Emiliano. Their efforts […] makes the space not only more secure but also highlights the narrative that there is lot of people within our ecosystem that cares for the success of the space,” said Kulechov.

While the whitehats’ response skills are widely appreciated, ReviewsDAO is in some ways an effort to cut back the frequency with which projects need them.

In Bonassi’s view, tension between the needs of projects and the limited resources of auditing firms is weakening the security of the Defi space writ large: auditors are always busy, but teams in the thick of the DeFi innovation race need to remain agile. While a project might want an audit on a few small changes, availability and costs often necessitate a larger order, leading to code “chunking.”

“Since they are not available, you usually prepare a bunch of stuff you want reviewed and ship it to them. The interaction is really, let’s say ‘snapshot-based,’ rather than having a continuous collaboration,” said Bonassi.

So, how to enable more frequent security reviews that better met the needs of projects? Bonassi says he initially considered a Gitcoin grant for a whitehat group as a solution, but ultimately determined that such a model would be overly-centralized and wouldn’t be able to scale. None of his whitehat peers had insight on how to solve the problem, either, so he opted for simplicity.

“If you don’t have any sort of idea, start from the basics: start a forum, let’s say a ‘market,’ where people can ask for reviews big or little, and also offer their expertise.”

He’s not aiming to replace audits and auditing companies entirely, Bonassi notes, and instead envisions the DAO as one that can help younger projects better prepare for an audit by providing “continuous review” and “liquid auditing.”

It’s a model that security expert Maurelian at OptimismPBC thinks leaves space for big auditing firms, while also acknowledging that there needs to be other security solutions as well. 

“IMO there is real value to an audit by a high quality firm, and nothing else really serves as an ‘alternative’, but I also think there is an issue of over-reliance on audits to provide security,” he said. 

Bonassi also believes ReviewsDAO could eventually become a kind of auditing “University,” where people with specialized knowledge can branch into other areas and young developers can grow into fully-fledged auditors — both taking stock of and bolstering the developer resources across DeFi.

“My goal is also to map people and projects — having a transparent place where people can exchange information, help us to understand how many people who are, basically, from a security perspective good enough, are present in the ecosystem.”

Skin in the game

While it meets a clear market need, Bonassi says there are no current plans for monetization or a ReviewsDAO token.

“I think that initiatives like this one should be community goods,” he argues.

This effort to avoid capital incentives is more than just idealism. These new auditing projects are arising because the current model isn’t fully sustainable, says Bonassi — a model that is “transactional,” meaning auditors don’t have as skin in the game that a more fully-engaged partner might. As a result the entire DeFi landscape (one which the auditors should ostensibly be securing) is suffering.

“They’re not a relationship. It’s not a partnership,” Bonassi says.

Nonetheless, even public good often have public funding, and it’s an open question whether developers  — who are often overworked to begin with — will be willing to donate time at what Andre Cronje calls the “Emiliano Bonassi Rate”: for no reward other than the recognition.

Bonsai notes that multiple major DeFi protocol founders have offered grants, which thusfar have been turned down. He’s stubborn to see if developers are willing to give back to the space that’s often given them so much, even when there’s other, potentially lucrative options available.

“What we really need in this ecosystem is more people who work on it — let’s say, someone may hate me but, less forks if they’re not adding value […] I don’t want to end up in the ICO era. I don’t want to go back to 2017.”

Early returns on the effort are promising. Coverage/insurance protocol Cover was the first project to be matched with a reviewer via ReviewsDAO.

“It was great,” says Pumpkin, a core dev for Cover Protocol and Ruler Protocol. “I was one of the few Emiliano shared the idea with right before release. I loved it immediately as it is what I have been looking for (to get external code reviews and more easily and quickly) […] I am not sure what will come out from the review, but the forum is certainly working well as intended.”

Maurelian also believes there’s hope for the perhaps-idealistic model — and that it may be more transactional than it seems at first blush.

“You get what you give. So participating in a project like this is probably a good idea if you’re planning to be in the space for the long haul,” he said.

Even if some developers donate time to curry future favors, Emiliano remains resolute is his vision that efforts secure the ecosystem should come from a place of altruism and love.

“That’s the ideal we should push. And since we have a lot of money, and this industry has a lot of money, you’re not supposed to need bounties, you’re supposed to do it because you love this industry. This is a call-out to all the people that want to grow the ecosystem.”

img-ads

Leave a Comment

Your email address will not be published.

You may also like

Bitcoin

$5.64 billion liquidated in 24 hours as Bitcoin extends losses — Is a relief rally near?

The price of Bitcoin (BTC) plummeted by more than 17% in the last 24 hours as the futures market saw mass liquidations across the board.

Liquidations occur when leveraged futures positions fall to a certain threshold. For example, a position using 10x leverage would get liquidated or turn worthless if the price of BTC drops by 5%.

What triggered the mass Bitcoin liquidation fest?

If the Bitcoin futures market is highly overleveraged and overcrowded, a minor price movement can trigger mass liquidations.

According to analysts at Santiment, a data analytics firm, an address was responsible for the second-largest Bitcoin transaction of the year, as Cointelegraph reported.

More than 2,700 BTC were transferred right before the drop, which were bigger than the 2,000 BTC inflow seen before the March 2020 crash when Bitcoin dropped below $4,000. The analysts said:

“As we noted yesterday, there was an 11x exchange inflow…

View More Article
Bitcoin Investment Latest Policy & Regulation Tech

Major Asian banks unite to form ‘multiple’ CBDC pact on blockchain

Several major banks across Asia have joined forces to construct a cross-border central bank digital currency, according to a joint announcement issued on Feb. 23.

Dubbed the Multiple Central Bank Digital Currency Bridge — or m-CBDC — the project sees the Hong Kong Monetary Authority, the Bank of Thailand, the Central Bank of the United Arab Emirates, and the Digital Currency Institute of the People’s Bank of China combine to create a CBDC prototype using distributed ledger technology.

Building upon the “Inthanon-LionRock” research project started in 2019, the latest phase of the exploration into CBDCs will develop a proof-of-concept to “facilitate real-time cross-border foreign exchange payment-versus-payment transactions in a multi-jurisdictional context and on a 24/7 basis,” states the announcement.

The stated aim of the project is to address “pain points” in conducting cross-border transfers. These include cost inefficiencies and the complex regulation which accompanies moving…

View More Article
Blockchain Business Latest Tech

State Bank of India joins JPMorgan’s blockchain payments network

The State Bank of India, or SBI, a major Indian government-owned bank, is looking to improve cross-border payments with a blockchain solution by American investment bank JPMorgan Chase.

According to a Feb. 23 report by The Economic Times, the SBI has joined Liink, a new blockchain-based interbank data network developed by JPMorgan. By integrating the technology, the bank expects to reduce transaction costs and improve cross-border payments for its customers.

SBI deputy managing director Venkat Nageswar said that the bank has already gone live on Liink. “We are excited to be the first bank in India to go live on the network and look forward to closer partnership with JPMorgan on implementation and exploring applications as part of the network to better serve our clients,” Nageswar stated.

Liink is a peer-to-peer network and ecosystem operating under the umbrella of JPMorgan’s blockchain and digital currency-focused business dubbed “Onyx.”…

View More Article
Bitcoin Markets

Bitcoin falls to $45K in sequel to 20% BTC price crash

Bitcoin (BTC) extended its losses on Feb. 23 as selling pressure took markets below $47,000 for the first time in over a week. 

BTC/USD 1-hour candle chart (Bitstamp). Source: Tradingview

Fresh dive takes BTC/USD to 8-day lows

Data from Cointelegraph Markets and TradingView painted a gloomy picture for bulls on Tuesday as BTC/USD hit lows of $45,000 on Bitstamp. 

The losses reverse a rebound that halted Monday’s 20% price crash from all-time highs near $58,000. Bitcoin bounced at $47,400 on the day to return to $54,000 before a fresh dip took hold.

At the time of writing, $47,000 was again acting as some form of focus for support, with the trajectory still unclear amid heavy volatility.

Analysis of buy and sell positions produced little hope for stemming losses should that level fail, with support lacking below $46,500.

BTC/USD support and resistance levels chart. Source: WhaleMap

$50,000 set…

View More Article
Bitcoin Investment Opinion Tech

Bill Gates warns Bitcoin buyers: If you have less money than Elon Musk — watch out

Microsoft founder Bill Gates has issued a warning to would-be Bitcoin (BTC) buyers looking to follow Elon Musk’s investment strategy. Speaking to Bloomberg’s Emily Chang, Gates suggested Musk had access to sophisticated trade management techniques that the average investor isn’t privy to.

When asked about the susceptibility of Bitcoin to tumble in price in reaction to a mere tweet (undoubtedly a reference to Elon Musk’s own social media posts), Gates said Elon Musk was probably insulated from such market crashes:

“Elon has tons of money and he’s very sophisticated so, you know, I don’t worry that his Bitcoin would randomly go up or down.”

On Feb. 23, little over two weeks since Tesla’s $1.5 billion acquisition of Bitcoin was announced, the price of Bitcoin fell 20% — from $58,258 to $46,624. At the same time, almost $400 billion was wiped off the…

View More Article
Bitcoin Tech

Bank of Korea chief says crypto has no intrinsic value, expects volatility

Amid a major downward correction in the cryptocurrency market, the head of South Korea’s central bank is skeptical about digital currencies like Bitcoin (BTC).

Bank of Korea Governor Lee Ju-yeol said that crypto assets like Bitcoin have no intrinsic value, local news agency Yonhap reports Tuesday. The official said that he expects more price swings on the market, stating, “It is very difficult to predict the price, but its price will be extremely volatile.”

Speaking at the National Assembly, Lee also addressed possible reasons behind the recent sharp crypto rally, which led Bitcoin to become a $1 trillion asset. The BOK governor cited a number of factors including global concerns over excessive inflation, growing institutional interest, as well as a massive $1.5 billion Bitcoin purchase by Elon Musk’s Tesla.

“These assets saw a steep rise in the shortest period of time,” Lee stated. “I would…

View More Article
%d bloggers like this: