#aave
Fork mainnet, doubt the callback, and never trust a rebasing balance. Abstract Aave is one of DeFi's most composable liquidity protocols. That is exactly why it keeps showing up in security reviews of protocols that are not Aave:...
SPIN TO REVEAL
0%
Trace the circle. Wake the page.
Tags
Fork mainnet, doubt the callback, and never trust a rebasing balance. Abstract Aave is one of DeFi's most composable liquidity protocols. That is exactly why it keeps showing up in security reviews of protocols that are not Aave:...
PPS is not an oracle. Yield is not collateral. Composability is just dependency injection with money. Source boundary This post covers publicly verifiable Yearn related integration issues: official incident disclosures, Code4rena...
Not your shares, not your solvency. Lido is one of the most widely integrated pieces of Ethereum infrastructure, and that is exactly why its integration bugs are interesting. Most of the serious incidents and audit findings around...
Commit first. Fold later. If it is not in the transcript, it did not happen. Plonky3 is easiest to misunderstand if we read it as a large Rust repository. The generics are long, the traits are layered, and the concrete examples as...
If the invariant is not enforced at the boundary, the mempool will prove the counterexample. Scope and thesis This post collects real, public fixed point AMM failures and near failures across production incidents, whitehat disclos...
Private bytes, public claims, no unconstrained wires. Version note This article studies the zkSecurity report on zk email and the code versions explicitly covered by that report. All GitHub paths are fixed to the audited commits r...
Bind the witness, or the witness binds you. Introduction Ziren is one of the more interesting zkVM targets we have looked at in a while, partly because it does not follow the now familiar RISC V path. It takes a MIPS32R2 execution...
If it is not in the statement, it belongs to the prover. Introduction Pico is exactly the kind of zkVM that rewards a close audit. On the surface, the pitch is compelling: a high performance, modular zkVM with multiple proving bac...
In zk systems, every shortcut becomes part of the threat model. Introduction Jolt is one of the more interesting zkVMs to read closely because it is not trying to hide its design tradeoffs. At a high level, Jolt takes a pragmatic...
Small tools, sharp edges, real workflows. I wanted a simple thing: open multiple ChatGPT tabs, give each tab its own list of prompts, and let each tab work through its own queue without talking to the others. No global dashboard....
The chain is the law. The app is merely what the law makes possible. 1. The shift: from smart contracts to systems of power For a long time, I looked at Web3 through the application layer. Which DEX has more volume? Which lending...
Small tools, sharp edges, real workflows. I wanted a simple thing: open multiple ChatGPT tabs, give each tab its own list of prompts, and let each tab work through its own queue without talking to the others. No global dashboard....
There is no such thing as "just an ERC20." Abstract The most dangerous token integration bugs rarely start with an obviously malicious contract. They usually start with a reasonable interface, a familiar symbol, and a hidden assum...
Not your shares, not your solvency. Lido is one of the most widely integrated pieces of Ethereum infrastructure, and that is exactly why its integration bugs are interesting. Most of the serious incidents and audit findings around...
Never trust spot. Never trust callbacks. Never trust a pool you did not whitelist. Abstract Uniswap v3 is not merely a swap venue. For protocols that integrate it, it is a callback driven execution environment, a permissionless po...
There is no such thing as "just an ERC20." Abstract The most dangerous token integration bugs rarely start with an obviously malicious contract. They usually start with a reasonable interface, a familiar symbol, and a hidden assum...
"One wei in, one vault out." Empty liquidity is not a neutral state. The phrase "First Deposit" sounds deceptively narrow. It suggests a bug that only exists in the first transaction of a vault, or a minor edge case that disappear...
If the invariant is not enforced at the boundary, the mempool will prove the counterexample. Scope and thesis This post collects real, public fixed point AMM failures and near failures across production incidents, whitehat disclos...
There is no such thing as "just an ERC20." Abstract The most dangerous token integration bugs rarely start with an obviously malicious contract. They usually start with a reasonable interface, a familiar symbol, and a hidden assum...
"One wei in, one vault out." Empty liquidity is not a neutral state. The phrase "First Deposit" sounds deceptively narrow. It suggests a bug that only exists in the first transaction of a vault, or a minor edge case that disappear...
If the invariant is not enforced at the boundary, the mempool will prove the counterexample. Scope and thesis This post collects real, public fixed point AMM failures and near failures across production incidents, whitehat disclos...
If the invariant is not enforced at the boundary, the mempool will prove the counterexample. Scope and thesis This post collects real, public fixed point AMM failures and near failures across production incidents, whitehat disclos...
The chain is the law. The app is merely what the law makes possible. 1. The shift: from smart contracts to systems of power For a long time, I looked at Web3 through the application layer. Which DEX has more volume? Which lending...
No invariant, no mercy. Scope This article is not a review of whether Uniswap v4 core is safe. The core protocol has its own security model, audits, bug bounty process, and threat boundaries. The focus here is narrower and, in pra...
Imperishable Night, but the boundary between miss and Game Over has been politely postponed. Sometimes the hardest part of a Touhou run is not the bullet pattern. Sometimes it is getting far enough into the game to understand what...
DYOR, but also read the diff. There is a particular kind of Web3 infrastructure project that is difficult to judge from the outside. It is not obviously fake. It has serious people around it, sometimes real research, sometimes non...
Fork mainnet, doubt the callback, and never trust a rebasing balance. Abstract Aave is one of DeFi's most composable liquidity protocols. That is exactly why it keeps showing up in security reviews of protocols that are not Aave:...
Never trust spot. Never trust callbacks. Never trust a pool you did not whitelist. Abstract Uniswap v3 is not merely a swap venue. For protocols that integrate it, it is a callback driven execution environment, a permissionless po...
No invariant, no mercy. Scope This article is not a review of whether Uniswap v4 core is safe. The core protocol has its own security model, audits, bug bounty process, and threat boundaries. The focus here is narrower and, in pra...
In zk systems, every shortcut becomes part of the threat model. Introduction Jolt is one of the more interesting zkVMs to read closely because it is not trying to hide its design tradeoffs. At a high level, Jolt takes a pragmatic...
Commit first. Challenge later. If it is not in the transcript, it did not happen. Plonky3 is best understood as a toolkit, not as a single proving system with one blessed prove() button and one fixed set of cryptographic choices....
Fork mainnet, doubt the callback, and never trust a rebasing balance. Abstract Aave is one of DeFi's most composable liquidity protocols. That is exactly why it keeps showing up in security reviews of protocols that are not Aave:...
Not your shares, not your solvency. Lido is one of the most widely integrated pieces of Ethereum infrastructure, and that is exactly why its integration bugs are interesting. Most of the serious incidents and audit findings around...
Not your shares, not your solvency. Lido is one of the most widely integrated pieces of Ethereum infrastructure, and that is exactly why its integration bugs are interesting. Most of the serious incidents and audit findings around...
Imperishable Night, but the boundary between miss and Game Over has been politely postponed. Sometimes the hardest part of a Touhou run is not the bullet pattern. Sometimes it is getting far enough into the game to understand what...
DYOR, but also read the diff. There is a particular kind of Web3 infrastructure project that is difficult to judge from the outside. It is not obviously fake. It has serious people around it, sometimes real research, sometimes non...
PPS is not an oracle. Yield is not collateral. Composability is just dependency injection with money. Source boundary This post covers publicly verifiable Yearn related integration issues: official incident disclosures, Code4rena...
Welcome to osu! Github Repo: https://github.com/N0zoM1z0/oszillator Live demo: https://n0zom1z0.github.io/oszillator/ Autoplay demo video: https://youtu.be/4uOumV5hzYE / https://www.bilibili.com/video/BV13VRSBFEaS/ https://youtu.b...
If it is not in the statement, it belongs to the prover. Introduction Pico is exactly the kind of zkVM that rewards a close audit. On the surface, the pitch is compelling: a high performance, modular zkVM with multiple proving bac...
Commit first. Fold later. If it is not in the transcript, it did not happen. Plonky3 is easiest to misunderstand if we read it as a large Rust repository. The generics are long, the traits are layered, and the concrete examples as...
Commit first. Challenge later. If it is not in the transcript, it did not happen. Plonky3 is best understood as a toolkit, not as a single proving system with one blessed prove() button and one fixed set of cryptographic choices....
Prove the root. Hide the leaf. Burn the nullifier. Semaphore looks deceptively simple from the outside: prove that a user belongs to a group, let the user send a message, keep the user anonymous, and stop the same user from signal...
Imperishable Night, but the boundary between miss and Game Over has been politely postponed. Sometimes the hardest part of a Touhou run is not the bullet pattern. Sometimes it is getting far enough into the game to understand what...
Fork mainnet, doubt the callback, and never trust a rebasing balance. Abstract Aave is one of DeFi's most composable liquidity protocols. That is exactly why it keeps showing up in security reviews of protocols that are not Aave:...
Never trust spot. Never trust callbacks. Never trust a pool you did not whitelist. Abstract Uniswap v3 is not merely a swap venue. For protocols that integrate it, it is a callback driven execution environment, a permissionless po...
No invariant, no mercy. Scope This article is not a review of whether Uniswap v4 core is safe. The core protocol has its own security model, audits, bug bounty process, and threat boundaries. The focus here is narrower and, in pra...
Prove the root. Hide the leaf. Burn the nullifier. Semaphore looks deceptively simple from the outside: prove that a user belongs to a group, let the user send a message, keep the user anonymous, and stop the same user from signal...
"One wei in, one vault out." Empty liquidity is not a neutral state. The phrase "First Deposit" sounds deceptively narrow. It suggests a bug that only exists in the first transaction of a vault, or a minor edge case that disappear...
Commit first. Fold later. If it is not in the transcript, it did not happen. Plonky3 is easiest to misunderstand if we read it as a large Rust repository. The generics are long, the traits are layered, and the concrete examples as...
Commit first. Challenge later. If it is not in the transcript, it did not happen. Plonky3 is best understood as a toolkit, not as a single proving system with one blessed prove() button and one fixed set of cryptographic choices....
There is no such thing as "just an ERC20." Abstract The most dangerous token integration bugs rarely start with an obviously malicious contract. They usually start with a reasonable interface, a familiar symbol, and a hidden assum...
Imperishable Night, but the boundary between miss and Game Over has been politely postponed. Sometimes the hardest part of a Touhou run is not the bullet pattern. Sometimes it is getting far enough into the game to understand what...
Never trust spot. Never trust callbacks. Never trust a pool you did not whitelist. Abstract Uniswap v3 is not merely a swap venue. For protocols that integrate it, it is a callback driven execution environment, a permissionless po...
No invariant, no mercy. Scope This article is not a review of whether Uniswap v4 core is safe. The core protocol has its own security model, audits, bug bounty process, and threat boundaries. The focus here is narrower and, in pra...
Small tools, sharp edges, real workflows. I wanted a simple thing: open multiple ChatGPT tabs, give each tab its own list of prompts, and let each tab work through its own queue without talking to the others. No global dashboard....
PPS is not an oracle. Yield is not collateral. Composability is just dependency injection with money. Source boundary This post covers publicly verifiable Yearn related integration issues: official incident disclosures, Code4rena...
"One wei in, one vault out." Empty liquidity is not a neutral state. The phrase "First Deposit" sounds deceptively narrow. It suggests a bug that only exists in the first transaction of a vault, or a minor edge case that disappear...
Welcome to osu! Github Repo: https://github.com/N0zoM1z0/oszillator Live demo: https://n0zom1z0.github.io/oszillator/ Autoplay demo video: https://youtu.be/4uOumV5hzYE / https://www.bilibili.com/video/BV13VRSBFEaS/ https://youtu.b...
DYOR, but also read the diff. There is a particular kind of Web3 infrastructure project that is difficult to judge from the outside. It is not obviously fake. It has serious people around it, sometimes real research, sometimes non...
The chain is the law. The app is merely what the law makes possible. 1. The shift: from smart contracts to systems of power For a long time, I looked at Web3 through the application layer. Which DEX has more volume? Which lending...
PPS is not an oracle. Yield is not collateral. Composability is just dependency injection with money. Source boundary This post covers publicly verifiable Yearn related integration issues: official incident disclosures, Code4rena...
Bind the witness, or the witness binds you. Introduction Ziren is one of the more interesting zkVM targets we have looked at in a while, partly because it does not follow the now familiar RISC V path. It takes a MIPS32R2 execution...
Prove the root. Hide the leaf. Burn the nullifier. Semaphore looks deceptively simple from the outside: prove that a user belongs to a group, let the user send a message, keep the user anonymous, and stop the same user from signal...
Private bytes, public claims, no unconstrained wires. Version note This article studies the zkSecurity report on zk email and the code versions explicitly covered by that report. All GitHub paths are fixed to the audited commits r...
Private bytes, public claims, no unconstrained wires. Version note This article studies the zkSecurity report on zk email and the code versions explicitly covered by that report. All GitHub paths are fixed to the audited commits r...
Bind the witness, or the witness binds you. Introduction Ziren is one of the more interesting zkVM targets we have looked at in a while, partly because it does not follow the now familiar RISC V path. It takes a MIPS32R2 execution...
If it is not in the statement, it belongs to the prover. Introduction Pico is exactly the kind of zkVM that rewards a close audit. On the surface, the pitch is compelling: a high performance, modular zkVM with multiple proving bac...
In zk systems, every shortcut becomes part of the threat model. Introduction Jolt is one of the more interesting zkVMs to read closely because it is not trying to hide its design tradeoffs. At a high level, Jolt takes a pragmatic...