HashEx
A Look inside a Smart Contract Audit
Published
Last, but not least, we use Tenderly.co for reviewing the mined transactions.
During the audit, figuring out the project and discovering the issues is the actual hardest part.
And after we give the preliminary report to the client, they might ask to lower the severity of an issue or remove something altogether. Of course, this has to be carefully managed because we wouldn’t compromise the integrity of the service we provide.
Stay safe and trust in research!
Never put your DeFi security down!
Besides the golden rules above, you should remember that there is hardly a comprehensive list to cover all potential vulnerabilities. The more blockchain and DeFi grow, the more sophisticated attempts hackers create to exploit the systems and steal your money.
HASHEX
Comments
2The interview is useful for understanding the handoff from automated findings to manual investigation. A tool warning still needs a reachable impact before it becomes a report finding. Could a follow-up trace a single warning through that investigation? I would want to see the input that reproduces the issue. The final report entry could then explain how the observed behavior supports its impact assessment.
A worked example of a disputed finding would be an interesting follow-up. The reasoning behind a severity decision can be as useful as the label itself. It would help to retain the assumptions each side used. A reproduction under those assumptions could show why the final classification changed.
Leave a comment
Share a question or observation about this article.