others
Get Smart – Ending Crypto’s Over-Reliance on Contract Audits – Crypto News
HodlX Guest Post Submit Your Post
Last year was a rollercoaster for crypto. There were aggressive regulatory actions, high-profile criminal convictions and shocking thefts.
And yet the total cryptocurrency market capitalization rose to over $1.4 trillion in 2023, a year-over-year growth of over 70.7%.
New users and institutions are getting involved.
Throughout 2023, the number of crypto investors grew by 2.8% per month, and Goldman Sachs has called it the year crypto became institutionalized.
The bulls and the bears are both right there is immense opportunity in the market right now, but also alarming risk.
The risk isn’t merely rooted in market volatility, though, or even the brazen criminal actions of exchange managers t’s baked into the very mechanisms of crypto transactions.
Smart contacts themselves are a vulnerable and alluring target for hackers, and our methods for securing them are letting us down.
Here’s a quick primer. A smart contract is a self-executing contract used in blockchain transactions. The terms of the transaction are written directly into the lines of the code.
These contracts are a juicy hacking target hey’re used to handle large sums and high-value tokens.
If you can manipulate the contract, you can direct the tokens however you want.
Blockchain entities protect themselves with smart contract audits, wherein independent reviewers inspect the smart contract for design flaws, security vulnerabilities, efficiency and other coding issues.
The auditors issue a public report, listing all the issues found and the steps taken to mitigate them.
So far, so transparent udits help blockchain companies ensure their smart contracts are secure and help investors make informed decisions.
The process is far from foolproof, though. There are no widely adopted standards for smart contract verification, and no audit can truly guarantee that a smart contract is bug-free.
As a result, lots of vulnerabilities slip through the cracks, often with devastating results.
Here are a few examples from 2023 alone.
LendHub $6 million exploit January 2023
LendHub left a depreciated version of the IBSV token in its smart contract during an update. Both the old and new versions were active in the contract at the same price.
Attackers were able to buy the old version and swap for the new, making off with $6 million in additional value.
BonqDAO $120 million exploit February 2023
Attackers were able to manipulate the ‘update price’ function in BonqDAO’s smart contract, allowing them to change the price of the AllianceBlock’s ALBT token.
The hackers then minted and swapped large amounts of tokens, eventually leading to the broad devaluation and liquidation of ALBT.
Euler Finance $197 million exploit March 2023
A flaw in Euler Finance’s smart contract allowed an attacker to deposit collateral and borrow against it without drawing down the initial collateral.
They used this bug to execute a flash loan attack that allowed them to withdraw nearly $200 million worth of ETH-based assets in moments.
We cannot staunch this bleeding with more audits. Euler Finance’s smart contract underwent 10 different audits from six different firms and still fell victim to one of the biggest single hacks of the year.
Part of the problem is that audits are backward-facing. They focus on known vulnerabilities, missing novel exploits.
Hackers are devious and creative we need security measures that can anticipate and respond to entirely new approaches.
AI may be useful in sealing up the cracks in the smart contract audit process.
In experiments using OpenAI’s GPT-4, OpenZeppelin was able to use AI to identify vulnerabilities in 20 out of 28 challenges from the Ethernaut smart contract hacking game.
However, real smart contracts are far more complex, and the opportunities to exploit them more varied than anything in a controlled environment like a game.
And what’s more atching 70% of vulnerabilities isn’t nearly enough.
If your network security team could only stop 70% of attacks, they would all be fired.
We’re going to be waiting at least another generation before AI can seriously assist in smart contract security, and we need solutions now.
These additional measures can be enforced at the wallet level so that transactions are vetted before being sent out on-chain.
Such measures could include addressing inspection to prevent rogue actors from executing contracts, smart contract history that traces any contract changes to their origins or front-running to stop any suspicious transactions before tokens are transferred.
Many smart contact exploits rely on speed. By building more friction into transactions, we can make them safer and less attractive to bad actors.
2024 kicked off with crypto in the strongest position it has occupied in years, but smart contract vulnerabilities have cast a shadow over this progress.
This is an inflection point, where the promise of blockchain meets the realities of its risks.
Now, our task is to get serious about security at every stage of blockchain transactions.
Daniel Chong is the CEO and co-founder of Harpie, the crypto security platform. While pursuing a Mathematics degree at Duke University, Daniel worked as a development and security consultant for a variety of crypto companies, leading award-winning projects to victory at conferences including ETHDenver. He’s dedicated to ending the threat of crypto theft and making smart contracts safe and accessible to all.
Follow Us on Twitter Facebook Telegram
Check out the Latest Industry Announcements
Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any loses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.
-
Metaverse1 week agoHow companies are turning AI on itself to fight fraud – Crypto News
-
Blockchain1 week agoHyperunit Whale Dumps $500M In Ethereum As Massive Crypto Bet Turns Sour – Crypto News
-
others1 week agoGrowth to moderate as BNM holds – UOB – Crypto News
-
others7 days agoIndian Rupee trades calmly against US Dollar ahead of US markets opening – Crypto News
-
Cryptocurrency1 week ago
TRUMP Coin Pumps 5% as Canary Capital Amends ETF Filing With New Details – Crypto News
-
Business1 week ago
Michael Saylor Says Strategy Can Cover Debt Even If Bitcoin Crashes to $8,000 – Crypto News
-
Blockchain1 week agoExtreme Bitcoin Shorts Could Predict A Bottom, Here’s The Significance – Crypto News
-
Business1 week ago
Bitcoin vs. Gold: Expert Predicts BTC’s Underperformance as Options Traders Price in $20K Gold Target – Crypto News
-
Technology1 week agoDevelopers key architect of AI; India stands at the centre: OpenUK CEO Brock – Crypto News
-
others1 week agoBudget support and equity-market push – Commerzbank – Crypto News
-
others1 week ago
XRP Price Prediction Ahead of Potential U.S. Government Shutdown Today – Crypto News
-
others1 week agoSolid growth outlook into 2026 – Standard Chartered – Crypto News
-
Cryptocurrency1 week ago
TRUMP Coin Pumps 5% as Canary Capital Amends ETF Filing With New Details – Crypto News
-
Cryptocurrency1 week agoCrypto Flows to Human Trafficking Services Jump 85% to Hundreds of Millions in 2025 – Crypto News
-
Business1 week ago
Michael Saylor Says Strategy Can Cover Debt Even If Bitcoin Crashes to $8,000 – Crypto News
-
Metaverse1 week agoMaharashtra’s MahaVISTAAR meets Amul’s Sarlaben – Crypto News
-
others1 week ago
Dogecoin, Shiba Inu, Pepe Coin Price Predictions As BTC Crashes Below $68k – Crypto News
-
Blockchain1 week agoLogan Paul Sells Controversial Pokémon card For $16.5M – Crypto News
-
Cryptocurrency1 week agoPublicly Traded Blockchain Lender Figure Confirms Customer Data Breach – Crypto News
-
Cryptocurrency1 week agoPublicly Traded Blockchain Lender Figure Confirms Customer Data Breach – Crypto News
-
Technology1 week agoFuture of AI is a governance question, not a technology race: Vilas Dhar of Patrick J McGovern Foundation | Interview – Crypto News
-
Blockchain1 week agoFigure Technology Data Breach Exposes Customer Personal Information – Crypto News
-
Cryptocurrency1 week agoSaylor’s Strategy (MSTR) Stock Rallies 9% Amid Bitcoin Price Rebound – Crypto News
-
Cryptocurrency1 week agoCould XRP slide toward $0.80 next? THESE signals hold the key – Crypto News
-
Metaverse1 week agoIndia will showcase small AI, early startups at Summit starting tomorrow – Crypto News
-
Technology1 week agoDecoded: AI buzzwords everyone talks about – Crypto News
-
Business1 week ago
Trump-Backed American Bitcoin Reserves Surpass 6,000 BTC, Now Worth $425.82M – Crypto News
-
Metaverse1 week agoMint Primer | Why is there a hype around AI summit in India? – Crypto News
-
Business1 week ago
HOOD and COIN Stock Price Forecast as Expert Predicts Bitcoin Price Crash to $10k – Crypto News
-
Blockchain1 week agoNexo Relaunches Crypto Platform in the United States – Crypto News
-
Metaverse1 week agoQuick commerce showcase to global audience trips on logistics issues – Crypto News
-
others1 week ago
Ethereum Price Outlook as Harvard Shifts Focus from Bitcoin to ETH ETF – Crypto News
-
others1 week agoAmazon Handing $309,000,000 To Customers in Settlement Over Alleged Failure To Refund Returned Items – Crypto News
-
Blockchain1 week agoParadigm Challenges Bitcoin Mining Narrative Amid AI Data Center Boom – Crypto News
-
Business1 week ago
Bitcoin Shows Greater Weakness Than Post-LUNA Crash; Is a Crash Below $60K Next? – Crypto News
-
Metaverse1 week agoAM Group challenges tech giants with $25 billion green AI platform – Crypto News
-
Blockchain1 week agoLogan Paul Sells Controversial Pokémon card For $16.5M – Crypto News
-
Blockchain1 week agoLogan Paul Sells Controversial Pokémon card For $16.5M – Crypto News
-
De-fi1 week agoOndo Global Markets Taps Chainlink for US Stock Price Feeds – Crypto News
-
others7 days agoWhen is the UK employment data and how could it affect GBP/USD? – Crypto News
-
Technology7 days ago
Wintermute Expands Into Tokenized Gold Trading, Forecasts $15B Market in 2026 – Crypto News
-
others7 days agoGBP/USD sinks nearly 100 pips as UK jobless rate hits decade high – Crypto News
-
Technology5 days agoApple Set to Bring Car Keys Function to Toyota Vehicles – Crypto News
-
Metaverse1 week agoAI isn’t taking over IT jobs—it’s changing who gets hired – Crypto News
-
Cryptocurrency1 week agoIs the Bear Market Over? – Crypto News
-
Blockchain1 week agoBitcoin On-Chain Data Indicates High Volatility Ahead Following Post-CPI Reaction – Crypto News
-
others1 week agoHackers Hit Android and iPhone Users’ Bank Accounts, Launch Mobile Spyware Platform Triggering Total Device Takeover – Crypto News
-
others1 week ago
Expert Predicts Bitcoin Dip to $49K as ‘Trump Insider’ Whale Dumps 5,000 BTC – Crypto News
-
others1 week agoWells Fargo Handing $56,850,000 To Customers After Allegedly Sending Botched Reports To Credit Agencies – Crypto News
-
Technology1 week agoOpenAI has deleted the word ‘safely’ from its mission – and its new structure is a test for whether AI serves society or shareholders – Crypto News
