May 5, 2020

Dan Guido, cofounder and CEO of Trail of Bits, and Taylor Monahan, founder and CEO of MyCrypto, discuss all the recent hacks in DeFi, how it can be made more safely and who is responsible. 

We tackle: 

  • the Hegic security incident: whose responsibility it was to make sure the contract was secure — the auditor (Trail of Bits) or the team (Hegic) — what Trail of Bits was saying in its audit summary, and how to read between the lines of an audit summary
  • how long an audit should be
  • upgradeability: particularly around when more advanced technology and contracts interface with older technology/contracts
  • centralization vs. decentralization: whether contracts can be made safely while maintaining adhering to the principle of decentralization, why Taylor would prioritize centralization and security, and how teams can create different levels of risk for users 
  • bug bounties: why asking what amount they should be is the wrong question
  • the security threats posed by oracles
  • and what a checklist for DeFi teams might look like

