

Cork Protocol
3.3K posts

@Corkprotocol
A programmable risk layer for onchain assets, including vault tokens, yield-bearing stablecoins, LSTs, and RWAs Backed by @RoadCapMgmt and @a16zcrypto CSX




The wallet that can pause your protocol should never be the wallet that can upgrade it. @Pybast, CTO of @Corkprotocol, walked through this at the Rekt Security Summit in Cannes. Giving Hypernative the pause role makes sense for rapid response. But if that role also carries upgrade permissions, you have introduced a new attack vector instead of closing one. The same logic applies to unpause. If the key that unpauses your protocol gets exfiltrated, an attacker can trigger a pause, wait, unpause, and exploit again. These are governance design decisions that need to happen before you integrate any security tooling. Learn more at buff.ly/ERwOrHs





Over 160 participants in the onchain credit ecosystem, and growing. We've mapped every single one of them across credit issuance, capital allocation, infrastructure, and risk management. Tomorrow - see this map in action in the State of Onchain Credit report by @solofunk.







