Guy

26 posts

Guy banner
Guy

Guy

@atlabs_

Yes

Katılım Şubat 2021
19 Takip Edilen89 Takipçiler
Guy retweetledi
Carter L. Woetzel ❎
Carter L. Woetzel ❎@l_woetzel·
🧵 Sophisticated Cosmos DeFi attack hits @Levana_protocol built on Osmosis - let's break down what happened👇 There are two kinds of oracles: 1⃣ Enshrined oracles (built into block production) 2⃣ Smart contract oracles (on-chain tx updates state) In the case of 2⃣ off-chain services submit a tx every X number of blocks to update the oracle price of an underlying asset. Once updated, pricing is no longer stale; reducing the delta (difference between actual prices & oracle prices). Protocols have a problem when using 2⃣ - the higher the frequency of updates, the greater the gas cost that is incurred to maintain accurate pricing. In Levana's case, non attacking txs actually trigger a oracle update: this adds in nice defensive entropy as normal users are helping update the pricing for everyone. However, the clever attacker found a way around this via a congestion attack... ------------------------------------------------------ The Attack ------------------------------------------------------ 1⃣ Spam txs such that no oracle update txs can get through (from either users or Levana infra) 2⃣ DDoS backend infra tied to regularly scheduled oracle update txs 3⃣ Have an intelligent system tracking the delta🔺between the stale data and the actual market pricing that is ready to get pushed 4⃣ Use a multiexecute tx to go long or short + update the stale data to market pricing - guaranteeing profit for the attacker as they know exactly what the stale price of the oracle is about to get updated to within their multiexecute tx while also comboing it with a long or short guaranteed to be directionally correct. 5⃣ Because the attacker was the source of congestion, they knew precisely where to submit txs such that they would get accepted by the nodes ------------------------------------------------------ Saving Graces ------------------------------------------------------ ✅ Delta neutrality limitations of Levana made it so that the size the attacker was able to leverage was limited (resulting in only ~10% drained) ✅ Appears the logic for positions already opened was decoupled from new positions (I'm still figuring out this one, was briefly mentioned in the blog) ------------------------------------------------------ This is BY FAR (in my opinion) the most complex attack on a DeFi protocol in Cosmos to date. The Levana team responded rapidly, and are updating the protocol to be safe from this attack by decoupling the placement of orders from the execution of orders using a queue that awaits the next oracle pricing update before executing txs. This unfortunately creates a worse UX, but guarantees better security. Overall, I think advances in L1 enshrined oracle services that are not on the smart contract level (but rather a part of regular block production) is going to be key to the long term DeFi security success of Cosmos. My heart goes out to the @Levana_protocol team - this was a complicated & targeted attack. Looking forward to the protocol continuing to become more resilient. Building DeFi is not easy folks. Apologies in advance if I mistated or missed anything. $LVN $OSMO #Cosmos blog.levana.finance/levana-exploit…
English
30
72
289
87.4K
Kryptic Inc
Kryptic Inc@Kryptic_io·
Join us in welcoming Guy Garcia of @atlabs_ 👋 to the @Kryptic_io team! Formerly of Shade Protocol, Guy brings invaluable smart contract experience as we work to improve @ArchX_Wallet. His expertise will be key as we expand our innovative product offerings in the ecosystem! 🤝🚀
English
2
1
7
677
Guy
Guy@atlabs_·
The week isn't over yet... there's still time for someone to one-up the rest 💀
English
1
0
4
0
V-IRL
V-IRL@V_IRL_DROPS·
🚨The Lord of Artisan has been summoned! 🚨 🎨Lets see your skills in creating a shoe that most represents you or a project you love! 🎁Best shoe will get a WL and become Lord of Artisan in V-IRL discord! 👇Post your shoe below or in Discord! ⭐️Have fun and stay V-IRL!
V-IRL tweet mediaV-IRL tweet media
English
10
7
27
0
Guy
Guy@atlabs_·
@AnonsNFT Shut up and take my money
English
0
0
1
0
Anons
Anons@AnonsNFT·
Fun to see this in action. There will be some Anon sneakers too👀👀
Tor Bair 🧑‍🍳@TorBair

Sp @v_irl_drops bridged my Secret NFT into a real life, exclusive @SecretNetwork asset. Then they sent me this. It's getting REAL now. Genesis Mint: May 29th 1700 UTC $SCRT is becoming the new home of Web3 innovation :)

English
2
5
40
0
Guy
Guy@atlabs_·
@73lV_ Sold last night for $ATOM and $SCRT. Maybe ill buy some back if the DEX works in the long term.
English
1
0
2
0
Hokage
Hokage@73lV_·
Who else sold all his $CRE I can’t be the only one on this table 🥺 I actually didn’t do much research on the project plus I didn’t get enough drop from it
English
40
3
54
0
ʕ •ᴥ•ʔ
ʕ •ᴥ•ʔ@alpeh_v·
Pro tip from a solidity auditor: if you launch a token but never launch a protocol you can never get hacked
English
4
6
95
0
Carter L. Woetzel ❎
Carter L. Woetzel ❎@l_woetzel·
Maybe we should stop valuing DeFi in terms of an inflated and centralized currency known as "USD" 🧐 Have some courage Web3. Perhaps the world is finally ready for Silk. $SHD $SILK @Shade_Protocol @Sutera_Duniya
Carter L. Woetzel ❎ tweet media
English
9
29
128
0
Assaf
Assaf@assafmo·
Attackers used a known @CosmWasm bug to halt @JunoNetwork just a few hours before they deployed a patched version. Here's a mini-breakdown of how it went down 👇
English
40
153
601
0
Guy
Guy@atlabs_·
@SecretNetwork @LegendaoNFT What's stopping me from creating fake accounts for the airdrop? Seems like a way to avoid doing the effort to grow their socials.
English
0
0
0
0
Secret Network
Secret Network@SecretNetwork·
Earlier we helped share details from @legendaonft's airdrop for $SCRT stakers. Many $SCRT community members have made it clear they will only participate if their privacy is preserved - a very understandable demand. We spoke to the @legendaonft team - here's what will change:
Secret Network@SecretNetwork

Ready for the upcoming $LGND-ary Airdrop? $SCRT Stakers will be eligible if they complete these missions: 1. Follow @LegendaoNFT 2. Join discord.gg/qtuD8caHxz 3. Add your scrt address, Twitter & Discord name: forms.gle/HNmbGMipJAgZbM… Mission ends April 10th $SCRT $LUNA $OSMO

English
28
52
164
0
sissonj.silk
sissonj.silk@sissonj_shade·
WHAT’S HAPPENING!!!!!! 👀👀👀
sissonj.silk tweet media
English
20
14
148
0