Top Crypto Security Audit Firm Struggles: Major Failures Raise Concerns

Top Crypto Security Audit Firm Struggles: Major Failures Raise Concerns
ôîòî ïîêàçàíî ñ : beincrypto.com

2023-4-26 10:42

Crypto security audit firm CertiK has been busy recently. However, failures on previously audited projects have raised a few eyebrows.

On April 26, CertiK founder and professor at Columbia University, Gu Ronghui, spoke to Chinese media.

He told the outlet (translation) that “We [CertiK] have turned blockchain security into a track almost by ourselves, which has attracted a lot of attention.”

He went on to boast that CertiK achieved a 70% share of the crypto security market. Furthermore, the cost of web3 security audits has been reduced by more than 90% by the firm, Ronghui added.

On April 24, the company posted an update on recently completed crypto security audits.

Completed CertiK Audits | Twitter/@CertiK Crypto Security Audit Firm CertiK Investigates Merlin

However, not all is as rosy as it seems at the crypto security audit firm.

“On the same day that this interview was published, the project Merlin, which Certik had just completed auditing, was stolen,” reported industry analyst Colin Wu.

On April 26, CertiK reported that it was investigating an incident on the Merlin decentralized exchange.

It said that initial findings point to a potential private key management issue rather than an exploit as the root cause. However, in its own self-defense, the firm added:

“While audits cannot prevent private key issues, we always highlight best practices to projects.”

As reported by BeInCrypto, the Merlin DEX suffered a $1.82 million liquidity pool hack on April 26.

The zkSync-based DEX was exploited following an attack on its liquidity pool, depleting funds in USDC which were then bridged to Ethereum (ETH).

The Certik audit has come into question, but the firm stated it highlighted centralization risks.

“In the audit report ‘Merlin DEX,’ the centralization risk is highlighted under the section ‘Decentralization Efforts.’”

However, those details were vague, according to DeFi researchers. “@DefiIgnas” pointed out that vital information was omitted from the audit summary.

“Reading your audit, you mentioned that the ‘owner account may allow the hacker to take advantage of this authority.’ But the audit summary did not have this info.”

Audits Not a Guarantee

However, these audits do not prevent exploits, nor do they detect all vulnerabilities.

According to the Rekt Database, which monitors DeFi exploits, rug-pulls, and thefts, there have been a total of 31 exploits on Certik audited protocols.

Four of those have been in 2023, with the largest two, Orion Protocol and dForce, both losing over $3 million.

Exploits on CertiK audited protocols – de.fi/rekt-database

Nevertheless, it should also be noted that many of these exploited protocols have also been audited by other leading security firms. Certik has also previously warned over centralization issues on many exploited DeFi protocols.

The post Top Crypto Security Audit Firm Struggles: Major Failures Raise Concerns appeared first on BeInCrypto.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

SherLOCK Security (LOCK) íà Currencies.ru

$ 0.1387 (+1.71%)
Îáúåì 24H $13
Èçìåíåèÿ 24h: 10.06 %, 7d: -33.06 %
Cåãîäíÿ L: $0.1387 - H: $0.1387
Êàïèòàëèçàöèÿ $0 Rank 3458
Äîñòóïíî / Âñåãî 0 LOCK / 4.969m LOCK

failures firm audit crypto security raise concerns

failures firm → Ðåçóëüòàòîâ: 12


Ôîòî:

FTX’s collapse:  Hayman Capital’s Kyle Bass says ‘there’s more to come’

FTX’s collapse is still causing reverberations across the crypto market, with the latest crypto news being Genesis’s lending business halting customer withdrawals. Kyle Bass, the founder and CIO of Texas-based asset management firm Hayman Capital Management, says FTX’s collapse could just be the beginning of even more turmoil and failures in the crypto sector.

2022-11-17 19:31


Ôîòî:

Estimated 4 Million Bitcoin is Lost Forever by Users’ Forgetfulness

As much as 20 percent of all the Bitcoin in existence is lost forever, Chainalysis has revealed — as the research firm says it handled contracts worth $750,000 since 2016. ‘We Don’t Help People Find Lost Bitcoin’ In comments to The New York Times, Chainalysis said that user failures to create robust methods of password storage meant as much as $20 billion of Bitcoin is locked out of reach.

2018-7-7 03:00