compound-protocol
security
Our great sponsors
compound-protocol | security | |
---|---|---|
16 | 3 | |
1,824 | 867 | |
0.5% | - | |
0.0 | 0.0 | |
5 months ago | almost 5 years ago | |
TypeScript | ||
BSD 3-clause "New" or "Revised" License | - |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
compound-protocol
- List of smart contracts to strengthen your Auditing skills
-
Deployment of the Compound Contract Bravo
https://github.com/compound-finance/compound-protocol/tree/master/contracts/Governance .
-
How to set max votes on DAO delegation?
I'm making an NFT crowdfunding protocol as a summer project and am using Compound Governance contract along with ERC20Votes to do so.
- 333
-
What protocols are doing with our money ?
I highly recommend you do two things, first, try and get a feel for the behavior of smart contracts, there are tools that can help with this, like the ones at blockchain.ey.com - you can get a free personal use account and has a pretty convenient smart contract and token explorer tool for Solidity, you just drop in the code from the protocol’s GitHub (like recommended above) and bam. Here’s Compound’s timelock contract as an example: https://github.com/compound-finance/compound-protocol/blob/master/contracts/Timelock.sol
- Testing governance functions?
-
Tranquil Finance FAQ's!
The Tranquil protocol smart contracts are forked from the Compound protocol with minimal changes. It is a deeply battle-tested and audited protocol with formal verification of its contracts.We plan to get audits for the Tranquil protocol as soon as possible.
- Where can I see solidity code of a audited DAO smart contract? If possible where the code is explained to some degree.
-
Cryptocurrency Loan Platform Implodes in $130M Hack
Yep however I don't think I'd consider it to quite the same extreme. No doubt it was bad however proportionally to the size of the platform Cream's exploit was far more damaging. Like the rekt.news post mentions, it was more of a banking/spec error than an outright vulnerability. Your spec can't protect you if the loss is due to intended behaviour. There are ways to mitigate this however. The main way is by making your spec concise and clearly representable as a series of state transitions & operations or as a series of transformations.
The Compound Finance paper spec essentially just lists "this subsystem does these things" and then each function/operation is a list of preconditions, what actions are taken in what conditions, and the expected result. This isn't bad per se but it's not great either. Instead the paper spec really should be showing what transformation is being applied to the state, why we want that transformation applied, what properties must hold throughout the transformation, and then demonstrating that those properties hold.
Compare this (Compound):
https://github.com/compound-finance/compound-protocol/blob/m...
-
Forta is thrilled to announce that we’ve partnered with Compound Grants to bring you our first Agent Development contest!
Provide alert for 10% or more change in Utilization Rate within a 60 minute window in a given pool.
security
- I just want to execute apps without memorizing sentences...
-
This man thought opening a TXT file is fine, he thought wrong
So, yes, there have been vulnerabilities obtaining remote code execution. Like this one: https://github.com/numirias/security/blob/master/doc/2019-06-04_ace-vim-neovim.md which has a little animated gif of a proof-of-concept attack.
What are some alternatives?
cosmos - Internet of Blockchains ⚛
Discover - Yet another discord overlay for linux
verified-smart-contracts - Smart contracts which are formally verified
dotfiles - The "replicable" heart of my personal workstations
verified-smart-contra
publications - Publications from Trail of Bits
security - Materials related to security: docs, checklists, processes, etc...
art-gobblers - An experimental decentralized art factory by Justin Roiland and Paradigm.
ethereum-burn-stats - Website that showcases EIP-1559 Burn
Publications - Misc. publications, conference slides, etc. For more, go to http://BartoszMilewski.com
ProteaV2Contracts