publications
verified-smart-contracts
Our great sponsors
publications | verified-smart-contracts | |
---|---|---|
51 | 10 | |
1,313 | 701 | |
2.2% | 0.0% | |
8.7 | 0.0 | |
7 days ago | over 1 year ago | |
Python | Solidity | |
Creative Commons Attribution Share Alike 4.0 | GNU General Public License v3.0 or later |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
publications
-
Skiff: Various Privacy Failures
Disagree, their reputation is tied to their audit quality.
But I'm pretty sure in this case the scope was bad. Like they coukd have had audits on "Do I use OpenSSL well?" and then misrepresent that all their privacy claims were audited.
Now it seems like Skiff conveniently didn't allow Trail of Bits to publish their reports, they are usually here: https://github.com/trailofbits/publications/tree/master/revi...
Disclaimer, I have used Trail of Bits service in the past (and 2 other auditors for an security campaign on a blockchain, cryptography + networking product).
- The Lisk v4.0 security audit 🔐
-
PyPI has completed its first security audit
Link to the report: https://github.com/trailofbits/publications/blob/master/revi...
They seem to not have analysed client-side of PIP itself, but I suppose there isn't anything you could say that isn't already obvious to everyone.
- SimpleX Chat security assessment by Trail of Bits [pdf]
-
Thoughts on Skiff? What do you like? What would you want to see improve?
Audits are mentioned on the Trail of Bits website https://github.com/trailofbits/publications and the Skiff one https://skiff.com/transparency. Skiff has been externally audited 4 times.
-
SimpleX Chat: private and secure messenger without any user IDs (not even random)
Here's the URL https://github.com/trailofbits/publications/blob/master/reviews/SimpleXChat.pdf It was in the article I have already linked.
-
Solidity digest fortnightly / 17-30 apr 2023
MYSO Finance Security Assesment by Trail of Bits
-
Audit Firms Ranking
Trail of Bits
-
Transparency at Skiff
Hi! I'm Skiff's CEO. We've had 3 security audits, including 2 from Trail of Bits - one of the best security auditing firms in the world https://github.com/trailofbits/publications. Skiff Mail is also open-source: https://github.com/skiff-org/skiff-mail as is our whitepaper https://skiff.com/whitepaper We've also been in the news quite a bit: https://www.theverge.com/2022/5/17/23075804/skiff-mail-email-privacy, https://www.wsj.com/articles/encryption-bans-what-is-this-russia-hacking-online-privacy-security-data-signal-whatsapp-emails-protection-11675436242 (I wrote this with our team!), https://techcrunch.com/2023/01/30/russia-skiff-block/, and more, even though we're only a year old. We collect no personally identifying information - not even IP addresses used - no backup emails, phones, etc. - no advertising, and we end-to-end encrypt BOTH email subject + body and don't have any metadata (time sent/received an exception). What can we do to share more of this with more people? We're a younger company but it's so important this is made public.
-
Skiff Apps
Hi! I'm Skiff's CEO. We've had 3 security audits, including 2 from Trail of Bits - likely the best security auditing firm in the world https://github.com/trailofbits/publications. Skiff Mail is also open-source: https://github.com/skiff-org/skiff-mail as is our whitepaper https://skiff.com/whitepaper
verified-smart-contracts
-
how is slippage of potential swap calculated on v3?
OP, if you are asking about price calculation, IMHO it still follows the original white paper, with many tweaks and improvements, but the fundamental principles remain from V1: https://github.com/runtimeverification/verified-smart-contracts/blob/uniswap/uniswap/x-y-k.pdf (chapter 3) - yes there is something called ticks and virtual liquidity in v3 but those formulas will still give you a good approximation.
-
Sandwich attacks in Liquidity Pools and how you could design pools without them.
You can find the CPMM formulas used by Uniswap here: https://github.com/runtimeverification/verified-smart-contracts/blob/uniswap/uniswap/x-y-k.pdf
- Coming very soon 😲
- Formal Specification of Constant Product (x × y = k) Market Maker Model (2018) [pdf]
-
Maiar Exchange Features
This formula can vary with each protocol. For examaple, Maiar DEX uses the industry standard "x*y=k" constant product AMM model, which has proven its reliability in existing implementations, and has been formally modelled and verified. In this formula, k is a fixed constant, meaning the pool’s total liquidity always has to remain the same.
- Cryptocurrency Loan Platform Implodes in $130M Hack
- Is Providing Liquidity a Less Volatile Method of Gaining Exposure to an Asset?
-
Tool and analyze farming gain and loss vs impermanent loss?
https://github.com/runtimeverification/verified-smart-contracts/blob/uniswap/uniswap/x-y-k.pdf https://uniswap.org/whitepaper.pdf
-
Need help understanding the pricing model
Hi, I was going through the formalised explanation of the Constant Product function and it's implementation as per this link. Could you link me to any article that could help me understand the formalisation better.
-
Uniswap V3
What is effectively a changelog of features for their new version is probably not the best place to start.
If you'd like to know more then this [0] is a brief summary of Uniswap and this paper [1] is a good introduction to the formalism of the `x * y = k` market making model used by Uniswap.
[0]: https://github.com/runtimeverification/verified-smart-contra...
[q]: https://github.com/runtimeverification/verified-smart-contra...
What are some alternatives?
slither - Static Analyzer for Solidity and Vyper
compound-protocol - The Compound On-Chain Protocol
manticore - Symbolic execution tool
verified-smart-contra
echidna - Ethereum smart contract fuzzer
security - Materials related to security: docs, checklists, processes, etc...
Publications - Misc. publications, conference slides, etc. For more, go to http://BartoszMilewski.com
codeql - CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security
circt - Circuit IR Compilers and Tools
whatlang-rs - Natural language detection library for Rust. Try demo online: https://whatlang.org/