#smartcontracts

5 posts · Last used 8d

Back to Timeline
Rubén Santos García @rsgbengi@infosec.exchange · Aug 02, 2026
In an upgradeable proxy, the funds live in the proxy and the logic is swappable. Own the pointer, own everything. This issue covers delegatecall storage collisions (Audius), uninitialized implementations (Wormhole's other bug), UUPS selfdestruct bricking (Parity froze 513k ETH), and the 2025 mempool bots front-running initialize() on fresh proxies. Plus slither-check-upgradeability to catch it. https://www.kayssel.com/newsletter/issue-61/ #InfoSec #CyberSecurity #Web3 #SmartContracts #BugBounty #DeFi
0
1
0
Trail of Bits @trailofbits@infosec.exchange · Jul 30, 2026
Attackers drained $20M+ from protocols built around Uniswap v4 hooks. The two largest were Cork (~$12M) and Bunni ($8.4M). Neither came from bugs in the PoolManager, Uniswap v4's central contract. The failures came from application and hook code. We analyzed dozens of audit findings to isolate seven ways hooks break, and created a checklist for keeping these bugs out of production. https://blog.trailofbits.com/2026/07/30/building-secure-uniswap-v4-hooks/ #infosec #DeFi #smartcontracts
2
0
1
BGDon 🇨🇦 🇺🇸 👨‍💻 @BrentD@techhub.social · Jul 20, 2026
Fungible Tokens for All! Here is the story and working details behind the Ethereum ERC-20 token standard. Ethereum quickly gained a strong reputation for hosting many/most of the largest crypto tokens including USDC, USDT, and BUSD and this success is due in large part to the establishment of the ERC-20 standard. In this TechAptitude post we dive into how ERC–20 tokens work and the ever growing scope of use cases supported. https://techaptitude.substack.com/publish/post/207464766?r=vn8b8&utm_campaign=post&utm_medium=web&showWelcomeOnShare=true #Crypto #CryptoToken #ERC20 #Ethereum #USDC #USDT #CryptoCurrency #FungibleTokens #ETH #SmartContracts #BlockChain #Interoperability #TechAptitude
0
2
0
Rubén Santos García @rsgbengi@infosec.exchange · Jul 12, 2026
Cross-chain bridges lost ~2B USD in 2022 alone. Every major hack lived in the same place: the attestation layer that decides a deposit really happened. Ronin (stolen validator keys), Wormhole (forged guardian signature via unchecked account), Nomad (0x00 trusted root looted by hundreds), BNB Token Hub (forged IAVL Merkle proof). New issue breaks down all five. https://www.kayssel.com/newsletter/issue-58/ #InfoSec #CyberSecurity #Web3 #SmartContracts #BugBounty #DeFi
0
1
0
Guia de TI @guiadeti@flipboard.social · Apr 08, 2026
0
0
0

You've seen all posts