The first Trillion Dollar Security (1TS) report identifies persistent smart contract security risks, including contract upgrade vulnerabilities, misconfigured access controls, reliance on unaudited components and low adoption of formal verification methods

Claim

Quotes that support claims

Unaudited components. While auditing and use of standard libraries has improved, developers sometimes rely on unaudited components in their applications.
Unauthorized Access, where a private key that is able to control the contract is obtained by a malicious actor.
Access control failures, where permissions are misconfigured or defined too broadly, allowing attackers to take malicious actions.
Low adoption of formal verification methods. Formal verification techniques are powerful, but they are complex, costly, require specialized domain expertise, and are not well integrated into standard developer workflows
Despite advances in smart contract security, there are still vulnerabilities that can lead to significant security issues, including: • Contract upgrade risk.

Referenced by

End-user risks - UX & smart contract security

Crypto news

Data block