Security in DeFi: Best Practices, Challenges, and the Road Ahead | ETHDam 2023
CryptoCanal·Sat, Oct 7, 2023, 12:00 AM
Harry Kikstra is a COO of Ease DeFi. Ricky Tan is a Head of Business Development at Nexus Mutual. https://twitter.com/rkstan Kiril Ivanov is a Co-Founder and Tech Lead of Bright Union. Evert Kors is a Co-Founder of Sherlock. https://twitter.com/Evert0x Moderated by Jonathan Knegtel. https://twitter.com/jpknegtel ETHDam is a Hackathon & Conference that gathered over 500 DeFi and Privacy builders on the 20th and 21st of May 2023 in Amsterdam. Privacy is normal. Following the arrest of Alex Pertsev, a Tornado Cash developer in the Netherlands, ETHDam 2023 is determined to counter the chilling effects of the lawsuit and bridge worlds to discuss the future of privacy and encourage to build on the shoulders of cypherpunk giants. ETHDam is powered by CryptoCanal, - a blockchain education and events platform growing in Amsterdam, spreading its roots to Rotterdam and Zurich. ETHDam 2024 is on the map already! Keep up with us to see updates: CryptoCanal https://www.cryptocanal.org/ CryptoCanal Twitter https://twitter.com/CryptoCanal Join CryptoCanal Community https://t.me/CryptoCanalCommunity We would like to thank our partners and sponsors that made this event possible. 🌷 Our BFF 1inch https://1inch.io/ Our Frens: Sismo https://www.sismo.io/ Aleph Zero https://alephzero.org/ Scroll https://scroll.io/ RAILGUN https://railgun.org/#/ And our Sisters: oasis.app https://oasis.app/#earn Maven11 https://www.maven11.com/ bitvavo https://bitvavo.com/en Lido https://lido.fi/ Spankchain https://spankchain.com/ API3 https://api3.org/ Gelato https://www.gelato.network/ VanEck https://www.vaneck.com/nl/en/crypto-etn Marlin Protocol https://www.marlin.org/ Silent Protocol https://www.silentprotocol.org/ Cyber Capital https://cyber.capital/ … and Proto https://twitter.com/protolambda 🍍
Transcript
foreign to move on to our next panel which is going to be on the security in defy best practices challenges and the road ahead I'd like to introduce the four panelists so first up we have Harry from ease if you'd like to come to the stage as well as Ricky from Nexus Mutual Carill from Bright Union and Everett from Sherlock please give a round of applause yeah you're gonna have to be a little bit comfy on there if each of you could give a very short introduction of yourself and also your association with defy security hello yeah hey uh yeah I'm Kerry also I'm a co-founder of bright Union so we are we are protocol that integrates their Aggregates their default Insurance protocols so basically like one inch but for insurance protocols for these guys where people can can choose the best the best cover for the defy investment and the best price and get a little bit of insight all the conditions are and what their what the payout conditions Etc uh yeah so my journey was not really from the I'm a builder so but uh my journey was not from the security perspective I approached from a slightly different angle when I was one of the first uh how to say the fans of decentralized insurance concept so the concept of insurance business but being put on chain and uh working as the without any intermediary and uh basically where people can participate in Insurance business which is historically been highly profitable and uh so we did it for a few years before and then we noticed that there are some protocols like these guys are who are targeting specifically D5 risks for def for decentralized insurance so not life risk not health risk but the the business for people to to secure their D5 risks and that's how we came to Bright Union idea and uh cool here we are thank you yes I'm an avid course I'm working on Sherlock I'm the co-founder of Sherlock and Sherlock does Smart contract Audits and we're also backing it by coverage so in case there's like a steel bug in the code after the all that happens we're paying out um I'm a technical background I'm a solidity developer and I've been working on Sherlock for the last two two years I'm Ricky tan I work at Nexus Mutual on chain decentralized insurance provider um I'm probably the least technical person here on the on the couch I I had BD and strategy no joke um and the funny thing is like we all actually work together speak with most of these guys almost on a weekly basis um I don't have a background in software engineering I used to be a Commodities Trader but got into crypto about eight years ago or something like that hi I'm Harry um I've been working with esd5 for the past two and a half years my background is actually old school crypto from Amsterdam digicash we used to build stuff on top of Ricky's protocol on Nexus to make the protocol even easier and more approachable for many people and then we started building our own coverage insurance protocol and insurance which is built to take away some pain points and make access to e to D5 much easier cool thanks a lot and yeah I think specifically to evote from Sherlock congratulations for getting through the last couple of months the roller coaster that it's been um which brings me on to my first question which is uh generally um there's a big conversation in the space of D5 versus C5 and I'm interested in kind of what your opinions are around how defy held up compared to C5 during 2022 and kind of what are what you see is kind of the main risks of the D5 versus C5 narrative well we sucked right I mean we use D5 we well we went down drastically right I'm glad to see that C5 actually also well risks in C5 also increasing we see that now really clearly risk site in D5 still unknown uh still high that's why we're here that's why we are doing business on yeah I think D5 of course has like an extra risk with the smart contracts and the decentralization and that everyone can exit this access it access it like at every time G5 is a little bit more protected in the terms that you have to go to like a human to accessifies sometimes there's like a lot of fishing happening and that and that kind of attacks those attacks can also happen on D5 but yeah I think D5 has that extra risk because it's so open I'm just going to piggyback and back at the top on top of this up but yeah it's the thing with C5 and especially with like you know the FTX bankruptcy um and all the other exchanges that kind of went under we see if I actually know how you're gonna get screwed in the end you know it's kind of like okay someone's either going to commit fraud someone's going to steal your money um someone's gonna lend out your funds without you having given the permission and it's just opaque and you don't know and at the end of the day you just lose your your stuff in defy like obviously we're very proud that in D5 everything's transparent and you can track it on chain but the thing in D5 is just like the unknown unknowns um which is only getting which is partially like why we exist but it's also what makes our job now more difficult because as the whole composability aspect is still you know still increasing people are building on top of each other layer over layer so your unknown unknowns actually increase exponentially so you can have I mean this is this was for example the case with Euler Euler 10 audits but 20 different Integrations different layers so at one point I'm one thing breaks and the rest just like goes under and that's just an example of you know on on the surface you might think oh this is legit team I trust them they've gotten nine or ten audits that's that's nice it's safe but it might not be as safe because there's just so much stuff that you just kind of can't grasp essentially yeah and I think it would be great like over time if we get to know like all the unknown unknowns but like people keep developing new protocols people keep like building on top of each other so it seems like for the initial period those will only increase like that complexity and that those are known unknowns unknowns yeah yeah I agree with with my colleagues here um the composability is a risk but in the end we are still building in prod entire system um and I think looking back at the total uh D5 tvl and all the stuff that's going on is actually not that bad all the hacks have taken place most of them were Bridges and if you take out the bridges then I think it's two billion less than 2 billion which is about the amount that people just in the UK lost on phishing scams non-crypto and much less than for example Deutsche Bank had to pay in fines for their role in the 2008 system so you should think about thread five versus CFI FTX of course versus D5 and I think we're doing quite well and we're learning from every little hack every big hack we learn a lot and I think this group of people here we've built our own little ecosystem within the ecosystem to protect users and I think that's very good yeah on that note um or anything I did hear from ever um uh recently about what happened and the fact that when there is a hack there's a war room can you maybe talk a little bit to the kind of how the industry despite you kind of being competitors in a way how in those situations you actually come together and work together uh yeah sure so the war room is when happens when an exploit happens or it's it's uh it's happening still and people come together from all different uh teams some security teams uh yeah we've been in the War Room a couple times political teams and we just discuss like how to mitigate the ongoing exploit or try to figure out what's happening um yeah and in in those times like everyone wants the best for the space and to figure out what's happening and to mitigate the attack because sometimes and that can happen and it can also apply to other protocols that are still like vulnerable so during those times like yeah everyone comes together and tries to figure it out and that that's when the best uh comes out of everyone I would I would add that so now people understand that the D5 risk it's always been been the case of course right but we know that all the all the D5 users are kind of self-selected for being risk to have a high risk appetite right so we've seen that in the previous presentation that most of people crypto friendly people they have like what 85 percent of their wealth exposure in crypto so but the funny thing is that every hack that happens is actually in a way good for us right because we are doing Define insurance right so we Ally for a couple of years now and uh when I was explaining less like a year ago to people like well you know guys well we all know the risk of freaking high right that maybe you should have the if you have such a massive exposure to defy one way to mitigate the risk is to buy the freaking defy cover right and then when I was doing this a year ago even then people like what Define insurance what is that is that is it going to be paid out or what they're gonna go to in return how to submit the claim Etc et cetera what the conditions are now actually after all this older cream and FTX and all this [ __ ] like that we it's it's much easier to sell basically I think all of us are seeing the the race of defy cover sales so people try to understand and understand it better the risks are in the way that defy cover might help to mitigate the risk so good and bad yeah could you guys maybe add on to that and specifically talking about D5 cover what really is the the main limit to adoption of D5 cover like at this moment in time because ultimately from from my perspective and I guess many people's perspective it is kind of really one of the few things that you can do to truly quote unquote de-risk your your default participation and protect against what the all the security threats I'll I'll start again soon so there's about two two issues right so in in Insurance the centralized Insurance there are two aspects where people can participate they can buy the cover or can they provide the capital to you basically to cover the risk for others right and both of those sites have some challenges when they buy buyers basically why they why there is no massive adaption not I think it's like only four percent of all the tvl in D5 is covered by Insurance four percenters almost nothing the issue I guess is well gas cost of course but ux sucks because you when you put your money in maker compound or whatever you need to recall that you need to go to one of those guys or to us and to buy the cover for the limited amount of time Etc so it's way too far from there from the actual users comparing to let's say when you buy the flight ticket right and there is a checkbox small checkbox like insurer my luggage so it must be like this so but it's coming it's not there yet on the the opposite side of liquidity providers the the biggest issue is that the risk is kind of unknown right if you if you because your is the liquidity provider you act as insurance company right you you provide the capital and then you can expect that this will be my yield and these are my risks right so but in general it should be bringing me some some some money right but if you go to any traditional Insurance risk modeler and say guys can you calculate please what the risk of maker or compound been hacked they will say okay give me the data that you have and when you give the data that is available now this is well you cannot calculate it freaking risk it's it's way too early it's well unknown so that's and I think many of people here are struggling with the capacity right so selling is not is complicated anymore but the capacity is is the issue yeah well not for everyone exactly don't drop the mic well we we built we built a system which is basically unlimited capacity as the deposits are the capacity so that's why we build a new system also to um to take away one of the other pain points which I think is cost it's easier in a bull markets when every little protocol has like 50 60 80 apy of a few thousand to spend a few percent on cover which just makes sense even if you're in for just a few weeks but in a bear Market where maybe you get 0.5 percent or 1.2 percent return then it's harder to justify the cost for a lot of people um we haven't had any acts in about 30 months and so we haven't had to do any payouts it works differently on a system but we also haven't charged any fees so people had 13 months of free coverage I think that's one of the things we should focus on lower cost but in general I think all the systems we represent work very well but we need to get more education it would it would help a lot if the big protocols themselves all the protocols that have cover available in one form or the other just point to the users and you can invest but you can also get coverage either directly via the protocol or just send us send them to us um I think that will help a lot yeah I think the the end game with um with you know defy insurances if you and as KIRO mentioned like from a product perspective you want to be as close to the customer as possible so you know there's not a lot of Integrations out there right now where a user can just like purchase a cover when you know when they deposit their funds with any of the lending protocols etc etc but I think the absolute end game is actually when the cover is completely embedded because that's the one thing that smart contracts do allow is that when you know you want to get to the stage where if somebody deposits money into compound or AVI or or whatnot that the yield will automatically pay for the cover and it'll do that on the block by block basis because if everything is composable or defy you know it just means that you can do these things which in traditional Finance are actually not possible um but that's that's part of a that's just that's still a matter of you know the tech Stacks all being slightly different um the BD teams having to work together to see the long-term case for for these types of Integrations Etc and I think also so that's on the product side on the user side I really relate to you know the present the previous presentation where most of the people in D5 are just very Advanced crypto users and excuse me for my French but they're just [ __ ] cocky they really think like I'm gonna put my money into this new Landing protocol that spun up on this new L2 and I'm going to make 10 if I then and I've done this user interviews if I ask these people all right would you be willing to pay two percent for to cover it they say [ __ ] no I want I want it all and I'm smarter than the rest of us and I'll just be in and out within a couple weeks or a couple of months because I'll find the next thing you know so they hop from from Degen thing to the next dgen thing and at one point in time they get hacked and then if you then speak to them after the hack they're like yeah I should have bought cover and like no [ __ ] you know but that's that's still just the mad that's still just like that's what the typical D5 user looks like like they're they are a bit audacious they are very risk-taking and they a lot of them truly believe they don't need cover so yeah yeah I tend to agree with the user there but I want to your vision of like the long-term end game of coverage I think I don't agree with that because uh if you bake it in the coverage in the contract itself it also is exposed to like risks of course so you have to cover like the those risks of like the automated coverage as well like how do you think about that do you think that needs to be covered in some way as well but like the traditional insurance or what's actually a good point like you basically need another form of reinsurance on top yeah yeah it can still reinsure everything of course it's what we're doing with the system at the moment as well but yeah I recognize that the basically two types of users at the moment all the power users are cocky as she said and think they don't need insurance while they likely do and there's a big group of people and especially new entrants that's also why the previous presentation is very good um that find it too difficult I mean there's a reason we call ourselves ease now because we need to make it easier for people we're actually going to sell easy tokens which are covered yield bearing tokens directly so people can buy them with ether stable coins and just don't think about all the steps in between um and get covered and just get a return on their investment without all the headaches so I think we should make it easier for everyone cool makes a lot of sense and and thanks for also disagreeing I appreciate that um yay for composability was my thought um yeah guys I'm gonna either to the audience and the people on the live stream I'm gonna be asking questions from slido in a second there's already one great question that happened which is about an event that happened maybe less than 24 hours ago always happens with these sorts of panels um so yeah the code here is three two three two on slido uh that's three two three two three two um the last question I guess that I have is from your guys's perspective what really are the biggest security threats in this moment in time unknown yet I mean see so what happens so we see the great a great evolution of the security tools for developers right it's been so many told over the past day here even so there are many tools which help you to make it much more secure code so it's it's it's improving however there are new techniques also appearing right so there there are cross chain Bridges there are cross chain liquidity there are new types of oracles etc etc so I'm afraid that what we see is that the the yeah the security tools are improving but the new features new ideas appear in at much much faster even so we're never gonna we're never gonna catch up with the new new new methodologies new new tools Etc so the risk always will be there and the next big thing or big big risk is unknown yet yeah I think if you look historically like 2017 like all the hacks were like very simple like checks that could have been mitigated so I think if you look at that way we have made good progress because right now most of the hacks are more complex and more complicated when you use like cross-train of course like protocol orientancy and those complex attacks so I think that's a good Trend that the exploits are getting more complex but yeah of course we don't you don't want any exploits to happen but I expect the space to get better in Catching these exploits and then maybe there was some end game where we've figured out all the complexity but as Korea said like yeah developers like to get more complex as well so it's a it's a game of playing catch-up mostly I think one of the biggest risks right now is almost is basically a human aspect to the industry where you know we're basically going through we've had a big Market correction um luckily a lot of the the junk has been washed out Bad actors are gone but at the same time yeah but at the same time because we're going through a bit of a law I think a lot of teams are have are at the risk of basically lowering their guards because they're you know they're they might not be reviewing their older code that much they might forget about certain pockets of liquidity that they still have in in not a completely deprecated version but like you know if you switch from as a protocol from V1 to V2 there might still be some liquidity V1 that has not migrated yet and as their focus just shifts to their their newer thing they forget about kind of like the older code and stuff that's actually as Avery said like fairly easy to you know to to exploit um and I I have this sense that right now some you you'll see this wave of very targeted attacks like on older parts of the defy the D5 world where you know people were like oh that's actually very simple hack but yeah I was just not looking at it anymore because it was old code so Yeah we actually we also um do bug bounties ourselves I mean we find bugs and we found quite several of them in older code which are either still active or forked by other protocols which is not a risk that people just blindly Fork protocols and not check back the human aspect is very important also by uh a lot of teams I tried are a bit cocky as well I like the word they should go more often to protocols like Sherlock to have the code audited by many more eyes than they do now not just by some Auditors I really like the protocol we work with them as well um and one other thing the human aspect is probably a nice bridge to your next user question I think I discussed it yesterday with a few people here Dao hacks I think that's a big risk coming up some of these doubts that control a lot of money are something controlled by one or two wallets and even if you trust the two people who are in control of those wallets they can still be hacked socially engineered and what have you or just do a rogue vote like what happened last night so I think that's a big risk factor yeah so that's a good shift into what happened last night so for those that might not be aware there was a governance attack on tornado cash uh where Tornado cash has obviously been a huge topic yesterday I find the timing absolutely obscene it's given how much this happened yesterday like how much we spoke about tornado cash yesterday um and yeah obviously this is the panel today on D5 security so I'm I'm not sure if you guys have read into it at all or seen what happened but very interested in your hot takes on what happened last night and kind of what the consequences might be yeah I think for uh first of all for protocol like tornado cash I think governance is not really a good feature you want it to be like on there without any uh factor for like a governance on Tech has happened last night so I think that might be seen as a design flaw um think to the attack specific I think they added I think they approved the code it's like oh this looks like a legit legit feature or legit update and then the Rush from way to drain all the tokens or something um yeah so books like that should have been caught like by an auditor in case it was audited so that's uh yeah it's a really shady situation but yeah yeah I think as I said the Dao systems um should be discussed more carefully maybe a theme for next year because it's there's so many aspects to that including all the voting I mean the guy just basically proposed to vote with an exploit in it and it got approved so people didn't look carefully enough at the vote and check what actually is going to happen and then it was too late um which is a attack factor which is probably possible with many many protocols so I think it's something to learn from yeah Ricky anything to no I actually had to ask avert earlier what happened it wasn't my birthday yesterday so I was a celebration cool uh well um I have one more question here and we'll call it a wrap is does defy Insurance defy cover introduce another layer of auditing and therefore also improve the security of the system in that way I think we might get some different explanations yeah I think when like when writing coverage like when actually covering a protocol you have like a very high incentive to actually make sure no exploits happen so yeah you can also twitch it around like if you write coverage there is like an incentive to not pay out so I think that's like you're reversing the Dynamics there but uh yeah this is a cool way to look at it I think I'm not sure that I mean you know just because it's Insurance it acts differently right so if you're insuring your car I'm not sure you're really actively reporting to BMW Mercedes about the boxing feature or box you you noticed so uh I think it tackles it helps it helps the end the users for sure whether it makes really the the space safer yeah sure like they they do it try to tackle it from that angle but in general I think it's slightly different mission for insurance yeah I'm busy as Harry and avert basement I'm a fan of kind of like the Sherlock or code Arena style bug bounties um I actually think that the average quality of the is called the centralized Auditors they're the the audit quality has significantly declined over the past years um in terms of the cover providers like us here on the couch I think one of the things that people forget is you know yes we're here to secure the whole landscape but as a result it also means we can't ship too fast and too ruthless so people often complain like why are you not implementing feature ABC well it's because we need to make sure that our own code is basically secure so you tend to see that the cover or in decentralized Insurance protocols move a little bit slower than you know a new perp exchange or whatnot but that's that's with a very specific reason in mind so definitely and to answer your question I think it really gives another layer of security for the users I mean we have a few very smart guys on our team that check all the protocols do bounty hunting not just for the bounties but also make sure that any protocol we put into our coverage system is checked again and not just some five-year-old Audits and and we did find even bucks and some very big bugs in some Blue Chip protocols that are covered everywhere um so yeah I think just the knowledge companies like ours have will make the space safer not just the products himself but the knowledge that goes into it cool well thank you so much guys for coming today and yeah hope the audience you got something out of that um we obviously touched a lot on D5 cover which I'm very happy about actually um so yeah thanks a lot guys cheers [Applause]
Automatic transcript — names and jargon may be misspelled.