Security Panel
ETH Warsaw·Tue, Oct 7, 2025, 12:00 AM
In a rapidly evolving blockchain landscape filled with noise and complexity, how can we determine if a protocol is trustworthy? With the emergence of Layer 2 solutions and zero-knowledge proofs, the stakes have never been higher. This panel will explore the key factors in assessing the security and reliability of blockchain technologies, from new protocols to innovative L2 solutions. Our expert panelists will share insights on how to sift through the noise to find real, actionable intelligence, and discuss best practices for building safe, secure applications in this dynamic space. Whether you’re a developer, investor, or blockchain enthusiast, join us to uncover the strategies and tools needed to navigate trust and security in the blockchain world. Let’s find out together how to build and recognize trustworthy and secure blockchain solutions with our distinguished guests. 🧜🏻♀️ ETHWarsaw is a series of educational and entertaining events for an active community of blockchain builders, developers and enthusiasts with focus on Ethereum-related tech. Once a year, we organize a large conference and hackathon for the community in the center of the Polish capital with speakers from the best web3 projects and participants from all over the world. Follow ETHWarsaw on social media for the latest updates! X (Twitter): https://twitter.com/ETHWarsaw LinkedIn: https://www.linkedin.com/company/ethwarsaw Telegram chat: https://t.me/joinethwarsaw See you all at our events in Warsaw 🙌🏻
Transcript
of you that left after the last talk and I have to tell you security is hard and it's the last place you get to so first you see the big money in your eyes all those startups and millions of dollars in those defi so then you start learning solidity and JavaScript and react and put your first application together and hopefully your successful and then all you wake up one day and all the money is gone and then you're like ah maybe the security topic was actually not that stupid of a panel to go to uh so you're the clever guys so without further adidea I would like to introduce today's speakers and we have a wonderful amazing uh speakers today panelists today so going from the my left or your right we have HST abona who is uh engineering at wallfacer an amazing product that I recommend everybody take a look at and then we have Damian rushinek from composable security and auditing company awesome company I recommend to everyone as well and finally we have p schlak p schlak is co at L2 beit a very important company that assess security among other properties but mostly security of different level twos and finally I'm your host for the panel I'm Marik kuk and I'm a CD at f so are you ready ready so we're going to start with very simple questions and then we're going to go deeper and deeper into technology and nuance and so on but let's start with some something simple and I have a bunch of questions but feel free if someone is like yeah this doesn't make sense what someone says I really would like to know more about this and that then feel free to raise your hand and we're going to try to answer all the questions because we came here to learn to understand more and put a little break into the for the future to be a little bit more secure right awesome so uh yeah let's start with very simple question why do people get hacked and I'm looking at youa here so so I would say that yeah a lot of people get hacked and in my opinion the bigger problem is that people don't understand what they are doing what they are supposed to do let's say uh recently we had this hack that yeah claim here your airdrop of something some token and then the person clicks and the transaction in metamask appears and it actually sends your token to someone else so yeah you you just need to know what you're doing if you click claim airdrop you shouldn't be sending your tokens to someone else and that's yes so basically understand what you are doing also you can use tools that can help you with that and let's take for as an example metamask wallet which is very basic and you don't have any like security features there but you can use different wallets that are better than metamask and for example okay they are better and they can add you some security level to your to your wallet let's say they can show you yeah this transaction will send this amount or this will approve some amount of tokens maybe you want to rethink sending this transaction right so how to how to set up how to so I'm new into crypto and I want to invest significant am am of M uh significant amount of money how do I set up my personal things how do I know which wallet is good and say metam mask maybe it's not so good but maybe someone else says what should I install metamask how do I know where to go yeah so I'll s go back to to what you said and that there is no um the the environment is not safe like secure by default and that's the problem uh because it's not always responsibility of users to be safe like if everybody's going to be security expert that that that's not going to work like if we expect that every user should know exactly what they do on each step that's not going to work they they they won't make it so we have to create um those environments that are that are secure by default and answering this question it's hard now because I don't know any solution that is uh non-custodial and is safe by default like you don't have to do almost anything to secure uh but so so it's always unfortunately at this moment you still have to understand some of those uh steps and do them by your own and uh depending on the amount that you want to manage like if we are talking about individuals who going to manage their uh assets uh if it's a big amount you could set up uh let's say a safe wallet um and keep the the most cral Parts um in the place like physically locked somewhere like for example if you have a safe wallet you have a uh few let's say you have a if it's only for you you have one um you have two keys that can manage that one of two you keep them in different places just for backup because that's also a threat uh you keep them in a physical safe place and you set up um another address that is your onchain multisig or single single Sig if it's only for you uh with some approvals and with some limits to manage the amount so even if you get hacked like it works in banking you have those limits if somebody steals your card they can spend let's say $1,000 per day so you can notice that and you can react then you take all the you take your Hardware wallet uh just to block this address and set up another one right so it's all about the procedures and it's it's unfortunately at this moment it's not that easy so Dam already kind of starts pushing us towards moldic wallets Hardware stuff and so on and I have a very interesting questions that I think touch that and P happens to be the next in the queue how do you build a secure build a secure setup for a company imagine you're a startup you build an MVP you went to a bunch of VCS you get a million maybe $2 million you hire a bunch of guys that going to work on your product you need to pay their salaries and you know it's all need to be secure but in the same time you need to be able to operate on the money that you get so P can you give us a little bit of insight how to how to what's the right way what's the secure way of building such a setup sure so um two things step number one uh you can keep the money in a bank and uh it will kind of work uh step number two uh if you want to keep money in crypto well definitely nose is safe is like a must right unless it's not ethereum then you of course have to find a comparable solution but uh from my experience on other Chains It's a bigger pain uh but let's say you're using uh some coins on ethereum the nosis safe is a must but then you can go a step further and think about okay let's say you have three founders you create a nosis safe at two or three right so uh whatever one of them one of you gets mugged well they're not going to steal all the money great what happens when two of you you know die um and well you might laugh unlikely scenario you both go on a plane you both get in a car uh or or you uh I don't know both lose your keys what happens to the safe now all of the money isn't accessible right in a maybe you can go like a legal route I don't know get some documents whatever you cannot do this on the blockchain so then the next step is after you have a safe while you're you're like secured uh against like very small accidents what about big accidents you can set up a Rec recovery mechanism uh safe has this nice option where you can set up an address that can basically take over a save uh after a certain amount of inactivity there are a lot more nuances to that that but it's it's built in so so you can like protect yourself in the long term that the money is always accessible but not hackable and uh this is uh you know how I would set it up and I have I would maybe add to that that not only multis is important but also your eoa is also very important that it's safe because we we know from the past that people usually keep all the seat phrases in on their computer so it's not safe if your seat Ras is on your computer all right that's that's a very good point so there's something weird that happen here like everybody's talking about different ways and we keep talking about multi where are the hardware wallets is it the forbid it's a of multis okay so it's okay that's what I also mentioned like if you're setting up this safe wallet and the the most crucial part which can execute any transaction those should be those Hardware wallets which you keep saing physically yeah I think do any of you guys use Save with Hardware wallets like only on on on on on scale from0 to 10 when 10 is completely usable and zero is an Nightmare and you don't want to do it you're doing it you're using metamask this is why it's hard right with Robie with Robie Hardware wallets work all right and also it depends on the amounts that you manage right just looking at the at the room if there is anyone from metamask here hope not they don't get offended all right guys so here is the next question three tips to avoid getting hacked as a company one TP each no repeating using harder wallet as your signer to multi cheating okay I I thought we you were you asking about three tips by each but if I had to find one just one uh I'll I I won't answer this question but it's very very important as well prepare to be hacked like because it's not about how to not get hacked because it's always a case like you can always be hacked and uh one important thing that we usually don't answer is what what happens then right and you should be prepared for that before you get hacked because after that it's too late and you don't have enough time and so build the procedures how you build how you start this war room who's going to be at the War Room uh what are the responsibilities so what are the steps after being hacked all those make those connections with people that can help you because of course you don't have your in-house uh skills for managing the the hack okay so tip number three is going to like expand which is security checkups once like every month is a good time because you have to pay your taxes you have to do other stuff like it's good to have like a for example spreadsheet with all the addresses that you manage like at L2 be we have the spre and private Keys as well right in the spread of course of course especially especially in Google Sheets like this is the best place to store your right now no no private Keys just seat phrases no in all honesty if just for clarity that was a joke yes 100% please don't put your private keys in SE phrases in Google spread sheets thank but but what I wanted to say is it's really easy Once you start doing a lot of crypto operations to like have especially if if your company is more than one person to have like a lot of different addresses so it's good to know like what this address is who can actually access it is it an EA is it a multis who has the keys and if this address gets used somewhere where is it used and then maybe right um consolidate funds into like long safe storage that you never touch stuff like that so that the the attack surface is minimized I would maybe add that um to Hardware wallets that guys you should know where your seat phrase is and also try to go through like backup um recovery backup uh process at least once because if you haven't done that it means that you don't know if it works yeah but we were talking about onchain stuff private keys but what's also very important if you're uh if you have a project are those components which which are which are outside that and I mean you should identify all the applications that you use as a project as a as a team uh like for example social media like payment um system whatever and make it secure so there are checklist for sure for for all of them and simply go through the checklist and set up all the stuff like starting from uh two Factor uh authentication or authorization uh or both and um and uh so that you know what you manage like like you mentioned the the the addresses and also you have the list of all the applications that you use you have them secured and also I would say another thing is the access control Matrix with all the people in your team because you're going to get new people on your on your board some people going to leave so this is the place where you see very easily uh what accesses you should revoke for for the person who leaves your company right I would add maybe one tip that is not that commonly talked about buy a physical safe or vault and use it like or your hard wallet seat phrases and that is so true for crypto as for other things and the gun like like yeah that that is unrelated but good advice yeah all right guys so yeah the gun yeah now we not starting on the guns though so guys we're moving away a little bit from personal company security and towards protocols the protocols we would like to use the protocols we would like to build and uh yeah again we're going to start with very simple question which is how does one know if the app or a protocol can be trusted youa would you like to start on this one it's hard to say you need to definitely like see the reputation of the page is it actually being used by many people is it actually not fake app and also for example rabie has this feature that yeah sorry guys I I will refer to rabie a lot because it's like really nice wallet that is very secure I have like ambassador program I could I should have seriously I could something I could join together with you and I should product placement I recommended rabi to so many people everyone was happy about so they should pay me for that I think the fun funny story is I think you wanted to build some features for rabie uh and then she discovered that they already exist or what what was your story I wanted to build like a wallet that is better than metamask and then discovered Rabbi that it actually does everything that wallet supposed to to do so like yeah so in rabby there is this feature that they say hey this site you are trying to interact with is wasn't used by anyone or is used like um not frequently so maybe you should verify so this is for sure uh like important but also yeah I know that you probably want to go into the direction of Auditors and yeah the site or protocol should be audited by like a d yeah like nice auditor T they they should have like a nice audits that are maybe I don't know Auditors with a great reputation and that we know that they they deliver like quality audits but that's not the most important thing because even if someone had been audited by has been audited by um an auditor that is like like that is very nice and uh everyone knows that they are quality Auditors maybe there is something in the audit that suggests that the protocol is not that secure and it cannot be trusted but you would need to read that so yeah you you just need to be very careful with that by the way how many Builders do we have in the room people who actually buil out okay so that's for the reference of the camera roughly a little bit under a half of the room can I have one question to the audience like mm uh who is not in security and have have read at least one audit report okay that's W for the refence more than I expected actually this is this is unexpected I just want to say it loud again for the people watching us on YouTube later or or streaming that almost the same amount of people who are building are actually reading audits for for for other protocols so wouldn't you guys say this is actually like it's a good thing in terms of like wow we're building awareness but but you can interpret it in a way that this space is so insecure that people who are not insecurity have to read audits so that they are safe right yeah but that's the problem of the uh security space in web 3 um because like coming back to the question how do you know if the project is trustworthy we've created a kind of methodology for our client to um rate the project that they may invest in and we have divided that into a couple of categories the first one was verifiability so that you check who's behind the project and I know that some projects are fully Anonymous and they are fine but they have to prove that they are fine like they have to operate for let's say years and you can see that there were no issues so that's that makes them okay but um if if the project is quite new you would like to know who's behind the project if it's not a someone who just uh scammed the people in their pre previous project right another thing is this Security in general like those audits but not in terms of whether reputable company has audited but on also in terms of the scope because sometimes the projects have AIT by let's say a reputable reputable company and um they changed the code or the scope didn't include some parts or included only small part like let's say the the audit was only for token but they have the whole um like a lot of different components in the project that are built on top of the token so that was the case to check the scope check the date because the the project if if you are not developing constantly your product uh you're behind right so you have to constantly improve your product so if the audit is from last year or two years ago it means that it's not um probably a recent one yeah it's Pro the project has something that was not audited so Dam I have a question for you yeah I imagine should Auditors be revealing all the audits they've done and include information how many of those protocols they were auditing got got hacked should Auditors do it by by themselves because we have or like in general have a like we have wrecked leaderboard where you can see like what were the biggest hack the biggest hacks and who's uh who's been auditing the those projects but there is a a interesting case here as well because at the beginning when the uh by the way who who knows w w. news yes and I think there is actually that that one is not that up to date anymore there is I think maybe defi Lama or somewh else there is a new safy I can't remember I think there are that are maybe more up to date I don't want to yeah but even get everyone confused but just even with re was that case when they initially just put the names of all the Auditors that were behind this project and then the companies and then the Auditors said comeand it's this was not in the scope this was for the previous version of this project so re uh changed that change the methodology how they know if the project was audited by this particular company and now like most most of them are simply un audited and this show this shows the scale because un audited doesn't necessarily mean that it was not audited at all but it mean it can mean that it the the the version that was hacked was not audited because it's not like it's not a onetime moment where you are safe where you're are secure it's a checking that out right now yeah you want to add something yeah yeah it makes sense I think it was The Nomad Bridge hack that it was a big hack but the way the hack work worked was that they did an audit like everything was like Tip Top right they did a deployment and they pushed a new version where they just changed one parameter or something and this part wasn't audited and they made an error in the parameter which meant that the entire thing was insecure or for example the proxy was not initialized and the state was so it was not the call by the setup yeah but this also shows a big problem with audits meaning that audits happen let's say at the GitHub level right and they should happen at the main net level because what you really want to audit is the deployment because the deployment has the parameters set up the deployment has the ownership set up uh and the codon GitHub has none of that and not not only deployment but also upgrades because nomat was a case when there was an upgrade the code was perfectly safe but one one value was wrong there is just so much questions I want to ask right now like you touched so many different interesting topic I'm going to start with the most direct question how to figure out if so so I wanted to ask the question how to figure out if the auditor is a good auditor but how about we flip it and say how do we know the auditor is a bad auditor CU maybe it's a simple qu simpler question if you have a bunch of Auditors to rule out those that are obviously not that good rather than keep find looking for a perfect one he hot take uh from the perspective of the end user every auditor is bad because they never work for you they work for the app and so the app pays the auditor so that the auditor finds vulnerabilities in the code given some assumptions right for example the app says hey there is this sorry finally a conflict on my panel let's go let's go I I I'm I don't want to say Auditors are bad I just want to say their incentives is to find vulnerabilities given some constraints so let's say I build this app I say I want to give have complete control over this app but no one else can steal money right and so the auditor says okay like I've checked the code no one else can steal money right but then what happens I lose the keys and the all the money is gone right so so from the perspective of the user a successful audit that says like no one else can steal the money doesn't still translate easily to the actual risk that the user is taking so I would say that's more test case where you have the rules like any governance address is out of scope don't report any findings for their governance address but in case of audits by companies like from our experience it's what you mentioned is actually more like security consultation when the client uh asks specific questions like can we be hacked in this uh functionality or what are the best practices to make it more secure but if they are uh asking for audit we always um report all the findings and one of them is uh centralized ownership let's say because this is like the most General name for this case where the the governance or mainly usually at the beginning it's the team or the the founder like even one person one eoa and there is there is no multis behind this governance or owner address there is like simply EA so let's say one person so we report that and in the end it's of course the decision of the client of the project how they going to um either fix that or accept this risk or acknowledge this finding so that's actually comes back to what you mentioned that even in the report there there can be findings which were not addressed by the by the project in the end and uh yeah the the client usually pays for the audit but the client also agrees when they um when they want to have an audit that we going to sub um we're going to report all those findings and we going to take let's say like straightforward we're going to take the the team as one of the Potential Threat actors but on the other hand like there can be a scenario when their key is lost because we when we do smart contract audit we don't audit um their key storage uh how they stor the key if it's secure so they can lose the key and if it's one EA so one private key and they keep it unsecure some they they don't have to be malicious they can be simply like their key can be simply stolen and somebody takes over the whole project right can I have a question ah there is a question from the audience the question is the question is what happens when the company that is being audited refuses to publish the audit well uh in our case in in our default um agreement we have this point that we can uh publish the the reports but sometimes clients they don't want to do that and they say we cannot agree on that and usually we agree on that because um we usually work with deps so our report is something that we are we are happy if it's published so that people can uh read it but we uh if the client wants to accept some risk they don't want to publish that we have to like agree on that because in the end it's their decision so this is the point to what P was saying like the incentive is there like the compan is working for the software company the auditing compan is working for the software company and ultimately that's the information for the end consumer that there might be a bug or some big issue that the auditing company found uh the the the smart contract author that the company that created the code just decided not to publish the code maybe went for the other auditor who didn't find the problem or issue and publish that one I think this this part is actually OV exaggerated because if and half of the room here said they reading out it so I I wonder if they're going to agree with me but when you read those audits there often there's one 2 three four criticals that just get fixed and the audit get published only after that gate fixed and get a status fixed so I never seen it like it had to be really terrible code base with 10 criticals or something but n none of the Auditors would find 10 criticals because they're going to be so tired after finding three or five and happy with the work I just wanted to answer what you mentioned that um usually uh the project want to have the the audit report to be published because that shows that they takes security seriously and also when we uh start cooperating with somebody so we are doing audit for somebody we uh tweet that so if the client uh doesn't publish that uh they like take this risk that you mentioned that they have the audit done and they are not publishing that so people will start asking questions why right so it's it's not that they can really hide it but okay nobody answered my original question we get into very interesting discussion how to figure out is a auditing company a bad company so I make it even more direct question to you yustina and tell me if some company is on the rec. news mentioned a few times I by the way check the rec. news in the meantime there's over 200 hugs I think roughly half of them is UN audited but some companies are still mentioned several times if such a company is mentioned several times is that a clear signal we should not use that company yes or no that's a risk to go for a company that was hacked already and many times for example so that's a risk you need to take if you decide to uh to get an audit from that kind of company so I wouldn't probably recommend it but that's what Damian said right that sometimes even though in re news it said like it says that this company was hacked by and audited by this auditor it doesn't necessarily mean that they followed the the findings that the auditor found so it's not that clear and it's not that black and white I also heard an argument that there are big companies like 100 hiring 100 or 200 people and there are small companies hiring like five people so if you're a big company you're going to get high act more often you you me the security companies or the the projects auditing companies yeah so like you have those big companies with 100 people doing you know whatever dozens of audits every month versus a small company that does maybe two three a month yeah like security is for sure very hard to scale but uh coming back to the question so does that mean the bigger company the bigger risk is not very good company is that well I'm sure I'm sure I'm sure there are big companies that know how to that have the methodology uh of scaling like of introducing new people working together with let's call them seniors um and uh and like transfer the knowledge so I'm not saying it's impossible but it's hard if you are uh accepting any any uh client and you have like huge line of clients and you you simply have to take care of them very very fast that's probably um uh a problem and you're going to you're not going to make it but if you're doing it um I don't want to say so slowly but uh in the time that you actually can manage keeping the the good quality I think it's doable but coming back to the question because we were talking about direct news leaderboard and there are some companies there um it doesn't actually mean that those companies are the companies that missed some critical bus because if we looked and at the back Bounty platforms and uh got all the highs or criticals there and then do the same list of companies that audited those projects and U you you would probably no have another option than uh hiring a company that has at least one high or critical uh missed right because it's it's it's even for unit SP before before which was audited by very many big companies smaller companies and I saw like they they haven't published and the audits yet but I saw on their GitHub there was uh some comet called like C1 which from audits which means probably critical one and I checked in the code and it seemed like a interesting case uh so I didn't get how ex what was the exact root cause there but I'm looking forward for the report uh for them and it shows you sorry okay uh so it shows you that even huge companies that have um great developers a lot of different completely different auditing companies behind them they still can have a critical back and I'm pretty sure there's going to be some maybe not criticals but some um let's say mediums um submitted on back Bounty platforms after they deploy but usually those maybe not usually but some some of those submissions are what P mentioned the the bugs not coming from the source code but coming from the configuration also like I was thinking a lot about the question like finding bad Auditors and I'm going to attack the premise of the question like why do you care if an auditor is good or bad you only care about it because you're going to have to pay for the auditor but if the end goal is to have your product secured right what you want to do is not find the best auditor but hire multiple Auditors and have a back Bounty program and have it continue after you launched so so it it really doesn't matter that you like know a good auditor from a bad auditor like pick a few reputable ones right to a bu Bounty program I don't exactly see how that's a wrong approach well some people would say if you put your code on code Arena or some other bug bounties for those of you who don't know there are like two types of bug bounties there are those you um do before you deploy to the production and there is uh so platforms like code Arena and there's IMM unify I think it's the name and it's for Life buik bounties once you on the production right so we're talking about code Arena likes so isn't that already like putting your code to multiple auditors well exactly but then attacking the premise of the question you don't even need to find the bad and good Auditors right you you don't need to have a predefined metric I wouldn't say that because you you want to find the auditor that will understand your code and not going through you know checklist seeing that yeah you have non rency uh issues or something like that you want someone you want to find someone that will understand the code will understand the vulnerabilities and will help you make it secure so you kind of want to know which one are the the best I I would say you're not looking for good or bad auditor you're looking for auditor that you're comfortable with so some some people that you feel the chemistry when you were working together because for example those contests so this predeployment back Bounty um there are some documentation there's some mentation sometimes they record walk through and a lot of people are starting the audit and a lot of questions arise on these discords and other uh channels other other platforms and they simply cannot answer all those questions so they are doing they are giving general answers so in this case you cannot work in close cooperation with the team and I think this is the this is crucial because without that you don't know the the assumptions those assumptions that you mentioned they are not very good because uh the the project can have some assumptions that you should disagree with but in the end you have to understand those assumptions because um some bags that you that are very hard to find are those business logic backs and you have to understand deeply how the project works and now when the projects are getting bigger and bigger this is even more crucial because you really have to uh have a source of information that instant information that that can answer all your questions so we we love to cooperate with clients when they let's say reserve a few Developers for us of course they do their daily work but whenever we have a question we we get answered in like half an hour depending on the time zone of course can can I actually ask a question instead of you cuz yes sorry back when I was still programming smart contracts I was like constantly frustrated with solidity as a language like it has so many pitfalls so many problems and and I was I was dreaming of a better language and and even even still today I'm no longer programming I'm I'm I'm I'm looking into smart contracts reviewing them for all twos and I'm still thinking like how many of those problems could could just be solved if we just had a better language and so yeah not JavaScript but but but I wonder like why don't projects that have millions of dollars of funding right invest into like better features in solidity like built-in re-entrancy protection right um better standard Library like if you've read smart contract source code you know that to interact with erc20 tokens you have to do some weird stuff you cannot just call transfer because some erc20 tokens do some weird stuff there and like but the fun fact is they try to fix it like three or four times and every time someone got hacked yeah so so so I'm thinking like why not and this goes back to what we talked at the very very beginning which is the the the the environment that we're working in is like insecure by default and why why don't we as an industry invest into like making it more secure by default like we're we're doing this all the stuff on the edges like B bounties and whatever but but as you said the projects grow right the the complexity grows and it's all built on this shaky Foundation like I would like to to to hear your your guys thoughts on that so you've got the Legacy right so it's hard we we would have to like reset and say that now we know how to do it properly so let's start again let's all move to salana I didn't say that but okay um I'm leaving you're moving to salana so so it's I think it's impossible to do it like easily like no we a switch I have a fun story about that so there's this guy in our company and he's a big fan of um what's the other blockchain cardano your mic isn't working sorry one more time so we have a guy in the company and he's big fan of cardano and he always talks how hcll is a better language and um why don't we use hcal card and all that stuff right and and the that but it it's I think it's a very valid question like and but I think and this has happened over and over and over that there is this thing called Network effect and this network effect I think people usually associate Network effect with say social media right I have all the friends on my social media but then there is Network effect on um blockchains it's usually in form of liquidity like all the liquidity seems to be on EVMS on ethereum ecosystem like vast majority of things that people do do on the blockchain they do do on in big eum ecosystem consider as you know l2s and alternative EVMS and so on right and but the same happens for languages right like JavaScript owns browser mhm so there was multiple attempts by the big tech companies like Google and Facebook to build better JavaScript and every every single attempt failed eventually Microsoft came with typescript and it's all becoming even more messy and and and today to set up a project in JavaScript is a nightmare it's never done it's a Act of I don't do it anymore right and with web box and new tools and this tool doesn't work with that tool and it's exactly solidity is on this Crossroad of those two net powerful Network effects on one hand we have all the liquidity on the evm it's super powerful Network liquidity related and the other is the other is developer Community which is solidity developer community and it just seems and so many companies Solana tried to break it cardano tried to break it many other before and later tried to break it and everybody failed yeah you even have different languages for evm like Viper for example which is in Python and has some build that's I guess the because first of all solidity was first right so there is plenty of resources how to learn solidity and not not so many how to learn Viper uh for example yeah I would maybe defend a little bit solidity because it evolves it changes so they are they are adding like constantly some improvements to this language and as Daman said it's difficult because we need to support the previous versions We and you have their reset um and also safe MAF is now built in and everyone is secure finally maybe maybe re-entrance in solidity n yeah maybe maybe in the future but I I don't like when somebody says that re-entrance is vulnerability it's a feature a feature sure it's a feature so there are project it's a feature that allows to extract millions of dollars from Smart contracts by hackers every year like you have those call backs and with re-entrance C it would be impossible right oh guys I want to interrupt we have just few more minutes and I have two I think very important question I want to ask I just want to summarize and everybody to hear that JavaScript and solidity are here to stay sorry good the the the one thing when we were talking earlier and I was trying to be you know facilitating a little bit of conflict but something start occurring to me when we were talking is like those companies are doing those Audits and then maybe developers going to apply order recommendation or not and even more importantly they can apply the code might be fine but the setup might be wrong right the deployment should we as a community broader developer community in blockchain space develop some kind of standard like every every project should have a website when it says you know those are the contracts involved those are the audit the ver those are the links to the AIT of that version specifically that deployed or that version has has been modified you know and you know this is the multic that can do this and that and so right is that something like we should be well that's something that we already try to do in composable so we created the standard that goes through the whole process starting from the building the architecture like not even implementing your code and then going through the implementation like all the sdlc right and then we also created the security guide uh which is like fre free to download from our website where you have all those security services at your disposal on all different stages like starting from the the idea in your head you can start with threat modeling because I like one thing I really hate about Security in web 3 is that audits audits audits audits like the only thing that we talk about audits audits audits because everybody does that like all the security companies do that we also do that because audits audits audits audit so why wouldn't we but it's so hard to introduce other um services and of course there are some other services uh like formal verification which are hard or or quite expensive or fuzzing which is uh maybe not expensive but also quite hard there not so many people that do that uh but we don't talk about the previous stages like for example building your in-house security it's not EAS it's not hard it's not expensive you can simply start doing that and it will pay off in a year you find somebody in your team a developer that is interested in security you reserve some uh budget for them some time for them and give them some um tasks security tasks like hey we've heard about red modeling can you research that and can you do it for us like your inter inhouse security threat modeling itself like knowing if if you collect if you make all your team members come together and talk about your project trying to build a high level view of your project and changing the mindset of how can we break that you will hear so many different um answers from so many different angles and this is very cool because you're doing it in house you don't need anybody uh if you don't know how to do it you can ask somebody but another thing is also having a security partner so a company security company that doesn't do only audits audits audits audits but also do some consultation can answer your questions if you have them and uh you don't have to like reserve them you have to just have a um Communication channel with them so that you can it can be a telegram group signal Group whatever or slack whatever you like and just somebody to uh ask questions and that's not expensive I think we have only three uh minutes left I have one more question so I propose I'm going to form it in a following way so three top tips one person each how to best prepare protocol or the for an audit and you now would you like to start I can take the basic one like having a good quality code with covered with tests and a reasonable process of code review and just continuous integration and I would say these are maybe I I told you three already but uh I would say documentation and I mean uh describing your main business flaws um the roles in your project the assumptions what the roles can do um and uh the the high level view diagram that you have created in house and the threats that you have identified by yourself so what are you afraid of okay and and my tip would be like apply the most important principle in software development that I know of which is the code should be written so that it can be read by anyone and then it can also be read by Auditors right can I can I say one one thing because we talked about the Audits and security and and I I just want to leave this because maybe someone hasn't heard about this tool and I think it's like the best tool for security in blockchain revoke docash you like click revoke on everything so like if you haven't heard this do it today thank you so if we can make last takes like if you're Builder having a project check out what is Seal 911 I'm not going to tell you what it is because I want you to be curious about it and Google that seal 111 911 okay so I will add also one more thing if you are building a protocol and you are M asking a user to approve just ask for approval of the exact amount you want to use not make unlimited approvals because then revoke cash doesn't make any sense if you have limited approvals you heard them us another tech lead at um w rer Damian Rush founder at composable security and P schlak Co at albit thank you very much for listening stay stay safe and give a nice round of applause thank you thank you thank you
Automatic transcript — names and jargon may be misspelled.