No Critical Findings: Twenty Blockchain Protocols That Passed Audit — and Got Exploited Anyway ler

Isbn 13: 9798175290289

epub No Critical Findings: Twenty Blockchain Protocols That Passed Audit — and Got Exploited Anyway

por

Escolha um formato:

Escolha um formato:

zip ler
rar ler
pdf ler
epub ler
txt ler
djvu ler

Descrição do livro

You've read an audit report that said "no critical or high findings." Weeks or months later, the protocol lost eight or nine figures anyway — not because the auditors were careless, and not because the team ignored their advice, but because the thing that broke was never a question the audit was built to answer.

This book is twenty real incidents in that gap.

Every protocol in these pages was reviewed — often by more than one respected firm, often more than once. Every one was exploited anyway, for reasons a source-code review was never positioned to catch: a price a flash loan could move within one transaction, a security property that held for every function except the one added six months after the audit closed, a compiler that quietly failed to preserve what the source code correctly specified, a governance vote that handed total control to whoever could borrow the most for twelve seconds, a validator set that turned out not to be as independent as its name implied.

Inside, you'll find full technical breakdowns of incidents including:

  • bZx, Harvest Finance, Mango Markets, and Cream Finance — flash loans and oracle manipulation, from the first of its kind to a case so clean the attacker argued in court it wasn't a hack at all
  • Euler Finance's $197M exploit — missed by six separate audit firms, including one that later paid a $4.5 million claim for its own miss
  • Poly Network, Wormhole, Nomad, and Ronin — four different bridges, four different chains, one repeating structural gap between "verified" and "authorized"
  • Parity's multisig — a single design flaw that caused two separate incidents, four months apart, because a fix for the first was scoped one contract too narrowly
  • The Vyper compiler bug — the one chapter where the source code was completely correct, and the vulnerability lived a layer below anything an audit was ever going to read
  • Terra/UST's $40 billion collapse — no bug, no missing check, no audit failure at all, and a catastrophe anyway

Each chapter follows the same rigorous structure: what the protocol did and why it looked clean, the vulnerable mechanism with real or faithfully reconstructed code, a working proof-of-concept you can actually run (Foundry for EVM chains, Anchor for Solana), the precise assumption that broke, an honest account of why the audit missed it, and a generalizable heuristic you can carry into your own review process.

This book deliberately resists hindsight bias. It doesn't ask "how did nobody see this coming" — it reconstructs what a competent, honest reviewer actually knew at the time, so you can recognize the next boundary before it costs anyone nine figures.

Written for experienced web3 developers, protocol architects, and security auditors who already know what gas, a PDA, and a reentrancy guard are, and who want a sharper, evidence-based account of exactly where "passed audit" and "safe" diverge — not a beginner's introduction to smart contract security.

Número de páginas :163
Isbn 13 :9798175290289
Encadernação No Critical Findings: Twenty Blockchain Protocols That Passed Audit — and Got Exploited Anyway:Capa Comum
Livros relacionados