CuraSec

tag: Defi · 2 items

2026-08-17 · arXiv cs.CR · source ↗ #defi#smart-contracts#audit-scope
  • Engineer — Skip
  • SOC/IR — Skip
  • Leader — Learn: Research across 135 DeFi incidents shows that the ‘audited’ label routinely overstates project-wide assurance — 67.6% of attack paths fell outside all identified pre-incident audit scopes. Useful context when evaluating what your own audit attestations actually cover in board or customer conversations.
2026-07-21 · BleepingComputer · source ↗ #defi#supply-chain#crypto
  • Engineer — Learn: The attack exploited off-chain price-feed infrastructure to manipulate a DeFi protocol — a useful design-level lesson for anyone building systems that trust external data pipelines (oracles, webhooks, enrichment feeds) without integrity controls. No patch available; review data-ingestion trust boundaries.
  • SOC/IR — Skip
  • Leader — Skip