CuraSec

tag: Smart-Contracts · 4 items

2026-08-17 · arXiv cs.CR · source ↗ #defi#smart-contracts#audit-scope
  • Engineer — Skip
  • SOC/IR — Skip
  • Leader — Learn: Research across 135 DeFi incidents shows that the ‘audited’ label routinely overstates project-wide assurance — 67.6% of attack paths fell outside all identified pre-incident audit scopes. Useful context when evaluating what your own audit attestations actually cover in board or customer conversations.
2026-08-03 · arXiv cs.CR · source ↗ #phishing#web3#smart-contracts
  • Engineer — Learn: Novel attack class showing how state-dependent smart contracts can make malicious transactions appear benign during wallet simulation previews; relevant for teams building Web3 integrations or DeFi applications, but no patch or configuration action is available for typical enterprise stacks.
  • SOC/IR — Skip
  • Leader — Skip
  • Engineer — Learn: Interesting research combining code slicing with LLM analysis to detect reentrancy and overflow in ERC-721 contracts, but no tooling release or actionable change to running systems today.
  • SOC/IR — Skip
  • Leader — Skip
  • Engineer — Learn: Research demonstrates a multi-agent pipeline that auto-generates executable exploits for 94% of tested smart contracts, a meaningful capability jump over prior tools; worth evaluating if your team ships or audits Solidity code, but no running-system action needed today.
  • SOC/IR — Skip
  • Leader — Skip