
DEF CON 32 - Web2 Meets Web3 Hacking Decentralized Applications - Peiyu Wang
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 24:15
Web3 DApps face significant security risks due to integration of web2 components and developer knowledge gaps, exposing them to both client and server-side vulnerabilities. 0:00
Key Takeaways:
• Client-side attacks via malicious JavaScript or session hijacking can enable unauthorized transactions, especially in apps with weak wallet connection checks 10:01-10:57.
• Server-side vulnerabilities include gas consumption attacks, transaction race conditions, and missing smart contract validations, leading to fund loss or asset manipulation 13:06-19:46.
• A bridge contract flaw due to missing address validation allowed fake smart contract deposits, resulting in unauthorized token releases 18:10-19:46.
• A lightweight trading app failed to validate token types, enabling scammers to inject fake NFTs and inflate balances via detection of newly active addresses 20:16-21:40.
Understanding web2 security is essential for securing DApps, as many vulnerabilities stem from poor backend design and developer expertise gaps. Hands-on experimentation with small investments is recommended to build foundational skills before pursuing formal audits.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
um yeah I hope my to can give guys a taste of web security so my name is p wayang I'm a security engineer uh so what I do is uh application P testing uh mostly web stre applications apps and wallet and I also do a smart contract Audits and security research U my past talk at Devcon are in the uh blockchain Village which I talk about uh exporting crypto wallets and uh divice scam ra pools so I outside like work I'm like a def apes and like a minan coin Traders so blockchain and DFS so since the first uh defi summer in 2020 uh the uh the blockchain ecosystem has exceptional growth there's a lot of thing being built and one way to catalyze them is like applications develop tools uh infrastructure and protocols which is the blockchain itself so apps aage and let's talk about applications uh so…