How to not get hacked and other security lessons learned | Riyaz Faizullabhoy & Nass Eddequiouaq

How to not get hacked and other security lessons learned | Riyaz Faizullabhoy & Nass Eddequiouaq

Source: YouTube · a16z crypto · published May 19, 2023 · 1:08:11

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This presentation covers security lessons learned from major Web3 incidents, focusing on how to prevent hacks through holistic security approaches 0:10.

Key Takeaways:
• Web3 security goes beyond smart contracts to include multiple attack vectors like code exploits, advanced persistent threats, Oracle/governance manipulation, and front-end compromises 2:11
• The Nomad Bridge hack resulted from a simple initialization error that allowed anyone to process transactions, highlighting the need for thorough testing of all updates to production 12:21
• The Ronin hack demonstrated how traditional Web2 attacks like phishing can compromise systems, as attackers gained access through a malicious PDF and then moved laterally across validator networks 20:00
• Badger DAO's front-end compromise showed how attackers can inject malicious JavaScript to redirect user approvals, emphasizing the need to secure all components of the system 26:19

Building secure Web3 systems requires implementing security throughout the development lifecycle, from design through testing and deployment 31:35.

Sources:

  • 0:10 Introduction to security lessons from Web3 incidents
  • 2:11 Overview of different attack categories in Web3
  • 12:21 Deep dive into the Nomad Bridge exploit
  • 20:00 Explanation of the Ronin Bridge phishing attack
  • 26:19 Analysis of the Badger DAO front-end compromise
  • 31:35(https://www.youtube

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

[Music] thank you so today our talk is all about security lessons learned from seeing incidents in the Wild theme out attack types and understanding holistically what are the threats and then given that how not to get hacked for your protocol or project or app and taking all those Lessons Learned and making it practical uh so before that as Jeff mentioned this is us we used to be a c Stone CTO at asystemz crypto thinking about security infrastructure kind of across the portfolio but the broader ecosystem we also worked at Facebook on the labor project so thinking about consumer scale security blockchain integration to Wallace custody and then also have thought about security from the institutional side so you're both at Anchorage early I was a founding engineer Nas joined also very early t…