A CertiK security analysis has uncovered more than 50 DeFi and NFT projects with critical vulnerabilities. We feel obligated to share these insights with our community.

All of these contracts share three code-based features that enable the developers to rugpull.

  1. Infinite Supply

By calling the function rewardHolders(uint256 amount) external onlyOwner…

Transaction Operations for a Common Token Transfer

When it comes to Ethereum, the first thing that comes to mind may well be “gas fee”. Nowadays, the mainnet of major blockchain projects are online, and their synonyms for ‘transaction fees’ are often inseparable from the word “gas”.

The high gas fee has always been a sore point for…

Navigating a CertiK Security Audit

The first time you check out a crypto security audit on the CertiK Security Leaderboard you might find the report a little daunting, confusing, and a little more like hieroglyphics than an essential asset to DYOR.

Whether it’s a security audit report of your favorite ERC20, an intricate and robust…

The hacker/s used fake credentials at the front desk, gaining the trust of the receptionist; the receptionist then handed over the keys to the vault.

Incident Description

On Aug 10, 2021, PolyNetwork suffered a cross-chain attack that resulted in a total loss of $600M. …

‘Transaction Operations for a Common Token Transfer

When it comes to Ethereum, the first thing that comes to mind may well be “gas fee”. Nowadays, the mainnet of major blockchain projects are online, and their synonyms for ‘transaction fees’ are often inseparable from the word “gas”.

The high gas fee has always been a sore point for…

In his early days, Minzhi never thought he’d become a Security Engineer for the largest crypto and blockchain security company in the world. With a background in software engineering, and a desire for DeFi, Minzhi has built upon his skillset to become a Security Engineer with CertiK!

Below, Minzhi shares…

The CertiK Security Team has successfully completed an audit of XEND Finance’s smart contract’s delta related to the rewarding group creator. The code in the audit is comprised of code related to rewarding a group’s creator with a percentage of the commission fee as well as to track total $XEND…

CertiK

Official Website: https://certik.com

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store