DeFi security and security protection types in Umee
In total, from 2011 to the present, there have been at least 140 attacks with security vulnerabilities, and more than 80 cases of exploiting the DeFi protocol.
There are certain standards in place to help protect users, including extensive code auditing to identify any potential weaknesses prior to product launch, as any small vulnerability can be a huge disaster for both the user and their savings.
That is why I want to present you with a few examples of how opportunities to exploit platform vulnerabilities are discovered, and what losses they brought.
I want to share with you three examples of very large losses in the history of DeFi.
PAID NETWORK
Reason: Vulnerability in the smart contract. Updating and replacing the original smart contract with a malicious version. Which allowed attackers to burn existing tokens and mint new ones, which eventually came under the complete control of attackers.
Cream Finance
Reason: Re-entry vulnerability. The attackers exploited a reentrancy vulnerability that arose because CREAM integrated AMP into its protocol. Attackers using this vulnerability could borrow more assets than were available to them.
POLYNETWORK
Losses: $610 000 000 (The attackers returned the funds)
Reason: Vulnerability in the smart contract. Through interactions between several of the project's smart contracts, the attackers were able to configure the custodian role to point to their address, allowing them to transact at will.
Examples of Types of Security Risks in DeFi
- Code Vulnerability Often, neglecting security auditing or poor validation of a smart contract before deployment leads to the fact that vulnerabilities in the code were overlooked, which can ultimately lead to irreparable consequences.
- Access Control Inefficient access control implementation (or if access control was not implemented at all) can lead to the fact that attackers can gain privileged access to the smart contract and use it at their discretion.
- Compromised Private Keys Due to the poor practice of generating keys with insufficient randomness, there are risks associated with theft or leakage of private keys.
- Attacks Using Instant Credits Instant loans could allow attackers to borrow governance tokens and manipulate the protocol to their advantage. This type of attack can also be used when the value of tokens in the liquidity pool is incorrectly valued.
- Frontal Attacks Attackers can look for a transaction that they can compromise by using the miner's extractable value (MEV) and including it in the ledger before the original one.
- Liquidity Pool Estimates If the project team has miscalculated the value of tokens in the liquidity pool, attackers can launch attacks using instant credits and exploit smart contract vulnerabilities to their advantage.
How does Umee keep itself safe?
Security is a priority for Umee and this project uses the best practices to ensure the security of its platform.
Umee has partnered with Forta for comprehensive security and monitoring.
Also partners with Halborn, a leading cybersecurity consulting firm.
Moreover, the project uses techniques such as extensive code auditing, which is why Umee hired several lead auditors (we already mentioned one of them Halborn) to check every line of code and identify any potential vulnerabilities before launch, which are listed below:
Auditor: Peckshield
Report: Umeev1.0 Peckshield Audit Report
Date: January 15, 2022
Auditor: Trail of Bits
Report: Trail of Bits Full Audit
Date: March 5, 2022
Auditor: Halborn
Report: WebApp Pentest
Date: March 17, 2022
Report: Umee Oracle & Price Feeded Security Audit
Date: June 3, 2022
Report: Umee Wasm Integration Final Audit Report
Date: August 31, 2022
Auditor: Least Authority
Report: Peggo Orchestrator Final Audit Report
Date: June 6, 2022
Auditor: Runtime Verification
Report: Umee Leverage Module Audit Report
Date: June 9, 2022
About Umee
Umee is a decentralized financial DeFi hub built for cross-chain interaction between networks. As a base-level blockchain, applications and monetary primitives can be built on Umee to allow access to cross-chain leverage and liquidity. The Umee blockchain facilitates the interoperability of the Tendermint Proof of Stake protocol with the Cosmos ecosystem, the Ethereum network, sidechain architectures, second layer extensions, and alternative base layer protocols.