Neodyme Profile picture
We secure software with deep-dive audits, cutting-edge research, and in-depth trainings. Secure your solana program with Riverguard @ https://t.co/VmxVHzx2U2 🏞️💂
Jerome Ku Profile picture 1 subscribed
Nov 12, 2022 17 tweets 6 min read
Who **actually** controls the largest projects on #solana? What's the deal with Upgrade Authorities? Are your funds more safu in DeFi contracts than they were on #FTX?

Let's find out 🧵👇 For this thread, we analysed the Upgrade Authorities of the top 10 TVL projects on DefiLlama.
Jun 21, 2022 4 tweets 2 min read
1/4 🧵
There's been a lot of fuss around the recent #Solend DAO vote, with lots of discussion about what a protocol should be able to change about its #Solana smart contract. 2/4
We think the more important question is: Who controls those changes? How can you be sure your funds won't just be taken by an authority or a DAO?
Dec 3, 2021 4 tweets 1 min read
We recently discovered a critical bug in the token-lending contract of the solana-program-library (SPL). This blog post details our journey from discovery, through exploitation and coordinated disclosure, and finally the fix. The total TVL at risk was about 2.600.000.000 USD. Some of that value is lent out, and some other low-value coins are not economically viable to steal, but the potential profit was easily in the hundreds of millions.