defi-threat icon indicating copy to clipboard operation
defi-threat copied to clipboard

a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations on decentralized finance

Results 20 defi-threat issues
Sort by recently updated
recently updated
newest added

see https://raw.githubusercontent.com/ossf/osv-schema/main/validation/schema.json example: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-26qj-cr27-r5c4/GHSA-26qj-cr27-r5c4.json ref: https://docs.github.com/en/code-security/dependabot/dependabot-alerts/editing-security-advisories-in-the-github-advisory-database

enhancement
help wanted

https://twitter.com/gauntletnetwork/status/1549834606781808641

documentation
help wanted
Document Attack Pattern
Clarify Attack Pattern
Example Attack Pattern

**Is your feature request related to a problem? Please describe.** Backend servers are often used for things like compounders, apis, oracles, etc.. This requires remote access, usually through SSH. Default...

documentation
help wanted
Document Attack Pattern
Example Attack Pattern

https://gist.github.com/rossgalloway/e7d28830b66ea0fcf9bbd4bb9cd6f46b

documentation
help wanted
Document Attack Pattern
Example Attack Pattern

## Problem The off-chain attacks section is pretty cool, and not something a lot of people consider. However the google sheets does not really mention any resources, guides, etc.. to...

documentation
enhancement

https://github.com/runtimeverification/verified-smart-contracts/wiki/List-of-Security-Vulnerabilities

see 1. https://www.nrel.gov/docs/fy21osti/77521.pdf 2. https://github.com/livnev/auction-grinding/blob/master/grinding.pdf

Smart Contract
documentation
network
proposal
New Attack Pattern

previous link was broken, also added a link to the older version just for convenience and minor style changes

https://snapshot.org/#/cow.eth/proposal/0x812273c78abe1cea303d8381e1fb901a4cb701715fd24f4b769d0a0b3779b3e2 ![0F99EBC1-7CED-463B-B7E5-FA5D9CCB25ED](https://user-images.githubusercontent.com/32783916/188647194-debdc76e-984e-461d-8e3f-3a999e92a087.jpeg)

bug
help wanted
New Attack Pattern
Document Attack Pattern

# Price Manipulation via Donation Attacks example from CREAM Finance attack Here is the exploit: donate double existing amount yUSD to yUSD Vault. This doubles the value of yUSD so...

Clarify Attack Pattern
Example Attack Pattern