Knowledgebase

Auditing and Verifying Contracts Print

  • blockchaindigitalassets, blockchain, billing, guide, howto, solution, zillionkinghost, hosting
  • 0

Establishing confidence before deployment.

WHAT AN AUDIT INVOLVES

Independent review of the code against its intended behaviour.

WHAT AUDITORS EXAMINE

Known vulnerability classes Access control Economic assumptions Interaction with other contracts Upgrade and administrative powers

WHAT AN AUDIT DOES NOT GUARANTEE

That the contract is safe.

WHY

Audits sample; they do not prove.

WHAT AUDITED CONTRACTS HAVE STILL DONE

Lost very large sums.

WHAT TO PROVIDE AN AUDITOR

The intended behaviour, documented The economic assumptions What should be impossible

WHY THAT LAST POINT

Without it, they can only check for known patterns.

WHAT FORMAL VERIFICATION PROVIDES

Mathematical proof that specified properties hold.

WHAT IT COSTS

Substantial effort, and it proves only what was specified.

WHAT BUG BOUNTIES PROVIDE

Continuing scrutiny, with payment for findings.

WHAT TO SET THEM AT

An amount competitive with exploiting the defect.

WHY

A bounty far below the exploitable value does not change the incentive.

WHAT TO DO BEFORE DEPLOYING

Test on a test network, extensively Deploy with limited value initially Increase gradually

WHAT TO PREPARE

A response plan, including how to pause if possible.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot