leapdao / meta

Everything meta and not-fitting to other repos
Creative Commons Attribution Share Alike 4.0 International
9 stars 7 forks source link

Newsletter 0x04 - "Phoenix from the Ashes" #216

Closed ghost closed 4 years ago

ghost commented 4 years ago

Bounty

new purpose, new strategies, new technologies, new fantasies... many things happened the last weeks, let's inform the world!

Scope

Deliverables

Send a newsletter to followers, informing about:

Gain for the project

Roles

bounty gardener & worker: @zschavi / 85% bounty reviewer: @saumyabratadutt / 15%

haikukoten commented 4 years ago

🤚 I'm up for review.

ghost commented 4 years ago

Leap Newsletter 0x04 - basic structure

Intro

Ecosystem Updates

Geek Garden

Outro

footer

haikukoten commented 4 years ago

This is good, should we include recent exploits mainly because DeFi is emerging?

ghost commented 4 years ago

Normally we only publish LeapDAO related information...or Plasma/Layer2 topics.

If you can propose some insights to this recent exploit/hack + how could plasma help to avoid such things, we would have a fitting paragraph 👍

I will update the above draft with content once it's ready. Hope we can ship the newsletter by end of week, or starting next one 💯

haikukoten commented 4 years ago

Sure. I will post some insights soon.

haikukoten commented 4 years ago

bZX 15 Feb attack was due to logical error. This could have been avoided by testing the code sufficiently. Finding logical errors are tough, especially when the programs doesn't flag problems in initial testing environment. More on the attack https://www.palkeo.com/en/projets/ethereum/bzx.html#b-the-compound-borrow

Second attack is of special interest since it exploited Oracle. The attack was well-thought. The basic of the attack was to eat up the liquidity from price feed provider hence screwing the price and using the screwed price to profit. Using single price feed especially from DEX with low liquidity can be dangerous, because it can be manipulated. These maybe fixed by using price feed of several external off-chain liquidity providers and exchanges because they have high liquidity plus using several of those can make manipulation harder.

ghost commented 4 years ago

new structure upcoming

ghost commented 4 years ago

as mentioned on 10 March, new structure.

this bounty is closed, due to long inactivitiy