Loading…
ETH Gathering has ended
✅ Check out the ️👇 MAP 👇to find your way around the venue 🗺️ 🥳🗺️
Security [clear filter]
Saturday, November 19
 

10:05am CET

Scaling Formal Verification to Find Bugs in Complex Smart Contract Systems
Formal verification is a technique for detecting bugs and mathematically proving their absence. By comparing the existing behavior of the program to its desired behavior, code security is drastically increased. However, most tools do not scale to handle realistic programs. I will explain how the Certora Prover successfully verifies programs with 10,000 lines of Solidity code.

Speakers
avatar for Mooly Sagiv


Saturday November 19, 2022 10:05am - 10:30am CET
Stage Apartment
  Talk

10:45am CET

Reverse Bug Bounty - Intro to Certora
This workshop will teach you everything you need to participate in the reverse bug bounty

It's important to pre-register for this session, please follow this link:

https://ethgathering.substack.com/p/eth-gathering-barcelona-2022-v3?r=40dzj&utm_campaign=post&utm_medium=web

Moderator / Facilitator
Saturday November 19, 2022 10:45am - 12:45pm CET
Workshop Loft

2:30pm CET

Security Pitfalls when Building with DeFi Money Legos
The explosion of DeFi has led to the creation of protocols e.g., on-chain funds, which allow users to manage funds they don't own and interact with multiple protocols. This raises many security challenges, allowing users to steal those funds. In the talk, we describe some common patterns people employ and some pitfalls they should be aware of.

Speakers
avatar for Ioannis

Ioannis

Engineer, ChainSecurity


Saturday November 19, 2022 2:30pm - 2:55pm CET
Stage Library
  Talk

3:00pm CET

Auditors & Protocols
  • Audit scope & effort
  • Documentation & testing
  • Prices
  • Lead time or scheduling challenges
  • Manual vs Tools
  • Private (our client = client)  vs Public (our client = community)
  • Severity of issues
  • Modifications in audits
  • Blame




Moderator / Facilitator
avatar for Rajeev

Rajeev

Secureum

Speakers
avatar for Hossam

Hossam

Halborn
avatar for Mooly Sagiv
avatar for Kurt Barry

Kurt Barry

MakerDAO
avatar for Emilie Raffo

Emilie Raffo

Founding partner, ChainSecurity
Emilie Raffo is a founding partner and the sales director of ChainSecurity, one of the oldest and most trusted smart contract auditing companies. ChainSecurity serves many large DeFi protocols such as MakerDAO, Lido, Compound, Curve, Yearn, 1inch and others. Discover our reports here... Read More →


Saturday November 19, 2022 3:00pm - 4:00pm CET
Stage Library

3:00pm CET

How to fix swapping in DeFi and how not to get hacked
At widolabs, we’ve been exploring the space of swapping non-liquid tokens like vaults, pools or farms. And we got hacked along the way.

In this workshop, I will briefly explain why non-liquid token swapping is important. As well as how to approach a product rollout to minimize the chances of being hacked.

Moderator / Facilitator
avatar for Roman Mazur

Roman Mazur

Founder, Wido
Founder of Wido Labs, building an API for swapping any token, including non-liquid tokens like vaults, pools or farms.

Saturday November 19, 2022 3:00pm - 4:00pm CET
Workshop Loft

4:10pm CET

Reviewing DAO Security
DAOs are a new form of governance whose number is increasing in the DeFi ecosystem. They help manage some of the biggest protocols. However, they are not immune to attacks. In this talk, we will review some of the most common vulnerabilities presented in this type of organization as well as the biggest hacks and some security measures that we can apply to try to avoid or minimize the risk.


Speakers
avatar for Mar Gimenez


Saturday November 19, 2022 4:10pm - 4:35pm CET
Stage Library

4:45pm CET

Secure DeFi smart contract development on Ethereum
ChainSecurity expert auditors will present a methodology for secure smart contract development. Attendees will be coached through exercises to improve their skills in the secure development of smart contracts.

Moderator / Facilitator
avatar for Ioannis

Ioannis

Engineer, ChainSecurity

Saturday November 19, 2022 4:45pm - 5:45pm CET
Workshop Loft
 
Sunday, November 20
 

10:50am CET

The Fight for MEV
The Fight for MEV is a talk that focuses on the two most "famous" MEV solutions designs, CowSwap and Flashbots. It will go over the differences in how each model is designed, and why each solution has made those choices (users, objectives). We will end with how we see the future at CowSwap in relation to the merge, MEV, and the overall Ethereum DeFi ecosystem.

Speakers
avatar for Alex Viñas

Alex Viñas

CoW Swap


Sunday November 20, 2022 10:50am - 11:15am CET
Stage Apartment

11:00am CET

Building Secure Contracts: Use Echidna Like a Pro
In this workshop, attendees will gain hands-on experience with Echidna - an open-source smart contract fuzzer - to build secure smart contracts. Echidna has been used in many professional audits, and fuzzing is a key component to increasing the contracts’ security. Attendees will learn how to define and write invariants and how to use Echidna efficiently. By the end of the session, they will know how to integrate property testing into their development process and write more secure code.

It's important to bring your own laptop for this workshop

Speakers
avatar for Gustavo Grieco

Gustavo Grieco

Trail of Bits


Sunday November 20, 2022 11:00am - 1:00pm CET
Workshop Loft

12:05pm CET

Web3 Profiles with ENS
Exercise to create and own your Web3 profiles and learn how to integrate them into your apps / dApps.

If you'd like, bring your laptop with a coding environment setup (JS based, NPM, Node etc). It's not a must :) Everyone is free to join and listen to the first part where we'll talk about what is ENS, how to register and set-up your account.

Moderator / Facilitator
avatar for tanrikulu.eth

tanrikulu.eth

ENSDomains

Sunday November 20, 2022 12:05pm - 12:35pm CET
Workshop Garden

2:00pm CET

Building EVM Radar
The nature of blockchain of being transparent and allowing everyone to see everything at any time while tons of smart contacts getting deployed every day to multiple EVM-based chains, some of them for educational purposes some of them are functional contracts and some of them are malicious.

In this presentation, I will explain how Halborn team built a chain-wide bytecode scanner to scan the entire EVM-based networks to identify vulnerabilities based on a signature database of EVM instructions leaving almost zero chance for false positive alerts. A lot of topics/tools are involved such as reverse engineering/distributed systems and EVM internals are discussed to give the community the ability to build more signatures and make EVM-based networks safer!

Speakers
avatar for Hossam

Hossam

Halborn


Sunday November 20, 2022 2:00pm - 2:25pm CET
Stage Apartment
  Talk

2:30pm CET

L2 Security
Moderator / Facilitator
avatar for Daniel Lumi

Daniel Lumi

Web3 Researcher & Consultant

Speakers

Sunday November 20, 2022 2:30pm - 3:30pm CET
Stage Apartment

3:35pm CET

OpenZeppelin - Contracts Bots Gang
An introduction to on-chain real-time bug discovery using Forta bots

Speakers
avatar for Dario Lo Buglio / xaler

Dario Lo Buglio / xaler

Openzeppelin - Contract bots gang


Sunday November 20, 2022 3:35pm - 4:00pm CET
Stage Apartment
  Talk

4:15pm CET

Monitoring & Incident Response
Please be advised that Andrew Beal (Forta) and Mitchell Amador (Immunefi) will connect remotely.

Moderator / Facilitator
avatar for Rajeev

Rajeev

Secureum

Speakers
avatar for Gonçalo Sá

Gonçalo Sá

ConsenSys Diligence
avatar for Dominic Bruetsch

Dominic Bruetsch

Chainsecurity


Sunday November 20, 2022 4:15pm - 5:15pm CET
Stage Apartment
 
  • Timezone
  • Filter By Date ETH Gathering Nov 14 -20, 2022
  • Filter By Venue Barcelona, Spain
  • Filter By Type
  • Info
  • Panel
  • Side Events
  • Talk
  • Wellness
  • Working session
  • Workshop
  • Tracks

Filter sessions
Apply filters to sessions.