지금 프로젝트를 보호하세요
최대 규모의 웹3 보안 제공업체로 프로젝트를 강화하세요.
CertiK 보안 전문가가 귀하의 요청을 검토 후 곧 연락드리겠습니다.

Paid Network ERC-20 Contract Stamped By CertiK

소식 ·공지사항 ·
Paid Network ERC-20 Contract Stamped By CertiK

NEW YORK, 26/01/2021 - We’re excited to announce that Paid Network’scodebase which contains the Paid ERC-20 Token, was successfully audited by CertiK. This article elaborates further on the scope of the audit.

Use-Case Profile

PAID Network is an ecosystem-powered decentralized application that leverages blockchain technology to deliver automated smart-contracts to enhance traditional business models with the efficiency and perks DeFi-enabled contracts offer. Paid Network allows its users to create their own policy, to ensure they Get PAID.

Paid Network offers standardized contracts with autofill smart-features, insurance pooling and escrow for international settlements, arbitration models governed by community stakers, reputation scoring, crowdfunding resources, and private and public auctions among other products and services.

Code Review & Auditing Process

The initial review was conducted between January 13th and January 24th, 2021, by CertiK security engineers Alex Papageorgiou, and Angelos Apostolidis.

The report represents the results of our engagement with Paid Network’s implementation of the native PAID token smart contract. Our findings were remediated on the latest version of the codebase. Hence, the issues identified pose no threat to the safety of the contract deployment.

A comprehensive examination will be performed, utilizing Static Analysis and Manual Review techniques. The auditing process focuses on the following considerations:

  • Testing smart contracts against both common and uncommon attack vectors.
  • Assessing the codebase to ensure compliance with current best practices and industry standards.
  • Ensuring contract logic meets the specifications and intentions of the client.
  • Cross-referencing contract structure and implementation against similar smart contracts produced by industry leaders.
  • Through a line-by-line manual review of the entire codebase.

A total of 6 findings were addressed on the vulnerability summary, half of which were informational (3), while only 2 minor and 1 major issue were identified. No critical issues were found during the auditing process, and the Paid Network team alleviated all issues highlighted by the CertiK Professional Services team, pointing towards a clean-cut codebase as written by the team’s engineers.

You can review the full audit here.

About Paid Network

PAID Network is an ecosystem DAPP that leverages blockchain technology to deliver DeFi powered SMART Agreements to make business exponentially more efficient. We allow users to create their own policy, to ensure they Get PAID.

Website| Twitter| Medium

About CertiK

CertiK is an edge-standards cybersecurity firm founded by Computer Science professors hailing from Yale and Columbia University respectively, aiming to improve the security and correctness of smart contracts and blockchain protocols on a global scale.

Leveraging a seasoned team of multi-skilled engineers and security auditors, CertiK’s mission is to apply a plethora of high-level industry practices, covering the entire spectrum of static, manual, and dynamic analyses, in order to ensure each project subject to a formal audit is up-to-date with modern security standards while offering their services to the broader DLT community.

Over the past few years, CertiK has serviced more than 100 top-shelf blockchains, DeFi protocols, among other complex and/or custom smart contracts, including but not limited to Binance, Tera, Bancor, Shapeshift, and Blockstack.

Consult with one of our experts at [email protected]

Stay connected!

Website| Twitter| Linkedin| GitHub

관련 블로그

Technical Deep Dive | CertiK Helped Fix a DoS Vulnerability in Solana’s Big-Integer Modular Exponentiation

Technical Deep Dive | CertiK Helped Fix a DoS Vulnerability in Solana’s Big-Integer Modular Exponentiation

This article takes an in-depth look at the importance of blockchain transaction fee models and their critical role in ensuring network security and efficient operation. By comparing the transaction fee models of Ethereum and Solana, it highlights how unsafe transaction pricing can introduce network security risks. The article especially focuses on a compute-unit (CU) accounting error in Solana’s big-integer modular exponentiation syscall discovered and reported by the CertiK team, which could lead to a potential remote DoS attack. It further analyzes Solana’s smart-contract pricing model, PoH-related timing mechanics, and parallel transaction processing, and reproduces the remote DoS process and cost via experiments on a private Solana cluster.

Building Secure Lightning Network dApps: Best Practices and Secure Check Lists

Building Secure Lightning Network dApps: Best Practices and Secure Check Lists

This post focuses on security areas that matter the most in real Lightning dApps. It is written from an audit perspective: what consistently causes loss of funds and stuck funds, common attack surfaces, and how developers can prevent them.

What are Decentralized Physical Infrastructure Networks (DePINs)?

What are Decentralized Physical Infrastructure Networks (DePINs)?

Learn more about Decentralized Physical Infrastructure Networks (DePIN) and how they are helping merge Web3 and physical infrastructure to create new possibilities.