DSS 2022

First Annual DeFi Security Summit

Paul & Mildred Berg Hall, Stanford, August 27-28

About

DeFi is an emerging suite of applications for decentralized asset management over blockchain technology. DeFi is becoming a major economic vehicle in modern society. The Ethereum blockchain alone already manages more than 235 billion USD worth of assets. One of the basic principles behind DeFis is that the code is law and computer programs called smart contracts that run on the blockchain dictate the conditions and the effects for asset transactions. This groundbreaking idea has many desirable benefits that originate from trust-minimizing and immutable aspects of decentralized public blockchains. However, vulnerabilities in smart contracts and in their applications may be exploited to steal or deny access to assets managed by them. Mitigation and prevention of such damages are challenging and require new software development and security design methodologies. Hundreds of millions in USD value have already been lost due to vulnerabilities in smart contracts. Therefore, smart contract security is a significant concern for DeFi applications.

Spearkers

Joran Honig

Security Researcher, Consensys

Mudit Gupta

CISO, Polygon

Tarun Chitra

Founder & CEO, Gauntlet

Emilio Frangella

VP of Engineering, Aave Labs

Mehdi Zerouali

Founder & Director, Sigma Prime

2022

Records

Teaching Smart Contract Security Through Damn Vulnerable DeFi v4 | Tincho (The Red Guild) | Speaker: Tincho
Eugene Pshenichny, Lido – Lido v2 upgrade from a security perspective
Emiliano Bonassi, DeFi Italy – The Big Red Button: How to Plan and Design for Security Events
Mitchell Amador, CEO of Immunefi – Security Incentives: From Six Figures to Billions in DeFi Bug Bounties
Samczsun, Research Partner at Paradigm, White-Hat Hacker – How Do You Even Write Secure Code Anyways
Emiliano Bonassi, Mitchell Amador, Samczsun – Discussion: White Hat Hacking
Daniel Von Fange, Senior Engineer, Origin Protocol – How to Understand a Smart Contract Hack
Christoph Michel, Security Researcher – Price Manipulation Exploits
Tina Qian, Blockchain Security Engineer, Coinbase – Smart Contract Governance
Daniel Von Fange, Tina Qian​, Kurt Barry – Discussion: Security
Mudit Gupta, Chief Security Officer at Polygon – TWAP Oracle? No, Thanks.
Tarun Chitra, CEO and Co-Founder of Gauntlet – Probabilistic Liquidity Attacks in DeFi
Nurit Dor, VP Product at Certora – From High-Level DeFi Properties to Concrete Security Bugs
Mudit Gupta, Tarun Chitra, Nurit Dor – Discussion: Security
Jack Sanford, Co-Founder of Sherlock Protocol – The Unreasonable Effectiveness of Audit Contests
Christopher Whinfrey, Co-Founder at Hop Protocol – Securing a Cross-Chain Bridge
Ryan Zarick, Co-Founder and CTO of LayerZero Labs – Pre-Crime and Library Upgrades: The Future of Omnichain Security
Layne Haber, Research Lead, Connext – Breaking Down Bridge Security Models
Yoav Weiss, Security Fellow at the Ethereum Foundation – Breaking Bridges – An Incomplete Sampler of Bridges Hacks
Christopher Whinfrey, Ryan Zarick, Layne Haber, Yoav Weiss – Discussion – Bridges
Kostas Ferles, Principal Scientist, Veridise – V for Verification: A Unified Service for Secure Blockchains
Jesse Tasman, Head of product at Redefine – DeFirewall: Combatting Attacks and Putting an End to “Blind Signing” on DeFi Transactions. A live demo.
David Tarditi, VP of Engineering at CertiK – Tools For Supporting Manual Auditing At Scale
Denys Ivanov, Hacken COO – What Should the Scope of the Web3 Audit Look Like?
Sebastian Bürgel, Founder HOPR – Privacy and Security
Everett Hildenbrandt, CTO of Runtime Verification – Formal Verification of Foundry Tests
Joran Honig, Security Researcher & Product Lead, ConsenSys Diligence – Scribble in a Nutshell
Natalie Chin, Security Engineer, Trail of Bits – Building secure contracts: How to fuzz like a pro
Michael George, Director of Product at Certora – Formal Verification with the Certora Prover
Jonathan Alexander, CTO of Openzeppelin – Runtime Threat Detection and Automated Response
Nick Selby, Michael Lewellen, Mehdi Zerouali, Jan Gorzny, Gonçalo Sa, Anton Permenev, Neville Grech – Auditing Panel
Mehdi Zerouali, Co-Founder and Director of Sigma Prime – Favorite DeFi Vulnerabilities
Michael Lewellen, Head of Solutions Architecture, OpenZeppelin – Securely Scaling Decentralized Governance
Filipe Casal, Cryptography Analyst, Trail of Bits – Static Analysis for Zero-Knowledge Programming Languages
Anton Permenev, Founding Partner at ChainSecurity – Alpha for Auditors: The Vulnerabilities of Tomorrow
Gonçalo Sa, Co-Founder and Security Researcher, ConsenSys Diligence – Clear as Mud – How Compilers Look Like VMs
Jan Gorzny, Head of L2 Scaling at Quantstamp – Not Quite Water Under the Bridge: Review of Cross-Chain Bridge Hacks
Neville Grech, Security Engineer and Founder, Dedaub – Billion Dollar Bugs
Yuchen Lin, storm0x, Nicolás Venturo – Discussion
storm0x, Contributor in Security and Core Development, Yearn – Risk Management Approach to Security
Yuchen Lin, Lead Security Engineer, TrustToken – Searching Outside the Streetlight
Nicolás Venturo, Head of Smart Contracts at Balancer Labs – Towards Verifiably Secure Governance
Kurt Barry, Jared Flatow, Emilio Frangella, Mark Toda – Discussion
Mark Toda, Protocol Engineer, Uniswap Labs – TWAP Oracles After the Merge
Emilio Frangella, Head of Smart Contracts at AAVE BGD – The Butterfly effect: Small mistakes, massive consequences – and how to avoid them
Jared Flatow, VP of Engineering at Compound Labs – Secure by Design
Kurt Barry, Smart Contract Specialist, MakerDAO – MakerDAO Smart Contract Safety – When Billions are at Stak
First Annual DeFi Security Summit John & Mooly – Opening

Book your Accomodation

17-19.11.#25
Buenos Aires, Argentina
apply to speak