GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar
OpenZeppelin

OpenZeppelin

Active

Crypto cybersecurity technology and services company

News Heat Trend

Project Overview

OpenZeppelin is a crypto cybersecurity technology and services company providing security products to build, automate, and operate dApps, as well as audits for decentralized systems.

Event-related news

Taiko: Attack Resulted from Off-Chain Signature Key Leak and Verification Process Gap

Odaily News: Ethereum Layer 2 network Taiko released a post-mortem of the June 21 security incident, stating that the attack resulted from an off-chain signature key leak and a verification process gap. The attacker exploited these to forge proofs and bypass the Prover whitelist, rather than breaking ZK cryptography or smart contracts. The attacker stole approximately $1.75 million from cross-chain bridges and Vaults, but over $11 million in assets were protected, and no user funds were lost. Taiko has fixed the vulnerability, restored the pre-attack state, and resumed operation on July 2; an OpenZeppelin audit confirmed the fixes with no high, medium, or low-risk vulnerabilities identified. The official statement also indicated that the Unzen upgrade, scheduled for August 6, will require ZK proofs for every block to further enhance network security.

Dragonfly Partner: DeFi "Hacker Doomsday" Warning Failed to Materialize, AI Hardening Significantly Improves Security of Major Protocols

Dragonfly 管理合伙人 Haseeb Qureshi(@hosseeb)在 X 平台发文,距 OpenZeppelin 创始人 Manuel Aráoz 发出"DeFi 全面不安全"警告已过去两个月,数据显示所谓"黑客末日"并未成真。 数据显示,2026年 DeFi 被盗金额年化值低于 2025 年全年,即便剔除异常月份(如 Bybit 黑客事件、Drift 及 KelpDAO 事件)后对比,2026 年每月被盗金额仍低于 2025 年;按 TVL 标准化后,2026年 DeFi 资金被盗比例同样略低于 2025 年。 Haseeb 指出,当前呈现出"攻击次数上升、单次规模下降"的结构性特征——攻击者主要针对无力承担 AI 安全加固成本的小型协议和废弃项目,而已完成 AI 代码加固的大型协议安全性实际上有所提升。他总结称,"DeFi 中平均每一美元的安全性与一年前持平,将资金存放于大型协议大概率是安全的。"

USDT0 Reveals Security Architecture Details: Implements 3/3 Verification Mechanism and Launches $6 Million Bug Bounty Program

following the Kelp security incident, Tether's asset interoperability protocol USDT0 has disclosed details of its protocol security architecture. It stated that the system currently utilizes a proprietary DVN (Decentralized Verification Network) with message veto authority, and requires 3 independent validators, operating on different codebases, to reach a 3/3 consensus before cross-chain messages can be settled. The current verification nodes include the USDT0 proprietary DVN, LayerZero, and Canary, with future plans to expand to 4/4 and 5/5 verification mechanisms.USDT0 also stated that all multi-signature transactions must undergo multiple reviews by internal teams, external security teams, and auditing firms before signatures are submitted. The relevant contracts have been audited by firms such as Guardian and OpenZeppelin, and a $6 million bug bounty program has been launched on Immunefi.

Taiko: Attack Resulted from Off-Chain Signature Key Leak and Verification Process Gap

Odaily News: Ethereum Layer 2 network Taiko released a post-mortem of the June 21 security incident, stating that the attack resulted from an off-chain signature key leak and a verification process gap. The attacker exploited these to forge proofs and bypass the Prover whitelist, rather than breaking ZK cryptography or smart contracts. The attacker stole approximately $1.75 million from cross-chain bridges and Vaults, but over $11 million in assets were protected, and no user funds were lost. Taiko has fixed the vulnerability, restored the pre-attack state, and resumed operation on July 2; an OpenZeppelin audit confirmed the fixes with no high, medium, or low-risk vulnerabilities identified. The official statement also indicated that the Unzen upgrade, scheduled for August 6, will require ZK proofs for every block to further enhance network security.

USDT0 Reveals Security Architecture Details: Implements 3/3 Verification Mechanism and Launches $6 Million Bug Bounty Program

following the Kelp security incident, Tether's asset interoperability protocol USDT0 has disclosed details of its protocol security architecture. It stated that the system currently utilizes a proprietary DVN (Decentralized Verification Network) with message veto authority, and requires 3 independent validators, operating on different codebases, to reach a 3/3 consensus before cross-chain messages can be settled. The current verification nodes include the USDT0 proprietary DVN, LayerZero, and Canary, with future plans to expand to 4/4 and 5/5 verification mechanisms.USDT0 also stated that all multi-signature transactions must undergo multiple reviews by internal teams, external security teams, and auditing firms before signatures are submitted. The relevant contracts have been audited by firms such as Guardian and OpenZeppelin, and a $6 million bug bounty program has been launched on Immunefi.

Related news

Taiko: Attack Resulted from Off-Chain Signature Key Leak and Verification Process Gap

Odaily News: Ethereum Layer 2 network Taiko released a post-mortem of the June 21 security incident, stating that the attack resulted from an off-chain signature key leak and a verification process gap. The attacker exploited these to forge proofs and bypass the Prover whitelist, rather than breaking ZK cryptography or smart contracts. The attacker stole approximately $1.75 million from cross-chain bridges and Vaults, but over $11 million in assets were protected, and no user funds were lost. Taiko has fixed the vulnerability, restored the pre-attack state, and resumed operation on July 2; an OpenZeppelin audit confirmed the fixes with no high, medium, or low-risk vulnerabilities identified. The official statement also indicated that the Unzen upgrade, scheduled for August 6, will require ZK proofs for every block to further enhance network security.

Dragonfly Partner: DeFi "Hacker Doomsday" Warning Failed to Materialize, AI Hardening Significantly Improves Security of Major Protocols

Dragonfly 管理合伙人 Haseeb Qureshi(@hosseeb)在 X 平台发文,距 OpenZeppelin 创始人 Manuel Aráoz 发出"DeFi 全面不安全"警告已过去两个月,数据显示所谓"黑客末日"并未成真。 数据显示,2026年 DeFi 被盗金额年化值低于 2025 年全年,即便剔除异常月份(如 Bybit 黑客事件、Drift 及 KelpDAO 事件)后对比,2026 年每月被盗金额仍低于 2025 年;按 TVL 标准化后,2026年 DeFi 资金被盗比例同样略低于 2025 年。 Haseeb 指出,当前呈现出"攻击次数上升、单次规模下降"的结构性特征——攻击者主要针对无力承担 AI 安全加固成本的小型协议和废弃项目,而已完成 AI 代码加固的大型协议安全性实际上有所提升。他总结称,"DeFi 中平均每一美元的安全性与一年前持平,将资金存放于大型协议大概率是安全的。"

OpenZeppelin Co-Founder Says “All DeFi Is Insecure”

According to The Block, Manuel Aráoz, co-founder of blockchain security firm OpenZeppelin, stated that he now believes “all DeFi is insecure” and has advised friends and family to exit all their DeFi positions, including those in Aave, MakerDAO, and Compound.

USDT0 Reveals Security Architecture Details: Implements 3/3 Verification Mechanism and Launches $6 Million Bug Bounty Program

following the Kelp security incident, Tether's asset interoperability protocol USDT0 has disclosed details of its protocol security architecture. It stated that the system currently utilizes a proprietary DVN (Decentralized Verification Network) with message veto authority, and requires 3 independent validators, operating on different codebases, to reach a 3/3 consensus before cross-chain messages can be settled. The current verification nodes include the USDT0 proprietary DVN, LayerZero, and Canary, with future plans to expand to 4/4 and 5/5 verification mechanisms.USDT0 also stated that all multi-signature transactions must undergo multiple reviews by internal teams, external security teams, and auditing firms before signatures are submitted. The relevant contracts have been audited by firms such as Guardian and OpenZeppelin, and a $6 million bug bounty program has been launched on Immunefi.