Filecoin Orbit Lagos on Saturday, June 4, 2022, hosted an online workshop titled, ‘Smart Contract Attacks & Vulnerabilities’.
Facilitated by Chukwuemeka Enoch Mbaeibe, Ambassador Orbit Community Program Lagos, the online event saw experts in the field of smart contracts demonstrate the vulnerabilities in smart contracts and how they can be avoided.
Chukwuemeka said that the workshop was the first online-only event by the Lagos Orbit community after several physical meet-ups since the beginning of the year.
This is our first online workshop, and we’re looking at the smart contract vulnerability, how to know your checks and trying to avoid loopholes for hackers to exploit your dApps.
Making the first discussion, Daniel Perez, a software engineer, who has been working on blockchain systems and smart contracts gave a timeline of what could have gone wrong with smart contracts using ‘THEDAO hack of 2016’.
Following a raise of $150m in ICO by THEDAO, it pretty soon lost $50m to hackers. This according to Daniel led to Ether’s price being halved, dependent contracts became unable to send funds, and around $280m was frozen.
Stating further, Daniel said that common vulnerabilities include; Reentrancy, unhandled expectations, integer overflow, dependency on destructed contracts, unrestricted action and transaction order dependency.
He also mentioned smart contract analysis tool which includes; Symbolic execution, EVM bytecode and checking vulnerabilities patterns. According to these tools, there are thousands of vulnerable contracts and hundreds of millions USD at risk.
In getting a hold of these vulnerabilities, Daniel stated the following; retrieve all transactions and its execution traces, encode execution traces to Datalog and Query Datalog for vulnerabilities.
Rounding up his session, Daniel mentioned a report which analyzed 23k contracts with 3M at risk with at most 0.27% of this Ether. less than 1Ok ETH was exploited. Lastly, Daniel concluded that high-value contracts seem to be secure.
Also speaking, Toyosi Salami a penetration tester, and according to her, smart contracts have been used in a variety of commercial fields, including digital assets exchange, supply chain, crowdsourcing e.t.c
Numerous security vulnerabilities in smart contracts have been disclosed, a result that has seen significant financial losses.
“Smart contracts’ execution environment is built on the decentralized, immutable nature of blockchain, these security issues present new difficulties to security research. As a result, new tools for detecting and addressing security flaws emerged. On a worldwide basis, it is vital to identify and address growing smart contract security risks”
As stated by Toyosi, one of the smart contract vulnerabilities is the possibility of Overflow and Underflow, giving a real-life example of this, she mentioned the POWH Coin developers flaw that led to a depletion of 2000 ETH.
She suggested the use of OpenZeppelin SafeMath Package to avoid such vulnerabilities. Toyosi also mentioned that there is yet to be a big DDoS attack on any blockchain network, however, TRON revealed a vulnerability earlier this year.
Concluding, Toyosi listed how to be safe using smart contracts
- Use an excellent development environment
- Use standard programming components that have stood the test of time
- Stay up-to-date with the latest developments in Solidity language
- Follow best practices e.t.c
Lastly, David Uzochukwu, a Smart Contract Developer at QuillHash gave an overview of smart contracts, while stating some common issues associated to it, which include, centralization, multiple Solidity Pragma, using Blocks as a proxy for time, unused safe ERC20 library, renouncing ownership and the likes.
Other flaws according to him are medium and high-security issues. Uzochukwu added ways to check vulnerabilities; Re-entrancy, timestamp dependence, gas limit and loops, use of tx.origin, byte array e,t,c
Te Filecoin Orbit Lagos is availabe to watch.
Don’t miss important articles during the week. Subscribe to blockbuild weekly digest for updates.



