Transparent recovery framework and a measured, security-focused path forward. This is the right way back. Rebuilding after an incident is the hardest work in this space Wishing the @ResolvCore team strength & luck!
Security is not a checkbox for us.
We’re proud to announce that @MixBytes has successfully audited Shift's smart contract.
Trusted by industry leaders like @LidoFinance and @aave, with 300 public reports delivered across 80 clients.
Full breakdown on Friday.
4/5 The review focused on core protocol logic, cross-chain interactions, and integrations, alongside checks for reentrancy, access control, arithmetic issues, and more
Slightly late update: with vote 199 enacted, Lido core contracts have been upgraded to v3.0.2! Shipping upgrades, tightening security! 🚢
Kudos to @folkyatina & @AlexanderDrygin for the fixes, and @MixBytes, @Certora & @tomer_ganor for the review! 🛡️💪
It might be tempting to describe this incident as simply a “compromised private key.” However, in this case the attack path appears more complex and involves multiple stages prior to the on-chain actions.
The attack vector itself is not fundamentally new, but its execution does not appear trivial and involves a sequence of steps that collectively led to the exploit.
As the ecosystem evolves — particularly with the growing role of automation and AI-assisted workflows — similar attack patterns may become more common. It’s important to look at such incidents more holistically rather than relying on simplified explanations.
@ResolvLabs has demonstrated strong capability and professionalism. We look forward to seeing the team recover and continue their work successfully.
1/4 🚀 Security audit complete: @yieldbasis Hybrid Vault, a system for managing leveraged positions across multiple YB markets with integrated stablecoin backing