Need an audit?
You shouldnβt need 20 intros, Telegram groups, and weeks of back-and-forth just to find the right security firm.
@Procur3 now has 50 security firms live on the platform, including some of the biggest names in Web3 security.
Find the right fit faster.
7 private keys. 1 infected developer laptop.
$32 million gone.
Humanity Protocol β a $50M-funded Worldcoin rival β was drained on June 9.
The code was never touched.
Details below
A 3-of-6 Gnosis Safe means nothing if 3 keys live on the same device.
Multisig is about distributed trust β not just distributed signatures.
Each signer should be: β On a separate hardware device β Air-gapped for privileged ops β Onboarded with documented key hygiene
In Web3, who should be getting a pentest?
Answer: Everyone.
The largest exploits aren't smart contract related.
Pentesting covers what audits miss: β Wallet connectors β Frontend & API vulnerabilities β Node & RPC misconfigurations β Key management & access control β Off-chain infrastructure
One RFP on @Procur3 gets you quotes from vetted pentest firms alongside your smart contract auditors.
Same platform. Full coverage. Free to use.
A protocol posted a RFP on Procur3 for a Daml audit on @CantonNetwork
15 quotes. 3 days. $6k to $48k range.
This is what security audit procurement should look like.
Fast - Transparent - Competitive
Last week StablR lost $10.4M to a multisig exploit.
This week, Superfortune lost $15.18M when a multisig execution silently swapped the recipient address β and nobody caught it until the tokens were gone.
Multisig is the leading exploit cause in value.
Details below.
How to protect against the Superfortune vector:
- Air-gap your signing device
- Never approve a destination from the browser UI alone
- Verify the full tx payload on your device (Ledger / Trezor)
When you've paid for the best audit firms to secure your smart contracts, use procur3.io to source:
- Multisig configuration audits / reviews
- Cloud infrastructure and deployment reviews
- Front-end testing
- Penetration testing and more from 50 verified firms.
An audit doesn't tell you what your signers see when approving a tx at midnight.
It doesn't test whether the destination can be swapped between signing and execution.
It doesn't verify your signers use hardware devices that independently render the destination address.
May 28. DxSale. $7.3M.
Legacy LP lockers from 2021, emptied. Owner privileges used to set fees near-zero, backdate unlock times to 1970, withdraw 1,400 positions.
On-chain links suggest team involvement. Project silent.
This is a multisig address substitution attack.
The signers approved. The contract executed correctly. But the destination was changed between signing and execution.
If you're not verifying the destination on your hardware device, you're trusting a screen you can't trust.
Also in the news:
May 30. Gravity Bridge β cross-chain between Ethereum and Cosmos.
Compromised signing key.
$5.4M drained in USDC, ETH, and USDT. ~2,102 ETH still in the attacker's wallet, being laundered via mixers.
No official statement.