03:42
Samczsun posted: Annual review of smart contracts is the crucial fourth step in ensuring the security of the protocol
ChainCatcher message, Security Alliance founder Samczsun posted that relying solely on code audits, formal verification, and high bug bounty rewards is still not enough to prevent hacker attacks. The annual review of smart contracts is the key fourth step to ensure protocol security.
Samczsun pointed out:
1. Higher bug bounties cannot prevent hacker attacks because it only doubles down on the assumption that white hats will find vulnerabilities before black hats. The same amount can be used to support multiple re-audits over several years.
2. Risk levels grow linearly with TVL, but security budgets do not increase accordingly.
3. Audit reports are only security assessments at a specific point in time, which can expire. Since the protocol environment is constantly changing, the only way to refresh the assessment is to conduct re-audits.
Samczsun believes that by 2026, the crypto industry should adopt an annual
- 1