Risk Map

Mitigation (Dowsers)

We leverage our extensive experience in formal methods and the application of the 50128 standard to complex software systems comprising hundreds of thousands of lines of code, including those where human safety is paramount. Given that smart contracts are computer programs, our analysis comprehensively assesses the behavior of smart contract code and ensures risk-free execution with the data received.

The exceptional mathematical rigor of formal methods allows us to analyze smart contract code with precision and accurately assess its security level.

Initially, we retrieve the code and on-chain and bring it to our off-chain platform to analyze it thoroughly in various simulated environments.

We classify code functions according to their risk level using internally developed safety indicators inspired by SIL levels from the 50128 standard. These indicators guide our choice of the most appropriate method to verify that the function meets our security properties. This ranges from interface code testing to formal proof for the most critical functions.

These properties are crafted by our experts using the FMEA (Failure Modes and Effects Analysis) method. For the most sensitive cases, formal proof provides assurance by covering all possible scenarios to mathematically demonstrate the absence of bugs, while tests can only prove their presence.

  1. Smart Contract Vulnerabilities : these risks  are covered by our analysis through the verification of our security properties. 
  2. Blockchain Risks : These risks are addressed in our analysis through the verification of our security properties. 
  3. Oracles Failure : These risks are addressed in our analysis through the verification of our security properties. 
  4. User Interface Risks : These risks are addressed in our analysis through the verification of our security properties.
  5. Bridge Risks : Bridges, as a type of smart contract, can be analysed using the same methodologies applied to all smart contracts. 
  6. MEV Risks :These risks are addressed in our analysis through the verification of our security properties.
  7. Composability Risks : These risks are addressed in our analysis through the verification of our security properties.
  8. Interoperability Challenges : These risks are addressed in our analysis through the verification of our security properties.
  9. Scalability and Network Congestion : these risks  are these risks  are covered by our analysis through the verification of our security properties
  1. Custodial risk: this risk  is covered by our analysis through the verification of our security properties.
  2. Tokenomics risk:  this risk  is covered by our analysis through the verification of our security properties.
  1. Operational Risks: These risks are addressed in our analysis through the verification of our security properties, with the exception of human error, which is unrelated to any malfunction in the code.
  2. Regulatory Uncertainty: These risks are addressed in our analysis through the verification of our security properties.
  1. Accounting conformance risks: These risks can be addressed in our analysis through the verification of our security properties
  2. Operational accounting risks: These risks are addressed in our analysis through the verification of our security properties.

 

 These risks are addressed in our analysis through the verification of our security properties.

 These arise when one party fails to fulfil their part of the deal. For instance, if a custodian of a wallet’s private keys is compromised, users could lose access to their assets.

  1. Pump-and-dump schemes: These risks are addressed in our analysis through the verification of our security properties.
  2. Liquidity Risks: These risks are addressed in our analysis through the verification of our security properties.

 Hacks in DeFi cost digital asset investor a staggering $2 billion per year and erode trust in builders and their protocols.

Avoid hacks