Tag: audit

  • Is Binance SAFE? Funds Fully Audited by Mazars

    Is Binance SAFE? Funds Fully Audited by Mazars

    Binance is tackling to issue of proving where user funds are by using the third-party auditor Mazars, a leading Hong Kong-based auditing firm, to prove independently that user funds held by the exchange are safe and “untouched”. This is particularly important as users are demanding to know that funds are safe (or “SAFU”) and that they can trust the exchange to keep holding their funds. Auditing centralized exchanges help to ensure that they are compliant with applicable laws and regulations, as well as industry best practices. This helps to protect users from fraud, manipulation, and other malicious activities.

    Binance BTC Reserves are Fully Backed

    Mazars, an international audit, tax, and advisory firm, has confirmed that Binance has more than enough Bitcoin (BTC) to cover all customer deposits. The report verified a 101% collateralization ratio on 575,742 BTC in net customer deposits as first published on their proof-of-reserves system on November 25. All assets included customers’ spot, options, margin, futures, funding, loan and earn accounts for BTC and wrapped BTC circulating on the Bitcoin, Ethereum, BNB Chain, and BSC blockchains.

    Learn more about Binance- Binance Exchange Review (2023) Best Crypto Exchange?

    To ensure customers’ assets are not being lent out or stolen without permission, Binance implemented a Merkle Tree proof-of-reserves system that allows customers to independently verify the safety of their assets.

    Binance Merkle Tree Proof-of-Reserves (Source: Binance)

    Binance Securely Controls Custodial Wallets

    Mazars has also asked Binance to perform transactions at specific times to prove that the wallets were actually under Binance’s control. This clarifies the situation in late November when Binance moved 127,351 BTC to an unknown wallet. According to the report, Mazars used Etherscan and BSCscan to check that the wallets indeed belong to Binance.

    Moreover, Mazars reviewed the scripts that Binance uses to extract the total net deposits, making sure there was no duplicated or rigged user IDs. This confirms that Binance’s Merkle tree is built with open source script developed by Silver Sixpence.

    What This Means for Investors

    Binance is the world’s largest crypto exchange by trading volume, and is arguably the most used platform for all crypto users. After the collapse of FTX, Binance CEO Changpeng Zhao (CZ) was jokingly hailed as the “savior” of crypto, doing everything he can to repair the industry. However, Binance itself is no exception to scrutiny as a result of FTX’s collapse. People need to know what centralized exchanges are doing with their money.

    Binance’s audit has cleared up a lot of doubt, restoring confidence in the exchange. However, there are still two issues raised by the crypto community:

    A Step in the right direction

    Overall, auditing centralized exchanges are essential for protecting users and ensuring that exchanges are operating in a safe and secure manner. By conducting regular audits, exchanges can help to ensure that their customers are protected and that they are getting the best possible service. Binance has also provided on-chain proof of funds using “Merkle” Proofs in November of 2022. This means that Binance has taken efforts to prove that both Fiat and Crypto deposits in their custody are safe.

    FAQ

    Is Mazars a reliable auditing firm?

    While most of the community praises Binance’s initiative, several Crypto Twitter users expressed concerns that Mazars is not one of the “Big Four” accounting firms: Deloitte, Ernst & Young (EY), PricewaterhouseCoopers (PwC), and KPMG. For the longest time, audits made by any one of the Big Four is the gold standard, and any other firms are deemed not “credible” enough.
    This is reasonable enough seeing as FTX was in fact audited by smaller accounting firms. But that might not be the case for Mazars. Founded in 1945, Mazars is one of Europe’s largest audit and accounting firms with global presence. In fact, Mazars was a longtime accountacy firm for former president Donald Trump. But after finding out Trump’s business filings were not adding up, Mazars cut ties with his business. Given their track record, it is safe to say that Mazars is reliable as they conduct due diligence on any business.

    Binance audit only accounts for BTC reserves

    The audit only focuses on BTC assets for now. As of now, Binance does not have a proof-of-reserves system for other cryptocurrencies. But at the end of the day, this is a big step towards a more transparent ecosystem. Let’s hope there will be more developments in the coming weeks.

    References

    Recently some users are reporting USD withdraw issues, CoinMagazine

  • Top 10 Blockchain Security and Smart Contract Audit Companies

    Top 10 Blockchain Security and Smart Contract Audit Companies

    We rank the top 10 performing blockchain security firms offering services such as smart contract audits, blockchain security analysis, penetration testing, formal verification, and security audits. Security audits are extremely important – this year we’re seeing the rise of Decentralized Finance (DeFi)— a new application of decentralized Blockchain technology that is poised to replace the trillion dollars Global Finance industry. However, recent events such as the dForce hack have shown us that hackers can exploit weaknesses in smart contracts and steal money. It’s almost like robbing a bank, except in this case the bank is flush with crypto AND can’t defend itself. In the case with dForce, the hacker stole $25,000,000 USD (talk about a good haul) and with crypto transactions, we know this is not reversible.

    Consequently, security solutions, tailored to the volatile nature of blockchain technology and its components, have started making moves to isolate and neutralize security threats common in the blockchain terrain. In this article, I will highlight and explore the workings of the top companies in the blockchain security niche.

    It is therefore extremely important for security audits of projects, exchanges and blockchains to be done. Users must also know what security tests have been performed and if any red flags were raised.

    Hacken

    Website: https://hacken.io/

    Hacken performs a wide range of security services for its clients. These suites of services include blockchain security consulting, web/mobile penetration testing, coordination of bug bounty programs, crypto exchange ratings, among other things. Although Hacken offers a long list of services targeted at blockchain and crypto firms, its ecosystem, however, encompasses security products ideal for IT companies as a whole. The company has built a commendable reputation as a security risk assessment for companies requiring a digital environment to create or enable services for their consumers.

    Hence, it comes as no surprise that Hacken has provided security services for non-blockchain giants like Air Asia. Furthermore, it has proven its commitment to blockchain technology by sponsoring and engaging security experts worldwide in security meetups.

    Hacken has also created the HackenAI security platform designed to protect the end user from security risks and account compromises. Key features such as Darknet monitoring immediately alerts users of compromised passwords and possible darknet attacks. HackenAI is available on Android and Iphone devices.

    Quantstamp

    Website: https://quantstamp.com/

    Quantstamp is a blockchain security startup unveiled at YCombinator W18 Batch. The security team of Quantstamp has experience in top IT companies like Google, Facebook, and Apple. And this is evident in the platform’s wide array of blockchain security tools and services. For one, Quantstamp has developed a decentralized security network for smart contract auditing. With this solution, users can perform automated smart contract security review on a “global network of decentralized security nodes.”

    Additionally, the platform provides expert security audits for clients blockchain projects and a 24/7 security monitoring software tool.

    Trail of Bits

    Website: https://www.trailofbits.com/

    Trail of Bits prides itself as a network of developers with the capabilities of identifying and fixing loopholes in software, devices, or codes. In other words, the solution provides an array of software security services that encompass smart contract audits, blockchain security research, software development, and so on. Over the years, Trail of Bits has developed formidable security tools for smart contracts. Some of these blockchain-focused solutions are Crytic, Slither, and Echidna.

    Apart from that, Trail of Bits developed the popular AlgoVPN. As well, it has a lot of security publications on GitHub, including public reports for 0x Protocol, Compound, NuCypher, and MakerDAO, which are some of its clients.

    OpenZeppelin

    Website: https://openzeppelin.com/

    The OpenZeppelin team is mostly known for its development of Solidity libraries known as OpenZeppelin Contracts. These libraries are used in most Solidity projects as a tested and standard template for contracts deployable on decentralized applications. Developers can integrate this solution through OpenZeppelin’s native SDK. Besides development, OpenZeppelin has a strong focus on smart contract security and audit services.

    Also, OpenZeppelin was one of the first teams to reinvent blockchain security by introducing elements of gamification to identify loopholes in smart contracts. Another of its products, Ethernaut, is a Web3/Solidity war game, which entails gamers to hack smart contracts to move to the next level.

    ConsenSys Diligence

    Website: https://diligence.consensys.net/

    US-based ConsenSys is one of the biggest and prominent blockchain incubators in the industry. Unlike other security firms mentioned on this list, ConsenSys dedicates its resources and technological know-how to the development of Ethereum blockchain applications and software, especially financial infrastructures. As such, its product, ConsenSys Diligence, offers security analysis for smart contracts. This audit product is at the cutting edge of sophisticated “cryptography, blockchain technology, and crypto-economic incentive analysis.”

    Another of its products, MythX, is one of the most powerful automated scanners for Ethereum smart contracts. This solution provides a robust API, which developers can use to access security analytics tools.

    Certik

    Website: https://certik.io/

    Certik is a security company looking to utilize topnotch formal verification technology in collaboration with some of the best cybersecurity experts to create end-to-end services. On its website, Certik claims that it has audited over 188,000 lines of codes and secured over $6.32 billion worth of assets. The team offers to mathematically validate the safety of smart contracts

    Therefore, it has developed Certik Chain, a public blockchain focused on leveraging Certik’s Formal Verification platform, to secure decentralized projects. Certik is officially a partner company of Binance, and it is backed by prominent investors, including Binance Labs, Lightspeed, Matrix Partners, and DHVC.

    LeastAuthority

    Website: https://leastauthority.com/

    LeastAuthority is a cybersecurity consulting firm with its main focus on privacy. It classifies itself as an enabler of private and disruptive storage solutions. At the moment, the platform has two major products available to its users. The first, Privatestorage (formerly S4), is a centralized system that provides storage infrastructure to end-users and offers them the autonomy over the collection, processing, and distribution of their private data. On the other hand, its second product, Tahoe LAFS, enables a decentralized, distributed, and fault-tolerant storage facility.

     In addition to providing different storage architectures, LeastAuthority has published security reports for Ethereum, Tezos, and others. It also works with developers throughout their development cycles to ensure that their projects are not susceptible to security threats. 

    PWC Switzerland (former Chainsecurity)

    Website: https://www.pwc.ch/en/services/risk-assurance/smart-contract-assurance.html

    Chainsecurity has joined PWC Switzerland to perform security review projects and create security solutions for the emerging blockchain industry. With this partnership, PWC Switzerland offers consultant services to blockchain projects from the exploration stage to the post-deployment stage. This platform assesses smart contract designs, tests their viability, and monitors metrics detailing their performances after deployment. It excels in its ability to combine automated analysis tools and the expertise of security professionals to identify and eliminate potential threats.

    As Chainsecurity, this blockchain team developed several security tools, including Securify and VerX. It makes sense to expect this team to continue its successful run in the blockchain security sector since it now has access to PWC Switzerland’s vast resources.

    Slowmist

    Website: https://www.slowmist.com/en/

    Slowmist is China’s leading blockchain security company. They perform extensive blockchain security services that include smart contract audits, blockchain security audits, wallet security testing, and much more. Slowmist also has a safe staking project for blockchain ecologies, which delivers real-time data on the growth and security patterns of EOS, Cosmos, Vechain, and other top blockchain projects. Another interesting bit of detail about this platform is its powerful firewall project for EOS smart contracts, named FireWall.X.

    Likewise, Slowmist is constantly tracking and publishing data and stats about security situation on crypto exchanges through their Blockchain Threat Intelligence (BTI) service. 

    Runtime Verification

    Website: https://runtimeverification.com/

    Runtime Verification is a research and development company focused on formal verification. According to the information on its website, this solution designs standard models for high-value applications and uses them as templates to develop security-sensitive products. Runtime Verification has developed two main smart contract security products. On the one hand, it offers smart contract correctness proofs with the help of the K framework to prove the viability of Ethereum and Cardano’s smart contracts. On the other, Firefly is a test coverage analysis tool for Ethereum smart contracts.

    Additionally, Runtime Verification has worked with Ethereum Foundation on building a formal framework for Ethereum 2.0 testing.

    What is the best Smart Contract Auditing Company

    Top tier smart contract auditing companies include Hacken, Trail of Bits and OpenZepplin