使用 Crytic 进行漏洞狩猎
blog.trailofbits.com | 博客 | #cloud | #web3 | #smart-contracts | #static-analysis | #vulnerability-detection | #blockchain | #trail-of-bits | #solidity | #crytic | #github-app | #bug-detection
摘要
Trail of Bits 的 GitHub 应用 Crytic 可在每次提交时自动运行 90 多种检测器扫描智能合约缺陷,并支持自定义安全属性。文中分享了它在 Ernst & Young Nightfall、DeFiStrategies 等项目中发现的 12 个问题,包括可免费铸造代币的关键漏洞与重入风险。
- 发布时间
- 收录时间
Skip to content