Shentu Chain Light-paper

Originally published
April 1, 2021

Your One Stop Shop For DeFi Security

You’ve almost certainly been told to do your own research (DYOR) before investing in a DeFi platform. But when the complexity of the ecosystem is increasing every day and not everyone is a smart contract developer on the cutting edge of coding, how can you ensure your research is comprehensive?

One method is to check if a project has been audited by a reputable firm before you commit any funds. This provides a brand-based guarantee as to the security of the platform.

CertiK’s mission is to create provably-secure software for the future of finance. We collaborate with projects to test and audit their contracts before deployment, ensuring the highest security standards. But our work doesn’t stop there.

We also have a powerful set of real-time monitoring tools that help ensure contract security when the risk is greatest: after deployment when real money is locked in the protocol.

Yet the information these tools provide can be technical and difficult to digest in their raw form, especially for those who consider themselves investors rather than developers.

So, in the interest of transparency and open-sourced knowledge, we’ve created a powerful but easily accessible dashboard and scoring system for all your security research needs.

DeFi users can leverage the expertise of our auditing and security teams to equip themselves with a deeper knowledge of security risks. These users push the whole ecosystem to new heights, while we provide the data that helps them make informed decisions.

Let’s dig deeper into the data the Security Leaderboard provides and how it can be used to make informed choices about security.

Audit History

The first tab on the Security Leaderboard is the project’s audit history. Here, you can view the contracts that CertiK has audited, the issues we uncovered in the code, and whether or not they’ve been resolved.

1Inch Audit History

If you’re interested, you can also check out the full PDF report for a deeper dive into the audit.

Skynet

Skynet is a unified set of security tool chains that leverages automated technologies to check deployed smart contracts against a wide range of known vulnerabilities at scale.

Bancor Skynet

Combining static analysis, on-chain monitoring, social sentiment, governance and autonomy, and overall market volatility metrics, Skynet provides a comprehensive overview of a project’s real-time risk.

Easily-digestible visuals make it easy to see where a DeFi platform is excelling and where it may be falling short.

Sentiment Analysis

CertiK’s powerful social monitoring toolset gives users the tools they need to react to market developments in real time.

Sentiment can change on a dime in the crypto markets, so it’s important to stay on top of trends.

AAVE Social Sentiment

The Sentiment dashboard gives a breakdown of the net positivity of recent interactions, a list of trending keywords, and a visualization of Twitter account activity.

It’s one more tool in the belt of any DeFi user.

Monitoring

If it’s detailed on-chain analytics you want, you’ve come to the right place. The Security Leaderboard’s Monitoring tab is a goldmine of transactional data.

Kylin On-Chain Monitoring

Here, you can view a graph of the total number of contract interactions over the previous 7, 14, or 30 days. You’re also able to see which addresses have interacted most with the token contract, making it a powerful tool for monitoring potential whale activity.

Security Oracle

CertiK’s Security Oracle monitors and guards on-chain transactions, preventing DeFi projects from malicious attacks through real-time security checks.

Goose Finance Security Oracle

The Security Oracle feeds a security score onto the blockchain via a decentralized network of nodes. This adds an important level of impartiality and decentralization to the CertiK security suite, all the while protecting DeFi projects in real time.

The resulting score can be used in a number of ways by project owners and end users.

Developers can integrate the Security Oracle to ensure the contracts their platform interacts with are secure. For example, if Contract A calls Contract B, it can ask the Oracle to first feed a security score for Contract B onto the blockchain. Now armed with this on-chain information, Contract A can require a certain security threshold to be met before the transaction is executed.

This score doesn’t need to be coded into a smart contract for it to be useful, though. Users can define their own security threshold and check a project’s real-time score before committing any funds to it.

By making the Security Oracle’s scores freely accessible to everyone, we are raising the standard of security across all of DeFi.

CertiK’s Security Leaderboard Arms You With the Most Powerful Tool: Knowledge

The CertiK Security Leaderboard makes our security expertise freely accessible to everyone. We want to enable a safe, transparent DeFi ecosystem for all. A major step towards this goal is giving investors the tools they need to conduct their own research into projects.

Since the beginning of 2021, the number of projects on the Security Leaderboard has more than doubled. We now list nearly 200 projects, including some of the top names in DeFi.

The Leaderboard ranks projects according to detailed and clearly-defined criteria. Users can easily visualize the elements that contribute to these rankings.

By combining pre-deployment auditing records, on-chain monitoring, and social sentiment, the Leaderboard provides a holistic view of a project’s real-time security.

When it comes to security in DeFi, trust is not enough. It must be proven. DeFi is an intricate web of interactions; no one tool is enough to form an accurate picture of what’s going on. Taken together, though, the powerful set of monitoring capabilities displayed on the Leaderboard helps users to make informed decisions.

Visiting the Security Leaderboard is an integral step on the journey through DeFi. It is just as vital to users as the range of platforms where they discover new projects, trade, and track their investments.