Home
Categories
EXPLORE
True Crime
Comedy
Business
Sports
Society & Culture
History
Fiction
About Us
Contact Us
Copyright
© 2024 PodJoint
00:00 / 00:00
Sign in

or

Don't have an account?
Sign up
Forgot password
https://is1-ssl.mzstatic.com/image/thumb/Podcasts221/v4/2b/fc/d5/2bfcd5f3-fcea-9a2d-0eac-60839ae0941a/mza_8624882748190331131.png/600x600bb.jpg
The Web3 Security Podcast
TheWeb3SecurityPodcast
11 episodes
3 days ago
Show more...
Technology
RSS
All content for The Web3 Security Podcast is the property of TheWeb3SecurityPodcast and is served directly from their servers with no modification, redirects, or rehosting. The podcast is not affiliated with or endorsed by Podjoint in any way.
Show more...
Technology
https://pbcdn1.podbean.com/imglogo/ep-logo/pbblog21209950/W3S-Pod-Episode-Cover_Deniz_Yilmaz9jajy.png
Six months before touching production: How Sky enforces context-building that delivers zero-finding audits | Deniz Yilmaz
The Web3 Security Podcast
1 hour 5 minutes
3 days ago
Six months before touching production: How Sky enforces context-building that delivers zero-finding audits | Deniz Yilmaz
When Sky's audits return serious issues, they don't just fix bugs and ship—they pull the brake and investigate what failed in their internal review process. Deniz Yilmaz, CTO of Sky Frontier Foundation, walks through the defensive layers behind USDS (third-largest stablecoin globally): six-month engineer onboarding requirements, spellcrafting governance with mandatory execution delays, and a protocol security team dedicated to codifying the implicit knowledge that keeps audit reports clean. Topics discussed: Treating audit findings as internal process failures requiring investigation, not just bug fixes Six-month mandatory onboarding periods before engineers can modify spellcrafting code Pre-audit internal review standards achieving consistent zero-finding results across multiple audit firms Spellcrafting governance requiring bi-weekly token holder votes and execution delays for all protocol changes LLM auditing integration delivering PR-level feedback before code reaches internal review Mandatory OPSEC certification with domain hash verification testing for multisig signers Protocol security workstreams codifying senior engineer practices into transferable frameworks Auditor selection prioritizing codebase-specific experience over firm reputation Subdao security enforcement maintaining core standards across autonomous entities with independent economics Game theory-based development considering internal actor exploitation during code design Listen to more episodes:  Apple  Spotify  YouTube Website
The Web3 Security Podcast