ETHWarsaw 2024

ETHWarsaw 2024

How to steal $1M from a DeFi Smart Contract
2024-09-06 , Vistula stage

In May 2024, I discovered a critical flaw in a DeFi smart contract that could have been exploited to steal $1.08 million. I will recount the story of how I uncovered the vulnerability and demonstrate the simulation I created to prove the bug. Additionally, I will explain how the issue was resolved and discuss strategies to prevent similar vulnerabilities in other projects.

Bartosz Barwikowski is a blockchain researcher and auditor at Hacken with a focus on L1 and L2 protocols. With >30 critical security issues uncovered in his career, he has a strong understanding of blockchain architecture and a passion for keeping it efficient & secure.
Since joining Hacken in June 2022, he’s been responsible for detecting vulnerabilities in L1 protocols and developing internal fuzzing services. At Hacken, he's also passed C4's CryptoCurrency Security Standard Auditor, Certified Ethereum Professional, and Certified Bitcoin Professional certifications.
Before Bartosz had experience speaking at the C4 panel on CryptoCurrency Security Standard and BlockchainHackers meetup in Denver on a glitch found in Binance PoR.