My good friend
@A_Leutenegger always says that access control is the main reason for DeFi hacks. In
@LidoFinance we agree with that. This is why we have developed “Execution Delegation Framework”, a tool that meaningfully improves the way your protocol interacts with off-chain actors holding important permissions.
The key idea is simple:
- Hot key is only for execution.
- Hot key is easily disposable and replaceable by the Owner.
- Owner is super secure but used only for hot wallet management.
So you have a hot wallet that you can rotate any moment, and owner that is immutable and very secure. This combination gives you a unique set of properties: governance less routine hot key management, easy access to the hot wallet, top level security control over the permission holder via the owner.
Read more about the basic version of EDF -
or dive deeper to learn about Lido-specific implementation that is getting added to the Lido protocol as you read it -
The click-bait doomer posting of "DeFi" being too dangerous yesterday by the founder of one of the biggest security projects in Ethereum is unquestionably the bottom.
83% of exploits are fixable by following best practises on access-control and opsec.
In about 6 months from now there will be standards and hard requirements for projects to validate they are following these best practises to be integrated anywhere.
The fastest projects to do this will get a leg-up on finding institutional liquidity.
Long-term, real DeFi will prevail over CeFi masquerading as DeFi both due to stronger risk assumptions, better margins, and regulatory clearance.
Show more