I have a slightly odd habit: after reading a postmortem, I don’t ask “patched yet?”, I look at how far a failure was allowed to run.
with Dusk-to-EVM Migration Service, what sticks in my mind is the money path 9,000 → 89,700 → 2,743,310 → 8,068,000.
8,068,000 / 9,000 = 896.4 times... the blast radius expanded by about 89,544%.
Consensus was still running, Protocol Vulnerability was not the cause, but once the Signing Wallet suffered Key Compromise, Permission Exposure had already become Asset Risk.
I often ask: are Signing Authority, Event Authority and Disbursement Authority standing too close to one another?
if they all sit on the same Operational Path, Permission Concentration is concerning, because a Single Point of Failure can reach the money directly.
frankly, I used to think that if Zero-Knowledge Proofs were strong, a Privacy Blockchain was already fairly reassuring... not anymore.
Bridge Security also lives in Event Processing, Recovery Mechanism and the way the system cuts off the flow of funds by itself.
Dusk separates Signing from Event Reception, turns a Migration Event into a Persistent Task, so an Independent Worker can handle seen, submitted, completed, failed, stuck.
Hot Wallet keeps a Near-term Operational Balance, once it hits the Threshold it stops, Fund Replenishment goes back to the Cold Wallet... Security Isolation has to sit directly in the money path.
suppose the Hot Wallet Cap were 1,000,000 instead of 8,068,000, theoretical direct exposure would drop by 87.6%.
the 8,910,000 hit that was blocked by Service Shutdown was about 10.4% larger than the 8,068,000 one... a Pause Mechanism at the right moment is worth more than marketing claims.
for me, a mature system must have Separation of Duties, External Verification and Auditable Operational Discipline tight enough that one failure does not drag the entire system down with it.
so do people rate a bridge by how fast it runs, or by the maximum amount of money it allows to go wrong before locking itself down?
#dusk $DUSK @Dusk
with Dusk-to-EVM Migration Service, what sticks in my mind is the money path 9,000 → 89,700 → 2,743,310 → 8,068,000.
8,068,000 / 9,000 = 896.4 times... the blast radius expanded by about 89,544%.
Consensus was still running, Protocol Vulnerability was not the cause, but once the Signing Wallet suffered Key Compromise, Permission Exposure had already become Asset Risk.
I often ask: are Signing Authority, Event Authority and Disbursement Authority standing too close to one another?
if they all sit on the same Operational Path, Permission Concentration is concerning, because a Single Point of Failure can reach the money directly.
frankly, I used to think that if Zero-Knowledge Proofs were strong, a Privacy Blockchain was already fairly reassuring... not anymore.
Bridge Security also lives in Event Processing, Recovery Mechanism and the way the system cuts off the flow of funds by itself.
Dusk separates Signing from Event Reception, turns a Migration Event into a Persistent Task, so an Independent Worker can handle seen, submitted, completed, failed, stuck.
Hot Wallet keeps a Near-term Operational Balance, once it hits the Threshold it stops, Fund Replenishment goes back to the Cold Wallet... Security Isolation has to sit directly in the money path.
suppose the Hot Wallet Cap were 1,000,000 instead of 8,068,000, theoretical direct exposure would drop by 87.6%.
the 8,910,000 hit that was blocked by Service Shutdown was about 10.4% larger than the 8,068,000 one... a Pause Mechanism at the right moment is worth more than marketing claims.
for me, a mature system must have Separation of Duties, External Verification and Auditable Operational Discipline tight enough that one failure does not drag the entire system down with it.
so do people rate a bridge by how fast it runs, or by the maximum amount of money it allows to go wrong before locking itself down?
#dusk $DUSK @Dusk