Andrew Beal on detecting hacks in DeFi with Forta

InterviewNovember 17, 202223:53

In this episode

Ashton Addison speaks with Andrew Beal, Ecosystem Lead at Forta Network, on their technology for detecting hacks and exploits in DeFi, how their surveillance can prevent the loss of funds from smart contracts and yield generating platforms, and why DeFi needs to continue to be monitored.

Bitcoin Trading at ByBit Exchange: 10% off the Best Crypto Portfolio Tracker: Get Buy and Sell Signal Indicators built into your charts!:

Key takeaways
  • Forta Network operates as a decentralized security monitoring system using community-run bots to detect suspicious and malicious activity across DeFi protocols in real-time.
  • DeFi exploits occur frequently due to unproven protocols holding customer funds, insecure web2 components, and lack of real-time monitoring beyond initial audits and bug bounties.
  • Forta monitors seven major EVM chains including Ethereum, Binance Chain, Polygon, Arbitrum, Optimism, and Fantom to provide actionable threat intelligence to protocols and users.
  • Most DeFi projects historically relied only on pre-launch audits and bug bounties, neglecting real-time monitoring and post-detection response protocols as critical security components.
  • The industry needs better frameworks for responding to detected threats beyond initial detection, as few protocols currently have comprehensive incident response plans in place.

Transcript

Read the full transcript 4,185 words, auto-generated

I'm Ashton Addison from Block West capital for investment pitch media and today on the crypto coin show we have Andrew Beale the ecosystem lead at forta Network Andy welcome to the show and thank you for taking the time thanks for having me Addison you're very welcome man um let's dive into Fortune Network what you're working on and looking at the intricacies of blockchain and I feel

like there's a lot to dive into especially with the recent news in the industry uh right now um where maybe Forte could come in handy for you know diving into uh the secrets of of what has happened uh in in cryptocurrency there's a lot to to unpack still that we don't know about and I feel like some of these investigative technologies will be on the Forefront of of uncovering uh sort

of you know there's what people say and then there's what they do and the blockchain never lies about about transactions so let's start off our conversation uh with just a high level overview of what you and your team are working at at forta Network and then we'll dive into all the details sure yeah happy to happy to sort of uh introduce Ford at a high level and

excited excited to dive in um his web 3 security is a I think one of the one of the bigger challenges and also opportunities in the space right now um so Florida network is a basically a a giant uh public security camera and alarm system for for web3 for for defy and and nfts those are the two kind of primary I just you know asset classes uh or verticals that kind of make up whip

through right now um so diving a little bit deeper into sort of what that like what is a what do you mean by a giant security camera an alarm system for for web3 so what does what does a a network that sits on top of D5 and sits on top of nft and is sort of looking down and watching all this on-chain activity happen right because everything in these everything

in these ecosystems is happening on on chain right the protocols are on chain the assets are on chain the trades are on chain just to differentiate that from things like you know coinbase and FTX and a lot of these centralized exchange operators right where most of the all the trading activities happening off off chain um so everything a device on chain and

uh the Florida Network collectively is watching all of that and looking for suspicious activity malicious activity anomalous activity um and uh and emitting alerts about all of that um and I think the the unique thing about Florida is that uh the Florida Foundation team who I uh who I work for we don't uh we don't dictate what is being

watched um the uh protocol teams individual developers security teams Etc are running uh Bots which are sort of the vehicle for monitoring they were like think about Bots like a little virtual security camera that you're running on Florida running on the Florida Network and that is what that is what is sort of watching on chain activity so protocol teams

publish a bunch of bots on the network that watch their own contracts that watch their own transaction activity people publish bots on the network that monitor other protocol activity that they're interested in um and collectively we kind of have this you know it it forms it creates this kind of giant shared security camera and alarm system that everybody in the

ecosystem can can benefit uh can benefit from so um looking forward to dabbing it yeah yeah I feel like there could be multiple goals uh that you could attain with this kind of Technology on one hand I see a defensive approach obviously looking for you know malicious activity or fraudulent funds you know if there was a hack somewhere uh it wears that money

moving to but on the other hand I also see like you could use this technology to see where funds are going to take advantage of you know if the there's legitimate funds moving into a protocol you could follow and track that and take advantage from a trading aspect so what are sort of the main goals that the end users of Fortune Network are are getting

out of using this technology yeah well the uh the mission behind Florida is to uh protect web3 and make it a make it a safe place for both like retail and um and you know institutional participants um and it was born out of you know the circumstances that unfortunately kind of were still in the middle of which is you know there are

um very frequent and very large exploits of D5 protocols right and there's a there's a there's multiple reasons for this um you know one of them is that uh a lot of a lot of Protocols are um you know fairly unproven and untested and and yet still responsible for holding a lot of customer funds right um

despite going through an audit and things like that um another challenge is that um you know I think it's it's a little bit of a we like to sort of compare like web3 and web 2 but the reality is that all of these D5 projects these sort of you know web 3 sort of native projects all have web 2 components to them they all have front ends they all have applications they all have apis

they all use like you know oftentimes Amazon web services and cloudflare and a lot of these sort of traditional web web services um and these are all and they all have uh access controls and sometimes you know private key management requirements and these are all these are all things that existed with internet you know businesses pre-crypto right um and these are also all attack vectors

for a hacker too right and so a lot of the hacks that happen in web 3 are because these web 2 components aren't secured properly right um so that's another that's another big um you know area of security that that I think you know that in general we can do a lot better at and then the third is um uh you know I think most projects today most let's say let's pick

a D5 project like most most D5 projects today uh certainly for certainly let's say this is definitely true a year ago um the extent of their kind of security plan was to get one or more audits before they launched their protocol and then once it was live they would put a bug bounty in place and that was often it it wouldn't do anything else um and there are two other big pieces of

um of kind of the security stack that were just being ignored which is real-time monitoring which is where Florida comes in right watching your system in real time and and looking for actually like not not not waiting for a threat to be you know um not waiting for you to be notified by a threat by someone in your community on Twitter or telegram which is how it

often gets reported right but but actually being proactive and like trying to identify those things ahead of time as they're happening and then reacting to it quickly um and those two pieces of kind of web the web 3 security stack are very very immature um and so anyway Florida is you know addressing this real-time monitoring kind of component and threat detection

but the other half is like once you detect something how do you what do you do about it right and so that's another that's another kind of conversation that that I think the industry needs to talk about a lot more um there's a lot of things we can do very few of them are actually happening right now um but I'm really optimistic that that's going to change over the next over the

next couple years so um so so that I guess to that was a roundabout way of kind of setting up my answer to your question which is you know what kind of value can what kind of value are users getting from the Florida Network so you know Florida is again we're the network collectively is watching everything on chain and we monitor the seven largest evm chains

today so ethereum uh you know Finance chain polygon operator of optimism Phantom Etc uh and watching everything in real time looking for threats looking for anomalies looking for suspicious activity and then alerting those teams and those communities about it so that they can do something right um so again I think the the security camera and alarm system analogy is a

really is a really good one so that's the value right we're delivering real-time intelligence to a protocol team a hedge fund an exchange and try to anyone that has contracts on chain or has exposure to those contracts or assets on chain um you know that once this intelligence so that they can take some action off based on it right and it can be defensive it could be it could be

offensive as you mentioned um so but that's our that's our that's our immediate goal and that's what we're really focused on that's great to hear when you can save uh any anybody from getting getting hacked hopefully before it happens uh then you know that's a green check for for D5 and a move in the right direction and over the years it has gotten better

you know whenever there's an exploit in in something then normally that's passionate and then that's that's a precedent like we shouldn't you know we should always take into account this issue that happened before but there seems to be new things coming up and as defies continuing to expand in New Directions uh new kind of exploits happen and last month in October it was

actually a record for you know D5 hacks and there was four or five different hacks that totaled almost 800 million dollars across different blockchains as well some of them I I believe you're following and some of them maybe your team isn't following but can you talk about what happened last month and was forwarded Network involved in in identifying any issues in in these defy

hacks so um I guess without diving kind of into any of the hacks specifically um yes there were there were certain exploits that were um aspects of them were detected by Florida and let me and I'll kind of break this down a little bit for for folks listening so a lot of the threat monitoring that's running on Florida so a lot of the you know think about like

okay we have a you know there's a group of kind of bots or AKA like little virtual security cameras running on the Florida Network that are watching certain watching for certain things so we have thing we have Bots that are protocol specific that are watching you know maker Dow and Lido and compound and Ave Etc but we also have Bots that are just looking for

um generic sort of threat activity and what we're looking for is based on patterns that we've seen in previous exploits so for example a lot of exploits start with a withdrawal out of tornado cash because the hacker has like obfuscated the source of the funds that they're going to use to pay for gas fees and other things so that's the first kind of red flag right that you're

looking for and then the next step that a hacker often takes is they they take those funds that have been obfuscated through a privacy protocol like tornado cash and they use those to they use those they deploy them with a new smart contract on chain and that's going to be the attacker contract that they're going to execute the exploit from so when we see those two

um activities in that order right when we see that basic pattern of activity that's kind of the first clue for us that um you know there's an attack that's being set up and there's there's a lot of other sort of complementary factors that we can red flags that we can look for other other kind of um what I'll call like signatures of of exploit activity that we're also looking

for in real time and um and then the network submitting alerts about that and uh what we're getting what we're getting better at is identifying um who the victim is or is intended to be um we're we're we're we're pretty good now at identifying obviously who the attacker is but the real value is identifying who the victim's going to be or who the victim is

um so that's something that our community is working on right now as well um and like I said you know uh there have been instances where Florida has generated you know one or more alerts about something that's an attack that's in progress um now that the the reality is that for those to be beneficial the team that is being exploited needs to be so they need

to be receiving those alerts right so if a team's not using Florida then they're not getting this Intel right so that that's one sort of uh reality the second reality is that um even if teams are receiving photo alerts they need to have the ability to respond quickly once they get that alert right you got to be able to react sometimes in seconds right and

unfortunately most teams don't have the ability to do that they either don't have someone watching for that alert 24 7 right depending on time zones and it can be challenging um and then oftentimes A team's only sort of uh mechanism for responding to a threat is to pause the protocol I think you know some folks who are listening may have heard of a pause

button um which is a feature that's baked into a lot of smart contracts that will allow you to sort of temporarily kind of bring down the system in response to a threat or a vulnerability that's identified right and the challenge is that actually initiating that pause process usually requires a multi-sig that you need to organize get up to speed then you all

need to sign transactions and then you then you can then you can sort of officially pause the the protocol and so that process is very time consuming it's not fast enough to you know usually prevent and exploit so this is what I this is kind of what I was alluding to earlier when I said that um you know threat threat detection is getting better but threat prevention is really

where the industry needs to make a lot of Investments because the mechanisms that we have for prevention today aren't fast enough they're not sufficient so um we're thinking a lot about and I know a lot of other teams are thinking about kind of where in the tech stack should we be sort of screening for malicious transactions or high risk transactions

right the same way that sort of a bank will screen for high risk transactions today right if you ask them if you walk into a bank and you want to cash a million dollar check like the bank is not going to give you a million dollars cash and lets you walk out right they may give you a little bit based on how much money you have in your account but then they're

gonna they're gonna hold the rest of that money to make sure that that check clears right um they want to avoid that check bouncing right and them being liable for that um so that doesn't happen with D5 protocols today right D5 Protocols are kind of it's a One-Stop it's it's a one-size-fits all as long as your transaction is technically valid it will

be processed and it doesn't take into account risk right um and so I think um that concept of kind of screening for risky transactions either at the like L1 level when you're building blocks or at the protocol level where protocols themselves are determining like what transactions are I'm going to let through to my system or not um both of those are sort of I think

worth spending a lot more time thinking about um so that anyway that that's where I think the the security conversation is moving and I think we're going to see a lot of cool developments there fascinating and with the news this week of FTX and becoming insolvent and centralized exchanges you mentioned at the beginning about how often a lot of these exchanges

you know the transactions that are going on on the exchange are sort of off chain and although it shows your balance of you know five Bitcoin on on your account uh it doesn't necessarily mean there's that exact five Bitcoin in a blockchain wallet that's attached to your account and these centralized exchanges are often probably using your money on the

back end moving it around making money off of it at the same time and with what it appears uh with FTX uh is that you know they didn't have 100 reserves of of the funds of the the users funds that were in The Exchange but at the same time there there are uh there are funds somewhere and those could be tracked on the blockchain uh if you know where their cold wallets are

and how they're moving funds around um and there are no not just you know mismanagement of funds but there have been a lot of hacks in centralized exchanges as well um do you think that this technology could have prevented or or made centralized exchanges better as well so it's a it's a it's a I think it's a great question

um I mean my I'll I'll preface my my answer by saying that like I think a lot of the a lot of the issues that we're sort of dealing with this week um in response to FTX and Alameda are a result of sort of poor risk management internally at these Opera at these companies um purpose management or no risk management um the use of yeah the the you know not

following what I consider to be sort of just a kind of a day one you know um uh sort of rule which is you know always always always always um maintain a one-to-one reserve with your customer deposits right fractional reserves are sort of the that's the death nail for any exchange and like there's been you know exchanges in sort of crypto history that have obviously

not done this and they've you know and and imploded as a result so um I would have thought that we were past sort of that but um clearly not um and and then you know just not having you know a lot of sophistication around kind of the financial reporting and audit functions right like um you know I just saw some just saw a tweet today about from SBF that just

said you know he was he was just sort of he was very claims to be very unaware of you know kind of the state of their books and liquidity and all those things and like that just shows you kind of like a like a a complete breakdown in like internal financial reporting which are you would think of a with a company that size right they would they would

you know they would have have invested in um sort of cleaning that up but um that wasn't the case so anyway so I think there's anyway there's a lot of there's a lot of issues there that you know Florida wouldn't have been able to address right just sort of internal company processes and um and controls that didn't exist or um you know if they did exist they you know

they weren't sufficient or being followed so that's that that's the big thing I think where um where forta can you know to the extent that there were on chain signals uh that you know would have um given the industry some more insight into maybe how funds were moving between these two entities um or trading activity right to the

extent that it was on chain um you know Florida could have um you know Forda potentially could have you know could have caught that um but again you know someone would have had to have been someone would have had to like deploy bots on the network that are monitoring for those specific things right so um someone would have had to sort of someone would have needed to have

thought about that and then developed a bot accordingly or a group of them and then deployed those on chain and made those alerts you know public for everyone to to see right um but I think it's a really interesting I think it's a really interesting sort of um it's a really interesting thought because uh I expect you know long term and you know I I um we're already kind of seeing this

right like this is all D5 in particular right it's all public infrastructure and you know right now the the people who care the most about that are like the core Dev team responsible for for that protocol right and then after them it's the it's you know the the people who have exposure to that protocol right the retail investors and social investors that are using that

protocol for for Lending or swaps or whatever right um but there's a there's a big pool of stakeholders outside of those two groups that can also you know that also care about that right and it can be it could be um other teams that are building on top of your protocol right there's a lot of composability in D5 right and so there's a lot of dependency

upstream and downstream for other contracts right oracles is a great example right of of sort of third-party dependencies that exist and so you not only need to be paying attention to your own stuff but you need to be watching other things that you have that you're dependent on right that if they break it has a downstream effect on your system right and so and that level of kind of

monitoring just doesn't really exist today in the in space so uh that's one thing that you know I think Florida can really enable is just sort of this you know we can bring a lot of public transparency to how these protocols at least operate um and and the health of them and the security of them sort of blocks a block um and I think it's important to

Regulators it's important to lawmakers it's important to um people who are integrating and Building Things on top of systems like that and it's also important for the core teams that are that are that are maintaining them um so very well said Andy and as D5 continues to grow and into the next Bull cycle whenever that does happen I feel like this technology will be very

important to ensure the safety and security of people's funds uh in Define in smart contracts and with nfts as well in the many industries that will they will expand into beyond the finance world so thank you so much for the insights uh what is the best way for people to learn more about Florida Network and follow along with the updates with your team

yeah so you can learn more about Florida at florida.org florida.org and you can follow us on Twitter at Florida Network um we regularly post we regularly host Twitter spaces um so if you're interested in sort of you know learning more about kind of the bleeding edge of web3 security every two weeks or so we have we have a great Round Table discussion usually on

Twitter so keep an eye out for for those and if anyone has any questions they can also reach out to me directly I'm at ajbl on Twitter sounds great Andy and I will leave those links in the description box below as well thank you for your insights into the industry all the best with Florida Network moving forward and let's follow up in the near future

thanks Ashton

More interviews

Browse all 1,090 interviews

Get new interviews firstThe BlockWest newsletter: markets, AI and policy, twice a week. Free.

Subscribe free