Finding – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sat, 28 Jun 2025 00:53:12 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Finding – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 My top 5 sneaky tips for finding legit tech deals during Prime Day 2025 — a guide for Android users https://earlybirdsinvest.com/my-top-5-sneaky-tips-for-finding-legit-tech-deals-during-prime-day-2025-a-guide-for-android-users/ https://earlybirdsinvest.com/my-top-5-sneaky-tips-for-finding-legit-tech-deals-during-prime-day-2025-a-guide-for-android-users/#respond Sat, 28 Jun 2025 00:53:11 +0000 https://earlybirdsinvest.com/my-top-5-sneaky-tips-for-finding-legit-tech-deals-during-prime-day-2025-a-guide-for-android-users/

It’s happening: Prime Day 2025 kicks off on July 8th and runs through the 11th, marking the first time that the Amazon sale has ever last four full days. It also means that we’re going to be experiencing a hectic week of sale events across the web, with all of your favorite websites and influencers alike inundating you with dozens of deals on everything from kitchen appliances to smartphones.

I’ve been working sale events like this long enough that I know exactly how to breeze through the week of Prime Day with relatively little stress. Whether you’re shopping for a smartphone, tablet, or simply browsing, keep reading for my top 5 tips for finding actually good deals during Prime Day 2025. No fluff, no tricks, just good old-fashioned discounts on tech. 

Quick links

Tip #1: Do your research

Comparing the displays between the Samsung Galaxy S24 Ultra and Samsung Galaxy S25 Ultra

(Image credit: Nicholas Sutrich / Android Central)

1. Do your research

This one might be a bit obvious, but if you plan to make a major purchase during Prime Day, it’s important to do a little research beforehand so you know what you’re looking for. Simply shopping for “any Android phone” during the sale, for instance, could lead to buyer’s remorse when you realize that you didn’t read up on these devices before making a purchase. 

Start by considering what’s important to you personally when you use your devices. Do you just need something simple and affordable? Maybe great cameras or battery life? What about AI features or long software support? Reading up on the best Android tech beforehand is a great way to make sure you’re prepared when the big sale goes live. 

Start shopping on July 8th with a wish list of the items you’re interested in. That’ll keep you from feeling overwhelmed and ensure you feel confident in your purchase once that order confirmation page appears. After all, tech can be expensive, and every penny counts these days. 

Tip #2: Look at price history

Samsung ecosystem of devices including the Galaxy S25 Ultra, Galaxy Watch Ultra, Buds 3 Pro, Samsung laptop, and Tab S10 Ultra

(Image credit: Andrew Myrick / Android Central)

2. Look at price history

When these major sale events go live, it can be hard to tell if a deal is actually good or if the retailer is just trying to make you think it’s good. Items marked with text like “Lightning Deal” can make you feel a sense of urgency on a discount that isn’t necessarily that special. This is where price tracking tools come in handy. 

Websites like Camelcamelcamel.com let you check the complete price history on items sold through Amazon. Pasting the product page URL into the site’s search field will give you a timeline of every instance that the item has been discounted, plus it will tell if you the current discount is record-breaking or if we’ve seen it before. This can be helpful if you’re trying to decide between making a major purchase today or waiting a few more months to buy.

The problem with websites like Camelcamelcamel is that the data can be a bit unreliable if a product has a lot of different color variants or storage configurations. Information can also be disrupted if the item has too many third-party sellers. Still, I wouldn’t make any purchase on Amazon without at least attempting to check the price history first. 

Tip #3: Check rival sales

Prime Day 2023 ad

(Image credit: Amazon)

3. Check rival sales

Of course, whenever Amazon launches a Prime Day event, you can expect most of its competitors to launch rival sales around the same time. Many of these sales match or beat Amazon’s prices, which can be great if you don’t have a Prime membership and aren’t interested in joining (even though there’s a 30-day trial that lets you shop the sale for free). 

Before you buy an Android device from Amazon during Prime Day, see if Best Buy or Walmart is offering an equal or better deal. Don’t forget to check for extra perks too. Buying a tablet from Amazon may get you the device alone, but purchasing the same tablet for the same price during Best Buy’s sale might also get you three free months of Apple Music or a free trial to Xbox Game Pass. 

Retailers like Best Buy and Samsung may also offer enhanced trade-in credit during their respective sale events, which could land you some additional savings if you have an old or broken device lying around. Needless to say, we’ll be covering all of the best Android deals from across the web that week — regardless of the source — so you can always check with us if you’re unsure about a discount.

Tip #4: Watch out for scams

An example of a scam text sent by a phony USPS rep

(Image credit: Jerry Hildenbrand / Android Central)

4. Watch out for scams

Although Prime Day presents itself as the perfect opportunity to find great deals this summer, it’s also an opportunity for scammers to target your data and bank account. Reports of scams and phishing attempts increase dramatically during the sale event, and it’s easy to fall victim to these traps if you’re not careful.

Watch out for emails or texts that are trying to compel you to click on a link concerning a recent purchase, especially if you haven’t placed an order lately. These scammers will often try to impersonate Amazon representatives or mail providers and will send emails from suspicious sources like “amazonusa[.]shop” or “amazonindo[.]com”. Other dishonest agents may attempt to contact you by phone. 

Rule of thumb, as Amazon clearly expresses on its site, representatives “will never send you an unsolicited message that asks you to provide sensitive personal information like your social insurance number, tax ID, bank account number, credit card information, ID questions like your mother’s maiden name or your password”. 

Tip #5: Stay calm

Garmin Fenix 8 vs. Galaxy Watch Ultra

(Image credit: Michael L Hicks / Android Central)

5. Stay calm

Last but not least, if you want to have a good time shopping this Prime Day, it’s important to stay calm. Email newsletters, search engines, and even celebrities will be flooding the airwaves that week with breathless endorsements and recommendations for top products, and it’s important to remember that it’s just a sale

Don’t get carried away by a false sense of urgency and buy a bunch of items you don’t need, and don’t get so overwhelmed by the flood of information that you end up missing a truly great deal. By simply researching products beforehand and preparing a list of everything you need in advance, you can wake up on the morning of July 8th and shop for deals at your leisure. 

And don’t forget: the entire Android Central staff (including yours truly) will be around to share our favorite deals and provide helpful shopping advice during the sale, so you’ll never feel too lost. 

]]>
https://earlybirdsinvest.com/my-top-5-sneaky-tips-for-finding-legit-tech-deals-during-prime-day-2025-a-guide-for-android-users/feed/ 0 44516
SUI Surges After Finding Strong Support at $3.75 Level https://earlybirdsinvest.com/sui-surges-after-finding-strong-support-at-3-75-level/ https://earlybirdsinvest.com/sui-surges-after-finding-strong-support-at-3-75-level/#respond Mon, 19 May 2025 01:32:07 +0000 https://earlybirdsinvest.com/sui-surges-after-finding-strong-support-at-3-75-level/

Global economic tensions and shifting trade policies continue to influence cryptocurrency markets, with SUI showing particular resilience.

The asset established a trading range of 4.46% between $3.70 and $3.86, finding strong volume support at the $3.755 level.

A notable bullish momentum emerged with price surging 1.9% on above-average volume, establishing resistance at $3.850.

The formation of higher lows throughout the latter part of the day suggests consolidation above the $3.775 support level.

Technical Analysis Highlights

  • SUI established a 24-hour trading range of 0.165 (4.46%) between the low of 3.700 and high of 3.862.
  • Strong volume support emerged at the 3.755 level during hours 17-18, with accumulation exceeding the 24-hour volume average by 45%.
  • Notable bullish momentum occurred in the 20:00 hour with price surging 7.2 cents (1.9%) on above-average volume.
  • Resistance established at 3.850 with higher lows forming throughout the latter part of the day.
  • Decreasing volatility in the final hours suggests consolidation above the 3.775 support level.
  • Significant buyer interest appeared between 01:27-01:30, forming a strong support zone at 3.756-3.760 with exceptionally high volume (over 300,000 units per minute).
  • Decisive bullish reversal began at 01:42, establishing a series of higher lows and higher highs.
  • Breakout above 3.780 occurred at 01:55, followed by consolidation near 3.785 with decreasing volume.

Disclaimer: This article was generated with AI tools and reviewed by our editorial team to ensure accuracy and adherence to our standards. For more information, see CoinDesk’s full AI Policy. This article may include information from external sources, which are listed below when applicable.

External References

]]>
https://earlybirdsinvest.com/sui-surges-after-finding-strong-support-at-3-75-level/feed/ 0 37017
SEC 'Earnest' About Finding Workable Crypto Policy, Commissioners Say at Roundtable https://earlybirdsinvest.com/sec-earnest-about-finding-workable-crypto-policy-commissioners-say-at-roundtable/ https://earlybirdsinvest.com/sec-earnest-about-finding-workable-crypto-policy-commissioners-say-at-roundtable/#respond Fri, 21 Mar 2025 19:45:47 +0000 https://earlybirdsinvest.com/sec-earnest-about-finding-workable-crypto-policy-commissioners-say-at-roundtable/

WASHINGTON, D.C. — The staff at the U.S. Securities and Exchange Commission has embraced the chance to finally work with the crypto industry to hash out policy for overseeing digital assets transactions, said Commissioner Hester Peirce, the head of the agency’s crypto task force.

The securities regulator is ready “to seek earnestly to find a workable framework,” Peirce said at the agency’s first crypto-focused roundtable on Friday. “I think we’re ready for the spring ahead,” she said, referring to the title of the day’s event, the “Spring Sprint Toward Crypto Clarity.”

The task, according to Peirce: “Can we translate the characteristics of a security into a simple taxonomy that will cover the many different types of crypto assets that exist today and may exist in the future?”

SEC Commissioner Hester Peirce (Nikhilesh De/CoinDesk)

SEC Commissioner Hester Peirce spoke ahead of the panel discussion at the Crypto Task Force’s roundtable. (Nikhilesh De/CoinDesk)

Mark Uyeda, the agency’s acting chairman, told reporters that despite recent SEC policy statements that certain areas of the crypto sector aren’t subject to securities laws — memecoins and mining, so far — it’s a “definitely possibility” that others will be defined as securities.

“We’re moving on multiple tracks here,” he said in answer to a question from CoinDesk. Each statement issued so far “ultimately is a staff statement” that doesn’t have legal backing, but he said the roundtable represents the entire commission — currently three members — looking at what a “potential commission interpretation might look like.”

In his opening remarks at the event, Uyeda, who was appointed by President Donald Trump as the SEC awaits a Senate confirmation of Paul Atkins, argued that the agency should have been more willing in recent years to make such interpretations public.

“When judicial opinions have created uncertainty from our participants in the past, the commission and its staff have stepped in to provide guidance,” Uyeda said. “This approach of using common rulemaking for explaining the commission’s process or releases rather than enforcement actions, should have been considered for classifying crypto assets under the federal security laws.”

Panel discussion

The panel discussion saw a dozen securities attorneys in the crypto sector weigh in on the specific issues they saw as they advised companies.

“What’s the biggest question that you face in trying to wrestle with this question?,” moderator Troy Paredes, a former SEC commissioner who now runs consulting firm Paredes Strategies, asked Sarah Brennan, the general counsel at Delphi Ventures and one of the 11 panelists.

Panelists speak at SEC Crypto Task Force's first roundtable discussion (Nikhilesh De/CoinDesk)

Panelists speak at the SEC Crypto Task Force’s first roundtable discussion (Nikhilesh De/CoinDesk)

“The specter of the application of securities laws has moved early-stage projects in the market to sort of take an arc very similar to [initial public offerings], where they stay private longer,” she replied.

“These assets in the traditional model are designed to have wide, broad early distribution and most of the market is hedging that on the application of securities laws, so it ends up looking a lot like your traditional markets where people will marshal their way to an exchange listing without that broad dissemination or price support or actually fully launching the technology.”

The panel featured critics of the industry alongside attorneys who have worked to develop the sector.

“Whether you’re talking yield farms or ostrich farms or orange groves, the whole point of securities regulation was to wrap that all up into a very big, broad, principles-based regulation,” former SEC attorney John Reed Stark said. His concern is that, even in 2025, much of the market lacks utility.

“If it all went away tomorrow and you weren’t speculating in it, you wouldn’t care,” he said.

Legislator questions

Ahead of the roundtable, Sen. Elizabeth Warren and Rep. Jake Auchincloss, both Massachusetts Democrats, wrote an open letter to Uyeda asking about the SEC’s staff statement on memecoins and how it was developed.

The letter asked whether anyone at the SEC communicated with the White House about the statement, whether the White House’s crypto working group had directed the SEC to do anything and why the staff statement was not built into formal rulemaking.

Warren and Auchincloss also asked the SEC to explain how it would specifically define memecoins as distinct from “general cryptocurrency,” how it would distinguish between actual memecoins and memecoins that don’t meet the staff statement, and which memecoins the SEC analyzed in drafting its staff statement.

]]>
https://earlybirdsinvest.com/sec-earnest-about-finding-workable-crypto-policy-commissioners-say-at-roundtable/feed/ 0 26459
Secured #6 – Writing Robust C – Best Practices for Finding and Preventing Vulnerabilities https://earlybirdsinvest.com/secured-6-writing-robust-c-best-practices-for-finding-and-preventing-vulnerabilities/ https://earlybirdsinvest.com/secured-6-writing-robust-c-best-practices-for-finding-and-preventing-vulnerabilities/#respond Tue, 18 Mar 2025 08:51:31 +0000 https://earlybirdsinvest.com/secured-6-writing-robust-c-best-practices-for-finding-and-preventing-vulnerabilities/

For EIP-4844, Ethereum clients need the ability to compute and verify KZG commitments. Rather than each client rolling their own crypto, researchers and developers came together to write c-kzg-4844, a relatively small C library with bindings for higher-level languages. The idea was to create a robust and efficient cryptographic library that all clients could use. The Protocol Security Research team at the Ethereum Foundation had the opportunity to review and improve this library. This blog post will discuss some things we do to make C projects more secure.


Fuzz

Fuzzing is a dynamic code testing technique that involves providing random inputs to discover bugs in a program. LibFuzzer and afl++ are two popular fuzzing frameworks for C projects. They are both in-process, coverage-guided, evolutionary fuzzing engines. For c-kzg-4844, we used LibFuzzer since we were already well-integrated with LLVM project’s other offerings.

Here’s the fuzzer for verify_kzg_proof, one of c-kzg-4844’s functions:

#include "../base_fuzz.h"

static const size_t COMMITMENT_OFFSET = 0;
static const size_t Z_OFFSET = COMMITMENT_OFFSET + BYTES_PER_COMMITMENT;
static const size_t Y_OFFSET = Z_OFFSET + BYTES_PER_FIELD_ELEMENT;
static const size_t PROOF_OFFSET = Y_OFFSET + BYTES_PER_FIELD_ELEMENT;
static const size_t INPUT_SIZE = PROOF_OFFSET + BYTES_PER_PROOF;

int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
    initialize();
    if (size == INPUT_SIZE) {
        bool ok;
        verify_kzg_proof(
            &ok,
            (const Bytes48 *)(data + COMMITMENT_OFFSET),
            (const Bytes32 *)(data + Z_OFFSET),
            (const Bytes32 *)(data + Y_OFFSET),
            (const Bytes48 *)(data + PROOF_OFFSET),
            &s
        );
    }
    return 0;
}

When executed, this is what the output looks like. If there were a problem, it would write the input to disk and stop executing. Ideally, you should be able to reproduce the problem.

There’s also differential fuzzing, which is a technique which fuzzes two or more implementations of the same interface and compares the outputs. For a given input, if the output is different, and you expected them to be the same, you know something is wrong. This technique is very popular in Ethereum because we like to have several implementations of the same thing. This diversification provides an extra level of safety, knowing that if one implementation were flawed the others may not have the same issue.

For KZG libraries, we developed kzg-fuzz which differentially fuzzes c-kzg-4844 (through its Golang bindings) and go-kzg-4844. So far, there haven’t been any differences.

Coverage

Next, we used llvm-profdata and llvm-cov to generate a coverage report from running the tests. This is a great way to verify code is executed (“covered”) and tested. See the coverage target in c-kzg-4844’s Makefile for an example of how to generate this report.

When this target is run (i.e., make coverage) it produces a table that serves as a high-level overview of how much of each function is executed. The exported functions are at the top and the non-exported (static) functions are on the bottom.

There is a lot of green in the table above, but there is some yellow and red too. To determine what is and isn’t being executed, refer to the HTML file (coverage.html) that was generated. This webpage shows the entire source file and highlights non-executed code in red. In this project’s case, most of the non-executed code deals with hard-to-test error cases such as memory allocation failures. For example, here’s some non-executed code:

At the beginning of this function, it checks that the trusted setup is big enough to perform a pairing check. There isn’t a test case which provides an invalid trusted setup, so this doesn’t get executed. Also, because we only test with the correct trusted setup, the result of is_monomial_form is always the same and doesn’t return the error value.

Profile

We don’t recommend this for all projects, but since c-kzg-4844 is a performance critical library we think it’s important to profile its exported functions and measure how long they take to execute. This can help identify inefficiencies which could potentially DoS nodes. For this, we used gperftools (Google Performance Tools) instead of llvm-xray because we found it to be more feature-rich and easier to use.

The following is a simple example which profiles my_function. Profiling works by checking which instruction is being executed every so often. If a function is fast enough, it may not be noticed by the profiler. To reduce the chance of this, you may need to call your function multiple times. In this example, we call my_function 1000 times.

#include 

int task_a(int n) {
    if (n <= 1) return 1;
    return task_a(n - 1) * n;
}

int task_b(int n) {
    if (n <= 1) return 1;
    return task_b(n - 2) + n;
}

void my_function(void) {
    for (int i = 0; i < 500; i++) {
        if (i % 2 == 0) {
            task_a(i);
        } else {
            task_b(i);
        }
    }
}

int main(void) {
    ProfilerStart("example.prof");
    for (int i = 0; i < 1000; i++) {
        my_function();
    }
    ProfilerStop();
    return 0;
}

Use ProfilerStart(““) and ProfilerStop() to mark which parts of your program to profile. When re-compiled and executed, it will write a file to disk with profiling data. You can then use pprof to visualize this data.

Here is the graph generated from the command above:

Here’s a bigger example from one of c-kzg-4844’s functions. The following image is the profiling graph for compute_blob_kzg_proof. As you can see, 80% of this function’s time is spent performing Montgomery multiplications. This is expected.

Reverse

Next, view your binary in a software reverse engineering (SRE) tool such as Ghidra or IDA. These tools can help you understand how high-level constructs are translated into low-level machine code. We think it helps to review your code this way; like how reading a paper in a different font will force your brain to interpret sentences differently. It’s also useful to see what type of optimizations your compiler makes. It’s rare, but sometimes the compiler will optimize out something which it deemed unnecessary. Keep an eye out for this, something like this actually happened in c-kzg-4844, some of the tests were being optimized out.

When you view a decompiled function, it will not have variable names, complex types, or comments. When compiled, this information isn’t included in the binary. It will be up to you to reverse engineer this. You’ll often see functions are inlined into a single function, multiple variables declared in code are optimized into a single buffer, and the order of checks are different. These are just compiler optimizations and are generally fine. It may help to build your binary with DWARF debugging information; most SREs can analyze this section to provide better results.

For example, this is what blob_to_kzg_commitment initially looks like in Ghidra:

With a little work, you can rename variables and add comments to make it easier to read. Here’s what it could look like after a few minutes:

Static Analysis

Clang comes built-in with the Clang Static Analyzer, which is an excellent static analysis tool that can identify many problems that the compiler will miss. As the name “static” suggests, it examines code without executing it. This is slower than the compiler, but a lot faster than “dynamic” analysis tools which execute code.

Here’s a simple example which forgets to free arr (and has another problem but we will talk more about that later). The compiler will not identify this, even with all warnings enabled because technically this is completely valid code.

#include 

int main(void) {
    int* arr = malloc(5 * sizeof(int));
    arr[5] = 42;
    return 0;
}

The unix.Malloc checker will identify that arr wasn’t freed. The line in the warning message is a bit misleading, but it makes sense if you think about it; the analyzer reached the return statement and noticed that the memory hadn’t been freed.

Not all of the findings are that simple though. Here’s a finding that Clang Static Analyzer found in c-kzg-4844 when initially introduced to the project:

Given an unexpected input, it was possible to shift this value by 32 bits which is undefined behavior. The solution was to restrict the input with CHECK(log2_pow2(n) != 0) so that this was impossible. Good job, Clang Static Analyzer!

Sanitize

Santizers are dynamic analysis tools which instrument (add instructions) to programs which can point out issues during execution. These are particularly useful at finding common mistakes associated with memory handling. Clang comes built-in with several sanitizers; here are the four we find most useful and easy to use.

Address

AddressSanitizer (ASan) is a fast memory error detector which can identify out-of-bounds accesses, use-after-free, use-after-return, use-after-scope, double-free, and memory leaks.

Here is the same example from earlier. It forgets to free arr and it will set the 6th element in a 5 element array. This is a simple example of a heap-buffer-overflow:

#include 

int main(void) {
    int* arr = malloc(5 * sizeof(int));
    arr[5] = 42;
    return 0;
}

When compiled with -fsanitize=address and executed, it will output the following error message. This points you in a good direction (a 4-byte write in main). This binary could be viewed in a disassembler to figure out exactly which instruction (at main+0x84) is causing the problem.

Similarly, here’s an example where it finds a heap-use-after-free:

#include 

int main(void) {
    int *arr = malloc(5 * sizeof(int));
    free(arr);
    return arr[2];
}

It tells you that there’s a 4-byte read of freed memory at main+0x8c.

Memory

MemorySanitizer (MSan) is a detector of uninitialized reads. Here’s a simple example which reads (and returns) an uninitialized value:

int main(void) {
    int data[2];
    return data[0];
}

When compiled with -fsanitize=memory and executed, it will output the following error message:

Undefined Behavior

UndefinedBehaviorSanitizer (UBSan) detects undefined behavior, which refers to the situation where a program’s behavior is unpredictable and not specified by the langauge standard. Some common examples of this are accessing out-of-bounds memory, dereferencing an invalid pointer, reading uninitialized variables, and overflow of a signed integer. For example, here we increment INT_MAX which is undefined behavior.

#include 

int main(void) {
    int a = INT_MAX;
    return a + 1;
}

When compiled with -fsanitize=undefined and executed, it will output the following error message which tells us exactly where the problem is and what the conditions are:

Thread

ThreadSanitizer (TSan) detects data races, which can occur in multi-threaded programs when two or more threads access a shared memory location at the same time. This situation introduces unpredictability and can lead to undefined behavior. Here’s an example in which two threads increment a global counter variable. There aren’t any locks or semaphores, so it’s entirely possible that these two threads will increment the variable at the same time.

#include 

int counter = 0;

void *increment(void *arg) {
    (void)arg;
    for (int i = 0; i < 1000000; i++)
        counter++;
    return NULL;
}

int main(void) {
    pthread_t thread1, thread2;
    pthread_create(&thread1, NULL, increment, NULL);
    pthread_create(&thread2, NULL, increment, NULL);
    pthread_join(thread1, NULL);
    pthread_join(thread2, NULL);
    return 0;
}

When compiled with -fsanitize=thread and executed, it will output the following error message:

This error message tells us that there’s a data race. In two threads, the increment function is writing to the same 4 bytes at the same time. It even tells us that the memory is counter.

Valgrind

Valgrind is a powerful instrumentation framework for building dynamic analysis tools, but its best known for identifying memory errors and leaks with its built-in Memcheck tool.

The following image shows the output from running c-kzg-4844’s tests with Valgrind. In the red box is a valid finding for a “conditional jump or move [that] depends on uninitialized value(s).”

This identified an edge case in expand_root_of_unity. If the wrong root of unity or width were provided, it was possible that the loop will break before out[width] was initialized. In this situation, the final check would depend on an uninitialized value.

static C_KZG_RET expand_root_of_unity(
    fr_t *out, const fr_t *root, uint64_t width
) {
    out[0] = FR_ONE;
    out[1] = *root;

    for (uint64_t i = 2; !fr_is_one(&out[i - 1]); i++) {
        CHECK(i <= width);
        blst_fr_mul(&out[i], &out[i - 1], root);
    }
    CHECK(fr_is_one(&out[width]));

    return C_KZG_OK;
}

Security Review

After development stabilizes, it’s been thoroughly tested, and your team has manually reviewed the codebase themselves multiple times, it’s time to get a security review by a reputable security group. This won’t be a stamp of approval, but it shows that your project is at least somewhat secure. Keep in mind there is no such thing as perfect security. There will always be the risk of vulnerabilities.

For c-kzg-4844 and go-kzg-4844, the Ethereum Foundation contracted Sigma Prime to conduct a security review. They produced this report with 8 findings. It contains one critical vulnerability in go-kzg-4844 that was a really good find. The BLS12-381 library that go-kzg-4844 uses, gnark-crypto, had a bug which allowed invalid G1 and G2 points to be sucessfully decoded. Had this not been fixed, this could have resulted in a consensus bug (a disagreement between implementations) in Ethereum.

Bug Bounty

If a vulnerability in your project could be exploited for gains, like it is for Ethereum, consider setting up a bug bounty program. This allows security researchers, or anyone really, to submit vulnerability reports in exchange for money. Generally, this is specifically for findings which can prove that an exploit is possible. If the bug bounty payouts are reasonable, bug finders will notify you of the bug rather than exploiting it or selling it to another party. We recommend starting your bug bounty program after the findings from the first security review are resolved; ideally, the security review would cost less than the bug bounty payouts.

Conclusion

The development of robust C projects, especially in the critical domain of blockchain and cryptocurrencies, requires a multi-faceted approach. Given the inherent vulnerabilities associated with the C language, a combination of best practices and tools is essential for producing resilient software. We hope our experiences and findings from our work with c-kzg-4844 provide valuable insights and best practices for others embarking on similar projects.

]]>
https://earlybirdsinvest.com/secured-6-writing-robust-c-best-practices-for-finding-and-preventing-vulnerabilities/feed/ 0 25798