Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create 2023-08-14-Rocketswap.md #388

Closed
wants to merge 3 commits into from
Closed

Conversation

svg-arch
Copy link
Contributor

@svg-arch svg-arch commented Mar 5, 2024

No description provided.

@svg-arch svg-arch requested a review from a team as a code owner March 5, 2024 21:27
@JediFaust
Copy link
Contributor

/articlecheck

Copy link

Fact Checking

Editor's Notes

In the Timeline section:

  • Standardize the date formats to "Month day, year, time PM UTC"
  • Add missing timeline events from the text

Suggested improvements:

  • Expand the Summary to provide more background context
  • Provide more details on the losses in the Losses section
  • Include preventative measures in the Security Failure Causes section

Hugo SSG Formatting Check

  • Does it match Hugo SSG formatting? ✅

Filename Check

  • Correct Filename: 2023-08-14-Rocketswap.md

Section Headers Check

  • Allowed Headers: ## Summary, ## Attackers, ## Losses, ## Timeline, ## Security Failure Causes

Metadata Headers Check

  • Allowed Metadata Headers: date, target-entities, entity-types, attack-types, title, loss
  • Notes:
    • The date metadata header matches the date August 14, 2023 mentioned in the text August 14, 2023 2023-08-14 ✅
    • The target-entities metadata header matches the affected entity Rocketswap mentioned in the text Rocketswap Rocketswap ✅
    • The loss metadata header matches the $868,000 loss mentioned in the text $868,000 868000 ✅
    • The entity-types header correctly indicates "DeFi" based on the target entity ✅
    • The attack-types header correctly indicates "Private Key Leak" based on the exploit details ✅

@evgenydmitriev
Copy link
Contributor

/articlecheck

Copy link

Duplication checker

Is this a new article for Crypto wiki? ✅

Copy link

Fact Checking Results

Editor's Notes

  • The timeline section should include the exact time in UTC for each event, e.g. "August 14, 2023, 10:53 PM UTC:" instead of just "August 14, 2023:".
  • The timeline is missing some key events like when Rocketswap reported the exploit and announced the new farm contract. These should be added with exact timestamps if available.
  • Some sections like "Attackers" and "Security Failure Causes" could benefit from more details and context. For example, what specific vulnerabilities enabled the private key compromise?
  • Overall the content is factual and well-structured, just needs some additional details and formatting tweaks in the timeline.

Hugo SSG Formatting Check

  • Does it match Hugo SSG formatting? ✅

Filename Check

  • Correct Filename: 2023-08-14-Rocketswap.md
  • Your Filename: 2023-08-14-Rocketswap.md

Section Headers Check

  • Allowed Headers: ## Summary, ## Attackers, ## Losses, ## Timeline, ## Security Failure Causes
  • Your Headers: ## Summary, ## Attackers, ## Losses, ## Timeline, ## Security Failure Causes

Metadata Headers Check

  • Allowed Metadata Headers: date, target-entities, entity-types, attack-types, title, loss
  • Your Metadata Headers: date, target-entities, entity-types, attack-types, title, loss
  • Notes:
    • The date header matches the date mentioned in the Summary section: August 14, 2023 2023-08-14 ✅
    • The target-entities header matches the affected entity mentioned in the Summary section: Rocketswap Rocketswap ✅
    • The loss header matches the total loss amount mentioned in the Losses section: $868,000 868000 ✅
    • The entity-types header "DeFi" corresponds to the target entity Rocketswap, which is a decentralized trading protocol. ✅
    • The attack-types header "Private Key Leak" matches the description of the private key compromise enabling the attack. ✅

@svg-arch
Copy link
Contributor Author

svg-arch commented Jun 9, 2024

@evgenydmitriev

The timeline is missing some key events like when Rocketswap reported the exploit and announced the new farm contract. These should be added with exact timestamps if available.

It has already been added.

Some sections like "Attackers" and "Security Failure Causes" could benefit from more details and context. For example, what specific vulnerabilities enabled the private key compromise?

It is only known that the keys were stored on the server, and the server was hacked.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants