The Aave wstETH incident shows why protocol security does not stop at code correctness.
A system can be logically secure in parts and still fail in production when coupled state stops moving in sync.
That is a security problem.
Thread below 👇: what broke, why it mattered, and the security lesson builders should not miss.

Omer Goldberg
@omeragoldberg
03-11
1/ stETH CAPO Misconfiguration
Today, a misconfiguration on Aave's CAPO oracle caused wstETH E-Mode liquidations, resulting in a loss of 345 ETH.
No bad debt was incurred, and all affected users will be fully reimbursed.
More below.
From Twitter
Disclaimer: The content above is only the author's opinion which does not represent any position of Followin, and is not intended as, and shall not be understood or construed as, investment advice from Followin.
Like
Add to Favorites
Comments
Share


