Callisto Network
WebsiteSecurity DepartmentTwitter
  • Whitepaper
    • ๐Ÿ‡ฎ๐Ÿ‡นWhitepaper (ITA)
    • ๐Ÿ‡ฎ๐Ÿ‡ณWhitepaper (TELUGU)
    • ๐Ÿ‡ฎ๐Ÿ‡ณWhitepaper (HINDI)
    • ๐Ÿ‡จ๐Ÿ‡ณWhitepaper (CN Traditional)
    • ๐Ÿ‡ญ๐Ÿ‡ฐWhitepaper (CN Simplified)
    • ๐Ÿ‡ซ๐Ÿ‡ทWhitepaper (FR)
    • ๐Ÿ‡ต๐Ÿ‡ญWhitepaper (PH)
  • ๐Ÿ“ŒStrategic Plan
  • Callisto Network Vision
  • ๐Ÿš€Callisto Network Progress Tracker
  • ๐Ÿ—“๏ธEcosystem Reports
    • Callisto Monthly - February 2023
    • Callisto Monthly - January 2023
      • ๐Ÿ‡ฎ๐Ÿ‡นCallisto Monthly - January 2023 (ITA)
      • ๐Ÿ‡ซ๐Ÿ‡ทCallisto Monthly - January 2023 (FR)
      • ๐Ÿ‡ฎ๐Ÿ‡ณCallisto Monthly - January 2023 (TELUGU)
    • Callisto Monthly - December 2022
      • ๐Ÿ‡ฎ๐Ÿ‡นCallisto Monthly - December 2022 (ITA)
      • ๐Ÿ‡ซ๐Ÿ‡ทCallisto Monthly - December 2022 (FR)
      • ๐Ÿ‡ต๐Ÿ‡ญCallisto Monthly - December 2022 (PHI)
    • Callisto Monthly - November 2022
      • ๐Ÿ‡ซ๐Ÿ‡ทCallisto Monthly - November 2022 (FR)
      • ๐Ÿ‡ฎ๐Ÿ‡นCallisto Monthly - November 2022 (ITA)
      • ๐Ÿ‡ฎ๐Ÿ‡ณCallisto Monthly - November 2022 (TELEGU)
    • Callisto Monthly - October 2022
      • ๐Ÿ‡ฎ๐Ÿ‡นCallisto Monthly - October 2022 (ITA)
      • ๐Ÿ‡ซ๐Ÿ‡ทCallisto Monthly - October 2022 (FR)
      • ๐Ÿ‡ต๐Ÿ‡ญCallisto Monthly - October 2022 (PHI)
      • ๐Ÿ‡จ๐Ÿ‡ณCallisto Monthly - October 2022 (CN Simplified)
      • ๐Ÿ‡ญ๐Ÿ‡ฐCallisto Monthly - October 2022 (CN Traditional)
      • ๐Ÿ‡ท๐Ÿ‡บMonthly - October 2022 (RU)
    • Callisto Monthly - September 2022
      • ๐Ÿ‡ฎ๐Ÿ‡นCallisto Monthly - September 2022 (ITA)
      • ๐Ÿ‡ซ๐Ÿ‡ทCallisto Monthly - September 2022 (FR)
      • ๐Ÿ‡ต๐Ÿ‡ญCallisto Monthly - September 2022 (PHI)
      • ๐Ÿ‡จ๐Ÿ‡ณCallisto Monthly - September 2022 (CN Simplified)
      • ๐Ÿ‡ญ๐Ÿ‡ฐCallisto Monthly - September 2022 (CN Traditional)
    • Callisto Monthly - August 2022
      • ๐Ÿ‡ฎ๐Ÿ‡นCallisto Monthly - August 2022 (ITA)
      • ๐Ÿ‡ซ๐Ÿ‡ทCallisto Monthly - August 2022 (FR)
      • ๐Ÿ‡ต๐Ÿ‡ญCallisto Monthly - August 2022 (PH)
    • Callisto Monthly - July 2022
      • ๐Ÿ‡ฎ๐Ÿ‡นCallisto Monthly - July 2022 (ITA)
    • Callisto Monthly - June 2022
    • Callisto Monthly - May 2022
    • Callisto Monthly - April 2022
    • Callisto Monthly - March 2022
  • Technologies
    • ๐Ÿ“ˆCallisto Dynamic Monetary Policy
      • Crypto-models To Overcome Inflation and Callisto Network's Approach
      • Skuld Hard Fork - Update On Progress
    • ๐ŸงŠCold Staking
      • Cold Staking And PoS Staking Comparison
    • ๐Ÿช™Wrapped Callisto (ccCLO)
    • ยฎ๏ธDexNS 2021
    • โ›๏ธProof of Work
      • ZPoW #1 - Exploiting The Block Time & Block Size
      • Callisto Network Introduces the Dynamic Gas Price
    • โ“‚๏ธCallisto Network Masternodes
    • ๐ŸŽ“Tutorials
      • Setting Up Metamask For Callisto Network
        • Update the RPC URL in MetaMask
      • How to buy Callisto with Your Credit Card
      • How to Run a Callisto Network Node?
      • Callisto Network Masternodes Set-up
    • ๐ŸŒCallisto Hub
    • ๐ŸงฉWeb 3.0 Infrastructure
    • ๐Ÿ”Chain Inspector
  • We Fund You!
    • ๐Ÿ’ฒWe Fund You!
      • We Fund You Award - 1st Edition
  • Security Department
    • ๐Ÿ”Auditing Department
      • Auditing Department Amendment v5
    • ๐Ÿ“–Documentation
      • ๐Ÿ›ก๏ธSecurity Department Best Practices
      • ๐Ÿช™ERC 223 Token Standard
        • ERC20 Standard Main Issue
      • ๐Ÿ–ผ๏ธCallistoNFT Standard
        • Roadmap
      • โœ–๏ธCross-Chain Bridges Security Model
    • Products & Services
      • ๐Ÿ”Security Audits For Smart Contracts
        • Mission: Securing The Smart Contracts Ecosystem
        • Trust and Smart Contracts: Code is the Limit
    • ๐ŸคVarious Contributions
      • Ethereum Classic
        • ECIP-1092 51attack solution: PirlGuard & Callisto proposal
      • Ethereum
        • Statement regarding Geth v1.10.8 split
      • EOS
        • Page 1Chintai (EOS resource exchange) low severity issue.
        • EOS congestion 9/13/2019 and EOSPlay hack
      • Ultimate solution to 51% attacks: amend the Nakamoto consensus
  • Hack Investigation Dept.
    • Hack Investigation Department
    • Helio Exploit
    • Binance Bridge Hack
    • TempleDAO's STAX Contract Hack Investigation
    • NFT Theft Analysis
    • AUDIUS Governance System Exploit Overview
    • LUNA โ€˜Hardforkโ€™ Review
  • One Earth, One Heart
    • ๐ŸŒŽOne Earth, One Heart
    • ๐Ÿ’šCallisto Charity Efforts
  • Community
    • ๐Ÿ“ฅCallisto Network Improvement Proposals
    • ๐Ÿ’ฌCallisto AMAs
      • Callisto Team's Ask Me Anything on 04/05/2023
      • Callisto Team's Ask Me Anything on 03/03/2023
      • Callisto Team's Welcome AMA on 10/11/2022
      • Callisto Team's Ask Me Anything on 10/10/2022
      • Callisto Security Team's Ask Me Anything on 02/09/2022
      • Callisto Team's Ask Me Anything on 28/07/2022
      • Dexaran's Ask Me Anything on 11/04/2022
    • ๐Ÿ“ŒGet Started
  • Callisto Enterprise
    • ๐Ÿช™Callisto Enterprise Token
      • Vision and Tokenomics
    • ๐Ÿ‘ฅTeam
      • Callisto Team Motivation System
  • In The Press
    • ๐ŸŸขCallisto Network
      • Ethereum, Ethereum Classic, Callisto Network, A Common History
      • Callisto Network: Three Years After Mainnet Launch
      • Czech Ethereum Killer
    • ๐Ÿ–ผ๏ธNFTs
      • Artist Creates And Then Destroys Art To Launch CallistoNFT
      • Security Network Develops New NFT Standard To Address ERC-721 Flaws
  • Miscellaneous
    • ๐ŸงฉMedia Kit
Powered by GitBook
On this page
  • The Importance of an Independent Expert
  • Actions
  • Transparency
  • Why Callisto Security Dept is doing this?
  1. Hack Investigation Dept.

Hack Investigation Department

PreviousUltimate solution to 51% attacks: amend the Nakamoto consensusNextHelio Exploit

Last updated 2 years ago

Callisto Network's Security Department was created in 2018 with a clear idea of its mission: "contribute to securing the smart contract ecosystem to promote its widespread adoption."

Since then, the Callisto Security auditors have been true to their mission and have contributed to securing more than 320 projects in all major blockchain platforms without a single one ever being hacked. The combined experience of Callisto Security auditors is unparalleled to this day and makes them an undisputed authority when it comes to smart contracts and blockchain security issues in general.

As blockchain and smart contract technologies are embraced, we see that the number of hacks is rising and has never been higher!

It is time to raise awareness among investors and developers alike!

The Importance of an Independent Expert

While the ecosystem is intended to be decentralized, it still relies on centralized platforms where communication can be censored (such as forums...) but also depends on mechanisms that are not transparent and whose DAOs can eventually be manipulated.

The example of Luna made it evident to us that the ecosystem needs to have independent experts whom the community can rely on in case of a lack of trust and transparency.

Callisto has taken on a new mission to raise cyber security awareness.

The hack investigation department will be charged with identifying the exact feature of the smart contract that led to the hack, creating a hack investigation report and making it publicly available.

Actions

  • Publishing guidance on the cyber-security best practices.

Perform hacking analysis and report findings on a regular basis.

We will publish reviews of 2 hacks per month. The community will be encouraged to take part in deciding which hacks should be reviewed via a vote held on Twitter.

The Callisto Security hack reports are structured as follows:

  • What happened: Description of the hack as perceived by the community and the crypto-press, as well as the context and amount of funds involved.

  • What Failed: Technical description of the hack and review of possible causes.

  • Conclusion: Reminder of securityโ€™s best practices to prevent this from happening again in the future.

Transparency

As an independent expert, it is important to adopt the highest level of transparency in each step of the analysis process.

  • The selection of the case to be analyzed will be made via Twitter allowing everyone the opportunity to participate in the voting.

  • If the hacked project audit report is available, it will be compared to the report made by Callisto Security.

To ensure the highest level of transparency, both reports will be made publicly available and securely stored in a censorship-proof data system.

Why Callisto Security Dept is doing this?

By design, Callisto Securitycontributes to other projects. After having audited 320 smart contracts, mostly without charge. Our auditors are undoubtedly among the most experienced security experts and it is only natural to share our experience with the community. Only together can we promote the adoption of the best practices in the ecosystem and finally create a better world for all of us through decentralization.

Indeed, hacks have cost the community more than alone. Our experience tells us that these hacks could have been avoided to a large extent if developers and users/investors had a better knowledge of good practices.

It all started with the Luna hack. Facing the disarray of the community (), Callisto Network took the case and produced an analysis, which was the "most read and commented on" during the Luna hard fork. Unfortunately, the analysis is no longer available on the Luna forum but is still available on the of Callisto Network.

First, with a giveaway to the crypto community, which has reached over and continues with the until September 22, 2022. And second, with the foundation of the Hack Investigation Department, which consists of a group of smart-contract security experts responsible for investigating the hacks on the community request.

Security starts with the developers; too many projects are launched based on ready-made templates, which often do not fit the actual use cases. More so, developers are still frequently testing their code "in production" without considering the impact a hack may have on the investors. We aim to provide them with a series of documents such as the "" to strengthen the ecosystem and significantly reduce the risk of hacking.

1,9 billion dollars in 2022
and also at its request
Gitbook
6 million entries on Gleam
AbsoluteWallet referral program
Security Department Best Practices