W3F and Trail of Bits release “Guidance for Secure Use of Hardware Wallets”

Image for post
Image for post

As all of our followers know, the Web3 Foundation conducted a public token sale last year for a 50% allocation in the Polkadot genesis block. Individuals around the world contributed $144 million, mostly in Ether. Unfortunately, that Ether became frozen due to a bug in a Parity library contract that our multi-sig contract referenced.

Not all of the funds collected were in that contract, and we’ve been able to continue to fund the development of the Polkadot project and other community initiatives such as the Ethereum Community Fund and Web3 Summit.

Following the fund freezing incident, we conducted rigorous audits on our processes for securing funds. We are committed to improving these processes and are excited to share our progress.

Since the bug exploit one year ago, Parity Technologies has developed increasingly better practises around secure coding, as outlined by their CTO Fredrik in a recent blog post “Secure from scratch: our new smart contract development processes”. Parity worked hand in hand with Trail of Bits to improve their secure development process.

The Web3 Foundation contracted Trail of Bits to conduct a security audit on our hardware wallets. The audit covered the setup of the devices as well as the processes surrounding their use.

We asked Trail of Bits if they would share the high level learnings from our audit report and we are happy to report that the security guidance provided to us in the audit is now open source for the community to read.

Read the Trail of Bits blog post.

Web3 Foundation

Web 3.0

Web3 Foundation Team

Written by

Web3 Foundation is building an internet where users are in control of their own data, identity and destiny. Our primary project is @polkadotnetwork.

Web3 Foundation

Web 3.0 Technologies Foundation nurtures and stewards technologies and applications in the fields of decentralised web software protocols.

Web3 Foundation Team

Written by

Web3 Foundation is building an internet where users are in control of their own data, identity and destiny. Our primary project is @polkadotnetwork.

Web3 Foundation

Web 3.0 Technologies Foundation nurtures and stewards technologies and applications in the fields of decentralised web software protocols.

Medium is an open platform where 170 million readers come to find insightful and dynamic thinking. Here, expert and undiscovered voices alike dive into the heart of any topic and bring new ideas to the surface. Learn more

Follow the writers, publications, and topics that matter to you, and you’ll see them on your homepage and in your inbox. Explore

If you have a story to tell, knowledge to share, or a perspective to offer — welcome home. It’s easy and free to post your thinking on any topic. Write on Medium

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store