Metropolis Wants to Make It Easier To Spot Faulty Smart Contract Permissions

Exclusive: No technical expertise required to visualize smart contract permissions

article-image

OV11/Shutterstock modified by Blockworks

share

Smart contract permissions have been at the center of many hacks in the cryptocurrency ecosystem since their inception.

From recent the Wormhole counter exploit to Euler finance’s hack and the bZx DAO ruling, identifying faulty smart contract permissions could help protect the broader cryptocurrency ecosystem.

Metropolis, a company committed to protect on-chain permissions, said it hopes to achieve this with the launch of “The Podarchy Explorer,” a spatial interface that allows users to visualize smart contract permissions.

“We’ve been doing a lot of thinking on how we can bring faulty permissions to the surface, because they pose both a security risk in terms of basic user funds, but they also undermine ownership itself,” Chase Chapman, governance researcher at Metropolis, told Blockworks. 

Using the platform, users can search any on-chain entity — including externally owned accounts (EOAs), multisigs, and smart contracts — and identify all relevant connections and permissions. 

“Governance tokens don’t mean anything if they don’t have permissions to govern,” Chapman said. “The Podarchy Explorer will surface those permissions and easily identify faulty permissions without having to deep dive into code.”

Specifically, the company has indexed two widely adopted vectors for on-chain control: Safe membership and OpenZeppelin access control. It intends this to enable users to search up any wallet and addresses associated with Safe membership and help them to view its permissions over associated smart contracts.

“The Metropolis team anticipates the Podarchy Explorer will reveal some major flaws and anti-patterns across the ecosystem, which is ultimately positive, as hidden faulty permissions are posing a massive threat to the entire space,” Chapman said.


Start your day with top crypto insights from David Canellis and Katherine Ross. Subscribe to the Empire newsletter.

Tags

Upcoming Events

Salt Lake City, UT

WED - FRI, OCTOBER 9 - 11, 2024

Pack your bags, anon — we’re heading west! Join us in the beautiful Salt Lake City for the third installment of Permissionless. Come for the alpha, stay for the fresh air. Permissionless III promises unforgettable panels, killer networking opportunities, and mountains […]

recent research

Screen Shot 2024-05-16 at 14.53.45.png

Research

Loss-versus-rebalancing (LVR) is arguably Ethereum DeFi’s biggest problem, and thus reducing LVR is fundamental to the success of Ethereum. This report dives into the world of LVR. We uncover its importance for AMM designers, discuss the two major mechanism design categories and various projects developing solutions, and offer a higher level perspective on the importance of AMMs in general.

article-image

Yesterday saw Congress’ upper chamber side with the House on a measure aimed at overturning SAB 121

article-image

Oklahoma’s new crypto bill will go into effect in November of this year

article-image

The deposits hit a $20 million cap in just 45 minutes

article-image

Twelve Democratic Senators voted in favor to pass the resolution Thursday

article-image

Pump.fun is “aware” that bonding curve contracts on Pump.fun were exploited, and has since paused trading

article-image

Some investment pros are mulling crypto allocations between 1% and 10% and seeking ex-BTC exposure for interested clients