Loading video player...
what you said on the OBSSEAC and like
taking a test before you can sign a
multi-IG transaction. That's super
interesting and fascinating [music] to
me. Can you say more about kind of what
some of those OBSSEAC measures are or
what's on that test?
>> What we ended up doing is we hired an
external company to give us a bunch of
trainings when it comes to OBSSEAC. So
making sure that communication channels
that people use that also those are very
well protected and just making people
aware of what good OBSC looks like.
Being on a multisc that's very
important. You can tell that as an
industry, we've had some pretty rude
awakenings the past 12 months. The big
exploits are moving away from like DNS
attacks. You get you social engineer
people so that they end up signing
malicious actions in a multisig. Making
sure that even in a complicated setup
like that, you are able to verify every
single hash that you see and make sure
that you do not sign it until you know
100% sure what you're doing.
Sky treats audit findings as process failures. When external auditors catch serious issues, they don't just patch bugs. They investigate why internal reviews failed. Deniz Yilmaz is CTO of Sky Frontier Foundation (formerly MakerDAO), which manages USDS, the third-largest stablecoin globally with years of operation across one of DeFi's oldest protocols. In this clip, Deniz explains how Sky achieves consistent zero-finding audits: engineers apply game theory during development, considering how bad actors (including internal ones) could misuse code. Audits serve as final verification, not development assistance. When audits surface issues, the team investigates what failed in their multi-layer review process. Key practices covered: - Investigating process breakdowns when audits find serious issues - Game theory code review: considering internal actor exploitation scenarios - High-context development preventing unintended cross-protocol interactions - Treating external audits as last stand verification, not QA help Listen to the full episode for Sky's security framework including six-month engineer onboarding requirements, spellcrafting governance with bi-weekly votes, subdao security enforcement, mandatory OPSEC certification for multisig signers, and LLM auditing integration: https://www.youtube.com/watch?v=FY4eY2hee2w