EPISODE · Feb 4, 2026 · 1H 5M
Sky's zero-finding audit framework: Six-month onboarding and process investigation | Deniz Yilmaz
from The Web3 Security Podcast · host TheWeb3SecurityPodcast
When Sky's audits return serious issues, they don't just fix bugs and ship—they pull the brake and investigate what failed in their internal review process. Deniz Yilmaz, CTO of Sky Frontier Foundation, walks through the defensive layers behind USDS (third-largest stablecoin globally): six-month engineer onboarding requirements, spellcrafting governance with mandatory execution delays, and a protocol security team dedicated to codifying the implicit knowledge that keeps audit reports clean.Topics discussed:Treating audit findings as internal process failures requiring investigation, not just bug fixesSix-month mandatory onboarding periods before engineers can modify spellcrafting codePre-audit internal review standards achieving consistent zero-finding results across multiple audit firmsSpellcrafting governance requiring bi-weekly token holder votes and execution delays for all protocol changesLLM auditing integration delivering PR-level feedback before code reaches internal reviewMandatory OPSEC certification with domain hash verification testing for multisig signersProtocol security workstreams codifying senior engineer practices into transferable frameworksAuditor selection prioritizing codebase-specific experience over firm reputationSubdao security enforcement maintaining core standards across autonomous entities with independent economicsGame theory-based development considering internal actor exploitation during code design
Embed this episode
Ready to play
Sky's zero-finding audit framework: Six-month onboarding and process investigation | Deniz Yilmaz
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.