logo

Runtime Environment and Smart Contract Security Modeling

ID: 603460c0-19ac-5ecf-a14c-6714c846c4f6

STIX ID: report--603460c0-19ac-5ecf-a14c-6714c846c4f6

Feed Name: CertiK Blog

Threat Score
55/100

Date Published: 2023-02-27

Date Updated: 2026-06-11

...
...

This blog post compares EVM and NEAR runtime models and demonstrates how asynchronous calls and storage staking on NEAR change smart-contract security. It describes reentrancy variants under NEAR's asynchronous callbacks, explains the Million Small Deposits denial-of-service risk, and introduces an "insolvency attack" where incorrect storage-fee accounting lets an attacker drain funds (notably impacting liquid staking contracts and bridges). The post outlines example flows and mitigation directions (e.g., mutexes, correct storage accounting, NEP-145).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.