Live data from Hacker News

Zcoin implementation bug enabled attacker to create over 500K Zcoins

makebitcoingreatagain.wordpress.com

21–30 of 223 posts

Re: Zcoin implementation bug enabled attacker to create over 500K Zcoins

#21
post #17

Earlier quoted context omitted.

Well, same thing goes to paper note forgery.

Except that, for the moment, paper note forgery is illegal but creating "extra" crypto coins doesn't seem to be.

And paper notes have the unfortunate characteristic of being.. paper.. the risk:reward logic is much different if you can pick your own jurisdiction to operate from and hide behind 7 proxies. It's also a very modern business model to avoid big capex expenses like printers and special paper.

Re: Zcoin implementation bug enabled attacker to create over 500K Zcoins

#22

From the blog post explaining the bug, https://zcoin.io/language/en/zcoins-zerocoin-bug-explained-i... , how is that not a "useless statement has no side effect" warning?

It does. It seems like the devs are of the "it compiles, ship it" sort. Building the source, I'm seeing all kinds of warnings -- the code trying to return consts, warnings about sign differences, etc. Looks like lots of potential places for naughtiness to occur.

Re: Zcoin implementation bug enabled attacker to create over 500K Zcoins

#23
post #2

> If the attacker managed to liquidate their Zcoins at an average price of $1.25, they may have netted themselves upto USD 750,000. If you are a skilled programmer / security expert / mathematician, crypto currency exploit creation seems to be an extremely lucrative hobby.

There's even room for marginally technically skilled to rake it in. I think Karpeles is still out on bail. And there's a few that did well with just marketing skill and vaporware mining gear.

Re: Zcoin implementation bug enabled attacker to create over 500K Zcoins

#24
post #4

Im curious. Is this actually illegal? Is there any requirement on how valid crypto currency is created? I understand the network could implement a fix and prevent future transactions or even roll back old ones if there's enough desire, that's what democracies are about right? But was there anything illegal about creating and then trading them? A rollback would hurt the exchanges, but if they didn't already have somet…

I think if you explained this in layman's terms to "a bloke down the pub", he'd consider it theft. The law generally feels the same way. (IANAL.)

Not the same, but it reminded me of years ago, I had £50 deposited in to my account, by mistake, a couple of months running. I asked my girlfriend's dad - who actually was AL (WAL?) - if I could keep it. He said it would be like someone parking their car on my driveway and leaving the keys in the ignition. Inconvenient, yeah, and I don't want it there - but it doesn't make the car mine.

Re: Zcoin implementation bug enabled attacker to create over 500K Zcoins

#25

Earlier quoted context omitted.

This could probably be spun as a violation of the cfaa. IANAL, but the practical interpretation of that seems to be "don't do bad stuff using a computer", kind of like mail fraud but worse.

> This could probably be spun as a violation of the CFAA I'm not sure there's much that couldn't

Your mildly snarky response has been recorded and you will be fined $120,000 for use of a computer for producing such a comment.

Re: Zcoin implementation bug enabled attacker to create over 500K Zcoins

#26
post #17

Earlier quoted context omitted.

Well, same thing goes to paper note forgery.

Except that, for the moment, paper note forgery is illegal but creating "extra" crypto coins doesn't seem to be.

You're never beyond the reach of a civil suit. If you identify yourself with the scheme and you're in the same country where there's adoption, you could be easily targeted.

Plus, the language in 18 U.S.C. § 1030(e)(2) (courtesy of CFAA) refers specifically to "any computer, when [it affects] use by or for [a] financial institution." And later it mentions "...affecting interstate or foreign commerce or communication...". This statute is one that gives so much leeway to prosecutors that it's frequently abused.

Re: Zcoin implementation bug enabled attacker to create over 500K Zcoins

#27
post #17

Earlier quoted context omitted.

Except that, for the moment, paper note forgery is illegal but creating "extra" crypto coins doesn't seem to be.

You're never beyond the reach of a civil suit. If you identify yourself with the scheme and you're in the same country where there's adoption, you could be easily targeted. Plus, the language in 18 U.S.C. § 1030(e)(2) (courtesy of CFAA) refers specifically to "any computer, when [it affects] use by or for [a] financial institution." And later it mentions "...affecting interstate or foreign commerce or communication..…

I would really like to see this happen. Without an EULA, is it even possible?

Perhaps the next generation of cryptocurrencies can have a simple EULA that prohibits exploitation and can be used to firewall off stolen coins.

Re: Zcoin implementation bug enabled attacker to create over 500K Zcoins

#28
post #18

Earlier quoted context omitted.

> used to ensure bugs like this...do not occur Then compensate for that. Create a pool that pays out for each year without vulnerabilities.

If there are vulnerabilities, those vulnerabilities will be exploited. That will reduce the currency value and the value of their 'founders reward'

Not if they cash out during "IPO." I don't like the idea of a founder/developer pool, but if they are going to have one, there should be a vesting period, such that the granted coins cannot be moved for X years after receiving them. This will keep the incentive alive, and I think Ethereum would have a lot more potential if something like this was employed.

Re: Zcoin implementation bug enabled attacker to create over 500K Zcoins

#29
post #27

Earlier quoted context omitted.

You're never beyond the reach of a civil suit. If you identify yourself with the scheme and you're in the same country where there's adoption, you could be easily targeted. Plus, the language in 18 U.S.C. § 1030(e)(2) (courtesy of CFAA) refers specifically to "any computer, when [it affects] use by or for [a] financial institution." And later it mentions "...affecting interstate or foreign commerce or communication..…

I would really like to see this happen. Without an EULA, is it even possible? Perhaps the next generation of cryptocurrencies can have a simple EULA that prohibits exploitation and can be used to firewall off stolen coins.

Uhhh, no. The whole point of cryptocurrencies is that they are permissionless.

Government censorship of coins or transactions is an attack vector, not a feature.

Re: Zcoin implementation bug enabled attacker to create over 500K Zcoins

#30
post #27

Earlier quoted context omitted.

You're never beyond the reach of a civil suit. If you identify yourself with the scheme and you're in the same country where there's adoption, you could be easily targeted. Plus, the language in 18 U.S.C. § 1030(e)(2) (courtesy of CFAA) refers specifically to "any computer, when [it affects] use by or for [a] financial institution." And later it mentions "...affecting interstate or foreign commerce or communication..…

I would really like to see this happen. Without an EULA, is it even possible? Perhaps the next generation of cryptocurrencies can have a simple EULA that prohibits exploitation and can be used to firewall off stolen coins.

An EULA ("End-User License Agreeement") has to do primarily with copyright (17 USC [1]). As such it's pretty much orthogonal to the criminal statutes related to this act of "misusing" cryptocoins.

> next generation of cryptocurrencies can have a simple EULA

This is anathema to the nature of cryptocurrencies, all (?pretty sure all that matter anyways) of which have Open Source implementations.

Really, most cryptocoins which are worth anything have already had a big market cap "bounty" that has effectively proven their safety.

We don't need a EULA. Like I said, you could maaaybe sue for damages. Unfortunately there's no easy way to undo the impact to a coin's reputation once it's shown to have a weakness like this. Even once the bug's patched and the nodes all get back on board, exchange rates will suffer for a long time.

[1] https://en.wikipedia.org/wiki/Title_17_of_the_United_States_...

Post reply on HN