Live data from Hacker News

Missing line in a smart contract leads to $10M hack

rekt.news

201–210 of 333 posts

Re: Missing line in a smart contract leads to $10M hack

#201
post #55

Many people are asking what happened, because the article does not go much into detail. The code is there (linked in the article): https://bscscan.com/address/0x7a8ac384d3a9086afcc13eb58e9091... After spending 2min on it and using this hint from the article: > The affected pool contract had an initialize() function that should have been activated after deployment. > The line: initialized = true; is missing from the f…

so where does one draw the line between theft and just doing what the code allows? I wonder in the future crypto courts is the defense, "your honor, the code allowed me to call initialize again, they specifically didn't set it to true." going to fly? Or will you have to prove that the 10 mil you now have was intended to be given to you and your "victim" isn't a victim at all.

I think that's the wrong question. If a court can decide (and enforce) what a smart contract "really means", then smart contracts don't really bring much to the table. It doesn't matter what the court would actually decide.

The main thing smart contracts bring to the table is a mechanism of enforcing contracts without government involvement or control. The contract gets enforced, period. The parties can be anonymous, it doesn't matter which country they're from, and so on.

Re: Missing line in a smart contract leads to $10M hack

#202
post #179

Earlier quoted context omitted.

> Of course, this only works when the smart contracts perfectly meet a correctly defined spec and have no bugs. In practice, if using a smart contract as a contract , the way you'd use a paper contract, then two parties would sit down and negotiate; draft the negotiated agreement into the form of a smart contract; and then agree (signatures, handshake, multi-sig deployment, whatever) that "what the smart contract doe…

Signing a paper contract doesn't mean you're bound to any bad thing that happens because of it for life. If a smart contract is so strict that eg it can be against public policy then it's not a real contract.

Note that in my above statement, the "network-consensus abstract machine" is the same kind of thing as "a judge": namely, both an arbitrator, and an official that declares certain clauses objectively void even if both parties like them.

See also: the DAO hard-fork that created Ethereum Classic.

Re: Missing line in a smart contract leads to $10M hack

#203
post #201

Earlier quoted context omitted.

so where does one draw the line between theft and just doing what the code allows? I wonder in the future crypto courts is the defense, "your honor, the code allowed me to call initialize again, they specifically didn't set it to true." going to fly? Or will you have to prove that the 10 mil you now have was intended to be given to you and your "victim" isn't a victim at all.

I think that's the wrong question. If a court can decide (and enforce) what a smart contract "really means", then smart contracts don't really bring much to the table. It doesn't matter what the court would actually decide. The main thing smart contracts bring to the table is a mechanism of enforcing contracts without government involvement or control. The contract gets enforced, period. The parties can be anonymous,…

If a court can decide/enforce what a smart contract "really means", then the smart contract still decides who has possession of the related assets before the courts get involved. That's for ill or for good. Anyone who wants to get the courts involved has to care enough about changing the status quo to pay for a lawsuit. Changing what the status quo is, before the lawsuit, changes the balance of power.

Re: Missing line in a smart contract leads to $10M hack

#204

Earlier quoted context omitted.

I share the general skepticism, but I am open to the idea that (much like other electronic commerce), the smart contracts might make 99% of transactions much more efficient; so the expensive manual interventions are only used on a small proportion. Of course, it is not necessarily obvious that blockchain-powered smart contracts are the only way — or the best way — to achieve that automation and efficiency!

> the smart contracts might make 99% of transactions much more efficient The entire point of proof-of-work is that it is inefficient, by design. Efficiency is counteracted: Advances in technology that lead to more efficient mining techniques directly mean the difficulty for the next block being adjusted up . Operating on traditional databases (where automation is regularly implemented, too) is orders of magnitude mor…

PoW wasn't designed to be more efficient, the Nakamoto consensus type implementation exists to improve honesty and security. There is no traditional database that's as secure as a blockchain, it's always a tradeoff between security/immutability and efficiency. But since efficiency does matter many 2nd generation chains have moved away from PoW.

Re: Missing line in a smart contract leads to $10M hack

#205
post #104

Earlier quoted context omitted.

I know this won't change your mind, but the reason you are seeing new terms is, because you're seeing the birth of new protocols. Pictures yourself in the early days of the internet and you want to learn about http and/or javascript (for example) - you would be overwhelmed with new terminology to concepts that didn't exist before like gui based web browsing. Crypto/Defi are this in many ways. Does that make it not a…

The Internet was something new that provided new capabilities and new abilities to humanity with extremely high reliability, and at a scale that didn't exist prior to that. Cryptocurrency doesn't provide any new capabilities at all. Money and trading existed before. Price fluctuations existed before. Markets existed before. Buying and selling existed before. But now, because it's so new, and because it's not technica…

"Cryptocurrency doesn't provide any new capabilities at all."

The new capability that cryptocurrency provides is that money is now "programmable" it's a fusion between money and software.

Wether or not this is a benefit, is subjective, but IMO it's a humble beginning with epic potential.

Re: Missing line in a smart contract leads to $10M hack

#206
post #4
post #2

I wonder when people will realize that the complexity inherent in human financial transactions will not go away just because you write code instead of natural language and 'decentralized finance' will reinvent everything it tried to get rid off (but shoddily) because nobody likes to lose their live savings because they missed a semicolon.

I think you have point. And, a key advantage I can imagine is that "checklists" could be implemented into code over time and that is potentially superior to natural language. I am not a crypto expert though.

Except checklists often ... just get checked.

c.f. people checking t&c's becuase they can't be bothered to read them (/sympathetic).

Re: Missing line in a smart contract leads to $10M hack

#207
post #63

After reading a bit, not knowing WTH is being talked about, I did some searching. Because the author(s) of this article forgot what makes hypertext so powerful. (In fact, I think a lot of people have forgotten that. Don't be afraid to link things, people. Linking to something literally saves you the trouble of explaining it yourself. LINK MORE, PLEASE. I will click.) So this is apparently about some stock market for…

> prices are easily swayed by a few famous individuals or sometimes a lot of unknown people, en masse, and you can earn and lose real money by trading the stuff Totally, this Gamestop stock market stuff is crazy. Oh, you were talking about cryptocurrencies?

Honestly, it sounds like the same people buying both to me.

Re: Missing line in a smart contract leads to $10M hack

#208
post #125

Earlier quoted context omitted.

so where does one draw the line between theft and just doing what the code allows? I wonder in the future crypto courts is the defense, "your honor, the code allowed me to call initialize again, they specifically didn't set it to true." going to fly? Or will you have to prove that the 10 mil you now have was intended to be given to you and your "victim" isn't a victim at all.

The legal system isn't a computer that implements the law strictly to the letter based on only factual information. There are "reasonable person" standards, allowance/tolerance for mistakes, etc. Relevant to this discussion is rules covering mistaken deposits to a bank account: recipients are obliged to return the assets, not shrug their shoulders and use the cash while they proclaim "Bank's fault; they're responsibl…

Nobody can predict the future of how business will get done years down the road, but I think Smart Contracts can potentially utilize both Oracles (systems like Chainlink) to provide objective data about the world for triggering Smart Contract logic, and Arbitration systems (something along the lines of Kleros) for humans to make subjective judgements about human concepts like "reasonableness" in contracts.

A very contrived example. Say a Smart Contract exists for a contractor to paint a boat cornflower blue and then get paid when the job is done, but the Oracle system says that the contractor messed up and painted it sky blue. It can be part of the Smart Contract in the event of some error that it can go to arbitration to some pre-agreed-to subject matter experts that both sides agreed to beforehand for a quick and reasonable resolution or fee.

This kind of thing can be planned for and made standard in smart contracts. It'll only happen if it saves businesses more time and money than it costs though, and many other question marks will be involved. I think it's very exciting conceptually though.

Re: Missing line in a smart contract leads to $10M hack

#209

Earlier quoted context omitted.

But also, surely the traditional legal system will still handle disputes over smart contracts just like it does with traditional contracts. I can’t imagine that a missing line of code (intentional or not) would be treated any differently by the legal system than a vaguely-worded clause in a traditional contract. The legal system almost certainly will not say “your contract was just code and the code executed properly…

Then what's the point of smart contracts? If you always must have some form of repudiation/reversal mechanism, you might as well go with the traditional contracts. You could argue there will be lowered costs in the happy path where nothing goes wrong, but I'm not sure that's valid since the underlying software still needs to written/supported by someone.

Smart contracts can automatically execute code that makes transactions happen. With a traditional contract you need a third party to do that (or you have to trust the other person).

This allows for a lot more efficiency as people who've never met can make trades on an open market without having to involve anyone else.

Re: Missing line in a smart contract leads to $10M hack

#210

Earlier quoted context omitted.

There is place for both systems. Most crypto people have made peace with the fact that they can lose it all. People overestimate conventional finance. Conventional finance is incredibly flimsy if you dig into it. Leveraged beyond repair, ductaping one unprecedented monetary experiment after another. No conventional currency has preserved substantial purchasing power over a span of say 100 years maximum. The mathemati…

conventional finance has ways of insuring money and getting back stolen funds. it also is more idiot proof. nothing like that exists with cryto. crypto way less forgiving of errors..

Because crypto is the first layer. It's like dealing with paper money and trades while living >200 years ago. Eventually "Trusted Institutions" will come along with insurance to keep your crypto safe for those with less risk tolerance.

The advantage then is that you get to choose how much control you want to give up for safety. Unlike the current system where you have to use these institutions to participate.

Post reply on HN