Live data from Hacker News

SafeDollar ‘stablecoin’ drops to $0 following DeFi exploit on Polygon

cryptoslate.com

151–160 of 577 posts

Re: SafeDollar ‘stablecoin’ drops to $0 following DeFi exploit on Polygon

#151
post #31

A point that most crypto heads miss is that the world does not run algorithmically. Legal contracts do not work like a software program and that characteristic is a feature not a bug. Not being able to reverse transactions that were part of an exploit is in infact a bug. Businesses need that tolerance for error. You need an oracle in your system. The oracle can maintain transparency of the attestations carried out if…

I'm gonna be honest I don't know what the audience is for a product where you risk losing your entire life savings because you typed a wrong word in a smart contract rather than paying a middleman a fraction of a percent. It's almost like a sort of willful ignorance of division of labour and the concept of pooling risk.

> rather than paying a middleman a fraction of a percent.

Having a middle man doesn’t ensure safety. It just means that you have someone to blame if it all goes wrong. And even if you blame them, they most likely won’t see any negative repercussions anyway.

Re: SafeDollar ‘stablecoin’ drops to $0 following DeFi exploit on Polygon

#152
post #12

So what type of exploit is this? Is this a problem with smart contracts? Could this be a problem for other cryptocurrencies with smart contracts, like Ethereum?

This is most likely a problem with this specific smart contract, from what I understand, if the EVM on the "winning" miner were to produce a state transition that did not faithfully follow the SC, that block should be rejected.

Polygon is a little different, due to its proof of stake system, where there is no "winner" and the validators (Heimdall instances) "check" the work of the actual block producers (Bor instances). It also has a slasher-like element where only one Heimdall instance needs to prove that a block is incorrectly executed for it to be rejected, so a malicious actor would need to compromise all active Heimdall instances to be able to lie.

Re: SafeDollar ‘stablecoin’ drops to $0 following DeFi exploit on Polygon

#153
post #93
post #46

Earlier quoted context omitted.

Oil is physical; it takes up space, and needs special protections to not pollute the container it's stored in. Digital goods, meanwhile, can just be transferred permanently "into the void" (i.e. to an account without an associated key.)

This implies there isn’t any contract obligations/fine print at the point of link to real world / real identity (exchange). In a hypothetical world, if coinbase made you sign things at signup and later demanded money for the upkeep of the network caused by your own transactions, I don’t think you can say no to that easily. Compare this to an HOA demanding a $100k payment from each condo owner in the Miami condo repai…

You can absolutely walk away and abandon your condo in that case.

Re: SafeDollar ‘stablecoin’ drops to $0 following DeFi exploit on Polygon

#154
post #80

Earlier quoted context omitted.

> that the world does not run algorithmically Sure it does: moving gold and commodities between countries in non-mutually-friendly regimes, very much resembles crypto. Fiat finance is a system of contract law built on top of a de-facto "state of nature" of irreversible no-arbitrator commodity transfers. It exists in places where people can agree on who the arbitrating party should be. It does not exist outside of tho…

So... sending money to where your own government forbids you to send it? It sounds like you're admitting that the point of cryptocurrency is simply to break the law, while pretending like the purpose is much bigger.

There is more than one "law." Each fiat ecosystem is its own system of financial law, each mutually-incompatible with any other fiat ecosystem. Cryptocurrency gives an alternative arbitrator that allows for these mutually-incompatible systems of law to be bridged.

Also, to be clear, in the example I mentioned, the government of the US does not forbid trading with Nigeria/Liberia/etc. Traditional money-transfer services (Paypal, Western Union, most savings banks, etc.) are just unwilling to do it, because of the frequency of those transactions being scams. But this prevents people who "know what they're doing" (like people employing people in those countries!) from having any means to send money there.

This is a gap in the market, in some sense, but it's one that couldn't really be filled by any other fiat "retail" solution, as that solution would then be what scammers use to bilk people. So you really need something that's "complex and finance-nerdy" in the way that crypto is, to ensure that it's hard enough for regular people to use it to transfer money, that scammers just don't bother to try talking people through it. (Such a product would then never find product-market fit, as it would have no retail customers. Only a system run "for its own sake", like cryptocurrency systems are, can really be a good base platform to enable such transfers over the long term.)

Re: SafeDollar ‘stablecoin’ drops to $0 following DeFi exploit on Polygon

#155
post #93
post #46

Earlier quoted context omitted.

Oil is physical; it takes up space, and needs special protections to not pollute the container it's stored in. Digital goods, meanwhile, can just be transferred permanently "into the void" (i.e. to an account without an associated key.)

This implies there isn’t any contract obligations/fine print at the point of link to real world / real identity (exchange). In a hypothetical world, if coinbase made you sign things at signup and later demanded money for the upkeep of the network caused by your own transactions, I don’t think you can say no to that easily. Compare this to an HOA demanding a $100k payment from each condo owner in the Miami condo repai…

> Now let us assume that condo is worth less than $100k. I don’t think you can just walk away and abandon your condo.

You can if you go bankrupt. It's not like condo ownership is non-dischargeable in the same sense that, say, Superfund site ownership is.

Re: SafeDollar ‘stablecoin’ drops to $0 following DeFi exploit on Polygon

#156

Earlier quoted context omitted.

It literally does not. The world runs advised by algorithms, but not governed by them. It's a fundamental difference. When algorithms in the real world create lose-lose outcomes, people override them, which is why when your credit card gets stolen you don't end up paying for stuff. You can bake that logic into a software contract, but if the design of your system is that the totality of software contracts are the fin…

> When algorithms in the real world create lose-lose outcomes, people override them, which is why when your credit card gets stolen you don't end up paying for stuff. An exploit where I take all your bitcoins isn't a lose-lose outcome, and neither is that. If I steal your credit card and you have to pay for my stuff, you're the only party who loses.

If you steal my credit card and buy things with it, I will call my bank and I won't need to pay for it when I settle my statement balance at the end of the month. The bank will follow up with the merchant and/or law enforcement and, in most cases, the bank will get its money back somehow. In the cases where it doesn't, I'm sure the bank is insured against losses. Banks and insurance companies probably have a complicated model for estimating $X/yr in theft.

If someone steals my wallet's private key (= stealing my credit card), I'm done. There is no recourse AFAIK.

Re: SafeDollar ‘stablecoin’ drops to $0 following DeFi exploit on Polygon

#157
post #154

Earlier quoted context omitted.

So... sending money to where your own government forbids you to send it? It sounds like you're admitting that the point of cryptocurrency is simply to break the law, while pretending like the purpose is much bigger.

There is more than one "law." Each fiat ecosystem is its own system of financial law, each mutually-incompatible with any other fiat ecosystem. Cryptocurrency gives an alternative arbitrator that allows for these mutually-incompatible systems of law to be bridged. Also, to be clear, in the example I mentioned, the government of the US does not forbid trading with Nigeria/Liberia/etc. Traditional money-transfer servic…

Wait, so BitCoin's benefit now is that it's too hard to use? lol

edit: And that's why it can't be used for scams! Oh my. I'm not sure what universe you live in, but it's different from mine.

Re: SafeDollar ‘stablecoin’ drops to $0 following DeFi exploit on Polygon

#158

Earlier quoted context omitted.

Agreed. I'd like to figure out how to build a cryptocurrency that is useful for conducting actual business but toxic to investors. An economy that lacked parasitic middle men would be a good thing for the status quo to have to compete with.

Every day the largest wallet is confiscated, divided into ten equal portions, and each piece is randomly awarded, lottery-style, with every transaction from the previous day serving as a lottery ticket.

I dunno, it's not about wealth concentration, be rich, that's fine. It's about whether your wealth was gathered by contributing useful work, or by parasitizing it.

I imagine a proof of work system where there's a community work queue, and "mining" is completing tasks in the queue, borderlands-style (though hopefully without the violence). The mined tokens can be resolved to nft's which stay attached to the wallet of the user who requested that the work be done.

There's also a web of trust and a UBI component (Circles-UBI style) to disinventivise sybil accounts.

If the work-originator deems the work unsatisfactory, they can invalidate the tokens that were mined from its "completion" and recoup a fraction of what they paid to have it done.

So doing business with somebody who has a reputation of doing shoddy work, or of failing to respect good work, is risky because your tokens might evaporate.

An would-be investor in this token would have to decide whose tokens to buy, which requires much more research.

You could also have some system to disinventivise hoarding, like a token half-life.

Or you know, something like that.

Re: SafeDollar ‘stablecoin’ drops to $0 following DeFi exploit on Polygon

#159
post #69

Is there a website along the lines of istheshipstillstuck.com or arewewebyet.org but for "Is that coin / smart-contract dead already" ? Would be an useful reference in this ever-changing landscape, though I would pity the maintainers.

https://rekt.news/leaderboard/

Is there one for all the scam ICOs from 2017/2018? I'm ashamed to admit I fell for one called KYC and one called Crc, which was supposedly supported by Crytek or something. It was just a hundred bucks, but I've always wondered what happened to that one given that it had a well known brand tacked on.

Re: SafeDollar ‘stablecoin’ drops to $0 following DeFi exploit on Polygon

#160
post #98

These incidents really illustrate the main flaw of smart contracts: a single bug in your code can lead to incredible losses. I simply don't think it's possible for human beings to write good enough software for smart contracts.

> I simply don't think it's possible for human beings to write good enough software for smart contracts. I agree, but think it's fixable. I believe we have missed a natural platform in between binary notation and computer languages. I believe there is a 2-D dimensional binary. Simply using a grid (with an array of cells forming a line, and lines stacked on top of each other—a spreadsheet basically), we can drop *all*…

> I believe there is a 2-D dimensional binary. Simply using a grid (with an array of cells forming a line, and lines stacked on top of each other—a spreadsheet basically), we can drop all syntax characters. The only thing you have is your cells and your semantic words.

I fail to see how this helps.

The reason why bugs crop up all the time in software isn't because syntax is confusing. It's also not because semantics is confusing--plenty of bugs have perfectly clear, well-understood bugs. The problem is that we as programmers don't think about how our software could fail. We don't ask ourselves "could this multiplication overflow?" frequently enough. We don't look at code and ask "who made sure this pointer points to valid data?" We believe that there's no way the price of an affiliated token could ever reach exactly $0, so we assert that it can't happen.

The way you avoid these bugs is to just simply make it impossible for the system to get into certain states. It's already the case with statically-typed languages that it's impossible to pass a string to a function that expected an int. If you design your API right, you can make it impossible to get an index into an array that is out-of-range (although this is way too rarely done). But, even then, you will still find people who will confidently use the escape hatch to say "this string is clearly UTF-8, I know it is from outside experience, so don't bother checking."

Post reply on HN