Live data from Hacker News

The bug which lost more than $600M in various cryptocurrencies a few hours ago

twitter.com

41–50 of 126 posts

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#41
post #23

There's a serious fundamental problem with DeFi that can't be solved with blockchains. Someone starts a blockchain company and hires a bunch of devs who make, idk, $40 to $100 per hour to build the thing. Maybe more, it doesn't really matter. Even just one dev or a few devs can make all the contracts needed for this. One day that dev notices a vulnerability in the smart contract he's writing! He has two choices: (a)…

Now say you're a company hired to do an audit. Same incentives.

The hilarious thing is nearly all of these high profile hacks happen even after being audited.

There was one company I remember being called out as a suspect, but I can't find the name.

Also given (a) anonymity (b) ability to take cover amid so many other hacks, you could do this for a few years, slow down, and remain a top tier firm claiming the lowest hack rate.

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#42
post #38
post #27

Earlier quoted context omitted.

A lot of these contracts, and especially those owned by first-tier cryptocurrency companies, are reviewed by 3rd party auditors. Of course that doesn't completely remove the risk, but certainly at least ensures that no obvious bugs are missed.

Do you have some sources for this claim? Or just a belief?

High quality protocols like PoolTogether for example have this: https://docs.pooltogether.com/security/audits-and-testing

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#43
post #36
post #14

Cryptocurrencies are fascinating but the irreversibility is not a feature but a bug. I don't get the appeal for irreversibility. A legitimate trade always occurs between willing partners, why would you be so afraid that the transaction would be cancelled? The only legitimate use that comes to my mind are complex financial instruments where things mostly happens with an assumption that the underlaying assets are very…

The appeal for irreversibility is the complete removal of counterparty risk. It's a sharp edge and you need to be structured/careful, but for certain types of transactions, the cost of being careful is 100x cheaper than the cost of finding and using a trustworthy counterparty. A strong example of where the irreversibility of crypto is very useful is in the online sale of expensive electronic goods. Especially for thi…

> in the case of online sales, the merchant is the known quantity with a reputation

This is absolutely not true. There’s plenty of risk buying expensive goods online, lots of problematic merchants. I don’t understand why merchants are inherently more trustworthy than customers?

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#44
post #27
post #23

There's a serious fundamental problem with DeFi that can't be solved with blockchains. Someone starts a blockchain company and hires a bunch of devs who make, idk, $40 to $100 per hour to build the thing. Maybe more, it doesn't really matter. Even just one dev or a few devs can make all the contracts needed for this. One day that dev notices a vulnerability in the smart contract he's writing! He has two choices: (a)…

A lot of these contracts, and especially those owned by first-tier cryptocurrency companies, are reviewed by 3rd party auditors. Of course that doesn't completely remove the risk, but certainly at least ensures that no obvious bugs are missed.

Auditors have never fully prevented bugs in any other computing domain, i dont know why cryptocurrency would be any different.

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#45
post #27

Earlier quoted context omitted.

A lot of these contracts, and especially those owned by first-tier cryptocurrency companies, are reviewed by 3rd party auditors. Of course that doesn't completely remove the risk, but certainly at least ensures that no obvious bugs are missed.

It’s very hard to take this claim seriously in this thread, which details a huge (and somewhat obvious) security vulnerability in a currency worth at least $600m (an amount anyone would assume is “first-tier”).

Yeah I can understand that. Once you dive into crypto however, you quickly realize that $600m is just not that much money (especially not if we are talking about digital assets valued at current ticker price). And that lots of money isn't necessarily the right measure of quality of the project.

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#46
post #23

There's a serious fundamental problem with DeFi that can't be solved with blockchains. Someone starts a blockchain company and hires a bunch of devs who make, idk, $40 to $100 per hour to build the thing. Maybe more, it doesn't really matter. Even just one dev or a few devs can make all the contracts needed for this. One day that dev notices a vulnerability in the smart contract he's writing! He has two choices: (a)…

but is it that simple though? Even in enterprise company we have to do 2-3 review on PR before merging.

I think proper DeFi company should have their own system on deploying contracts. Further, they should have their own security team that audit everything.

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#47
post #23

There's a serious fundamental problem with DeFi that can't be solved with blockchains. Someone starts a blockchain company and hires a bunch of devs who make, idk, $40 to $100 per hour to build the thing. Maybe more, it doesn't really matter. Even just one dev or a few devs can make all the contracts needed for this. One day that dev notices a vulnerability in the smart contract he's writing! He has two choices: (a)…

That's what you hire auditors for.

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#48
post #38

Earlier quoted context omitted.

Do you have some sources for this claim? Or just a belief?

High quality protocols like PoolTogether for example have this: https://docs.pooltogether.com/security/audits-and-testing

Most people have never heard of PoolTogether, so I’m not sure if your definition of “first tier” and “high quality” is objective.

Regardless, this quote from your link stands out: “it should never be expected that 100% of the deployed code has been formally audited.”

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#49
post #36
post #14

Cryptocurrencies are fascinating but the irreversibility is not a feature but a bug. I don't get the appeal for irreversibility. A legitimate trade always occurs between willing partners, why would you be so afraid that the transaction would be cancelled? The only legitimate use that comes to my mind are complex financial instruments where things mostly happens with an assumption that the underlaying assets are very…

The appeal for irreversibility is the complete removal of counterparty risk. It's a sharp edge and you need to be structured/careful, but for certain types of transactions, the cost of being careful is 100x cheaper than the cost of finding and using a trustworthy counterparty. A strong example of where the irreversibility of crypto is very useful is in the online sale of expensive electronic goods. Especially for thi…

This just moves the risk from the vendor to the consumer.

I assume that most chargebacks happen for purchases made with stolen credit cards. So the chargeback just returns the money to the rightful owner.

If the consumer used bitcoin, and someone stole their credentials to buy something, then they would have no way to get their money back.

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#50
post #43
post #36

Earlier quoted context omitted.

The appeal for irreversibility is the complete removal of counterparty risk. It's a sharp edge and you need to be structured/careful, but for certain types of transactions, the cost of being careful is 100x cheaper than the cost of finding and using a trustworthy counterparty. A strong example of where the irreversibility of crypto is very useful is in the online sale of expensive electronic goods. Especially for thi…

> in the case of online sales, the merchant is the known quantity with a reputation This is absolutely not true. There’s plenty of risk buying expensive goods online, lots of problematic merchants. I don’t understand why merchants are inherently more trustworthy than customers?

It's not that merchants are inherently more trustworthy, it's that the buyer has ample opportunity to research the merchant and establish credibility. If there's a merchant that only accepts crypto and the buyer can't get comfortable that the merchant is trustworthy, the buyer can walk away instead of making a purchase.

The merchant has much less to go on. There aren't review websites detailing the reputation and history of every random buyer that enters a credit card onto your website.

Post reply on HN