Live data from Hacker News

The bug which lost more than $600M in various cryptocurrencies a few hours ago

twitter.com

71–80 of 126 posts

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#71
post #23

There's a serious fundamental problem with DeFi that can't be solved with blockchains. Someone starts a blockchain company and hires a bunch of devs who make, idk, $40 to $100 per hour to build the thing. Maybe more, it doesn't really matter. Even just one dev or a few devs can make all the contracts needed for this. One day that dev notices a vulnerability in the smart contract he's writing! He has two choices: (a)…

> Actually, it's worse than that, because unlike normal banks, the code used by these digital banks is open source, and anyone in the world can go bug hunting.

An argument that open source is less secure, and on Hacker News! Now I've seen it all.

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#72
post #55
post #49

Earlier quoted context omitted.

This just moves the risk from the vendor to the consumer. I assume that most chargebacks happen for purchases made with stolen credit cards. So the chargeback just returns the money to the rightful owner. If the consumer used bitcoin, and someone stole their credentials to buy something, then they would have no way to get their money back.

The chargeback returning the money to the rightful owner doesn't help the merchant who shipped $6,000 of hardware to some stranger. Certain types of electronic sales simply can't be done online because of the high rates of fraud. When you add crypto, these sales become possible. Yes, they become possible at the cost of putting the counterparty risk onto the consumer, but that's better than the sale being entirely non…

I don’t understand your line of reasoning at all. Like the others have said, moving risk from sellers to customers is not a solution.

Especially when the risk of customers committing fraud is incredibly low. Why would you start with an assumption that this is something so rampant it needs to be solved in a way that harms literally all honest customers?

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#73
post #48

Earlier quoted context omitted.

Most people have never heard of PoolTogether, so I’m not sure if your definition of “first tier” and “high quality” is objective. Regardless, this quote from your link stands out: “it should never be expected that 100% of the deployed code has been formally audited.”

It has $175 M locked in the protocol, it is also featured on https://ethereum.org/en/dapps/ , and is one of the oldest DeFI projects. By my definition, it is both "first tier" and "high quality". We can of course have the philosophical debate of objectivity and if such thing even exists, not sure if it's needed here though. The audits of this protocol is also continuous.

175M$ is like 1/4th of the hack that this thread is discussing.

Also, they specifically state that not everything is audited? Nowhere do they mention continuous audits.

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#74
post #19

I'm having a great laugh every time I hear about crypto-stuff goofs. Who thought an amazing new P2P invention would improve the image of normal money and traditional banks?

Rome was not built in a day. Examples of 2008, GME fiasco, and many other display a clear and obvious need for decentralized finance.

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#75
post #55
post #49

Earlier quoted context omitted.

This just moves the risk from the vendor to the consumer. I assume that most chargebacks happen for purchases made with stolen credit cards. So the chargeback just returns the money to the rightful owner. If the consumer used bitcoin, and someone stole their credentials to buy something, then they would have no way to get their money back.

The chargeback returning the money to the rightful owner doesn't help the merchant who shipped $6,000 of hardware to some stranger. Certain types of electronic sales simply can't be done online because of the high rates of fraud. When you add crypto, these sales become possible. Yes, they become possible at the cost of putting the counterparty risk onto the consumer, but that's better than the sale being entirely non…

Fraud is a cost of business. Prices can be raised to take it into account; different markets have different rates of fraud, but fundamentally it can be priced in.

Merchants are in a much better position to price this in than consumers. Merchants structurally execute a lot more transactions within a market vertical than consumers ever do.

If the merchant can't do that, because deals are simply too high value or aren't frequent enough, then insurance companies or intermediaries (e.g. payment processors) can pool risk across merchants, using actuarial techniques to assign a price to the insurance. For example, professional indemnity insurance for property transactions.

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#76
post #23

There's a serious fundamental problem with DeFi that can't be solved with blockchains. Someone starts a blockchain company and hires a bunch of devs who make, idk, $40 to $100 per hour to build the thing. Maybe more, it doesn't really matter. Even just one dev or a few devs can make all the contracts needed for this. One day that dev notices a vulnerability in the smart contract he's writing! He has two choices: (a)…

I wonder if there's some way to make a "thief monkey". Some program that searches your code for vulnerability patterns and rips you off if it can. (Obvs, a tame monkey will then give you the money back).

Humans might be motivated to sit on a bug until they can reach the cybercafe. Bots, not so much.

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#77
post #70
post #27

Earlier quoted context omitted.

A lot of these contracts, and especially those owned by first-tier cryptocurrency companies, are reviewed by 3rd party auditors. Of course that doesn't completely remove the risk, but certainly at least ensures that no obvious bugs are missed.

As this space evolves, I think there will be insurance and basic best practice safety measures. Also considering that almost all blockchains are open by design, it's no trivial task to liquidate a large sum of stolen tokens. So its not exactly a straight path from writing a script at Starbucks to making hundreds of millions of dollars.

I agree. There are already some insurance protocols in place - see Cover Protocol or Unslashed Finance. Its still very early in this space, but things are definitely developing!

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#78
post #14

Cryptocurrencies are fascinating but the irreversibility is not a feature but a bug. I don't get the appeal for irreversibility. A legitimate trade always occurs between willing partners, why would you be so afraid that the transaction would be cancelled? The only legitimate use that comes to my mind are complex financial instruments where things mostly happens with an assumption that the underlaying assets are very…

Irreversibility is one of its best features. Imagine a scenario in 50 years when 80% of token holders are dead... This could result in a non-trivial % of tokens being lost forever; this greatly reduces the remaining circulating supply of tokens and thus makes everyone else who still remembers their keys wealthier (less supply, same demand translates to higher price).

On the other hand, stocks are more susceptible to demographic collapse; for example, if a lot of shareholders die and all their relatives inherit their stocks, you can expect a selloff to occur which could crash the stock price. With stocks, shares are never lost forever; they just get passed down to an increasing number of increasingly lazy and incompetent heirs. That's not to say that cryptocurrencies cannot be passed down (they can) but the fact that they are tied to a secret passphrase (instead of the legal system) makes it more likely that they can get lost. The negative economic effects of wealth inheritance are not as strong in crypto space.

The idea that negligent people may lose their tokens is highly meritocratic as it transfers wealth from negligent people to careful people.

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#79
post #73

Earlier quoted context omitted.

It has $175 M locked in the protocol, it is also featured on https://ethereum.org/en/dapps/ , and is one of the oldest DeFI projects. By my definition, it is both "first tier" and "high quality". We can of course have the philosophical debate of objectivity and if such thing even exists, not sure if it's needed here though. The audits of this protocol is also continuous.

175M$ is like 1/4th of the hack that this thread is discussing. Also, they specifically state that not everything is audited? Nowhere do they mention continuous audits.

You are right, it's not mentioned, but they do in fact spend hundreds of thousands every few months for audits. You'll find more info here: https://gov.pooltogether.com/

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#80
> So someone realized that they could send an cross-chain message directly to the EthCrossChainData contract.

> By sending this cross-chain message, the user could trick the EthCrossChainManager into calling the EthCrossChainData contract, passing the onlyOwner check. Now the user just had to craft the right data to be able to trigger the function that changes the public keys.

Could this bug have been avoided by extra safety features in the language used to write the contracts like a better type system? Or the code wasn't using all the language features it could? I found the cause of the bug hard to understand to be honest.

Post reply on HN