Live data from Hacker News

DeFi protocol BadgerDAO exploited for $120M in front-end attack

theblockcrypto.com

21–30 of 151 posts

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#22
"Decentralized" also means nobody takes accountability, something a lot of our society is built upon, evolved over many generations.

But a mix of snake-oil salesmen and nerds dreaming of utopia try to convince everybody that their approach is somehow magically better.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#23
post #4

It says a lot that these articles are always quantified in dollars.

I guess it's hard to quantify an entire portfolio in their own fluctuating valuations? Would be interesting if they listed a longer list of their actual holdings though, but $usd (and not just any fiat) is still a great proxy for understanding the impact.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#24
post #5

Earlier quoted context omitted.

Stolen ETH goes here to get a shave and a new suit, then it can go wherever it likes https://tornado.cash/

Could someone ELI5 how Tornado Cash achieves (or doesn't achieve) privacy? Their FAQ say: > Is it possible to compromise the protocol and find out information about depositors? -- No, Tornado Cash is a decentralized protocol based on zero knowledge proofs. Its smart contracts are immutable, have no admins, and the proofs are based on strong cryptography. Only the user possessing the Note is able to link deposit and w…

I fail to see the contradiction. All they claim is that the protocol is secure.

It obviously cannot prevent you from revealing your transaction via other means. For example, by publicly announcing it.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#26
post #2

Another day another DeFi project rekt. What happened: > The front end to the BadgerDAO website was reportedly acccessed, according to comments in the project's Discord channel, and used to intercept transactions. One admin said it appears that an API key for Cloudflare was compromised. > One user had around 900 bitcoin ($50.8 million) worth of tokens stolen in a single transaction. Another lost $5 million worth of to…

Regulations in DeFi would do nothing but turning it into traditional, permissioned finance but on blockchain. Nobody wants that.

I think that's the point. Regulations on finance are, in part, to avoid attacks, scams, misunderstandings... Blockchains only offer some security in a part of the transaction, but they do nothing for the "real world" part. If you want serious finance that people can rely on you'll end up looking like traditional, permissioned finance but on blockchain.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#27
post #8

Reading guide: DeFi: Decentralized Finance DOA: decentralized autonomous organization; an organization represented by rules encoded as a computer program that is transparent

> DOA: decentralized autonomous organization;

DAOs are actually DOAs 'Dead on Arrivals' due to fundamental trust issues.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#28

Earlier quoted context omitted.

Nobody forces you to put your money in DeFi protocols.

That's a non-argument. Nobody forces me to buy baby milk. Yet it makes perfect sense for the FDA to regulate what is allowed to be in baby milk.

Baby milk is a disingenuous analogy since it's not expected to be consumed by the buyer.

If consenting adults voluntarily went out of their way to get an unregulated product, without harming anyone but themselves, then why should they be stopped?

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#29
post #20
post #8

Reading guide: DeFi: Decentralized Finance DOA: decentralized autonomous organization; an organization represented by rules encoded as a computer program that is transparent

DAO* not "DOA"

Actually DOA is more fitting :)

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#30
post #5

Earlier quoted context omitted.

Stolen ETH goes here to get a shave and a new suit, then it can go wherever it likes https://tornado.cash/

Could someone ELI5 how Tornado Cash achieves (or doesn't achieve) privacy? Their FAQ say: > Is it possible to compromise the protocol and find out information about depositors? -- No, Tornado Cash is a decentralized protocol based on zero knowledge proofs. Its smart contracts are immutable, have no admins, and the proofs are based on strong cryptography. Only the user possessing the Note is able to link deposit and w…

If you put 123ETH into Tornado from address A and then withdraw 123ETH shortly after from Tornado to address B this will be written to the blockchain.

It might not be evidence that A and B are your addresses, but strong implications.

So, you put it into Tornado and wait days, weeks, or even months, so it could be a random transaction.

Post reply on HN