Once again cryptocurrency shills are disproven in their core belief that they can do finance better than status quo.
DeFi protocol BadgerDAO exploited for $120M in front-end attack
81–90 of 151 posts
Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack
#82Reminder that every DAO is a self-administering bug bounty for all of the value under its control. Reminder also that you don't have to "hack etherum"; there are plenty of spots more vulnerable than the blockchain itself at which value can be stolen. (I would however be interested to know where all this stolen value ends up, and how well it can ultimately be laundered into the real world, or if this is more like driv…
Stolen ETH goes here to get a shave and a new suit, then it can go wherever it likes https://tornado.cash/
Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack
#83It says a lot that these articles are always quantified in dollars.
For instance, the Quebec Maple Syrup Heist is reported as both "3,000 tons of maple syrup" because, wow, that's a shit ton of maple syrup AND that the value of the heist was an "estimated $18.7 million".
Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack
#84Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack
#85Earlier quoted context omitted.
Could someone ELI5 how Tornado Cash achieves (or doesn't achieve) privacy? Their FAQ say: > Is it possible to compromise the protocol and find out information about depositors? -- No, Tornado Cash is a decentralized protocol based on zero knowledge proofs. Its smart contracts are immutable, have no admins, and the proofs are based on strong cryptography. Only the user possessing the Note is able to link deposit and w…
It's a coin mixer: you deposit ETH into a common pool shared with a bunch of other people, and you get back (off-chain) a code that can be used to redeem your deposit at a later date. Since there is no link between the code and the sender on-chain, nobody knows which contributor to the pool withdrew. So if there are N deposits then later N withdrawals, the only thing you know is that each withdrawal matches one of th…
If there were e.g. three deposits for 5.542, 3.799, and 10.4322 ETH, and someone withdrew 3.799 ETH, then it seems like you'd know which deposit they made.
Best case, you wait long enough and maybe someone else deposits 3.799 ETH.
Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack
#86Just remember - code is law. No takesies-backsies :)
The person who lost the 50 million probably insured his money with something like https://nexusmutual.io/ . If you invest a large sum, you should always insure it against hacks.
Nexus Mutual just told on Twitter that since it is not a smart contract attack, they're not going to pay.
Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack
#87Earlier quoted context omitted.
Could someone ELI5 how Tornado Cash achieves (or doesn't achieve) privacy? Their FAQ say: > Is it possible to compromise the protocol and find out information about depositors? -- No, Tornado Cash is a decentralized protocol based on zero knowledge proofs. Its smart contracts are immutable, have no admins, and the proofs are based on strong cryptography. Only the user possessing the Note is able to link deposit and w…
It's a coin mixer: you deposit ETH into a common pool shared with a bunch of other people, and you get back (off-chain) a code that can be used to redeem your deposit at a later date. Since there is no link between the code and the sender on-chain, nobody knows which contributor to the pool withdrew. So if there are N deposits then later N withdrawals, the only thing you know is that each withdrawal matches one of th…
Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack
#88Earlier quoted context omitted.
It's a coin mixer: you deposit ETH into a common pool shared with a bunch of other people, and you get back (off-chain) a code that can be used to redeem your deposit at a later date. Since there is no link between the code and the sender on-chain, nobody knows which contributor to the pool withdrew. So if there are N deposits then later N withdrawals, the only thing you know is that each withdrawal matches one of th…
> the only thing you know is that each withdrawal matches one of the deposits, but not which one. If there were e.g. three deposits for 5.542, 3.799, and 10.4322 ETH, and someone withdrew 3.799 ETH, then it seems like you'd know which deposit they made. Best case, you wait long enough and maybe someone else deposits 3.799 ETH.
Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack
#89Earlier quoted context omitted.
It's a coin mixer: you deposit ETH into a common pool shared with a bunch of other people, and you get back (off-chain) a code that can be used to redeem your deposit at a later date. Since there is no link between the code and the sender on-chain, nobody knows which contributor to the pool withdrew. So if there are N deposits then later N withdrawals, the only thing you know is that each withdrawal matches one of th…
> the only thing you know is that each withdrawal matches one of the deposits, but not which one. If there were e.g. three deposits for 5.542, 3.799, and 10.4322 ETH, and someone withdrew 3.799 ETH, then it seems like you'd know which deposit they made. Best case, you wait long enough and maybe someone else deposits 3.799 ETH.