Live data from Hacker News

DeFi protocol BadgerDAO exploited for $120M in front-end attack

theblockcrypto.com

101–110 of 151 posts

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#101
post #5
post #3

Reminder that every DAO is a self-administering bug bounty for all of the value under its control. Reminder also that you don't have to "hack etherum"; there are plenty of spots more vulnerable than the blockchain itself at which value can be stolen. (I would however be interested to know where all this stolen value ends up, and how well it can ultimately be laundered into the real world, or if this is more like driv…

Stolen ETH goes here to get a shave and a new suit, then it can go wherever it likes https://tornado.cash/

Amazing. So now you can steal a bunch of crypto and wash it. Holy shit, if you then create some BS coin which gets a bunch of "investors" (really just you investing the coins you stole), you could steal hundreds of millions if not billions of dollars and get it fully laundered and recognized as legitimate by the government, all from your computer anywhere in the world.

What a time to be alive as a criminal hacker!

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#102
post #66

Once again cryptocurrency shills are disproven in their core belief that they can do finance better than status quo.

Can you elaborate on how this event constitutes proof of your claim?

i'm not worried about my DIS shares getting hacked as they chill in the digital world compounding interest. It appears that investing in crypto is not quite as safe? One of my bros got hacked in mt gox and since then i've been a bit weary of putting serious sums of money into it (i have maybe 1-5% of my portfolio in crypto and not planning on betting the house anytime soon).

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#103
post #25

Just remember - code is law. No takesies-backsies :)

The person who lost the 50 million probably insured his money with something like https://nexusmutual.io/ . If you invest a large sum, you should always insure it against hacks.

The only thing riskier than smart contracts would be smart contract insurance products atop smart contracts. I'm sure they only allow for vetted contracts, but the incident discussed in this article was not a contract hack, it was a website hack to change the approve addresses. If that type of thing is going to be covered then it's well beyond smart contract due diligence. That would require evaluating end-to-end op sec practices on an ongoing basis.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#104

Can someone ELI5 DAOs please? Ideally without the buzzwords and more focused on the value they create and how. I'm a software engineer but the idea of a "smart" contract working as an "organisation", none of which can be undone when there is an error seems like it has massive risk attached and little to no benefit. It doesn't seem "decentralized" as there are still organised parties to write and deploy code and the t…

You have to accept the premise that code as an absolute authority is a good thing, if you accept that premise, a DAO makes a lot of sense and can deliver a lot of value: no longer are we beholden to the weakness of corruptible man, we are now empowered by the strength of noble technology.

of course, as a software engineer, you know that is a hellish nightmare because the code we write is fallible so this entire thing makes no sense whatsoever.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#105

Earlier quoted context omitted.

Not every law is a restriction of freedom. My freedom ends where yours begins. Sadly, some people are more than happy to force their worldview on others, "for their own sake".

What is an example of a law that does not restrict freedom?

A law that bans murder. There is no freedom to murder so it does not restrict any freedom.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#106

Earlier quoted context omitted.

Not DAOs, but users can examine the transaction that they are prompted to sign and make sure that it is interacting with the right smart contract.

That technically just moves the problem one step further. How are users supposed to learn what is the right smart contract to begin with?

Is this not the same problem when interacting with any other site? There is nothing stopping people from navigating to faecbook.com and entering their account details. At some point there is a bare minimum literacy expected of users.

As to how they would know if it's the real smart contract: they would see what it was via their wallet after interacting with it the first time.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#107
post #98

Earlier quoted context omitted.

Even things like buying houses (and I have heard of people buying houses with ETH). People generally like privacy when it comes to medium and large purchases, regardless of what it is that they are purchasing.

It would be illegal to anonymously buy property in the UK. https://www.gov.uk/government/publications/how-to-buy-a-home... > People generally like privacy when it comes to medium and large purchases The "war on money laundering" goes against this.

https://www.cbsnews.com/news/pandora-papers-uk-real-estate-h...

> But the recent Pandora Papers leak has revealed that U.K. properties worth nearly $5.5 billion, according to those who've analyzed the documents, have been purchased through offshore shell companies that hide the owners' identities.

> "Using a shell company means that no one need ever know that the asset is yours," said anti-corruption activist Duncan Hames, Director of Policy at Transparency International. "Indeed, the British government probably doesn't know."

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#108
post #101
post #5

Earlier quoted context omitted.

Stolen ETH goes here to get a shave and a new suit, then it can go wherever it likes https://tornado.cash/

Amazing. So now you can steal a bunch of crypto and wash it. Holy shit, if you then create some BS coin which gets a bunch of "investors" (really just you investing the coins you stole), you could steal hundreds of millions if not billions of dollars and get it fully laundered and recognized as legitimate by the government, all from your computer anywhere in the world. What a time to be alive as a criminal hacker!

I do wonder at what point this gets serious and starts interacting with OFAC; if it really worked as uncensorable finance, we'd have seen a tanker of Iranian oil sold for bitcoin. Doesn't quite seem to have reached that scale yet. I suspect a lot of nonsense is tolerated by the US authorities because it's enabling Chinese nationals to evade China's export controls, though.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#109
post #108
post #101

Earlier quoted context omitted.

Amazing. So now you can steal a bunch of crypto and wash it. Holy shit, if you then create some BS coin which gets a bunch of "investors" (really just you investing the coins you stole), you could steal hundreds of millions if not billions of dollars and get it fully laundered and recognized as legitimate by the government, all from your computer anywhere in the world. What a time to be alive as a criminal hacker!

I do wonder at what point this gets serious and starts interacting with OFAC; if it really worked as uncensorable finance, we'd have seen a tanker of Iranian oil sold for bitcoin. Doesn't quite seem to have reached that scale yet. I suspect a lot of nonsense is tolerated by the US authorities because it's enabling Chinese nationals to evade China's export controls, though.

Isn't even better than that? They'd have anonymous internet cash to use to bribe foreign officials at a time when many nations have been tightening the noose around finance and what an individual is allowed to own.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#110

Can someone ELI5 DAOs please? Ideally without the buzzwords and more focused on the value they create and how. I'm a software engineer but the idea of a "smart" contract working as an "organisation", none of which can be undone when there is an error seems like it has massive risk attached and little to no benefit. It doesn't seem "decentralized" as there are still organised parties to write and deploy code and the t…

You have to accept the premise that code as an absolute authority is a good thing, if you accept that premise, a DAO makes a lot of sense and can deliver a lot of value: no longer are we beholden to the weakness of corruptible man, we are now empowered by the strength of noble technology. of course, as a software engineer, you know that is a hellish nightmare because the code we write is fallible so this entire thing…

Ok I can (hypothetically) accept that.

Let's imagine I'm creating a fresh business and choose to structure it as a DAO, does this mean that the ever understanding code is the CEO steering the company? Or is the DAO the product of the company itself? I don't understand the relationship here.

Following on from that, I am the party that writes the code for the DAO. Now I can claim that my code is perfect and we can trust the machines to execute it. But I'm still running the deployment of it and the weakness of corruptible man can still abuse the trust given to the code they create.

Post reply on HN