Live data from Hacker News

DeFi protocol BadgerDAO exploited for $120M in front-end attack

theblockcrypto.com

111–120 of 151 posts

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#111

Earlier quoted context omitted.

What is an example of a law that does not restrict freedom?

A law that bans murder. There is no freedom to murder so it does not restrict any freedom.

Where there is no law against killing people, people are free to do that.

And when people who want to kill people and have been free to kill people get told they are no longer allowed to, they have also been unhappy about it.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#112
post #111

Earlier quoted context omitted.

A law that bans murder. There is no freedom to murder so it does not restrict any freedom.

Where there is no law against killing people, people are free to do that. And when people who want to kill people and have been free to kill people get told they are no longer allowed to, they have also been unhappy about it.

No, there is no freedom to murder people no matter where you are. My freedom ends where yours begins.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#113
post #101
post #5

Earlier quoted context omitted.

Stolen ETH goes here to get a shave and a new suit, then it can go wherever it likes https://tornado.cash/

Amazing. So now you can steal a bunch of crypto and wash it. Holy shit, if you then create some BS coin which gets a bunch of "investors" (really just you investing the coins you stole), you could steal hundreds of millions if not billions of dollars and get it fully laundered and recognized as legitimate by the government, all from your computer anywhere in the world. What a time to be alive as a criminal hacker!

Tornado cash doesn't launder your crypto. Just breaks the link between the heist and your new crypto address. If you steal billions, you still have the problem of justifying them.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#115
post #100
post #47

Earlier quoted context omitted.

Isn't that a bit like saying cash is dirty? I don't think we are under obligation to keep our funds traceable? Perhaps we are getting closer to that point though.

You're still required to keep records for things like tax purposes. More importantly, however, this is a service specifically designed to launder money which is going to look like a public declaration of intent to law enforcement types. Since this costs money to use, most people are not going to use it unless they're trying to hide something so the big risk I'd worry about is similar to the risks of running a Tor exi…

This is like saying that Tor is specifically designed to buy drugs. It is designed for privacy, just like Tornado.cash is. Privacy can be used for many things.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#116
post #25

Just remember - code is law. No takesies-backsies :)

The person who lost the 50 million probably insured his money with something like https://nexusmutual.io/ . If you invest a large sum, you should always insure it against hacks.

https://twitter.com/nexusmutual/status/1466395880806928387?s...

Looks like they’re refusing to cover it because it was a supply chain attack.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#117
post #2

Another day another DeFi project rekt. What happened: > The front end to the BadgerDAO website was reportedly acccessed, according to comments in the project's Discord channel, and used to intercept transactions. One admin said it appears that an API key for Cloudflare was compromised. > One user had around 900 bitcoin ($50.8 million) worth of tokens stolen in a single transaction. Another lost $5 million worth of to…

900 bitcoin. Just sitting there in some fragile little exchange, or whatever this DAO is. If these people are so rich, why aren't they so smart?

It is possible that you make more money by taking this risks, 300% yearly yield in crypto is not unheard of.

So it could be just cost of doing business.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#118
post #111

Earlier quoted context omitted.

Where there is no law against killing people, people are free to do that. And when people who want to kill people and have been free to kill people get told they are no longer allowed to, they have also been unhappy about it.

No, there is no freedom to murder people no matter where you are. My freedom ends where yours begins.

The same is true for selling poisonous baby milk or wine.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#119

Can someone ELI5 DAOs please? Ideally without the buzzwords and more focused on the value they create and how. I'm a software engineer but the idea of a "smart" contract working as an "organisation", none of which can be undone when there is an error seems like it has massive risk attached and little to no benefit. It doesn't seem "decentralized" as there are still organised parties to write and deploy code and the t…

The DAO model makes more sense when it’s only controlling on-chain cryptocurrency in ways that can be controlled entirely with smart contracts that can be voted on.

However, the most popular version of this DAO appears to be literal Ponzi schemes operating in the open. It seems people are more likely to trust the Ponzi scheme when they feel they have some degree of control over it.

Many of the high profile DAOs fail for exactly the reasons you highlighted: They’re sold as being built to buy or control off-chain assets (like a copy of the constitution or an NBA basketball team) but they lack any of the real-world contractual obligations that would actually link the DAO to the real-world asset. They’re relying entirely on the real-world volunteers to do what they claimed to do in agreement with what the DAO voted. This is why the constitution DAO had to make it clear that contributions were donations and tokens did not constitute actual ownership.

It’s possible that a future DAO will go through the trouble of setting up the appropriate real-world contracts and entities to make this all legally binding and an actual security, but at that point the legal entity is doing all of the heavy lifting and the DAO is just a very expensive donation and voting system where gas fees consume hundreds of dollars of every member’s interactions. Any breach of contract would still have to be handled in the real-world legal system, so the DAO wouldn’t really protect anything other than providing a record of who voted for what.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#120

Earlier quoted context omitted.

No, there is no freedom to murder people no matter where you are. My freedom ends where yours begins.

The same is true for selling poisonous baby milk or wine.

If I want to sell a poisonous wine to an adult that understands the risks and still wants it, then it's none of your business.
Post reply on HN