Live data from Hacker News

DeFi protocol BadgerDAO exploited for $120M in front-end attack

theblockcrypto.com

121–130 of 151 posts

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#121
post #100

Earlier quoted context omitted.

You're still required to keep records for things like tax purposes. More importantly, however, this is a service specifically designed to launder money which is going to look like a public declaration of intent to law enforcement types. Since this costs money to use, most people are not going to use it unless they're trying to hide something so the big risk I'd worry about is similar to the risks of running a Tor exi…

This is like saying that Tor is specifically designed to buy drugs. It is designed for privacy, just like Tornado.cash is. Privacy can be used for many things.

People who really care about privacy don’t use public blockchains. Leaving a permanent public log of your transactions for analysts is reckless in general.

In this specific case, you’re talking about a service people have to pay to use. That lowers the pool of people using it considerably which makes techniques like timing analysis easier and increases the odds that your transactions will be mixed in with someone else’s criminal activity.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#122

"Decentralized" also means nobody takes accountability, something a lot of our society is built upon, evolved over many generations. But a mix of snake-oil salesmen and nerds dreaming of utopia try to convince everybody that their approach is somehow magically better.

No. "Decentralized" means everybody takes accountability, as opposed to just one corporation. But you have to make use of it - e.g. by using https://nexusmutual.io/ .

"everybody takes accountability" and "nobody takes accountability" have the same meaning. Accountability is tightly linked to delegation, and essentially behaves like a normalized variable.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#123
post #121

Earlier quoted context omitted.

This is like saying that Tor is specifically designed to buy drugs. It is designed for privacy, just like Tornado.cash is. Privacy can be used for many things.

People who really care about privacy don’t use public blockchains. Leaving a permanent public log of your transactions for analysts is reckless in general. In this specific case, you’re talking about a service people have to pay to use. That lowers the pool of people using it considerably which makes techniques like timing analysis easier and increases the odds that your transactions will be mixed in with someone els…

Plenty of people concerned with privacy use public blockchains - you don't need to dox yourself to use them, just need a private key. Unlike traditional finance, where you just have to hope that your PII data won't get leaked one day with all your transaction history.

Timing analysis is a real concern, that's why they warn you about it on the front page and ask to wait before you withdraw.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#125
post #113
post #101

Earlier quoted context omitted.

Amazing. So now you can steal a bunch of crypto and wash it. Holy shit, if you then create some BS coin which gets a bunch of "investors" (really just you investing the coins you stole), you could steal hundreds of millions if not billions of dollars and get it fully laundered and recognized as legitimate by the government, all from your computer anywhere in the world. What a time to be alive as a criminal hacker!

Tornado cash doesn't launder your crypto. Just breaks the link between the heist and your new crypto address. If you steal billions, you still have the problem of justifying them.

Unless you happen to know of jurisdictions where there's a "no questions asked buy government bonds jubilee".

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#127

Earlier quoted context omitted.

You have to accept the premise that code as an absolute authority is a good thing, if you accept that premise, a DAO makes a lot of sense and can deliver a lot of value: no longer are we beholden to the weakness of corruptible man, we are now empowered by the strength of noble technology. of course, as a software engineer, you know that is a hellish nightmare because the code we write is fallible so this entire thing…

Ok I can (hypothetically) accept that. Let's imagine I'm creating a fresh business and choose to structure it as a DAO, does this mean that the ever understanding code is the CEO steering the company? Or is the DAO the product of the company itself? I don't understand the relationship here. Following on from that, I am the party that writes the code for the DAO. Now I can claim that my code is perfect and we can trus…

There's difficulty in translating these new concepts into examples using existing real-world concepts but as a broad generalisation: a DAO is a "company" that the shareholders govern and the DAO's code is the shareholder agreement which has zero implicit rights or behaviours.

The DAO itself could have code that enables something like, "the code for this DAO can be updated as if 50% of token holders vote yes" and then 50% of token holders could vote yes to a code change that appoints a CEO who has absolute authority or they could vote to change the code so that no vote could ever take place in future, and the code becomes "stuck" forever.

The code for a DAO lives and runs on the blockchain, so the integrity of the DAO is linked to the integrity of the network on which it runs: although there's no absolutes, in the case of a network like Ethereum, it is for all intents and purposes, secure, so deployment and execution is not a network-level attack vector.

Does that help?

The reason DAOs are considered _the future_ by some is the implicit assumption that perfect code is possible to produce. Many non-software engineers believe that _if we have the integrity of the network to guarantee the code cannot be changed without consent, then we can have absolute faith in the code_... but of course, as software engineers, we know code is very fallible, whether it's unintended side effects or malicious backdoors or just an honest misunderstanding of what the code is meant to do, there's millions of ways for code to go wrong long before we need to worry about code integrity.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#128
post #47

Earlier quoted context omitted.

Isn't that a bit like saying cash is dirty? I don't think we are under obligation to keep our funds traceable? Perhaps we are getting closer to that point though.

> I don't think we are under obligation to keep our funds traceable? Oh, you do. Not being able to prove the source of your funds puts you at serious risk of asset forfeiture.

That's not quite what I'm talking about. Obviously if you transfer money to your account you need to be able to explain where it comes from. But once you have the money, you can turn them into cash or gold if you want. At that point they are anonymous.

If you the give them to someone, well then they need to explain where it came from.

Also, if you want to put them back into your account, you'd need to show provenance.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#129
post #121

Earlier quoted context omitted.

People who really care about privacy don’t use public blockchains. Leaving a permanent public log of your transactions for analysts is reckless in general. In this specific case, you’re talking about a service people have to pay to use. That lowers the pool of people using it considerably which makes techniques like timing analysis easier and increases the odds that your transactions will be mixed in with someone els…

Plenty of people concerned with privacy use public blockchains - you don't need to dox yourself to use them, just need a private key. Unlike traditional finance, where you just have to hope that your PII data won't get leaked one day with all your transaction history. Timing analysis is a real concern, that's why they warn you about it on the front page and ask to wait before you withdraw.

It's not just timing analysis — look at their long list of difficult measures needed to make these transactions private and ask whether that's remotely plausible for widespread use:

https://medium.com/@tornado.cash/how-to-stay-anonymous-with-...

Very few people are so ideologically committed that they're going to pay extra and live with those constraints, which is a major problem for a protocol which is critically dependent on volume to deliver privacy and repudiation.

> Plenty of people concerned with privacy use public blockchains - you don't need to dox yourself to use them, just need a private key. Unlike traditional finance, where you just have to hope that your PII data won't get leaked one day with all your transaction history.

This is confusing a number of things. Most PII breaches are not the banks but the merchants who collect things like addresses because they need them for shipping or to satisfy legal requirements, and paying with a blockchain won't change any of those needs.

Similarly, very few people have a way to generate and spend a significant amount of cryptocurrency entirely for anonymous online services and will thus need to identify themselves for most transactions — a cryptocurrency exchange isn't exempted from Know Your Customer, companies which have to deal with abuse are going to want to prevent sock puppets or shell accounts, airlines aren't going to lose interest in checking your identity, buying a house without showing where you got the funds is going to attract a lot of attention, etc.

That link to the real world is the common reason why these promises don't pan out. In general, ask yourself how a particular activity would go if you showed up with a suitcase full of cash and refused to say where it came from. Cryptocurrency will be exactly the same in all but a very few cases.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#130
post #47

Earlier quoted context omitted.

Isn't that a bit like saying cash is dirty? I don't think we are under obligation to keep our funds traceable? Perhaps we are getting closer to that point though.

We are totally under the obligation to justify funds. To start with, because taxes, but also there are a lot of legislation put in place to prevent money laundering under threat of very high fines for non compliance, even if no laundering happened

This all applies to when you receive the money. The discussion concerns what you then proceed to do with them.
Post reply on HN