Live data from Hacker News

DeFi protocol BadgerDAO exploited for $120M in front-end attack

theblockcrypto.com

131–140 of 151 posts

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#131

Earlier quoted context omitted.

That technically just moves the problem one step further. How are users supposed to learn what is the right smart contract to begin with?

Is this not the same problem when interacting with any other site? There is nothing stopping people from navigating to faecbook.com and entering their account details. At some point there is a bare minimum literacy expected of users. As to how they would know if it's the real smart contract: they would see what it was via their wallet after interacting with it the first time.

Proving the correctness of a program is a famously hard CS problem, not “bare minimum literacy”.

> As to how they would know if it's the real smart contract: they would see what it was via their wallet after interacting with it the first time.

In other words, the system is not safe to use. People will reliably be fooled into thinking that they're interacting with someone else — the difference is that if you go to amaz0n.com and enter your credit card info, your liability is capped at a low amount and will likely be zero because the regulated financial industry has a fraud handling mechanism better than “the people who profited from you buying their tokens will mock you for being phished”.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#132
post #113
post #101

Earlier quoted context omitted.

Amazing. So now you can steal a bunch of crypto and wash it. Holy shit, if you then create some BS coin which gets a bunch of "investors" (really just you investing the coins you stole), you could steal hundreds of millions if not billions of dollars and get it fully laundered and recognized as legitimate by the government, all from your computer anywhere in the world. What a time to be alive as a criminal hacker!

Tornado cash doesn't launder your crypto. Just breaks the link between the heist and your new crypto address. If you steal billions, you still have the problem of justifying them.

That is the point of the BS coin, that is what you attach your identity to and then you trade all of the washed coins for your new BS coin. Creating/mining the BS coin is where your legitimacy comes from.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#133

Earlier quoted context omitted.

What is an example of a law that does not restrict freedom?

A law that bans murder. There is no freedom to murder so it does not restrict any freedom.

Murder means to unlawfully kill a person. Without laws against killing there is no such thing as murder.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#134

Earlier quoted context omitted.

Not true! A lot of code written for financial applications, and a lot of the complexity in those systems, is there just to synchronize, reconcile and settle between the independent data silos maintained by the various entities involved in a transaction. Blockchains can do a lot to eliminate that complexity. Also, there are interesting advantages to the transaction authorization model that blockchains have whereby a m…

Traditional finance did settling just fine before. The only reason they are getting into blockchain now, is that it's a real alternative that people prefer to the banks.

Just because they did it just fine before, doesn't mean that there isn't a better way that will provide massive competitive advantages to companies that adopt them.

Big companies ran payroll 100 years ago without IBM machines, but IBM made it easier for big companies to run payroll, so companies that bought IBM machines were able to scale.

Company budgets were done just fine on big sheets of paper 50 years ago before PCs loaded with VisiCalc or Excel deployed to every desktop. What company that still did it the old way survived the 1980s?

Credit card transactions even 30 years ago were still often done with a physical mechanical impression at the point-of-sale. That worked just fine, didn't it? Yeah, there was some fraud, but the people who were given credit cards were few enough that it wasn't unmanageable. But online POS systems now mean that almost everyone today makes payments with debit or credit cards most of the time.

Is "things are working just fine" a reason to not innovate?

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#135
post #129

Earlier quoted context omitted.

Plenty of people concerned with privacy use public blockchains - you don't need to dox yourself to use them, just need a private key. Unlike traditional finance, where you just have to hope that your PII data won't get leaked one day with all your transaction history. Timing analysis is a real concern, that's why they warn you about it on the front page and ask to wait before you withdraw.

It's not just timing analysis — look at their long list of difficult measures needed to make these transactions private and ask whether that's remotely plausible for widespread use: https://medium.com/@tornado.cash/how-to-stay-anonymous-with-... Very few people are so ideologically committed that they're going to pay extra and live with those constraints, which is a major problem for a protocol which is critically de…

Timing analysis is the main thing to worry about, if you're just looking to get some anonymous ETH such that people looking at the blockchain can't track it easily. Those difficult measures are not a requirement and can be ignored depending on your threat level.

And I don't know why are you talking to a strawman about a suitcase full of cash, etc. I just said that Tornado.cash offers privacy and that privacy is not always used for evil things.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#136

Earlier quoted context omitted.

Can you elaborate on how this event constitutes proof of your claim?

i'm not worried about my DIS shares getting hacked as they chill in the digital world compounding interest. It appears that investing in crypto is not quite as safe? One of my bros got hacked in mt gox and since then i've been a bit weary of putting serious sums of money into it (i have maybe 1-5% of my portfolio in crypto and not planning on betting the house anytime soon).

It's certainly not as safe. And one hack doesn't constitute "proof" that the entire space is a total fail at beating traditional finance, which should be obvious. Instead we have people like OP making sensational claims about "shills", providing nothing of value to any conversation about the topic.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#137

Earlier quoted context omitted.

A law that bans murder. There is no freedom to murder so it does not restrict any freedom.

Murder means to unlawfully kill a person. Without laws against killing there is no such thing as murder.

So if the laws allow murdering people you would think that you have the freedom to murder people? Or that such laws are psychopathic and don't respect anyone's freedoms at all?

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#138

Earlier quoted context omitted.

Murder means to unlawfully kill a person. Without laws against killing there is no such thing as murder.

So if the laws allow murdering people you would think that you have the freedom to murder people? Or that such laws are psychopathic and don't respect anyone's freedoms at all?

Laws "cannot allow murder"; murder is illegal by definition. For example, if two hypothetical killings take place under identical circumstances but under two different legal jurisdictions, the killing could be considered murder in one place but justified in another. This happens all the time, see Florida's stand your ground laws for instance.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#139
post #66

Once again cryptocurrency shills are disproven in their core belief that they can do finance better than status quo.

Can you elaborate on how this event constitutes proof of your claim?

One of the core pillars of cryptocurrency, and DeFi, is that traditional finance is anachronistic, and full of stupid stuff not fit for the modern age.

Take the first sentence on ethereum's intro to DeFi: "DeFi is an open and global financial system built for the internet age – an alternative to a system that's opaque, tightly controlled, and held together by decades-old infrastructure and processes. "

Lots of the slowness and beurocracy of old finance is scoffed at as being, in more words, "stupid bullshit".

Rule after rule, and obstacle after obstacle, is loudly ranted about how terrible it is.

So the solution, in these people's explicit methods, is to throw away everything and start green field.

Now, I'm a software engineer. I understand the allure of green field. Surely, "how hard could it be"?

So because the description of how stupid cryptocurrency is can fill books (and there are several), let's stick to a short summary of the outcome of DeFi so far:

It's barely newsworthy every time one of these LARP banks topple over, losing all the money.

It's almost a weekly occurance.

And not only is all the money stolen, it's also not reversible!

When one of the founders of the pirate bay hacked a (real) bank's mainframe, he didn't actually get away with much (a couple of hundred dollars, I think was all that his accomplices managed to withdraw from ATMs). The rest was transferred back. (also suddenly "lack of extradition treaty" became a non-problem)

Basically cryptocurrencies and DeFi is software engineers with no understanding of economics, law, or society, discovering why all of the rules, laws, and procedures currently in place exist.

Another example is that AML/KYC laws didn't fall from the sky. "Well what if we didn't have laws at all?" is not really a rational place to start.

That's not to say that traditional finance is perfect. Absolutely not. But the cure for bad laws is not "The Purge".

So yeah, it's not this event, so much as this happens all the fucking time.

Imagine if these people were selling cars, and complaining about how much pushback they're getting for putting them on public roads, while every day there's deaths all over from unregulated cars that have swords on them, chopping heads off of the drivers themselves, and innocent pedestrians.

Like, how do you not see why this is causing pushback and that your way of replacing the seatbelt with a potato is stupid, and that actually the law that says a seatbelt is not allowed to be a potato maybe has a valid point?

Especially since things are more subtle than that. A non-techie cannot tell the difference between a seatbelt and a potato, and that's why the law says your car needs to have actual seatbelts.

Re: DeFi protocol BadgerDAO exploited for $120M in front-end attack

#140

Earlier quoted context omitted.

i'm not worried about my DIS shares getting hacked as they chill in the digital world compounding interest. It appears that investing in crypto is not quite as safe? One of my bros got hacked in mt gox and since then i've been a bit weary of putting serious sums of money into it (i have maybe 1-5% of my portfolio in crypto and not planning on betting the house anytime soon).

It's certainly not as safe. And one hack doesn't constitute "proof" that the entire space is a total fail at beating traditional finance, which should be obvious. Instead we have people like OP making sensational claims about "shills", providing nothing of value to any conversation about the topic.

It's not one. It's like one per week.

And every smart contract is a self-funded hack bounty.

Smart contracts are a complete misunderstanding of what contracts are, and what the hard parts of the space of contracts are. They're simply changing the simple problem to be enormously complex, without making the hard problems any easier. In fact it makes the hard problems harder too.

causing great public interest and excitement.

> OP making sensational claims

Def 1. "causing great public interest and excitement"

Well, not really. This story is just "huh, another one". Brings to mind the meme "I'm shocked, shocked!, to see another one of the cryptocurrency LARPers topple over"

Def 2. "very good indeed; very impressive or attractive."

Thank you!

Post reply on HN