Live data from Hacker News

The math prodigy whose hack upended DeFi won’t return funds

bloomberg.com

211–220 of 409 posts

Re: The math prodigy whose hack upended DeFi won’t return funds

#211

Earlier quoted context omitted.

What specific law was broken? In the US, generic "hacks" generally fall under the computer fraud and abuse act, which is notoriously vague about what qualifues as "authorized". Perhaps some other lawvis applicable. But I cannot think of any that are obviously on point. Nor can I think of a clear precedent that clarifies the issue.

> What specific law was broken? Market manipulation, fraud.

Market manipulation might work, but since it was all inside of a flash loan that's harder to argue.

I'm skeptical that any fraud happened here.

Re: The math prodigy whose hack upended DeFi won’t return funds

#212

Earlier quoted context omitted.

Citibank mistakenly sent $900M to a bunch of hedge funds. Many refused to return it. Citi lost the court case. https://www.cnn.com/2021/02/16/business/citibank-revlon-laws...

They accidentally repaid their loan early, which was explicitly allowed in the contract. The hedge funds were under no obligation to pay them back, since the money was now rightfully theirs.

They repaid someone else's loan early.

Re: The math prodigy whose hack upended DeFi won’t return funds

#213
Smart contracts are badly named lambda functions. They need the same regulation as any other code, the difference being, the regulation can come in the form of more lambda functions.

The judiciary could write the latter any time they got the right technical input. The question really is - what’s worth putting in the effort right now?

And those answers are coming soon.

But we shouldn’t conflate smart contracts with legal contracts in discussions.

Re: The math prodigy whose hack upended DeFi won’t return funds

#215

Earlier quoted context omitted.

And everything done in this case was in a smart contract. That’s the idea.

I don't think the smart contract explicitly said "there's this arbitrage opportunity available", but it's definitely a fine line.

This kind of automated index fund seems pretty suggestive of arbitrage to me.

And flash loan contracts are a bright neon sign saying "arbitrage opportunity!"

Re: The math prodigy whose hack upended DeFi won’t return funds

#216

Earlier quoted context omitted.

> With this worldview, if the attacker simply exploited poorly-written code to find a loophole, how do the owners of Index have a leg to stand on? They don’t. They simply have to accept it as a bug bounty successfully collected and paid out, and treat it as a learning experience and evolutionary process. Do better next time, if there is a next time.

Good luck making that argument in court. Intent is key, and if this is not the intent of the "smart" (lol) contract, "finder's keeper's" is not a legal defense. The legal system doesn't care about your blockchain arguments.

Can they make a strong case about what their intent was? Do they have some legal agreement with the hacker that the judge can use to divine their intent and the hacker's violation of it beyond reasonable doubt?

Or might the hacker and his clever lawyers have an equally strong case that whatever the code allowed was the "true" intent, that the code is the ultimate arbiter of intent, regardless what Index might have said otherwise?

I kind of hope it does go to court, will be interesting to see what the opposing legal teams come up with.

Re: The math prodigy whose hack upended DeFi won’t return funds

#217

> Medjedovic added that he'd taken on “substantial risk” in pursuing this strategy. If he'd failed he would have lost “a pretty large chunk of my portfolio.” (The 3 ETH he stood to lose in fees was worth about $11,000 at the time.) This is misleading, either intentionally or due to Medjedovic's incompetence. You can fork the current head of the mainnet blockchain to localhost and try infinite permutations for free to…

Jesus, and we wonder why grandma is entirely unsuited to putting her savings in this crap.

That's just a complicated way of saying "you can locally test a smart contract that you're coding".

Nobody is suggesting grandmas code their own smart contracts.

This is not the reason to keep grandma's savings away.

Re: The math prodigy whose hack upended DeFi won’t return funds

#218
post #198
post #132

Earlier quoted context omitted.

A smart contract deployed on a public permissionless blockchain is not owned by anyone. Only the contract's logic determines how one can interact with it. This is a fact. It doesn't matter who can make the best argument in court. A good enough lawyer can convince a stupid enough jury of pretty much anything.

Let's say that I place a vending machine in a public space, such as a street or a park. The public is able to interact with it by inserting FIAT coins to purchase DRNK. Someone clever figures out a way to interact with the vending machine to extract DRNK at less than it's intended FIAT price. Two questions at this point: (a) Is this a theft from the person who placed the vending machine? Why or why not? (b) How is th…

That sort of depends on what the exploit is, right?

For example, if DRNK costs $1 per unit, but I find out that by putting in $1.25 I get 2 units, have I actually exploited the machine? Is it not reasonable to assume that discount was intended?

Now, of course, if I'm prying open the machine with a prybar then we could argue that's just theft. But, putting money in the machine and getting units out is the intended interaction.

Similar to how if a gas station accidentally puts the price of gas at $0.20 per gallon, even though everyone knows that's probably a mistake, it isn't on them for taking advantage of the artificially low price.

So, that's what I'd say the difference is. A smart contract defines all the interactions that are valid. Thus, it is impossible to interact with a smart contract in a way that is "invalid" or "stealing". That'd be different if the user could modify the contract (apply a prybar) however, that's sort of the point, that you can't modify the contract to fix it.

If the contract said "all your deposited crypto goes to cogman10" would we call that a theft when someone put their crypto into that contract? Perhaps if I misrepresented the contract, but then the whole point of these contracts is they are visible to anyone that wants to read/use them.

Re: The math prodigy whose hack upended DeFi won’t return funds

#219

Earlier quoted context omitted.

There are 2 different issues here. Do courts physically have the ability to change the blockchain so that an NFT goes to a different wallet? No. Do courts have the ability to arrest someone when they ignore a court order to transfer an NFT? Yes. I don't think the courts really care about some pure intentioned "code is law" argument, because they tend to think law is law.

With the ledger being public, it could be very simple for courts and police to deal with it given the appropriate legislation. Mark the result of theft or other illegal transactions, and any subsequent transaction as dirty. Make any exchange, any vendor, any trader, and any user check with a government database before or immediately after receiving a payment, with penalties prescribed by law. You immediately limit st…

Except crypto is decentralized, and you can use mixers, which are not owned by anyone, to anonymously move coins from a blacklisted wallet. There is no mechanism in decentralized crypto to freeze an address, and I don't think the crypto community would adopt such a blockchain.

Re: The math prodigy whose hack upended DeFi won’t return funds

#220

-- EDIT -- i found the address and i take everything back and declare the opposite, that address is not random at all. -- original post -- > The Ethereum address used for the attack included the number ... shorthand for ... So Bloomberg thinks people choose the numbers in their wallet addresses and are responsible for any perceived numerological meaning. Are they for real? Sure the guy could have sat there recreating…

I’ll give the full quote: > The Ethereum address Medjedovic used for the attack included the number “1488”—shorthand for a neo-Nazi slogan—and he’d written the N-word into the code itself, 16 times. A Twitter user called him the “Dylan [sic] Roof of Balancer Pools,” a reference to the mass shooter who killed nine Black people at a church in Charleston, S.C., in 2015. Medjedovic liked the tweet. Here’s another: > Medj…

[deleted]
Post reply on HN