Live data from Hacker News

The math prodigy whose hack upended DeFi won’t return funds

bloomberg.com

261–270 of 409 posts

Re: The math prodigy whose hack upended DeFi won’t return funds

#261
post #50

> But in our email exchanges, he argued that he'd executed a perfectly legal series of trades. In real finance, there is an understanding that technical loopholes can exist, since not every outcome can be foreseen when writing laws, but the legal system can frequently prosecute against a series of actions which are, individually, legal, but which together are taken in order to achieve something illegal. That is, mode…

This is a twitter thread apparently from the lawyers hired by Indexed "I want to explain to you why what you did was illegal and wrong": https://twitter.com/ohaiom/status/1451142195369725957

Until this pans out in an actual court this is basically a strongly worded vaguely threatening letter from a lawyer. If they actually had him dead to rights they wouldn’t be posting their legal theory publicly and asking pretty please give it back or else these other people we’re not at all affiliated with and have no control over (but don’t pay attention to that fact) might put you in jail.

Re: The math prodigy whose hack upended DeFi won’t return funds

#262
post #198

Earlier quoted context omitted.

Let's say that I place a vending machine in a public space, such as a street or a park. The public is able to interact with it by inserting FIAT coins to purchase DRNK. Someone clever figures out a way to interact with the vending machine to extract DRNK at less than it's intended FIAT price. Two questions at this point: (a) Is this a theft from the person who placed the vending machine? Why or why not? (b) How is th…

That sort of depends on what the exploit is, right? For example, if DRNK costs $1 per unit, but I find out that by putting in $1.25 I get 2 units, have I actually exploited the machine? Is it not reasonable to assume that discount was intended? Now, of course, if I'm prying open the machine with a prybar then we could argue that's just theft. But, putting money in the machine and getting units out is the intended int…

> For example, if DRNK costs $1 per unit, but I find out that by putting in $1.25 I get 2 units, have I actually exploited the machine? Is it not reasonable to assume that discount was intended?

What if you remove the last part? What if you know, clearly, that your interaction what not what the designer wanted?

> So, that's what I'd say the difference is. A smart contract defines all the interactions that are valid.

Implementations are not specifications. What do you mean by "valid"?

Re: The math prodigy whose hack upended DeFi won’t return funds

#263

> Medjedovic added that he'd taken on “substantial risk” in pursuing this strategy. If he'd failed he would have lost “a pretty large chunk of my portfolio.” (The 3 ETH he stood to lose in fees was worth about $11,000 at the time.) This is misleading, either intentionally or due to Medjedovic's incompetence. You can fork the current head of the mainnet blockchain to localhost and try infinite permutations for free to…

* MEV has entered the chat *

This is of course entirely untrue, and anyone who has done even the smallest amount of onchain trading would know this.

Re: The math prodigy whose hack upended DeFi won’t return funds

#264
post #203

Forget about the exploit itself. Why are people trusting two young nobodies (Day and Kellar of Indexed Finance) with so much money in the first place? Ok, so Day has some decent academic credentials, but he's just one person. Who was doing risk analysis? Which independent experts analyzed their algorithms? Which accounting firm audited them? Where's the oversight? These two guys whipped something up, threw it out in…

Because people want to and decided the risk was worth it to them? If a consenting adult wants to deposit their money into a system that they have full visibility into, why should we stop them? > This is how crypto operates. Buyer beware. This statement rings very true for me, and perhaps is the bit we agree on. With crypto there is no "oversight" that blocks you from depositing your funds into unsafe contracts, etc.…

> If a consenting adult wants to deposit their money into a system that they have full visibility into, why should we stop them?

We already do exactly that, e.g. Accredited Investor.

Re: The math prodigy whose hack upended DeFi won’t return funds

#265
post #198

Earlier quoted context omitted.

Let's say that I place a vending machine in a public space, such as a street or a park. The public is able to interact with it by inserting FIAT coins to purchase DRNK. Someone clever figures out a way to interact with the vending machine to extract DRNK at less than it's intended FIAT price. Two questions at this point: (a) Is this a theft from the person who placed the vending machine? Why or why not? (b) How is th…

That sort of depends on what the exploit is, right? For example, if DRNK costs $1 per unit, but I find out that by putting in $1.25 I get 2 units, have I actually exploited the machine? Is it not reasonable to assume that discount was intended? Now, of course, if I'm prying open the machine with a prybar then we could argue that's just theft. But, putting money in the machine and getting units out is the intended int…

And what if the vending machine measures coins by weight, and you so happen to have a "coin" that is just a properly-weighted blank. You're still interacting with the vending machine as technically intended. But by not inserting the correct amount of money, you are not interacting with it as intended by the creators.

The smart contract implements a technical intent, just like the vending machine. But that technical intent will always have limitations. Some exploits are non-destructive, such as properly-weighted blanks. Some are destructive, such as crowbars. But let's not pretend that they aren't, in fact, exploits.

Re: The math prodigy whose hack upended DeFi won’t return funds

#266

Earlier quoted context omitted.

With the ledger being public, it could be very simple for courts and police to deal with it given the appropriate legislation. Mark the result of theft or other illegal transactions, and any subsequent transaction as dirty. Make any exchange, any vendor, any trader, and any user check with a government database before or immediately after receiving a payment, with penalties prescribed by law. You immediately limit st…

Except crypto is decentralized, and you can use mixers, which are not owned by anyone, to anonymously move coins from a blacklisted wallet. There is no mechanism in decentralized crypto to freeze an address, and I don't think the crypto community would adopt such a blockchain.

Blacklisting doesn't have to be a feature of a blockchain. It's enough if most countries decide to make it illegal for anyone to spend coins received from a blacklisted address. It's not easy to enforce of course, but people would be afraid they get in trouble if they're ever deanonimized, and businesses could be required to report their trades, just like taxes.

This will force creation and use of wallet reputation checkers for most users of cryptocurrencies. Mixers will not want to be left holding all the blacklisted coins, since that causes them financial loss. Therefore mixers will launder coins at a very high premium (lemon market) and compete on developing their own systems for reputation checks and escrows to reduce their risk of being left with coins nobody wants.

Re: The math prodigy whose hack upended DeFi won’t return funds

#267

> Medjedovic added that he'd taken on “substantial risk” in pursuing this strategy. If he'd failed he would have lost “a pretty large chunk of my portfolio.” (The 3 ETH he stood to lose in fees was worth about $11,000 at the time.) This is misleading, either intentionally or due to Medjedovic's incompetence. You can fork the current head of the mainnet blockchain to localhost and try infinite permutations for free to…

Jesus, and we wonder why grandma is entirely unsuited to putting her savings in this crap.

This is only slightly different than what goes on in the stock market

But yield farmers and high value targets should open insurance policies

And the insurance pool participants should also be wary ha

Re: The math prodigy whose hack upended DeFi won’t return funds

#268
post #198

Earlier quoted context omitted.

Let's say that I place a vending machine in a public space, such as a street or a park. The public is able to interact with it by inserting FIAT coins to purchase DRNK. Someone clever figures out a way to interact with the vending machine to extract DRNK at less than it's intended FIAT price. Two questions at this point: (a) Is this a theft from the person who placed the vending machine? Why or why not? (b) How is th…

Imagine in your example the vending machine has a variable pricing and lowers its price if nobody purchases soda. Is it theft to wait longer than the designers thought people would wait and purchase the DRNK at price lower than the machine owner thought they would. I think a better example is a claw gambling machine. You pay Fiat for a chance to grab fiat out of a pool. If you come up with a strategy whereby you can…

Broken slot machines do happen, and it's been made very clear that the player does not benefit.

https://www.aol.com/2016-11-02-broken-slot-machine-dupes-wom...

https://www.foxnews.com/us/not-a-winner-oregon-woman-denied-...

However, this works both ways. If the mistake is in the favor of the player, they are obligated to pay out:

https://www.msn.com/en-us/news/us/a-slot-machine-in-las-vega...

Re: The math prodigy whose hack upended DeFi won’t return funds

#270

> Medjedovic added that he'd taken on “substantial risk” in pursuing this strategy. If he'd failed he would have lost “a pretty large chunk of my portfolio.” (The 3 ETH he stood to lose in fees was worth about $11,000 at the time.) This is misleading, either intentionally or due to Medjedovic's incompetence. You can fork the current head of the mainnet blockchain to localhost and try infinite permutations for free to…

* MEV has entered the chat * This is of course entirely untrue, and anyone who has done even the smallest amount of onchain trading would know this.

He used some form of MEV shielding but not clear in which way (like if it went straight to miners) but its improbable that the transactions he formed would have been able to be frontrun
Post reply on HN