Live data from Hacker News

White hat hacker awarded $2M for fixing ETH-creation bug

cryptoadventure.com

11–20 of 354 posts

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#11
post #3

Prior discussion of this incident (and the $2M bounty) here on Hacker News: https://news.ycombinator.com/item?id=30289240 My (I'm the hacker) article / post-mortem this blog post is referring to: https://www.saurik.com/optimism.html At the time of this last getting traction a few days ago, some people were sad that the title of my article and the discussion that resulted focused more on the bug instead of the bounty…

I’m glad you seem to be happy with your payout, but can we talk for a moment about how much you got? For an exploit like this, especially given how much effort was put into it and how much the market rate of a security engineer like this would be, plus given how much this could be worth on the exploit market, $2 million is literally pennies. This could’ve easily been a bug worth hundreds of millions of dollars. I gue…

This is $2 mil of clean money.

> This could’ve easily been a bug worth hundreds of millions of dollars

That doesn't mean that you could find someone to give you $100 mil, clean or unclean.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#12
post #11

Earlier quoted context omitted.

I’m glad you seem to be happy with your payout, but can we talk for a moment about how much you got? For an exploit like this, especially given how much effort was put into it and how much the market rate of a security engineer like this would be, plus given how much this could be worth on the exploit market, $2 million is literally pennies. This could’ve easily been a bug worth hundreds of millions of dollars. I gue…

This is $2 mil of clean money. > This could’ve easily been a bug worth hundreds of millions of dollars That doesn't mean that you could find someone to give you $100 mil, clean or unclean.

We have atomic swaps to monero now, cleaning your stolen eth is easier than ever.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#13
post #3

Prior discussion of this incident (and the $2M bounty) here on Hacker News: https://news.ycombinator.com/item?id=30289240 My (I'm the hacker) article / post-mortem this blog post is referring to: https://www.saurik.com/optimism.html At the time of this last getting traction a few days ago, some people were sad that the title of my article and the discussion that resulted focused more on the bug instead of the bounty…

I’m glad you seem to be happy with your payout, but can we talk for a moment about how much you got? For an exploit like this, especially given how much effort was put into it and how much the market rate of a security engineer like this would be, plus given how much this could be worth on the exploit market, $2 million is literally pennies. This could’ve easily been a bug worth hundreds of millions of dollars. I gue…

If we choose to value everything we touch by way of "the next highest bidder might have paid $X for this" while fully ignoring their intentions (and so allowing black market sales to be in scope for the implied auction), I think you won't actually enjoy the society you end up with :(. Like, as a security researcher yourself, it might feel interesting to posit the exact addition of value we protect per incident, but I think the ramifications on how other work gets valued as well as what adverse side effects result from this mental model are scary.

It is thereby really only "required" (for the world to function) that there is sufficient monetary motivation for people who don't want to spend the rest of their life feeling either the guilt or stress (even if merely due to the ramifications of people finding out) of having done something "wrong" (which I put in quotes as I feel the "code is law" argument that can result at this point isn't actually that useful in a discussion of morality) to bother to then go out of their way to help (as opposed to not searching hard in the first place, looking the other way instead of reporting, or merely hoarding the bug as a parlor trick).

And so like, while I totally see how this bug could easily be worth at least tens of millions of dollars to someone, it isn't clear to me that finding and reporting this bug should imply that I would need to be paid (and "by who?" is a then a hard question to answer even if we think this, one which might bleed into "and how?" a bit as the first answer is probably awkwardly decentralized in scope) the tens (or even hundreds) of millions of dollars that that hypothetical black hat might have figured out how to extract (which I make a bit theoretical as profiting from crypto hacks is harder than people often assume, something I touch on in my article; I think you might have to go for extortion, and even that didn't work for the Wormhole hacker)... most people simply aren't of the moral constitution to be black hats (which is probably a good thing).

(In this case, the main lingering ethics question related to this bounty that I come back to occasionally is that there are projects--such as Metis--that forked Optimism and now compete with it using Optimism's own code and vision... projects that (in the case of Metis) are actually of similar size to it (based on "total value locked", which is imprecise but probably the best measure here for potential impact: Defi Llama lists Optimism at $344M and Metis at $347M) which are still relying on Optimism to motivate the security efforts for their platform... it feels at least awkward to me that they should get a "free pass" here simply because their listed bounties were lower than Optimism's? Like, even if you don't think I should get money from them, maybe they should be helping compensate Optimism?)

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#14
post #11

Earlier quoted context omitted.

I’m glad you seem to be happy with your payout, but can we talk for a moment about how much you got? For an exploit like this, especially given how much effort was put into it and how much the market rate of a security engineer like this would be, plus given how much this could be worth on the exploit market, $2 million is literally pennies. This could’ve easily been a bug worth hundreds of millions of dollars. I gue…

This is $2 mil of clean money. > This could’ve easily been a bug worth hundreds of millions of dollars That doesn't mean that you could find someone to give you $100 mil, clean or unclean.

In past threads I’ve heard about exploit brokers and how their rates are typically much higher than bug bounties. If Hacker News commenters know about these avenues I’m sure bug hunters can find ways to cash out for more money. Calling it unclean is stupid anyways, since the company clearly isn’t paying enough for bugs in their own service…this is the same kind of thinking that leads to “responsible disclosure” and all that junk.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#15

Earlier quoted context omitted.

I’m glad you seem to be happy with your payout, but can we talk for a moment about how much you got? For an exploit like this, especially given how much effort was put into it and how much the market rate of a security engineer like this would be, plus given how much this could be worth on the exploit market, $2 million is literally pennies. This could’ve easily been a bug worth hundreds of millions of dollars. I gue…

Morals aside, which seems to be popular in sec communities, Do you not understand the immense amount of effort they would have needed to expend to hide, not to mention the ongoing stress involved afterward?

Surely someone with the skills to find bugs like these would be an expert in cashing out on those bugs?

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#16
post #3

Prior discussion of this incident (and the $2M bounty) here on Hacker News: https://news.ycombinator.com/item?id=30289240 My (I'm the hacker) article / post-mortem this blog post is referring to: https://www.saurik.com/optimism.html At the time of this last getting traction a few days ago, some people were sad that the title of my article and the discussion that resulted focused more on the bug instead of the bounty…

Congratulations. I'm not sure if this was discussed in the previous thread, but does the bug allow the creation of real ETH coins, or it just increase the counter in the Optimism database (or whatever system they are using)?

Optimism is a blockchain quite a bit like Ethereum, so the "database" mental model might be a bit confusing for a frame here (as it isn't like they are some centralized service), but no: this doesn't let you directly create ETH (which would be much much more devastating); it only lets you create something we might call "OETH", which is Optimism-specific.

The native currency on Optimism (used to pay gas, like ETH is used on Ethereum) is effectively ETH; but, as it isn't Ethereum, that ETH on Optimism has to actually live on Ethereum: it gets locked into a contract there which acts as a repository/reserve for all of the ETH being used on Optimism.

When you deposit ETH in this reserve on Ethereum you get credited the same amount on Optimism in the form of cryptocurrency IOUs (which we might call "OETH"), and you can later withdraw that money back to Ethereum, whereupon the OETH is destroyed and ETH is unlocked from the reserve contract.

The bug here (which I go into detail in in my post-mortem, along with another / different description of how these "bridges" work) was in the VM used for the smart contract behaviors on Optimism, which would mean you could arbitrarily replicate OETH (the IOUs for ETH).

For avoidance of any doubt: you couldn't use this bug to create an arbitrary amount of ETH/Ether, but the issue is that a lot of people call the money on Optimism--which is normally backed 1:1 with ETH--"ETH". (There is a discussion about what it should be called in the Ethereum chains database; I personally think what we need is a terminology for describing the full path whenever you have "ETH via an indirect path".)

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#17
post #3

Prior discussion of this incident (and the $2M bounty) here on Hacker News: https://news.ycombinator.com/item?id=30289240 My (I'm the hacker) article / post-mortem this blog post is referring to: https://www.saurik.com/optimism.html At the time of this last getting traction a few days ago, some people were sad that the title of my article and the discussion that resulted focused more on the bug instead of the bounty…

Your postmortem page throws a "Error code: SSL_ERROR_UNSUPPORTED_SIGNATURE_ALGORITHM" in Firefox under Fedora.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#18

Earlier quoted context omitted.

Morals aside, which seems to be popular in sec communities, Do you not understand the immense amount of effort they would have needed to expend to hide, not to mention the ongoing stress involved afterward?

Surely someone with the skills to find bugs like these would be an expert in cashing out on those bugs?

Those skills are unrelated.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#19
post #3

Prior discussion of this incident (and the $2M bounty) here on Hacker News: https://news.ycombinator.com/item?id=30289240 My (I'm the hacker) article / post-mortem this blog post is referring to: https://www.saurik.com/optimism.html At the time of this last getting traction a few days ago, some people were sad that the title of my article and the discussion that resulted focused more on the bug instead of the bounty…

I’m glad you seem to be happy with your payout, but can we talk for a moment about how much you got? For an exploit like this, especially given how much effort was put into it and how much the market rate of a security engineer like this would be, plus given how much this could be worth on the exploit market, $2 million is literally pennies. This could’ve easily been a bug worth hundreds of millions of dollars. I gue…

gtfo with that. it's a generous payout.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#20
post #3

Prior discussion of this incident (and the $2M bounty) here on Hacker News: https://news.ycombinator.com/item?id=30289240 My (I'm the hacker) article / post-mortem this blog post is referring to: https://www.saurik.com/optimism.html At the time of this last getting traction a few days ago, some people were sad that the title of my article and the discussion that resulted focused more on the bug instead of the bounty…

No post body was provided.
Post reply on HN