Live data from Hacker News

The bug which lost more than $600M in various cryptocurrencies a few hours ago

twitter.com

111–120 of 126 posts

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#111
post #57
post #32

Earlier quoted context omitted.

> A legitimate trade always occurs between willing partners Charge back fraud (also called friendly fraud) is a big problem in commerce, where the buyer will buy something, receive it and then cancel the payment. The merchant will often have to swallow the cost.

But that is an illegitimate trade and cuts BOTH WAYS. When the buyer is fraudulent the merchant swallows the cost AND when the merchant is fraudulent the buyer swallows the cost. That's actually why credit cards come with protection against fraudulent merchants and you need a good enough credit score to actually get a credit card. On top of that, payment processors run fraud detection systems that block suspicious ac…

> Irreversibility turns the trade into a competition over who is the better fraud. The only thing that the crypto guarantees is that the winner keeps the prize.

I think it's more complicated than that. It moves the fraud risk to one specific spot (the consumer) which VASTLY simplifies the checkout process + the costs associated with online purchasing. Right now online payments are a giant mess - every single merchant has to implement anti-"fraud" tools to try and ascertain the identity of the consumer and determine if it matches the owner of the card.

As a consumer, I would happily take this trade for lower prices.

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#112
post #29
post #7

So as someone very critical of the whole DeFi / Smart Contracts philosophy (purely in terms of practicality, not the high-level concepts behind it) - please explain to me how the impacts of those bugs are going to be mitigated going forward. At will and ex-post broadcasting "oops, we had a bug - please roll back or block the bad actors" doesn't strike me as a solid solution, nor a fair & automated one. I was under th…

I bet that we will see insurance companies emerge in the market. Contracts will send a portion of the transaction to an insurance company. The insurance company would mandate "layers" to validate the contract. Users can then claim damages if there was a bug in the contract. Once all this is done, the transaction fees will be equal or higher than traditional banking systems :-p

There are a number of "smart contract" insurance companies already, Nexus Mutual is one of the main ones, and the rate of return after paying for insurance on a number of platforms exceeds what normal banks would pay you.

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#113
post #44
post #27

Earlier quoted context omitted.

A lot of these contracts, and especially those owned by first-tier cryptocurrency companies, are reviewed by 3rd party auditors. Of course that doesn't completely remove the risk, but certainly at least ensures that no obvious bugs are missed.

Auditors have never fully prevented bugs in any other computing domain, i dont know why cryptocurrency would be any different.

Can't the same be said that auditors have never fully prevented fraud in the real-world?

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#114
post #44

Earlier quoted context omitted.

Auditors have never fully prevented bugs in any other computing domain, i dont know why cryptocurrency would be any different.

Can't the same be said that auditors have never fully prevented fraud in the real-world?

The real world has ways to reverse fraudulent actions. Crypto does not.

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#115
post #41
post #23

There's a serious fundamental problem with DeFi that can't be solved with blockchains. Someone starts a blockchain company and hires a bunch of devs who make, idk, $40 to $100 per hour to build the thing. Maybe more, it doesn't really matter. Even just one dev or a few devs can make all the contracts needed for this. One day that dev notices a vulnerability in the smart contract he's writing! He has two choices: (a)…

Now say you're a company hired to do an audit. Same incentives. The hilarious thing is nearly all of these high profile hacks happen even after being audited. There was one company I remember being called out as a suspect, but I can't find the name. Also given (a) anonymity (b) ability to take cover amid so many other hacks, you could do this for a few years, slow down, and remain a top tier firm claiming the lowest…

Are you thinking of solidity.finance?

https://rekt.news/deathbed-confessions-c3pr/

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#116
post #98

Earlier quoted context omitted.

“You can’t really write software without bugs” - which is why crypto will never be for me

This is plain silly. Even centralized payment settlement systems do depend on thousands of lines of closed source code that contain bugs. Banking backends have bugs. Cars have bugs. Even buildings may have fuck ups that need to be dealt with after construction. If you think it through you simply can not rely 100% on anything humans build. But still societies as a whole thrive and human progress is real. DeFi is no ex…

Centralized payment settlement systems are mutable. That’s the difference and the whole argument.

A bug in a DeFi contract? Sorry nothing we can do! Bug in Wells Fargo account settlement code? Ah we’re sorry, let’s roll that back for ya!

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#117
post #84
post #69

Earlier quoted context omitted.

I don't quite buy that. The ability to claw back credit card payments to fraudulent merchants enables commerce before credibility is established. This is in the merchant's interest too, especially when they're starting out.

It's only in the interest of the merchant if they are selling items that have a low enough chargeback rate. Credit cards and clawbacks work great in-person and for low value online merchandise but it's non-viable for online high resale value merchandise.

>it's non-viable for online high resale value merchandise.

What does that mean?

The phrase "high resale value merchandise" sounds like it refers to the stuff that, in physical stores, is kept in a locked case so you have to ask someone to open it.

But that stuff is readily available online, isn't it?

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#118
post #23

There's a serious fundamental problem with DeFi that can't be solved with blockchains. Someone starts a blockchain company and hires a bunch of devs who make, idk, $40 to $100 per hour to build the thing. Maybe more, it doesn't really matter. Even just one dev or a few devs can make all the contracts needed for this. One day that dev notices a vulnerability in the smart contract he's writing! He has two choices: (a)…

> quit his job, wait a month, go to a coffee shop with a hoodie on, boot into whonix, connect to the internet with a 4g dongle, run a few lines of code, and get $600 million dollars.

Think again. In the wild wild west that is cryptocurrency the first thing people assume is an inside job.

People with a lot of money and a cut-throat ethic will send death threats to your front door merely for small bugs you accidentally commited to github or for a governance dispute on a forum where you posted pseudonymously.

If you dare steal money as an insider you had better make sure you know how to use it to quickly get high-end personal security for you, your family, and friends. This of course simultaneously outs you as guilty.

Any hack occurs and you are immediately woken up in the middle of the night to be interrogated by people you've never seen before let alone heard of, stomping through your apartment. Your life becomes a movie.

Angry vicious actors with few scruples and long memories will loudly and expensively hunt for you for the rest of your life so you can make them whole. LEOs aren't even your biggest concern at that point.

Being an insider or former insider after a large hack sucks whether or not you're guilty.

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#119
post #98

Earlier quoted context omitted.

This is plain silly. Even centralized payment settlement systems do depend on thousands of lines of closed source code that contain bugs. Banking backends have bugs. Cars have bugs. Even buildings may have fuck ups that need to be dealt with after construction. If you think it through you simply can not rely 100% on anything humans build. But still societies as a whole thrive and human progress is real. DeFi is no ex…

Centralized payment settlement systems are mutable. That’s the difference and the whole argument. A bug in a DeFi contract? Sorry nothing we can do! Bug in Wells Fargo account settlement code? Ah we’re sorry, let’s roll that back for ya!

Ethereum contracts are not 100% immutable. They need to maintain state like a token‘s balance. That’s why Ethereum‘s VM supports contract variables.

You can also use variables to store addresses to other contracts and call external methods indirectly using these pointer like structures. If I understood the bug correctly, the hacker was able to modify such a pointer and redirect all transactions to a wallet contract she controlled.

So this is how you can upgrade contracts: There is the „implementation contract“ pattern. Basically, you define a user-facing proxy contract defining the interface but all it does is delegate user calls to the actual implementation contract by maintaining a variable pointing to it. Using a privileged call you can update that address even after deploying the proxy.

Re: The bug which lost more than $600M in various cryptocurrencies a few hours ago

#120

Here's the original thread, as opposed to a random person quoting a random tweet halfway into it: https://twitter.com/kelvinfichter/status/1425217046636371969 https://threadreaderapp.com/thread/1425217046636371969.html

Calling dang.

Email the HN moderator team directly: hn@ycombinator.com
Post reply on HN