Live data from Hacker News

OptiFi Program Incident Report

medium.com

111–120 of 158 posts

Re: OptiFi Program Incident Report

#113
post #78

This is one of the biggest flaws in crypto. Small errors can erode hundreds of millions of value. That's when most crypto companies right now are very small. Can you imagine the chaos if crypto were to actually become big and dev count were to grow to 1k+ people spread across multiple offices? There's definite efficiency gains with crypto (a dex like Uniswap can do massive volume with very few developers for instance…

> This is one of the biggest flaws in crypto. Small errors can erode hundreds of millions of value. That's reality. Same thing would have happened if they had put all that cash on a boat, and accidentally sunk it.

Sure - but a lot of systems have a safety net of test environments and change control, and a safety net as they can revert changes, and a safety net as they can restore backups, and a safety net as they can ask counterparties nicely to help undo things, and a safety net through the legal system, and a safety net of insurance.

The normal banking industry is operating chainsaws very cautiously, with a lot of safety equipment and training. The cryptocurrency industry may be operating the same chainsaws, but they're trying to juggle them naked, on a floor slick with the blood of their peers.

Re: OptiFi Program Incident Report

#115

Earlier quoted context omitted.

It's a solid practice in UX design. Physically having to type or copy/paste it in really highlights the action for the end user. There's only so much you can do to stop people setting their own house on fire but something like that puts the onus on them and fairly places the blame where it belongs.

The problems start when you know you want to light a house on fire, but you pick the wrong house. It's almost never the case that blaming the user is actually going to help nor that adding more eyeballs will prevent people from making mistakes. If it's routine, we'll apply it to the wrong entity. If it's not routine, we'll not understand all the implications of our actions.

Some actions have to be irreversible by design (think: emptying the trash to free up space on your drive, or deleting sensible user data). At some point, someone has to greenlight that action, and the best you can do is trying to ensure the user is aware of what they're about to do – and you have to trust that they're using their brain for once. You know, that thing in your head which distinguishes you from that thing sitting in the metal box under your desk... If it were possible to automate that decision in a flawless, 100% safe and correct way, there'd be no need for a human to press the button.

Re: OptiFi Program Incident Report

#116
> Strictly execute *peer-surveillance approach*that requires at least 3 peers to engage in the deployment process

> - We will adopt a peer-surveillance approach which requires at least 3 peers to engage in the deployment process. They have the responsibility to remind the main deployer of any potential risk, and make sure each step complies with the deployment guides and norms.

> - In case anything abnormal happens during the deployment process, such as bad network status or insufficient deployment fee, we should calm down and have a discussion with peers to make sure each operation is safe. Meanwhile, we should mark down every command line and returned message for further reference.

I wonder if that’s enough stack of Swiss Cheese to prevent such an accident from happening again. Hopefully they expand on the “we should calm down” to not be limited to saying “calm down please”. Calming down is quite difficult when you’re in the throes of something, and proper procedures tend to be put aside for the sake of pressure relief.

I wish them swift recovery from their predicament.

Re: OptiFi Program Incident Report

#117
post #5

For all its flaws (and there are countless) the one thing about the show cryptocurrency space that stands out to me as a programmer is that programming errors can be suddenly very costly (granted, in this case it was more of a DevOps blunder). Being able to very easily put a price tag on sloppy programming is intriguing to me.

The level of self-perceived vs. actual competence in the crypto space never ceases to amaze.

A mea culpa of “The one thing we purport to be good at we actually have literally no understanding of and when shit doesn’t work we just run it a few times with different arguments.” My god.

Re: OptiFi Program Incident Report

#118
post #108

Earlier quoted context omitted.

>CitiBank can't get the money back they accidentally transferred to another company. Given it was an accidental early repayment of a loan, this isn't quite the slam dunk you think it is. If they had paid a company they didn't owe money to, they could get the money back through the courts. Crypto is meant to evade those courts.

The reason was not because of a repayment but because you wouldn't expect a respectable bank like CitiBank to do such a mistake. > “To believe that Citibank, one of the most sophisticated financial institutions in the world, had made a mistake that had never happened before, to the tune of nearly $1 billion, would have been borderline irrational,” he wrote. https://www.nytimes.com/2021/02/16/business/citibank-revlon-…

Not really. Right in the paragraph above that one:

> Recipients of cash wired in error are typically required to return it.

Re: OptiFi Program Incident Report

#120
post #50

Earlier quoted context omitted.

Apparently 95% of that money was by the company itself or employees of the company. So the loss for normal users is very limited.

I can take a box containing 1001 conkers, sell one to you for $1000, then claim that I have $1m in my bucket. What was lost was not money, but electronic conkers of which a small number people paid real money for.

The currency was USDC, which is a stablecoin pegged at $1 by Circle (www.circle.com) who are generally held to be reputable, so it very much was real money.
Post reply on HN