Live data from Hacker News

A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

medium.freecodecamp.org

171–180 of 440 posts

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#171

Is it possible to track where the money goes from the hackers account onwards? Or is then opaque? How easy will it be for the hacker to move the funds around so it cannot be traced back to the theft?

It is, but it turns out exchanges don't actually care. Bitcoins from the Bitfinex hack are slowly being dumped on exchanges, for example. It's like someone rocked up to a bank with a big duffelbag full of dye-stained notes known to have been stolen from another bank, and went "no worries lol".

Well, it's unlikely the coins when straight from the hack accounts to the exchange accounts (they might have, i'm not sure in this case)

The coins just have to go through a single intermediate account for there to be doubt that the hacker still owns them

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#172
I have to expect that some bug like this has surely happened with a traditional bank too, causing them to lose a bunch of money. Humans inevitably write buggy software regardless of the platform. The difference with blockchain-based currencies is that their failures are forced to happen in public. I'd be interested to know what banks do when they discover that something doesn't add up in their ledger. I can't believe that it has never happened and never will.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#173

> Having sounded the alarm bells, a group of benevolent white-hat hackers from the Ethereum community rapidly organized. They analyzed the attack and realized that there was no way to reverse the thefts, yet many more wallets were vulnerable. Time was of the essence, so they saw only one available option: hack the remaining wallets before the attacker did. > By exploiting the same vulnerability, the white-hats hacked…

> something is very wrong with your system To be clear, neither of the two situations is "more moral" than the other. In the end however, the question remains: who you trust. Governments have resolved the question long ago (by enforcing trust), cryptocurrencies are just now starting to face the same question. You are correct however that who you Trust remains the greatest issue behind creating a currency.

Look, no. One hundred times, no.

Governments in the west are quite accountable, voted for and with a system of checks and balances that has evolved over time, through wars and revolutions.

Some random benevolents overlords (white-hat hackers) that save you just because they are magnanimous was the only option only in the most primive societies.

Thankfully we moved on from those times, don't you agree?

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#174
post #88
post #55

Earlier quoted context omitted.

I grant your point, but disagree with your framing of the problem. I think a good analogy here is to compare to American settlers. You're going to have a few waves: the explorers who move into totally uncharted territory and take on significant risk by using smart contracts. These are kinda crazy people who love the innovation, and I'd argue this is the majority of people in the space right now. Eventually there will…

Serious question: How can smart contracts create the "proper" trustless environment for most workplace contracts? For example, stock option agreements are usually pretty straightforward... until a termination date has to be decided on. How does the termination get put into the contract? Though I suppose smart contracts could exist as an automation mechansim , but there's a "wrapper contract" that provides "real deal"…

They can't do that on their own - interaction with the physical world requires a trusted party to decide/verify if a particular real world condition has been met or not.

Coincidentally, that's (part of) the role our court system plays in contract disputes; but there are other existing systems e.g. arbitration.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#175

Earlier quoted context omitted.

I do get it. I just don't think that's realistic. What smart contracts should be according to you is mostly irrelevant to how the law will treat them.

You still don't get it. The law will not have anything to say about smart contracts because the law will not be able to enforce a contract one way or another depending on some judge but it will simply execute and that's the end of that . This so that some guy in China or India and some guy in the United States can agree on terms without having to haggle over whose legal jurisdiction will kick in if and when there is…

The "contract execution" can't touch anything in the real world. People do that. Maybe a "smart contract" says Joe Hacker is entitled to reside in 168 Park Avenue. Maybe everyone on the Ethereum blockchain agrees that Joe is entitled to reside in 168 Park Avenue. If a judge rules that it's Bob's house and Joe has no right to be there, that's gonna trump all of that, if only because the judge has more people with guns to call on.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#176

I think the fundamental problem here is an economic one. Make three assumptions: 1) most contracts worth implementing in Ethereum are fairly complex 2) even given great developers, bugs are inevitable in complex code 3) the budget of the contract-makers' security team MUST be smaller than that of the hackers You quickly see that if the chance of a bug is nonzero, "smart contracts" don't make economic sense. If you ha…

Your logic doesn't add up. Attackers are only willing spend $90k if there's a 90 percent chance they can exploit a bug in the contract to extract the entire $100k value. Clearly if TWO hackers both spend $90k and only one extracts the value, the other one has lost their entire $90k - unless there's a way to be sure you are the one who will win that, your expected return on the $90k is only $50k if there are two parti…

People here love to extol the virtues of cash, but most decent law-abiding folk prefer to keep their assets in safer forms for precisely that reason.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#177

Earlier quoted context omitted.

> Next time, I'm going to use this case as a counterexample, because when the solution to the problem of "hackers robbing banks" is "vigilantes robbing the remaining banks", something is very wrong with your system I can see what you're saying, but I don't think that this is a problem with cryptocurrencies specifically , it's a problem with buggy software, yes, but it's something that is the case with every dangerous…

This is a problem that everybody seems to skip over with cryptocurrencies. Cryptocurrencies are being sold as eliminating trust and allow us to rely on the cold certainty of mathematics. Only trust hasn't been eliminated from the system, it's just been shifted from a central bank to the authors of the software client you're using. To the majority of the miners in the network. The awful politics, lies, greed, corrupti…

Love my job, since I've been bringing in $82h… I sit at home, music playing while I work in front of my new iMac that I got now that I'm making it online… •••••••••>>http://ow.ly/iBXm30dNtIZ

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#178
post #96

Earlier quoted context omitted.

>I wonder how do you ride your plane then? When I was in physics undergrad, I remember talking to engineering students taking statics. In general physics, we were allowed to make simple numerical errors, the emphasis then was on figuring out the solution and understanding the physics. My friends on the other hand complained how they, after acing gen. physics, would get mercilessly docked off points for minor arithmet…

That means there is an entrepreneurial prospect for you to enter the space with a team that has a more serious background, right? Eventually people will generally understand that contracts require serious correct engineering, and you'll be able to capitalize on expertise. Smart contracts have only been generally available for like a couple of years. Most people are clueless about how to do them properly. That means i…

The kind of person who's risk-averse enough that they'd pay extra for a better contract engineer is probably not the kind of person who's using smart contracts at all. And buying contracts is lemon market, which is only really solvable via regulation - but its biggest fans are regulation-averse people.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#179

Earlier quoted context omitted.

> something is very wrong with your system To be clear, neither of the two situations is "more moral" than the other. In the end however, the question remains: who you trust. Governments have resolved the question long ago (by enforcing trust), cryptocurrencies are just now starting to face the same question. You are correct however that who you Trust remains the greatest issue behind creating a currency.

Look, no. One hundred times, no. Governments in the west are quite accountable, voted for and with a system of checks and balances that has evolved over time, through wars and revolutions. Some random benevolents overlords (white-hat hackers) that save you just because they are magnanimous was the only option only in the most primive societies. Thankfully we moved on from those times, don't you agree?

Your Whig history of an ever progressing political system is not accurate in my opinion.

I've written this comment before, and I'll repeat it as it's relevant to your comment:

Societies have gradually grown more unfair as the political system has strained under their growing complexity. According to political scientists, the average voter has an extremely limited understanding of what their government is doing. The typical person's understanding of economics is similarly extremely limited.

This opens the door to manipulation by demagogues and special interests. The growing control that government exerts over society, seen in everything from the emergence of a mass-surveillance system of unprecedented scope, to the number of regulations on the books, to the percentage of GDP made up of government spending, is not healthy, and needs a counter balance in privacy technology that empowers the individual and limits the Kafkaesque tendencies of collective society.

Re: A hacker stole $31M of Ether – how it happened, and what it means for Ethereum

#180

Earlier quoted context omitted.

Whether or not you (or anyone else) think the law should influence the outcome of smart contracts...it certainly does. So far a few states (US) have passed laws regarding "blockchains", "smart contracts" and the like. For example, seeking to avoid any legal uncertainty surrounding blockchain transactions and smart contracts relating to certain digital assets, Arizona passed HB 2417, the following on point: - A very s…

It's not about whether or not it should, I'd be happier living in a world where they can be, but since the whole goal is that it can't and there are people working really hard on trying to achieve that goal it would be more realistic to adjust to the eventuality that it will at some point be done. The biggest stick that governments have is that they could make it illegal for their constituents to engage in smart cont…

Smart contracts are not laws of nature, they are contracts. I totally agree you could come up with a few examples where enforceability would be a practical impossibility, but that's also the case with standard contracts.

Just like the Arizona law I cited restricting use of smart contracts for "fire arm tracking", the law could restrict smart contracts in all sorts of ways to protect the public. Examples:

-drafters of smart contracts must be licensed and bonded/insured

-parties to smart contracts must purchase insurance to coverage sufficient to cover losses in full

-criminal liability when marketing materials are inconsistent with the smart contract itself (see: DAO)

-just like many contracts, deeds, trusts must/can be filed with the state...the states could require the same of smart contracts

Now I understand such laws undermine the purpose/intent of many smart contract opponents, but my point is judges/legislature are not powerless insofar as the laws of nature.

Post reply on HN