Live data from Hacker News

White hat hacker awarded $2M for fixing ETH-creation bug

cryptoadventure.com

241–250 of 354 posts

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#241
post #3

Prior discussion of this incident (and the $2M bounty) here on Hacker News: https://news.ycombinator.com/item?id=30289240 My (I'm the hacker) article / post-mortem this blog post is referring to: https://www.saurik.com/optimism.html At the time of this last getting traction a few days ago, some people were sad that the title of my article and the discussion that resulted focused more on the bug instead of the bounty…

Congrats. Love your work and glad you got a proper bounty!

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#242

Earlier quoted context omitted.

They revert the money (if they like you), but usually if money flows one way, something else flows the other way, and they can't revert that half of the fraudulent transactions without great expenditure. Often it's not worth it and they just write it off and the whole economy bears the cost. I'm not saying it's a better or worse plan than whatever might happen under an alternative system, but just that it's not exact…

Just imagine for a second if there was a bug in the US Treasury that let anybody order the treasury to print new money and deliver it to their bank account. That would rightly be seen as total incompetence by the treasury and cast doubts on the soundness of the entire monetary system. But with ETH we have the community patting themselves on the back for it. It’s madness. You are making a false equivalency when you co…

Are you sure there doesn't exist such a bug in the US Treasury? They would never in a million years let the public know if an exploit occurred, there's zero transparency

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#243

In other words: ETH was an insecure blockchain and once compromised, there is no legal or operational recourse, with the implication that issues could indeed exist today. House of Cards.

This is like saying that because someone is able to write buggy money transference software that lets users change their own account balance within _that buggy software_ that your personal bank is now insecure.

No it's not, though.

I expect that my bank is not perfectly secure. And when it fails, there will be ways to redress the problem, i.e. account insurance, bank refunds, legal recourses etc..

Blockchains have 'no way out'. When there is a problem, it breaks everything. Recently, there was a grift on ETH and to overcome the problem, there was a massive fork, which is enormously hypocritical because it implies that there are 100% 'Central Authorities' with ETH, who are unarmed, unrestrained by any regulation or oversight, policy and probably any legality. Etc.

The only way for Blockchains to maintain their ideological integrity is if they are 'perfect'. But they are not 'perfect' and require 'maintenance and oversight'. Ergo they are self defeating their own purpose.

Ultimately, it's a ruse or will mostly be used as such.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#244
post #200

Earlier quoted context omitted.

From the bounty: "The Summary On 2/2/2022, I reported a critical security issue to Optimism—an "L2 scaling solution" for Ethereum—that would allow an attacker to replicate money on any chain using their "OVM 2.0" fork of go-ethereum (which they call l2geth)." No - sorry - ETH doesn't get a 'pass' on this. The 'Rest Of The World' is tired of the Crypto Scam Delusion masquerading as something reasonable and watching th…

This was a critical success for Optimism's bug bounty program, if anything? No one got rug pulled. Optimism's liquidity could have been drained in the worst case, and still ETH L1 would remain unaffected.

It's great for a 'bounty program' - but it speaks negatively to the intercity of a system that is not supposed to have any centralised control.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#245
post #42

Earlier quoted context omitted.

So how many lambos are you buying? More seriously, will you keep it in the bank and extract $100k a year the rest of your life? What are you going to do?

I do not expect to make any major expensive lifestyle changes as a result of having more money (and to the extent to which I have already been being paid better recently due to working on Orchid, I have only barely done so and usually only quite temporarily), which I realize disappoints some people who had wanted me to post a concrete picture of something expensive I purchase to help motivate others to reach for bug…

[deleted]

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#246
post #200

Earlier quoted context omitted.

This was a critical success for Optimism's bug bounty program, if anything? No one got rug pulled. Optimism's liquidity could have been drained in the worst case, and still ETH L1 would remain unaffected.

It's great for a 'bounty program' - but it speaks negatively to the intercity of a system that is not supposed to have any centralised control.

I think it speaks to the reality of a development process lead by humans in uncharted territory. Figure it out, audit it, test it for a long time, eventually cross fingers and blow the fuses. After that, either it successfully becomes a permanent public fixture, or maybe there's a small chance it implodes one day, who knows?

Certainly anything that's absolutely mission critical should not live on these L2 networks yet.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#247

Earlier quoted context omitted.

Can you name any examples of cryptocurrencies being used that are not scams, ponzi schemes or for speculative purposes? All I see are people holding coins and not using them at all for anything else other than 'I want coin to go up'.

https://thegraph.com is one example. Tokens are used to have a stake as an indexer (data provider) and to pay for query fees (data consumption), and if indexers tamper with the data they lose their stake. It was released last year and has a long way ahead to mature, but it's an amazing product and tokens/blockchain is essential to its decentralized nature. Simply put, there is no way to accomplish this if the network…

Again, this can be done without using a blockchain.

Just like all the other coins, the only use case is burning up the planet by using Ethereum, BTC, etc, racking up high fees and being used by speculators while everyone else who invests in the ponzi scheme lose their money when it all crashes.

Nothing has changed.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#248

Earlier quoted context omitted.

No. People buy lottery tickets for a lot of reasons. It is a fun bit of escapism and entertainment that costs just a few dollars. You're making the assumption that everyone plays the lottery because they think it is a smart financial decision.

My only beef with lottery players is that they always take forever in the convenience store line.

Before I read this I was thinking this exactly!

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#249
post #206

Earlier quoted context omitted.

At the moment, USDC is the only stable coin I’m comfortable holding. Are there are any other stable coins that are like backed by hard assets?

What’s the reason of holding USDC, isn’t that same as holding cash in bank?

It can be used in smart contracts, DeFi (such as a decentralized crypto exchange or earning interest), and can be used for very fast transfers between centralized exchanges/services that might not allow actual USD deposits/withdrawals or that require waiting for an ACH transfer to go through. Several cryptocurrencies are good for transferring between centralized services, but USDC will be price stable in comparison. Fees can be a problem though.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#250
post #61

Earlier quoted context omitted.

Rich people of HN, is this true? I’d always heard each million is worth about $50k a year. Was that just during boom times, or simply mistaken?

Historically, 4% withdrawal rate is likely to last you at least 30 years with funds invested.* Currently people are pessimistic about stock market returns going forward so it could be lower (3-3.5%). And even lower if you want it to last longer than 30 years. * https://en.wikipedia.org/wiki/Trinity_study

The key is risk. Funds are definitely not risk-free. If you rely on funds to produce cash, chances are that, when 2008 happens, you get to spend a few years living on ramen. Sure, they might recover eventually, but in the meantime you have to sell the car to keep the lights on.
Post reply on HN