Live data from Hacker News

White hat hacker awarded $2M for fixing ETH-creation bug

cryptoadventure.com

281–290 of 354 posts

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#281
post #246

Earlier quoted context omitted.

It's great for a 'bounty program' - but it speaks negatively to the intercity of a system that is not supposed to have any centralised control.

I think it speaks to the reality of a development process lead by humans in uncharted territory. Figure it out, audit it, test it for a long time, eventually cross fingers and blow the fuses. After that, either it successfully becomes a permanent public fixture, or maybe there's a small chance it implodes one day, who knows? Certainly anything that's absolutely mission critical should not live on these L2 networks ye…

"I think it speaks to the reality of a development process lead by humans in uncharted territory."

Yes, exactly, and that's why we can't have distributed systems with 'no central authority' - if those systems are inherently and always faulty there needs to be intervention of some kind by an 'authority'.

There is no such thing as a trestles system, the whole thing depends on webs of trust.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#282

Earlier quoted context omitted.

The whole assumption that your ethics have a pricetag attached is faulty, it's not as if the choices were 'commit crime / get bounty'.

Everyone’s ethics have a price tag. It’s better not to pretend otherwise, since it clarifies a lot of human behavior.

Many people's ethics have a price tag.

Don't bleed all over us!, or let others bleed on us.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#283

In other words: ETH was an insecure blockchain and once compromised, there is no legal or operational recourse, with the implication that issues could indeed exist today. House of Cards.

Ethereum has forked to roll-back hacks in the past, likely for something as big as making ETH from thin air they'd do the same with even less hesitation.

Yes, and they can do it for whatever reason they want. One might argue therefore that ETH is centrally controlled, and with considerably less oversight and reasonable oversight than, for example, most central banks.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#284
post #164

Earlier quoted context omitted.

The bounty amount was denominated in USD and is being paid in USDC (a stable coin, which is means it is intended to map effectively 1:1 with--in this case--USD).

At the moment, USDC is the only stable coin I’m comfortable holding. Are there are any other stable coins that are like backed by hard assets?

UST?

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#285
post #200

Earlier quoted context omitted.

This was a critical success for Optimism's bug bounty program, if anything? No one got rug pulled. Optimism's liquidity could have been drained in the worst case, and still ETH L1 would remain unaffected.

It's great for a 'bounty program' - but it speaks negatively to the intercity of a system that is not supposed to have any centralised control.

Optimism, Arbitrum, and other Ethereum L2 rollups plan to have decentralized sequencers.

It’s all new technology so they’re taking it slow.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#286

Earlier quoted context omitted.

Not sure it's actually applicable. That Reddit comment is about poor people winning lots of money by chance, not smart people earning lots of money by working. The risks are very different, not to say that the scale between 2 million and 170 million is way bigger than you seem to think.

> is about poor people winning lots of money by chance, not smart people earning lots of money Assuming that was unintentional, now might be a good opportunity to reflect on unconscious bias.

I come from a poor family and now my family is no longer poor because of my work. I wouldn't say I'm smarter than the average person, but somehow I'm luckier. But with that said, I don't seem to be even smart enough to realize what unconscious bias you're referring to, care to spread some light for me?

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#287
post #164

Earlier quoted context omitted.

The bounty amount was denominated in USD and is being paid in USDC (a stable coin, which is means it is intended to map effectively 1:1 with--in this case--USD).

At the moment, USDC is the only stable coin I’m comfortable holding. Are there are any other stable coins that are like backed by hard assets?

USDP (Paxos) and surprisingly, BUSD (Binance USD) which is just a white labeled version of USDP, also managed by Paxos.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#288
post #246

Earlier quoted context omitted.

I think it speaks to the reality of a development process lead by humans in uncharted territory. Figure it out, audit it, test it for a long time, eventually cross fingers and blow the fuses. After that, either it successfully becomes a permanent public fixture, or maybe there's a small chance it implodes one day, who knows? Certainly anything that's absolutely mission critical should not live on these L2 networks ye…

"I think it speaks to the reality of a development process lead by humans in uncharted territory." Yes, exactly, and that's why we can't have distributed systems with 'no central authority' - if those systems are inherently and always faulty there needs to be intervention of some kind by an 'authority'. There is no such thing as a trestles system, the whole thing depends on webs of trust.

I guess we’ll find out Soon(TM). Trustless computation is the plan. Maybe it’s possible to build a system that’s correct/antifragile enough, when you restrict yourself to some hundreds of lines of code tops?

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#289
post #3

Prior discussion of this incident (and the $2M bounty) here on Hacker News: https://news.ycombinator.com/item?id=30289240 My (I'm the hacker) article / post-mortem this blog post is referring to: https://www.saurik.com/optimism.html At the time of this last getting traction a few days ago, some people were sad that the title of my article and the discussion that resulted focused more on the bug instead of the bounty…

Wow, what a find. And save. Very well deserved reward too.

Wondering (some of it aloud), how long was the vulnerability present in the code? Is it possible to know if someone was actually using this exploit to mint OETH's? How would a disconnect of this sort show up? Regular reconciliation (hourly, daily) or perhaps there are other methods.

Re: White hat hacker awarded $2M for fixing ETH-creation bug

#290
Why is there such hostility towards crypto?

I can understand the anger at Proof-of-Work cryptos, or perhaps the current somewhat "wild west" state of them, where fly-by-night operations work to separate people from their money, but ultimately I see them as the wave of the future.

Ultimately I think the cryptos that see the most success will likely be those that can be better regulated, which is somewhat at odds with why crypto came about, but without some protection it would be like an unregulated stock market.

Post reply on HN