12 ms·
Zerocoin implementation bug
- wmf 10y agoWhat's better that stealing magic Internet money? Creating anonymous magic Internet money out of thin air, then selling it. Brilliant. But seriously, I'm not sure which is worse: Watching your stolen money move around the blockchain knowing you are helpless to do anything about it, or being provably unable to even tell the difference between "real" and "counterfeit" coins.
- jordz 10y agoWelcome to the world of 2017, where dreams really can come true!
- miguelrochefort 10y ago> out of thin air You don't understand economy.
- alvarosevilla95 10y agoBut that's literally what happened...
- NeuroKix 10y agoI'll just leave this here: https://www.youtube.com/watch?v=vaqhGyOxp8I https://www.youtube.com/watch?v=vaqhGyOxp8I
- deleted 10y ago[deleted]
- deleted 10y ago[deleted]
- StavrosK 10y agoI never thought I'd see counterfeit cryptocurrency, yet here we are.
- X86BSD 10y agoThat's NO different than what the "Federal reserve" does. Creates paper money out of thin air.
- matt4077 10y agoConsidering programmers almost exclusively deal in abstract ideas, and even their manifestation is in the realm invisible to the naked eye, it's surprising how hard it appears for many to grasp concepts such as "law", "culture", or "trust". So here we have a bunch crypto-anarchists with their usual "fiat is fiction"-spiel. Let me ask you to put your worthless paper money[0] where your mind is: I have drawn this wonderful $1 note, and will add as many zeros as you wish, giving you a 10-for-1 payout for useless US treasury fiat. oh well. At least every time one of these great new ponzi schemes finds a new way for provable-secure technology to be insecure, we can enjoy the knowledge that another $100mill is in the hands of a more worthy owner. [0] most of it isn't even paper, but apparently paper is a better symbol for evanescence than "electric charge" or "a linen/cotton-blend"
- dwaltrip 10y agoI think it's because it's difficult for even programmers to deeply grasp the slippery nature of the small scale abstractions we use in software projects. This is why design patterns are so easily misused. It's tricky stuff. The large scale, society-level abstractions and shared fictions, such as money, are a whole different beast.
- matt4077 10y agoI don't think the principle of money is actually that difficult. We've all had that moment in middle school where we realised that money would be worthless if everyone stopped caring about it. It's just that some people stopped running around wide-eyed telling others about this revelation a few days later. I guess we did get lucky in that the object of obsession they chose wasn't the law. Please don't tell them that murder is only a crime because enough people believe it to be or they'll throw us all in blockchains.
- brilliantcode 10y agoBlockchain and Cryptocoins will face the same fate HYIP forums / Liberty Reserves went through-regulatory enforcement and social stigmatization.
- wyager 10y ago> regulatory enforcement The only place regulatory enforcement could hit Bitcoin is at the fiat exchanges, which are already beholden to KYC/AML. > social stigmatization People have already tried that; "Bitcoin is only for illegal drugs and guns!" Didn't work.
- arglebarnacle 10y agoI mean sure, maybe they will. But people have been saying this for at least 6 years. When will this happen exactly, and why? Bitcoin may never achieve the status its proponents hope for, but interest from investors and the financial sector in bitcoin and it's underlying technology suggest it's unlikely to suffer this fate anytime soon. Unlike HYIP, which are a malicious scam, and LR, which essentially only existed for money laundering and had a single point of failure, bitcoin is at least some kind of innovation. This position isn't really better than the knee-jerk "bitcoin will replace the Federal Reserve". Both are based on feelings or ideology rather than research, and both fail to acknowledge the great uncertainty that clearly surrounds the future of bitcoin and blockchain technology.
- Kenji 10y ago>Creating anonymous magic Internet money out of thin air, then selling it. Well, not much different from what our banks do.
- hueving 10y ago>trading will resume once pools and exchanges have had time to update their code. A new release will be pushed out pretty soon. Does this imply this company has the power to stop all trading on the currency? If so, why would anyone ever want to use this?
- tlrobinson 10y agoNo, it implies they can nicely ask the exchanges to stop all trading, and the exchanges can make that decision or not.
- qeternity 10y ago> Prior to this announcement we had disclosed the hack to the exchanges for them to assist in our investigations. No, but it does sound like they disclosed the vuln to exchanges before announcing so that trading could be halted and patches applied.
- aftbit 10y agoHmm, I know about Zcash and Monero, but I haven't read much about Zerocoin. I'll be staying away, especially after a 410 BTC hack. They even cited the ability to detect hacks like this as a key advantage over Zcash. http://blog.zcoin.tech/zcoin-and-zcash/ http://blog.zcoin.tech/zcoin-and-zcash/
- arez 10y agoall these blockchain currencies seem to have really good bug bounty programs, this one gave out almost half a million dollars (410BTC)
- Cyphase 10y agoSeriously though, anyone who could find a serious bug in Bitcoin could cash in.
- brilliantcode 10y agoEthereum takes the record for paying out $53 million dollars (943 BTC X 53 = lots). Technically, it wasn't even theft or a bug since Ethereum & DAO proudly claimed "Code is Final Law". I almost feel like cryptocoin and blockchains are set out to do 1 thing really well-show how superior centralized systems are and how easy it is to trick people with pseudo academic jargon-just read Vitalik's writing peppered with superficial pseudo-academia-charlatan pendant language it's zealots gladly eat up-with little to know effort to dissect and analyze fact from fiction.
- wyager 10y agoWhile I don't feel that your argument generalizes (e.g. Bitcoin actually probably is the best extant value exchange mechanism in many ways), the whole Ethereum thing was embarrassing. People fell for the mumbo-jumbo and then the whole project rendered itself pointless by going back on its "code is law" principle.
- blunte 10y agoIn a way, they did actually prove that code is law - but they proved that "currently consensus-agreed-upon code is law." That old buggy code was law until the new code became law and changed the rules :). But of course its redundant to say "current code is law" because it's obvious by the logic of how consensus works. The confusion for people was their belief that code at one point in history would forever remain "the law".
- ng12 10y ago> A typographical error on a single additional character in code Really wonder what this was.
- epmatsw 10y ago== vs = perhaps?
- emmelaich 10y agoYeah that seems quite possible. (And people mock me for putting constants first! i.e. if (someconstant == somevar) { ... [edit: nope, looks like this is it] https://github.com/zcoinofficial/zcoin/commit/b20c177032de3c4bfae62b5ada768a5dc2b4fa67 https://github.com/zcoinofficial/zcoin/commit/b20c177032de3c...
- daira 10y agoNo, that is not the bug. See Ian Miers' comments.
- desdiv 10y agoAnyone know which line of code they're talking about? I took a glance at their Github bug tracker and couldn't find any references to this bug. [0] https://github.com/zcoinofficial/zcoin/issues?q=is%3Aissue+is%3Aclosed https://github.com/zcoinofficial/zcoin/issues?q=is%3Aissue+i...
- ycmbntrthrwaway 10y agoBetter look at commits. I am not familiar with their code base, but latest commit seems like a bugfix: https://github.com/zcoinofficial/zcoin/commit/33796c839f7d4df4fb89c2775ec971982cfc8996 https://github.com/zcoinofficial/zcoin/commit/33796c839f7d4d...
- gukov 10y agoLooks like they replaced a 50 with a 100.
- notimetorelax 10y agoSo... were's a unit test to make sure this never happens again?
- edsouza 10y agoI rather actually see a real comment if there is no time to create a unit test. Why does changing ZQ_PEDERSEN to ZQ_WILLIAMSON fix the bug? Having meaningful named constants would make much more sense. Edit: On full view of the code, the bug could be avoid if they broke out the if <demoninationX> blocks into their own function, and to prevent "typo" errors, it would be good to have a local variable named current_demoniation = demoniationX, and then reference that local variable instead of referencing the constant everytime.
- Rangi42 10y agoApparently those are names for 50 and 100 BTC. From this presentation[1] or the source code[2]: 1 Lovelace = 1 Bitcoin 1 Goldwasser = 10 Bitcoin 1 Rackoff = 25 Bitcoin 1 Pedersen = 50 Bitcoin 1 Williamson = 100 Bitcoin But yes, those are meaningless names in themselves. Metric prefixes like "hectobitcoin" would be better. [1]: https://sar.informatik.hu-berlin.de/teaching/2013-w/2013-w%20Electronic%20Identity/slides/Anonymit%C3%A4t_in_Bitcoin_.pdf https://sar.informatik.hu-berlin.de/teaching/2013-w/2013-w%2... [2]: https://github.com/Zerocoin/libzerocoin/blob/master/Coin.h#L19-L27 https://github.com/Zerocoin/libzerocoin/blob/master/Coin.h#L...
- josu 10y agoThe current market cap of Zcoin is 1,538 BTC [0], so this person created 1/4 of all the coins in circulation (410 BTC), and these guys are saying: "We knew we were being attacked when we saw that the total mint transactions did not match up with the total spend transactions". It took them way too long to realize that they were being outsmarted. EDIT: u/aftbit also posted this on the thread: "They even cited the ability to detect hacks like this as a key advantage over Zcash. [1]" [0] https://coinmarketcap.com/currencies/zcoin/ https://coinmarketcap.com/currencies/zcoin/ [1] http://blog.zcoin.tech/zcoin-and-zcash/ http://blog.zcoin.tech/zcoin-and-zcash/
- desdiv 10y agoOr alternatively, the developers designed this hard-to-find typo/bug years ago and have now just quietly cashed out.
- meowface 10y agoSeems very unlikely since it would inevitably cause many to lose faith in the currency. If they really want to cash out, they can just do what almost every other upstart cryptocurrency founder does and make it clear they're taking some of the pie.
- GrinningFool 10y agoIf they just want out, the things that happen to the currency don't matter to them - they're already gone.
- koolba 10y agoSo who eats the loss for this?
- thinkloop 10y agoEvery owner eats a tiny bit of it with the downward pressure on value caused by the artificially increased supply. Also, decreased trust reduces demand pressure further lowering value for everyone.
- brilliantcode 10y ago"In a decentralized economy, one person's mistake must be distributed to the collective." Hackers rob the mortgage downpayment you made with Bitcoin, said platform gives everybody an haircut because platform provider won't take responsibility and claim it's the cost of decentralization without really understanding the responsibility of the platform still falls upon the main facilitator. What a great new thing decentralized economy is, everyone will be dying to get in on the action!
- oh_sigh 10y agoIt's not really a tiny bit... ~30% of the networks value was fabricated.
- alvarosevilla95 10y agoAnd every coin owner took a tiny bit of that loss.
- deleted 10y ago[deleted]
- Cyph0n 10y agoExploiting such a tiny bug is damn impressive if you ask me. The bloke who pulled this off deserves the cash.
- nemo1618 10y agoUnless the "bug" was inserted by a developer... I'm really curious to see the "single character" in question and assess whether it might have been intentional.
- fpgaminer 10y agoLet me get this straight. Zerocoin has a bug, money gets stolen, the bug is fixed. Everyone in the comments lose their shit and call doom and gloom for all cryptocurrencies. The experiment is failed, centralization was right all along! Meanwhile, centralized systems like credit cards are stolen en masse, identity theft abounds, anybody can file your taxes with the IRS and collect your refund, and an ACH can be initiated against your bank account using all the information helpfully printed on every check you hand to strangers... and no one bats an eye? I don't get it.
- wmf 10y agoThere is an excess of schadenfreude here, but people are only judging cryptocurrencies against their own inflated claims.
- drcode 10y agoNot really sure where the "shadenfreude" comes in if ethereum was originally sold for 30 cents per ether and is now about 13 dollars an ether.
- kentonv 10y agoStating the obvious here, but... Fiat financial security is based on monitoring, paper trails, and legal consequences for fraud. Yes, you can initiate a fraudulent ACH knowing only the numbers printed on a check you received, but you'll probably end up in jail for it. It's far from perfect but it mostly works. Cryptocurrency intentionally doesn't have any paper trails. Anonymity is the selling point. If you find a bug in the code and exploit it, the anonymity protects you and you likely won't be caught. That means that security depends entirely on the code (and the theory!) being correct. So yes, when bugs in fact lead to massive amounts of money being lost... some point are going to argue that cryptocurrency may not be a good idea. (Note: My personal opinion is mixed.) > Zerocoin has a bug, money gets stolen, the bug is fixed. You say this as if it isn't a big deal. Sure, the bug is fixed, but the attacker essentially stole 25% of everyone else's zcoin (via inflation), and fixing the bug doesn't bring any of it back. That seems like a big deal to me.
- ianmiers 10y agowhat went wrong: TLDR probably Ctrl-C,Ctrl-V. (Just to be clear, this is about Zcoin, not Zcash/Zerocash. The two are completely different) The fix is here. https://github.com/zcoinofficial/zcoin/commit/33796c839f7d4df4fb89c2775ec971982cfc8996 https://github.com/zcoinofficial/zcoin/commit/33796c839f7d4d... What happened? First, some stylized facts about ZCoin: 0) ZCoin is a fork of Bitcoin that uses a 4 year old academic research library, libzerocoin, to make anonymous payments using the Zerocoin protocol. 1) Unlike Zcash/Zerocash, the Zerocoin protocol has only fixed value coins. 2) To get multiple denominations, you have completely separate instances of the anonymous currency that just happen to live on the same blockchain as the other denominations. 3) Zerocoin has its own bitcoin like non anonymous base currency. Call it basecoin. 4) You spend basecoins to get zerocoins. 5) When you spend zerocoins, you get basecoins. 6) ZQ_WILLIAMSON and ZQ_PEDERSEN are denominations, worth 100 and 50 respectively, defined in libzerocoin. So what went wrong? When you convert a zerocoin into 100 basecoin, the ZCoin code forked from bitcoin checked if the coin was a valid instance of ZQ_PEDERSEN (worth 50 ) not ZQ_WILLIAMSON (worth 100). So you paid 50 for the zcoin,got it into the instance for ZQ_PEDERSEN, but got back 100. Free money. Why did this happen? Well, it looks like in order to support the multiple denominations libzerocoin offers, the ZCoin developers wrote some code for one denomination and then duplicated it for each remaining denomination. There are five in total, ZQ_LOVELACE=1,ZQ_GOLDWASSER=10, ZQ_RACKOFF = 25, ZQ_PEDERSEN = 50,ZQ_WILLIAMSON = 100. But on the last one, ZQ_PEDERSEN was not changed to ZQ_WILLIAMSON in a few places. This caused the bug. Caveat: I have nothing to do with ZCoin. However, I am an author of the zerocoin protocol, libzerocoin, the zerocash protocol, and am involved with Zcash.
- ballenf 10y agoAny idea why they would describe the code error as "a single additional character in code"? It looks like about 10 characters or so based on your link. There are also some other code changes associated with that commit
- ianmiers 10y agoI have no idea. If you can find a single character edit in the commit history, I will look at it. But this certainly is a bug. And it would allow you to steal funds.
- Entalpi 10y agoFinally money can have bugs.