28 ms·
Attempt to Reverse a $55 Million Ether Heist
- deleted 9y ago[deleted]
- passivepinetree 9y ago"Just as the global WannaCry ransomware attack in May laid bare weaknesses in computer operating systems, the DAO hack exposed the early frailties of smart-contract security and left many in the community shaken because they hadn’t found the bug in time. " This seems like a tenuous connection at best.
- atomical 9y agoIs it even illegal to hack Ethereum? Some purists would say the smart contract was behaving as written.
- stale2002 9y agoWhether something is "illegal" is a function of the court system. So the question is, could you convince a jury that it is illegal?
- dboreham 9y agoThat's an easy "yes".
- wwwv 9y agoShould be easy to describe then.
- yorwba 9y agoIANAL, but here is how I would argue: The DAO was created with the intention to allocate its funds according to a certain voting scheme, with everyone's power determined by the number of tokens they held. But the program did not correctly implement this intention, and the DAO hack exploited the difference to bring the funds under control of the attacker. This most likely violated the Computer Fraud and Abuse Act, and was thus illegal.
- Zarath 9y agoAs I understand it, the DAO website explicitly stated that the code of the contract superseded any written or stated intent. Basically: The code is the law.
- bhaak 9y agoI can write anything on a website. That doesn't mean that it is legally binding.
- moomin 9y agoThe behaviour of the founders would almost certainly mean the phrase was interpreted as advertising rather than a legal commitment.
- jessaustin 9y agoAdvertisers are occasionally held to some sort of legal commitment with respect to statements made in their ads. The "hackers" in this case might claim they wouldn't have invested their money if they hadn't believed the ad...
- PeterisP 9y agoThe actual law is the law, and contract law (and criminal law i.e. regarding fraud) states that the intent does matter. The DAO website doesn't make legislation - the code may specify the rules about which transactions the Ethereum system will approve, but in the real world the actual laws matter and they will determine whether some people will have their stuff taken away, their movement restricted, or be forced to do some transactions in the Ethereum system.
- stale2002 9y agoSure, the law cares about intent. But the question that is to be debated is, was the intention of the DAO too follow the code of the contract EVEN IF it had a bug. There is an argument to make that, given that "the code is law" was plastered all over the DAO, that being hacked and having all their money stolen, was explicitly allowed.
- skinnymuch 9y agoCan't you ask for a case to be heard only by a judge? So the judge actually has to understand everything and go strictly by the law?
- pmyteh 9y agoDepends on the jurisdiction (and the crime). In the UK, for the most serious (indictable-only) crimes, then no. But you can ask the judge to end the trial after the prosecution case if no reasonable jury could convict, including if as a matter of law no crime has been committed.
- wwwv 9y agoThe principle of Ethereum is that code is law, the "hacker" followed the law to the letter and acted in a prescribed manner. What's the crime here exactly?
- DINKDINK 9y agoThe ethereum foundations reaction to the DAO hack proved that the "code is the contract" is not true. Which questions the very value of smart contracts on the ethereum blockchain because it's proven that they're immutable now This is a good discussion: https://www.bloomberg.com/view/articles/2016-06-17/blockchain-company-s-smart-contracts-were-dumb https://www.bloomberg.com/view/articles/2016-06-17/blockchai...
- wwwv 9y agoAll obfuscation around a central controlling group that have the ability to reverse any transactions they don't like or negatively financially impact them, in other words.
- tajen 9y agoSaid "hacker" could even take Ethereum to a civil court and win a trial for changing the DAO's code: Ethereum long claimed that transactions were unrevokable and only contracts had value, causing tort to the hacker when rules were reversed... Given the number of people involved, it could even be juged as organized crime against one person...
- vuyani 9y agohmm true. Maybe smart contracts also need a good old fashioned terms & conditions signed. At least that protects against unknown bugs and exploits?
- MereInterest 9y agoIn that case, they are no longer smart contracts. The entire appeal was that they would be knowable in their entirety, automatically executed, and irrevocable. The goal as I understood it was too have something that would enforce itself, not needing an external authority to interpret it. Instead, as others have pointed out, the hard fork demonstrated that this was not at all the case. Ethereum contracts can be voided, and the entire premise is therefore flawed. Terms and conditions would just be another way that contracts could be voided, another flaw.
- AJRF 9y agoIt isn't, if you take the case under contractual law there is absolutely no basis to charge the person who extracted the $55m. The contract had 'flaws' but it was the contract, so tough cookies it agreed to something you didn't like, but you wrote it! (Except we know now it was too big to fail, which in turn means centralization) The DAO was pumped up by VCs and friends of the founder of Ethereum, which, before the launch, attracted some people who had clout from the big banks and enterprises, ergo, if the DAO failed then Ethereum failed in the eyes of the most lucrative customers & developers there. The thing that pissed of purists so much was, that when it first came out it was marketed as this beautiful "world computer" that would be incorruptible by anyone, but the hard fork made it apparent that the values of the Ethereum community had changed to value support of banks & business over that idea. I was at a conference this week and watched a lecture by one of the founding board members of the Enterprise Ethereum Alliance, who was getting the crowd fired up about the idea of ICO's, and then directly after his talk, David Birch from Consult Hyperion came on and said that people who are involved in the launch of new tokens in this current feverish phase are extremely likely to go to jail for fraud. Was hilarious
- Jabanga 9y agoDavid Birch has been bashing cryptocurrency since around 2012. It seriously goes that far back for some of these ideologues. Edit, just to give people an idea of where he's coming from ideologically, these are some of his comments that show the kind of world he wants to see: https://youtu.be/c8mdr8iwX20?t=6m49s https://youtu.be/c8mdr8iwX20?t=6m49s "law-abiding taxpayers like me are subsidizing criminals to use cash and not pay taxes" https://youtu.be/c8mdr8iwX20?t=10m47s https://youtu.be/c8mdr8iwX20?t=10m47s "so getting rid of cash has some other benefits which will lead to unexpected changes. For example for economists, getting rid of cash means that you lose the zero lower bound on interest rates. You can't have interest below zero because if you drop interest rates below zero people will just draw out the cash and just hold it. If you don't have cash you can have negative real interest rates. So getting rid of cash has a lot of benefits." https://youtu.be/c8mdr8iwX20?t=13m55s https://youtu.be/c8mdr8iwX20?t=13m55s "So if you allow us technologists to build the stuff so we build something like Bitcoin which let's pretend it's anonymous. Do you know what you get if you let us build that? You get a giant electronic Somalia. If you want to live in a society which is entirely driven by anonymous cash, where the rich aren't accountable anymore, where whoever's got the most money can be the warlord and do what they like, well that's what you're letting us build now" His demonization of cash remind me of this: "The cashless society – which more accurately should be called the bank-payments society – is often presented as an inevitability, an outcome of ‘natural progress’. This claim is either naïve or disingenuous. Any future cashless bank-payments society will be the outcome of a deliberate war on cash waged by an alliance of three elite groups with deep interests in seeing it emerge" https://aeon.co/essays/if-plastic-replaces-cash-much-that-is-good-will-be-lost https://aeon.co/essays/if-plastic-replaces-cash-much-that-is...
- roryisok 9y agoThis Post Title Needs Sentence Case, More Words Ether thief remains a mystery, one year after $55m digital heist
- SolarNet 9y agoPart of the problem is they based this language off of JavaScript on purpose no less. It should be hard to make mistakes like this yet a single capitalization would change the semantic meaning enough to prevent this! Terrible design choices for a financial banking language.
- dyscrete 9y agoSolarNet what makes you think it's based on js
- vuyani 9y agoSolidity is a contract-oriented, high-level language whose syntax is similar to that of JavaScript and it is designed to target the Ethereum Virtual Machine (EVM). http://solidity.readthedocs.io/en/develop/ http://solidity.readthedocs.io/en/develop/
- MichaelGG 9y agoThat's more the fault of choosing bad function names, not case sensitive language features.
- codedokode 9y agoThe problem is not in a language but in poor choice of naming scheme that made it easy to pick the wrong function.
- vfclists 9y agoThat page is virtually unreadable. Why the fancy CSS, Javascript and fonts?
- devdoomari 9y ago> ". Over email, he said, “We might be up the creek ;).” Later, when Gün pointed to the error in line 666, Daian replied, “Don’t think so.” well, isn't the financial law against this kind of incompetence in the first place? I don't think the thieves would be guiltier than the team behind DAO. ps: and line 666??? who the hell keeps a single source-code file that big? no wonder bugs are around...
- pjc50 9y agoBlockchain currency advocates like to claim that the law doesn't apply to them. Line 666 is an entertaining coincidence but that is really not that large a file for most languages.
- dmix 9y ago> Blockchain currency advocates like to claim that the law doesn't apply to them. Example? Or do you just mean like every financial organization ever (even beyond Wall St) that pushes back on regulatory oversight? Attempting to regulate Ethereum with human gatekeepers sounds ridiculous to me, especially at this point, and entirely defeats the purpose of the whole system. These people who put money into that DAO fully knew the risks of what they were doing. And none of them are calling for centralized oversight from the US gov as a result. So I'm not sure who this would be protecting or helping.
- mannykannot 9y ago> Attempting to regulate Ethereum with human gatekeepers sounds ridiculous to me, especially at this point, and entirely defeats the purpose of the whole system. The problem is that Ethereum cannot live up to its intended purpose, at least not the hyped, pie-in-the-sky purpose that it is being promoted with. >These people who put money into that DAO fully knew the risks of what they were doing. Pretty clearly, they did not - and when it went pear-shaped, they abandoned all their principles to rescue themselves from the situation they had created. They appointed themselves as agents with more powers than any statutory regulator has.
- kator 9y ago> Another decision he made when he had no idea of the bug shows how quirky and unforgiving code can be. “If the capital ‘T’ in line 666 had been a small ‘t,’ that would also have prevented the hack,” he says. Can someone familiar with this explain how something financially based can have a capitalization flaw? I would expect a smart contract language to have very strict type and variable linking. Humans make many mistakes in coding but most of the time it doesn't cost $55m. A transaction language should be very strict so either the smart contract language is flawed or the author of this article is overstating something for dramatic effect. EDIT: Found this: https://github.com/slockit/DAO/blob/v1.0/DAO.sol#L666 https://github.com/slockit/DAO/blob/v1.0/DAO.sol#L666 on a deeper dive: http://hackingdistributed.com/2016/06/18/analysis-of-the-dao-exploit/ http://hackingdistributed.com/2016/06/18/analysis-of-the-dao...
- kefka 9y agoThat's primarily because Ethereum is pure amateur hour. When Bitcoin had built in checksums on addresses, Eth Dev's just said "watch where you send money". They ended up having to later add in a capitalization scheme to serve as a hash. I have no clue how they managed to fool so many people with poor and shoddy work. But they have so far. And they've fooled everyone that this is a 'hack' even after saying time and again "The code is the contract, and the contract is the code"... Unless lead devs lose money.
- pmorici 9y agoTheir greatest skill is marketing.
- NicolaiS 9y agoThe 't' vs 'T' has _nothing_ to do with checksums. `Transfer` and `transfer` are two different functions, one creating an "event" (think a signal on the blockchain) and the other actually transfering tokens. The true flaw lies in the reentrant attack on `.send()`
- Laaas 9y agojesus christ, who the fuck would make two identical symbols differentiated by only capitalisation? (Other than these guys obviously)
- unlmtd 9y agoIt wasn't USD, it was ETH. Very different.
- jokoon 9y agoThis story really needs an ELI5
- dsacco 9y agoA guy came up with an idea of digital money that doesn't require contracts using "smart contracts", where the code is the law. The guy went to a bunch of people with the idea and they liked it. The people talked about it a lot and many more people joined in. They all pooled their money together to launch this cool money. Some other guy came over, saw all of this, looked at the code, and used the code to transfer $55M to his wallet. Arguments about law and contracts ensued.
- djrogers 9y agoThat’s all stuff leading up to he hard fork and rollback...
- mopedtobias 9y agoIsn't Bruce Wanker the hacker? https://youtu.be/_O5fdMFKEC0 https://youtu.be/_O5fdMFKEC0
- RcouF1uZ4gsC 9y agoIf R2-D2 used Ethereum. C-3PO: He made a perfectly legal move. Han: Let him have it. It’s not wise to upset a Wookiee (The Ethereum founders). C-3PO: But sir. Nobody worries about upsetting a droid (a regular contract user without influence). Han: That’s cause a droid (regular contract user) don’t pull people’s arms out of their sockets (hard fork the entire crypto currency and call you a thief) when they lose. Wookiees (The Ethereum founders) are known to do that. C-3PO: I see your point, sir. I suggest a new strategy, R2. Let the Wookiee (Ethereum founders) win. With Chewbacca's and the Ethereum founders' behavior, you would be a fool to play their game again thinking that they follow the rules.
- rtpg 9y agoisn't it a bit disingenuous to say it was just the position of Ethereum founders? People wanted their money back. It's almost as if some recourse for actions done in bad faith is a useful tool to have as a society...
- RcouF1uZ4gsC 9y agoOf course, people also want to take back losing moves in chess. The whole point of Ethereum was that the code alone specified the contract.
- bluejekyll 9y agoBut code is written by humans... have you ever seen code with no bugs? In 20 years of professional development I have not. Given that humans are imperfect, and could even potentially act in bad faith, isn't it reasonable to have an exception clause? I get the argument to not have one; that it's impossible to have favorites and central figures manipulate the system, but nothing is perfect.
- microcolonel 9y agohttps://github.com/seL4/seL4 https://github.com/seL4/seL4 https://www.mitls.org/ https://www.mitls.org/
- 7ewis 9y agoSo I'm assuming the fork, Ethereum isn't at risk? At least as far as we're aware.
- vuyani 9y agoIt still and will always be. They have set a dangerous precedence. If another group of large developers decide to revert a certain transaction. They could. The one platform that still has its integrity is ethereum classic
- kerkeslager 9y agoBut Ethereum classic is still subject to the problems of Ethereum main's amateurish codebase.
- vuyani 9y agobut the core difference here is there is no precedence set. Especially since classics core belief is immutable transactions. As long as the community has that integrity. Then its safe. but ultimately. It is a consensus based system. So its not to say its not impossible
- n8n3k 9y agoThief? He strictly followed the terms of a contract by people who were very clear that "code is law" and who did not want institutions were the result is decided by human judgement.
- foepys 9y agoIt's always been like this. Be smug and aggressive when it goes right and cry for help when something goes wrong. The housing crisis was the same. Claim you got the thing that makes everybody rich and when everything went inevitably downhill, ask the "enemy" aka the regulator/government/police to bail you out.
- confluence 9y agoEveryone's a hero until the bullets start flying.
- yangchi 9y agoIt's been long time since I read Too Big To Fail, so what I recall could be wrong, but i don't think your statement about the 2008 bailout is entirely true if that book wasn't a lie. Almost the majority of Wall Street refused the bailout money. Paulson almost force them. The bailout money eventually made a profit ($15B). One could argue that the return rate was low (0.6% annualized), but still, this is far different from what most people have believed till this day: i.e., US gov just gave taxpayer's money away to the banks to cover their ass. Paulson also almost managed to save Lehman Brothers until British Gov said no to Barclay's role in the plan. (Wall Street banks would acquire LB's "good assets" while Barclay would buy their toxic ones as its gateway to become a more influential player in US market.). But even Lehman didn't reach out to Pualson to get itself saved. It's the other way around: Paulson was trying many ways to save Lehman because he knew when Lehman went down, market would panic and then even those banks in good shape would be affected.
- caoilte 9y agoThe British make very convenient scapegoats and were responsible for a great deal of the Financial Crisis, but not the collapse of the Lehmans deal http://www.reuters.com/article/barclays-lehman-idUSLDE62B25820100312 http://www.reuters.com/article/barclays-lehman-idUSLDE62B258... You can't trust anything in Too Big To Fail, unfortunately. Shame, it reads really well.
- kbody 9y agoThis case feels so closely to the very interesting case of Aviva France[1], where a not "well-futureproofed" life insurance contract is making a person very rich by the day. Unfortunately for Aviva, their contracts are actually law in contrast to Ethereum where if the devs feel like it, they can do/revert anything. [1]: https://ftalphaville.ft.com/2015/02/27/2120422/meet-the-man-who-could-own-aviva-france/ https://ftalphaville.ft.com/2015/02/27/2120422/meet-the-man-...
- malloreon 9y agohere's a link not behind a signup wall: http://www.independent.co.uk/news/business/news/max-herve-george-the-man-fighting-a-merciless-legal-war-against-insurance-giant-aviva-10168427.html http://www.independent.co.uk/news/business/news/max-herve-ge...
- bayonetz 9y agoWow! I'd love to hear the reasoning that went into issuing those policies.
- jffry 9y agoFrom [1], it sounds like it was issued at a time when today's near-real-time info on the value of the investments was unthinkable, not to mention the amount of time it would take to send and process requests for changes. [1] http://www.proz.com/kudoz/french_to_english/insurance/6252629-arbitrage_%C3%A0_cours_connu.html http://www.proz.com/kudoz/french_to_english/insurance/625262...
- BenjiWiebe 9y agoAm I missing something? I thought the devs had to have everyone agree to do a hard fork. If the devs were in complete control, that wouldn't have been necessary.
- nebabyte 9y agoIf the devs "just reverted anything if they felt like it", people would quickly move to a different fork.
- mannykannot 9y agoOne thing not mentioned in this article is that the hard fork was only feasible because there was not much else in the way of contracts on Ethereum at the time, other than the DAO itself. If there had been vast networks of interdependent, concurrent contracts and their obligations, as envisioned by many of the most vociferous proponents of smart contracts, I think a rollback would have been impossible, at least in practice. Next time, they may not be so lucky.
- kerkeslager 9y agoThe success of the DAO performing a 51% attack on Ethereum virtually ensures that Ethereum is useless for other contracts. Your contracts hold no value of they can be rolled back at the whim of the holders of the largest contract in the system for reasons that have nothing to do with your contract.
- zenkat 9y agoEtherium's fundamental premise -- "code is law" -- presupposes a general solution to the formal verification of program correctness. This is an unsolved problem (and is likely unsolvable in the complete case). Put simply, all code has bugs. How can Etherium ever work in practice at scale?
- kerkeslager 9y agoThere are proposed Ethereum-like systems which use tables and formal proving systems to validate contracts, which may be a good-enough solution to bugs in contracts (this is untested). However, the Ethereum community as a whole doesn't even see this as a problem, and is happy with their JavaScript-like contract language, so I don't see any real potential that they will even attempt to solve this problem.
- dmix 9y ago> How can Etherium ever work in practice at scale? Aren't there a to of Bitcoin organizations with hundreds of millions of dollars flowing through them? If these companies found a way to operate safely with manageable risk, through things like cold storage and encryption schemes, than how is it much different from Ethereum? It's fun to say things like "code is law" and imagine everything happens within this self-contained bubble but this stuff still operates in the real world and there are risks and consequences for actions as well as real world security mechanisms regardless.
- mannykannot 9y agoIt works because Bitcoin is only the ledger - the accounting part. All the contractual aspects of the business activity are external to the blockchain, and are handled in the traditional way - through civil law and procedures.
- nexus9 9y agoYet another HN circle jerk filled with vacuous comments by uninspired myopic cretins and dogmatic crypto shills. It'll be a joy to revisit these threads once Ethereum has become the ubiquitous super-dominant tech platform of the future.
- sctb 9y agoCould you please spamming HN with this? If you have a point to make about the topic, please make it and do so civilly and substantively.
- kensai 9y agoI don't understand why people keep complaining it was an "injustice" to reverse the transaction. Most people followed the hard fork the reversed the effects of the heist. If it was that unjust, Ethereum Classic would be the major Ethereum fork now.
- Fej 9y agoAre there any terse explanations out there of the DAO bug?
- exabrial 9y agoIs Etherium not formally proven? One would think that would be a check box among many things for a financial interchange system...
- mannykannot 9y agoIt is not even close. Nor is any other financial interchange system, but they have external checks, balances, and a formalized way to correct errors.
- harwoodleon 9y agoHe was a thief, in the spirit that the money invested in the DAO was never intended to go directly to one individual (i.e. him). It was an error in the contract, as outed by numerous individuals. Code as law is right, but laws can (and should) change, because the effect they can have can be devastating if loopholes do the opposite of the intention behind the law. The fallacy here is that we have one immutable law that governs everything, that is set at one time and never changed - how ridiculous. This is utter nonsense. The DAO was a beautiful experiment that went badly wrong. In the grand scheme of things, if this was a heist in the traditional sense - everyone would have lost out. But as it stands, it's probably the biggest bug bounty in history. Hopefully no one got hurt. We learn and move on.