30 ms·
153k Ether Stolen in Parity Multi-Sig Attack
- niahmiah 9y agoLet me guess... another hard fork to undo this.
- LeoPanthera 9y agoThe same old tired snark, in every single Ethereum-related story.
- dna_polymerase 9y agoBut it's true. If "code is law" is your key feature you don't simply undo a "code is law" decision and gain investors trust.
- ythn 9y agoYou prefer a hard spoon? ...it'll hurt more
- lettergram 9y agoHard fork can't even undo this, from my understanding.
- olegkikin 9y agoI'm pretty sure a hard fork can undo anything on the block chain. You can start over from the block before the hack. There's probably a cleaner solution than that though.
- csomar 9y agoThe problem is, how do you reassign the funds after the hardfork? The funds are attached to addresses and not persons.
- pyrale 9y agoYou can revert the funds to the address that paid into the contract in the first place, since transactions are public.
- csomar 9y agoThat wouldn't move the money to their rightful owner but to the previous owner.
- deleted 9y ago[deleted]
- olegkikin 9y agoI don't think that's correct. If you only revert the stolen money transactions and all the branches of them since, almost nobody loses. The few stolen ETH that got sold will be a loss, but it's nothing compared to $35M.
- wyldfire 9y agoStart at block n-1, disable the buggy contract, leave the "stolen" funds where they were.
- csomar 9y agoThey were in the contract (or the contract addresses).
- sushid 9y agoWhy wouldn't hard fork be able to undo this transaction?
- saalweachter 9y agoPiecing together the comments up thread: there was apparently a unique twist to the infamous DAO hard-fork which allowed someone to steal the funds but not withdraw them (ie, transfer them to an exchange and get dollars out), so they were able to undo the transaction. There was no such twist this time around which means the funds could already have been transferred to an exchange and withdrawn as dollars or BTC. You can only undo the ETH part of the transaction, which would take money away from the exchange (or from people who have since bought the stolen coins from the exchange unknowningly) and give it back to the victim. That's a lot less palatable than taking the money from the thief, so it's unlikely to happen.
- urda 9y ago> Hard fork can't even undo this, from my understanding. This is completely incorrect. A hard fork can undo anything, it's just backing up before this happened and continuing down another path as if it didn't.
- dvcc 9y agoI know this is a joke, but what would prevent the thief from attaching high transaction costs to the withdrawal of ETH from the target wallets? Say they place 50% of the value into the transaction costs - miners would assume a healthy profit off of the theft and it wouldn't be beneficial for them to rollback the chain.
- Anderkent 9y agoTakes longer for such a change to propagate than for the miner to just move his coins. Unless you implement it as some kind of history tracking for wallets, but then the hacker can just send a tiny transaction to literlaly every wallet around, and everone's paying the 50% cost.
- soared 9y agoA hypothetical hacker could robin hood easily then.. only steal coins from wallets with massive amounts, and "give them away" to miners via transaction costs
- RandomKid 9y ago> Let me guess... another hard fork to undo this. Nah, Vitalik is not affected by the bug this time. You only hard fork, when your money are stolen.
- abhi3 9y agoThat's like 30 Million USD at current prices? This is close to the DAO hack in USD value, not another fork now surely?
- 52-6F-62 9y agoA hard fork couldn't undo the damage if everybody wanted to. The exploiter/hacker/scammer, whatever you want to label them, can move ETH into other coins on exchanges immediately. This will cause an innocent party to buy them, removing any chance of reversal affecting the person[s] responsible. During the DAO hack, the funds were prevented from moving anywhere so a hard fork caused a direct reversal. That's my understanding, anyway.
- chillydawg 9y agoEth is worth less right now, as there is an implicit chance that all transactions will be rolled back to a few hours ago. Hence any buyer of ETH will be getting a fair price for the risk. Wild west all round.
- 52-6F-62 9y agoNone of that is true at all. Rolling it back would do nothing for anybody affected, so there's no way a consensus would form. That and a majority of the hacked accounts were prevented loss by whitehats as things look now.
- chillydawg 9y agoThe probability of rollback is not 0% (or at least it wasn't last night when I wrote that comment). It might only be 0.2%, but it's not 0%.
- sinieovercosie 9y agoETH was also worth a lot less at that time. DAO hackers took a lot more than 150k ETC.
- 9y ago
- codewiz 9y agoCan someone ELI5? I use Parity, I have a wallet contract deployed, it's night and I'm wearing sunglasses.
- codewiz 9y agoOh shit: https://www.reddit.com/r/ethereum/comments/6oalcq/important_wallets_created_with_paritys_multisig/ https://www.reddit.com/r/ethereum/comments/6oalcq/important_...
- jerrylives 9y agoApparently it's an issue with the initWallet() function which is used to set the owner of the wallet
- kevinwang 9y agoCan anyone explain? Don't know what I'm looking at.
- 52-6F-62 9y agoThere was a faulty contract in Parity's multi-sig wallet, which is more like a vault than a typical wallet. The page linked to here is the blockchain address of whoever exploited that fault and was able to take control of a large number of wallets and forward all of the ETH to their account. They've sold ~20 ETH so far (~4100 USD), and have ~150,000 sitting at that address still.
- notsofastbuddy 9y agoParity shipped with a built-in Solidity contract to implement multi-sig wallets. That contract had a vulnerability that is now being exploited. Importantly, the contract is not part of the Ethereum protocol, so other implementations and non-multi-sig Parity wallets are safe.
- saghm 9y ago> Importantly, the contract is not part of the Ethereum protocol, so other implementations and non-multi-sig Parity wallets are safe. Safe from this bug, maybe. But there's nothing to say that they might not also have bugs of their own.
- abhi3 9y agoFor some context: http://www.coindesk.com/30-million-ether-reported-stolen-parity-wallet-breach/ http://www.coindesk.com/30-million-ether-reported-stolen-par...
- finnh 9y agoI've posted this before [0], but it's still apropos regarding the foolishness that is Ethereum. [Ethereum] only makes sense if all of the following obtain: (a) the code is 100% bug-free (b/c accidents cannot be rewound) (b) all code-writers are 100% honest (their code does what they say) (c) all contract participants are 100% perfect code readers (so as to not enter into fraudulent contracts) (Strictly speaking, only one of (b) and (c) needs to be true). None of these conditions will ever obtain. [0] https://news.ycombinator.com/item?id=14471465 https://news.ycombinator.com/item?id=14471465
- grandalf 9y agoNot really true. Nothing has to be perfect if there is insurance infrastructure. People should not use contracts they have no reason to trust. As a contract becomes more important it should be viewed/vetted/trusted by as many entities as possible. Users of the contract should pay an insurance fee that goes to the vetters, who promise to reimburse in case of unpredictable behavior. Yes, this means applying some meatspace solutions to Ether. However the smart contract infrastructure itself is ideal for implementing this. Ethereum offers immutability, and blockchains can foster new kinds of trust, but trust still has to grow organically in the ecosystem.
- twblalock 9y ago> Ethereum offers immutability, and blockchains can foster new kinds of trust, but trust still has to grow organically in the ecosystem. If you need a source of trust outside of the blockchain, why would you need the blockchain after such trust has been obtained?
- thiagocsf 9y agoAutomation? Guaranteed immutability?
- grandalf 9y ago> outside of the blockchain The blockchain offers characteristics (immutability, consensus, distributed backup) that allows entities to trust each other efficiently. But when you introduce a non-trivial smart contract, there is a chance that it (a black box) has behavior that is not obvious from its source code. Since the behavior of the contract will cause immutable changes to the blockchain, and since humans can't perfectly mentally model all conceivable source code behaviors and interactions, there must be some other mechanism for establishing that the behavior of the contract matches the common understanding of what the contract does. This could be sandbox testing, parameter range verification, formal verification, star ratings, etc. As the would-be user of a contract I generally want some reason to trust it. Ethereum offers the building blocks to create an elaborate vetting, verification, simulation, etc. system. Thusfar, existing institutions have leveraged their own reputations to make users of Ethereum comfortable trusting their contracts. The DAO is an example of the folly of this, but many other contracts are examples of the reasonableness of it. Over time, Ethereum will build the right meta building blocks to create very rich trust mechanisms which put the meatspace hedging/insurance industry to shame while also shedding much of the inefficiency that ambiguous legal enforcement creates.
- WhatsName 9y agohttps://cryptowat.ch/kraken/ethusd https://cryptowat.ch/kraken/ethusd
- jimrandomh 9y agoThat ticker shows the current price as higher than it was 48 hours ago.
- rocky1138 9y agoHow do we know this is stolen? The link doesn't provide much detail.
- sna1l 9y agoSeems unlikely that 3 different multi-sig wallets sent so much ETH to the same wallet.
- samstave 9y agoForgive me for being harsh: Why is there no "pen-test" phase to any crytocurrency which hits the market. So, let me understand; you're ostensibly smart enough to (perhaps as a body of contributors, even) develop a cryptocurrency offering - yet youre also fucking stupid enough to not have same/wider network of ppl attempt to hack the fuck out of your plan? Does this already occur? or some savant comes and owns them? We have fucking HIPPA FFS and the compliance systems for something as trivial as my stupid name. so; ELI5: WTF are currencies doing/not-doing which allow for such hacks (1) and allow for exploits to go unseen (2)
- 52-6F-62 9y agoIt has nothing to do with any currency or protocol. It was a broken feature in a piece of software used on the network that was bad. Unfortunately, it was widely used and somebody caught the fault and exploited it. It's more like a company's open source software allowing somebody to steal your bank password. It doesn't have anything to do with USD or the Fed, or even the bank's larger practices. It has to do with how negligent they were with regard to a particular feature.
- vkou 9y agoOf course, there is a very large financial system designed to deal with the fallout of a bank password being stolen. There is no such system with crypto-currencies.
- dahdum 9y agoThis...it was a poorly written contract just like the DAO was. Parity developers didn't follow the most basic contract safety steps, and people used it because they trusted them too much. Each of these situations is a painful learning experience, but moves the platform forward.
- trakout 9y agoCryptocurrencies do go through pen tests. I think instances like these are a good analogy to how even multiple tests run by 3rd parties will only get you so far -- particularly when the "bounty" is potentially worth millions.
- cl0rkster 9y agoA much more useful explanation: https://press.swarm.city/parity-multisig-wallet-exploit-hits-swarm-city-funds-statement-by-the-swarm-city-core-team-d1f3929b4e4e https://press.swarm.city/parity-multisig-wallet-exploit-hits...
- onychomys 9y agoThank you for this, because the OP link is totally baffling for those of us who aren't coin-nerds.
- campbelltown 9y agoSorry :) I didn't want to link anything that had potential for bias. Just the account with the amount. But, wow, this post blew up.
- calafrax 9y ago> The Swarm City Core team is more committed than ever to the development of Swarm City. The real value of our token lies in the community, and the technology the developers are creating. Black hat hackers, vulnerabilities, and bugs will not stop us from creating the decentralized sharing economy our community and the world craves. What?!? That seems like a pretty relaxed response for someone who just lost 8m dollars.
- deleted 9y ago[deleted]
- earlz 9y agoHere's the root error I believe: https://github.com/paritytech/parity/blob/master/js/src/contracts/snippets/enhanced-wallet.sol#L216 https://github.com/paritytech/parity/blob/master/js/src/cont... The initWallet function should have been marked internal, but was instead not marked. Unmarked functions default to public in Solidity, so anyone can call that function and reinitialize the wallet to be under their control
- dvcc 9y agoWhy would an unmarked function get the broadest possible scope in a language designed for contracts? I'm always surprised by the decisions made around Ethereum, and just how much value people have poured into it.
- TylerE 9y agoBecause the cryptocurrency space attracts only the brightest minds.
- wheelerwj 9y agoi know that you're not really serious when you generalize against all of us crypto simpletons, but anytime theres a stupid amount of money on the table people are bound to rush to pick it up. and that means mistakes. the work being done on public blockchains is unlike anything else done before. You don't have he luxury of keeping your db behind a vpn running on a vm platform secured and maintained by the worlds largest companies. These engineers put themselves out there, waaaaaaaay out there to try and make shit happen. And they mostly do good work. But if banks and major retailers who have huge budgets can get hacked, of course we can too.
- kbenson 9y agoI think a big part of the complaint is about the implicit assumption that because people are smart, and have experience with cryptography, they necessarily have the experience to design a sane and safe programming language given their goals. They did put themselves way out there, and that takes ambition, but also hubris. I wish they were able to figure out which one was driving them at certain points a bit better, as while some of these problems are because they are doing new and interesting things, some are old as dirt for computing, and there's little defense. If some company tried to tout a new language with all the pitfalls of C, but none of the benefits of being really inter-operable and known the same way, I'd like to think we could recognize that as having some very bad design choices given what we've learned from C, and at little benefit other than being different. Ignoring decades of research and experience on the topic through ignorance is not laudable, even if you've put yourself out there. I can't help but feel we have a similar scenario going on here.
- sna1l 9y agohttps://etherscan.io/address/0x1dba1131000664b884a1ba238464159892252d3a https://etherscan.io/address/0x1dba1131000664b884a1ba2384641... -- white hat group exploited the vuln and are holding people's crypto for them.
- Deimorz 9y agoI don't follow Ethereum closely at all, but I don't really understand a few things about this: - Who's the "white hat group"? Why do people have confidence in it? - Why does everyone believe they'll give back $75M+? If they decided to just keep it, what could anyone do? - How will people even be able to claim ownership of the ETH in a way that's verifiable so they know they're giving it back to the right person?
- blattimwind 9y ago> If you hold a multisig contract that was drained, please be patient. They will be creating another multisig for you that has the same settings as your old multisig but with the vulnerability removed and will return your funds to you there. It definitely is an uncanny read.
- draw_down 9y agoThe question makes sense, but really why do people have confidence in any of this, you know what I'm saying?
- pg_is_a_butt 9y agobecause it's hashed... so you can't hack it.
- oh_sigh 9y agoYou don't really have a choice right now. Either trust them and wait to see if your eth is returned, or start rabblerousing for yet another hard fork to undo this 'hack'
- eco 9y ago
- mtgx 9y agoSo will the devs create another Ethereum fork to recover this money?
- Tepix 9y agoNot sure if they can this time. The money isn't locked for several weeks like it was last time, is it?
- rboyd 9y agoyou can see that this is also effecting tokens. check the whitehat effort (Token Transfers / View Token Balances) on this wallet https://etherscan.io/address/0x1dba1131000664b884a1ba238464159892252d3a#tokentxns https://etherscan.io/address/0x1dba1131000664b884a1ba2384641.... $30M worth of BAT, $26M ICONOMI, $17M CFI, $1.4M EOS historic episode here which is sure to spur many a conversation about what disclosure means in the blockchain era.
- joshschreuder 9y agoLet's play hypotheticals. If you were the attacker and you now have the ETH in your wallet, how do you cash out without anyone identifying you and maximising your profits? Also has the attacker broken a law by exploiting a bug in the contract?
- Woofles 9y agoIANAL but if someone leaves their front door open, it's still illegal to walk in and take their possessions. I would imagine this falls under a similar ruling.
- 0x0 9y agoIn most cases yes, but isn't ethereum all about "the code _is_ the contract"? If you as the owner of a house put an ad in the paper saying "if you can manage to enter my house feel free to take whatever you want", should you complain if someone did exactly that?
- deleted 9y ago[deleted]
- vasilipupkin 9y agoThe analogy is if you accidentally leave the door of your house unlocked, it doesn't make it legal fir someone to walk in and steal your piano
- saurik 9y agoThis comment fails to address the point of the comment it is replying to... you simply repeated the original point, but the person you responded to worked within that analogy and then modified it to try to address the statements by Ethereum.
- vasilipupkin 9y agoRight, I am saying the analogy I responded to is flawed. Ethereum doesn't invite people to violate the intended use of the contract. It's like claiming that if a corporation got hacked due to lax security, then those hacking are in the clear because that corporation invited them in
- icelancer 9y agoBlack hat hackers nabbed $31MM in ETH. Not a bad payday due to a coding error. https://etherscan.io/address/0xb3764761e297d6f121e79c32a65829cd1ddb4d32 https://etherscan.io/address/0xb3764761e297d6f121e79c32a6582...
- curiousgal 9y agoMaybe it was a feature not a bug.
- dvcc 9y agoCan someone explain how immutable contracts get updated? From what I understand you can have one contract forward requests to another, and you can use some storage in the forwarding contract to determine the real target contract. But why would someone participate in a contract that is mutable? I guess I am just wondering how this contract can be updated, given its on the blockchain and considered immutable.
- pimeys 9y agoThere are architectural ways as you said, but basically you don't update them. You know the possible bugs, you document the contract, methods and your process early on, you write tons of tests, use auditing tools, do code review with the team, hire somebody to audit your code, test it with bounties, implement emergency stops and speed bumps and some proper monitoring. When it's about your money, you should be able to do all that. And yes, Solidity is pretty horrible. I hope there will be better options such as Idris in the future.
- jeeceebees 9y agoThe contract code is immutable. The code that you agree to can be pretty complicated though and might not do exactly what you think it does. In this case, by some stupid mistake the contract allowed anyone at all to change who was considered an owner of a wallet. The code wasn't changed; one of the functions it specified was used to change a variable.
- tbarbugli 9y agohow much money is that?
- draw_down 9y agoIt's "cynical" to point out these problems will keep happening, but then they keep happening. So, not much to say.
- drcode 9y agoWell yeah, as long as there are cars, people will get in car accidents... That doesn't mean we should ride horse buggies forever.
- doener 9y ago"my favorite part of this latest ICO hack is that it appears to have gone to same wallet as the dao hack ....." https://mobile.twitter.com/IamNomad/status/887776981777092613?ref_src=twsrc%5Etfw&ref_url=https%3A%2F%2Fredcursor.net%2F https://mobile.twitter.com/IamNomad/status/88777698177709261... "incredible plot twist: whitehat hacker supposedly saved most tokens from being stolen using the same vuln." https://mobile.twitter.com/bcrypt/status/887775417406431232?ref_src=twsrc%5Etfw&ref_url=https%3A%2F%2Fredcursor.net%2F https://mobile.twitter.com/bcrypt/status/887775417406431232?... "Multisig wallets affected by this hack: - Edgeless Casino (@edgelessproject) - Swarm City (@swarmcitydapp) - æternity blockchain (@aetrnty)" https://mobile.twitter.com/maraoz/status/887755889897295872?ref_src=twsrc%5Etfw&ref_url=https%3A%2F%2Fredcursor.net%2F https://mobile.twitter.com/maraoz/status/887755889897295872?...
- sillysaurus3 9y agomy favorite part of this latest ICO hack is that it appears to have gone to same wallet as the dao hack ..... Any proof of this? EDIT: This appears to be false. From https://blog.ethereum.org/2016/06/17/critical-update-re-dao-vulnerability/ https://blog.ethereum.org/2016/06/17/critical-update-re-dao-... The leaked ether is in a child DAO at https://etherchain.org/account/0x304a554a310c7e546dfe434669c62820b7d83490 https://etherchain.org/account/0x304a554a310c7e546dfe434669c... But that site shows the account hasn't received anything since July 8.
- sna1l 9y agoYeah, the tweet and subsequent replies are absolute garbage.
- sharkmerry 9y agoWhitehat address is listed in the known attackers here https://gist.github.com/ckeenan/fa1a77823dba5b193c7cfeaa00acb756 https://gist.github.com/ckeenan/fa1a77823dba5b193c7cfeaa00ac...
- codewiz 9y agoThe bug in the wallet contract was fixed one hour ago with this commit: https://github.com/paritytech/parity/pull/6102/files/e06a1e8dd9cfd8bf5d87d24b11aee0e8f6ff9aeb https://github.com/paritytech/parity/pull/6102/files/e06a1e8... Parity bug: https://github.com/paritytech/parity/pull/6102 https://github.com/paritytech/parity/pull/6102
- matt_wulfeck 9y agoI'm sure they'll just hard fork again. And nobody cares because ethereum isn't actually being used for anything real, just a bunch of enthusiasts trying to get rich.
- codewiz 9y agoHow is rolling back transactions that are clearly part of a robbery a bad thing?
- swsieber 9y agoBecause it's rolling back transactions that were done under "the law" (e.g. the ether contract stuff) by human intervention when the entire draw of the ether contract stuff was the promise of no human intervention
- resf 9y agoIn a blockchain, the participants in the network have unlimited authority to modify the "law" of the blockchain, even retroactively. If there is sufficient consensus among Ethereum users for a hard fork, then it can happen.
- oh_sigh 9y agoYes, and that 'feature' of block chains is never really touted by blockchain supporters. Basically, if 51% of the network think you have too much money, they can just take it from you with no recourse available.
- lawrenceyan 9y agoSilver lining: https://etherscan.io/address/0x1dba1131000664b884a1ba238464159892252d3a https://etherscan.io/address/0x1dba1131000664b884a1ba2384641... Looks like about +300,000 ether was able to be drained before it could be stolen thanks to a white hat group.
- ricardobeat 9y agoOnly good if they can keep the group together after amassing 70+ million dollars.
- swamp40 9y agoThe begging in the comments section, along with their wallet ID's, looks like a glimpse of the internet 100 years into the future.
- beelle 9y agohttps://www.amazon.es/dp/1521567476 https://www.amazon.es/dp/1521567476
- jondubois 9y agoThe problem with Ethereum is that it's just way too complex. The more complex something is, the more bugs and vulnerabilities there are going to be.
- aresant 9y agoFrom the post mortem (1) -=> - A hacker managed to exploit a ICO multisig wallet vulnerability and drain 44,055 ETH - $9,119,385 at present. - A white hat showed up and "saved" 377,000 ETH - $78,039,000 !!! - by draining other accounts. I get the "see cryptos are too insecure / it's a pyramid / it's a bubble / ICOs are scams / etc" arguments. But holy shit turning a world currency into the wild west - for better or worse - is going to be disruptive, period. That $10m out the window is like a Series A for a nefarious hacker with deep crypto skills, what does this success embolden or create? I can only imagine the debacles that we have to look forward to, and I say that in full support of and as a long term believer in both blockchain and cryptocurrencies. (1) https://press.swarm.city/parity-multisig-wallet-exploit-hits-swarm-city-funds-statement-by-the-swarm-city-core-team-d1f3929b4e4e https://press.swarm.city/parity-multisig-wallet-exploit-hits...
- sillysaurus3 9y agoThe real lesson is: don't store your coins on a third party anything. This was a third-party wallet. Everyone used it because everyone else used it. Exactly like Mt Gox. There was no reason to store coins on Mt Gox, just like there was no reason to use this wallet. A moment's reflection would have prevented this foolish decision.
- ChrisClark 9y agoThis wasn't a third party wallet actually. It is the local Parity wallet and node. What this was, was a bug in the multisig contract that Parity would give you to deploy. So it is a contract you personally deploy onto the ethereum network and then interact with. You do own it, you own the private keys for the address, etc. But the bug allowed any other address to add themselves as owners and withdraw from it. Luckily not many people used it and the white hat was able to claim all the rest before anyone else.
- sillysaurus3 9y agohttps://github.com/paritytech/parity https://github.com/paritytech/parity About Parity Parity's goal is to be the fastest, lightest, and most secure Ethereum client. We are developing Parity using the sophisticated and cutting-edge Rust programming language. Parity is licensed under the GPLv3, and can be used for all your Ethereum needs. Parity comes with a built-in wallet. How is this not a third-party wallet? They say right on the page that they're trying to be the best implementation of Ethereum. That means they're not the core implementation, right?
- nkrisc 9y agoJust thinking hypothetically here as a coin novice: could a bug like this theoretically have been implemented intentionally? If the code is the law, and the code is sufficiently complex, couldn't it be feasible to dupe people?
- SittingTemplar 9y agoYes. Contracts are only as secure as the people interpreting them, and when people can't interpret them because they're code, suddenly you need third parties to interpret them and then you've got to pay third parties to do this efficiently and suddenly you've reinvented the concept of being a lawyer.
- SkyMarshal 9y agoYes. You're thinking more like a battle-scarred veteran than a novice here.
- jamespitts 9y agoHelpful information for users potentially affected by this issue: - The vulnerability is in Parity's "enhanced" multi-sig contract - This affects Parity 1.5 and later - Parity 1.5 was released on January 19, 2017 (have you created multi-sigs in Parity since then?) - The canonical multi-sig contract used in Mist / Ethereum Wallet does NOT have this vulnerability - 0x1db is a community "white hat" sweep effort and not an attacker (See: https://etherscan.io/address/0x1dba1131000664b884a1ba238464159892252d3a https://etherscan.io/address/0x1dba1131000664b884a1ba2384641... )
- tudorw 9y agoEntropy, not something you want from a currency, also, paper money is not magic, it's a network of trust. I think block chain applications are out there, I just don't think cryptographic currencies are their best use.
- campbelltown 9y agoIt appears the hacker has begun moving ether from the account. The number presented in this link will no longer match the amount in the title. There is currently 83K ether remaining.
- theptip 9y agoCan someone explain to me why you would want a smart contract for multi-sig? This is a feature that can be implemented easily off-chain, i.e. using split keys (Bitcoin has had this approach for some time). Seems like having this complex logic on-chain is asking for it to be exploited.
- ericb 9y agoAs Charlie Lee said: If the creator of Solidity, Gavin Wood, cannot write a secure multisig wallet in Solidity, pretty much confirms Ethereum is hacker paradise. https://twitter.com/SatoshiLite/status/887781929726038016 https://twitter.com/SatoshiLite/status/887781929726038016
- runeks 9y agoI'm confused. Did Gavin Wood write the code for the Parity wallet, forgetting that he had created a language where function visibility defaults to "public"?
- drcode 9y agoCharlie Lee is wrong: The bug was introduced by another, less experienced, developer submitting a commit to the repo (though of course Gavin Wood arguably still bears some responsibility as leader on the parity project)
- heliumcraft 9y agoGavin Wood didn't not make the code change that caused this...
- ericb 9y agoThings like this are why I think Tezos, when/if it comes out, has a bright future. I want a formal proof for any contract I use with real-money.
- abrkn 9y agoCan you provide any reading material into formally proven contracts?
- splintercell 9y agoWhat kind of reading material are you looking for? Formally proven Smart Contracts would be the same as formally proven non-smart contract computer programs. There is a paper[1] written by some researchers on how using a more powerful language (Such as Idris) could prevent a whole category of errors in smart contracts development, but it doesn't necessary talk about formal verification of smart contracts. 1. https://publications.lib.chalmers.se/records/fulltext/234939/234939.pdf https://publications.lib.chalmers.se/records/fulltext/234939...
- ericb 9y agoNo rollback this time. The chain with this hack must have the longer Proof-Of-Vitalik. https://twitter.com/VitalikButerin/status/887782650026631168 https://twitter.com/VitalikButerin/status/887782650026631168
- 6nf 9y agoTime for another hard fork!
- 6nf 9y agoTime for another hard fork!
- kensey 9y agoThe great thing about reading this comment thread is that I basically already read it a couple of weeks ago, because a friend of mine (David Gerard, of Wikipedia, RationalWiki and Rocknerd Internet fame) let me preview his forthcoming e-book _Attack of the 50-Foot Blockchain_. There's a whole section in there about smart contracts, Ethereum, and The DAO that goes over much of what commenters here have mentioned ("non-reversibility, till it's our money at stake", the requirement that everyone write and read code perfectly, the problems with the very idea of immutability in contracts, etc.) If people are interested, it's on Amazon: http://amzn.to/2trOjJS http://amzn.to/2trOjJS (I have no financial interest in it, but I bet a lot of people in this thread would enjoy reading it and/or writing long diatribes on why he is wrong about everything in it.)
- davidgerard 9y ago:-D Ask me anything ;-) I have, like, a whole chapter about smart contracts which answers everything about this latest disaster. The idea is that it will be a handy rhetorical ammo dump for when someone asks you about those blockchain things and why the business needs them ...
- splintercell 9y agoI hope you are mentally prepared for the sheer amount of negative reviews you're going to get on Amazon.
- davidgerard 9y agoTheir money is still fiat!
- davidw 9y agoI miss patio11's posts on these things.
- patio11 9y agoSorry -- been a bit too busy with work and a 5 month old to understand Ethereum deeply enough to feel like my get-some-popcorn genre of posts would add value. On the plus side, Bitcoin popcorn futures continue their steady progress up and to the right.
- rjurney 9y agoI can't even understand what you are all talking about. Crazy kids. I'm not even kidding. Usually I can figure out what the topic of conversation is if I'm not familiar with it, but in this case I'm like three degrees removed from comprehension. Sounds like this is all probably dot com bullshit, but maybe something genius will come out of it that is unforeseen now.
- coinme 9y agoBetter techniques are required. Solidity is clearly not ready to be used to secure billions of dollars that can be anonymously stolen in an instant. Fuzz testing should be an absolute minimum. Formal proofs, and a simpler language should be the ultimate goal. Hopefully the ethereum foundation takes note because this problem is not going away, and they are responsible for 20B$ market cap of value. I realise that ethereum is still young but they have chosen to build a product that can be used in a multitude of ways without enough thought about how to keep the value secure. I wouldn't even know where to start when deciding whether it's safe to use a smart contract, and I understand the concepts well. If ethereum is ever going to grow into it's current market cap if will have to be safer for use by everybody.
- likeclockwork 9y agoIf the code of the contract IS the contract, how was anything 'stolen'?
- redm 9y agoThe blog announcement from Parity: https://blog.parity.io/security-alert-high-2/ https://blog.parity.io/security-alert-high-2/
- imron 9y agoDon't worry, they can just do another hard fork and get the money back, amirite?
- int_19h 9y agoJust skimming through the Solidity docs, I see a lot of unwise decisions there aside from the weird visibility defaults. All state is mutable by default (this includes struct fields, array elements, and locals). Functions can mutate state by default. Both are overridable by explicit specifiers, much like C++ "const", but you have to remember to do so. Even then, the current implementation doesn't enforce this for functions. Integers are fixed-size and wrap around, so it's possible to have overflow and underflow bugs. Granted, with 256 bits of precision by default that's harder to do than usual... but still pretty easy if you e.g. do arithmetic on two inputs. Operators have different semantics depending on whether the operands are literals or not. For example, 1/2 is 0.5, but x/y for x==1 and y==2 is 0. Precision of the operation is also determined in this manner - literals are arbitrary-precision, other values are constrained by their types. Copy is by reference or by value depending on where the operands are stored. This is implicit - the operation looks exactly the same in code, so unless you look at declarations, you don't know what it actually does. Because mutability is pervasive, this can can have far-reaching effects. Map data type doesn't throw on non-existing keys, it just returns the default value. The language has suffixes for literals to denote various units (e.g. "10 seconds" or "1000 ether"). This is purely syntactic sugar, however, and is not reflected in the type system in any way, so "10 second + 1000 ether" is valid code. Statements allow, but do not require, braces around bodies. This means that dangling "else" is potentially an issue, as is anything else from the same class of bugs (such as the infamous Apple "goto fail" bug). Functions can be called recursively with no special effort, but the stack size is rather limited, and it looks like there are no tail calls. So there's the whole class of bugs where recursion depth is defined by contract inputs. Order of evaluation is not defined for expressions. This in a language that has value-returning mutating operators like ++! Scoping rules are inherited from JS, meaning that you can declare variables inside blocks, but their scope is always the enclosing function. This is more of an annoyance than a real problem, because they don't have closures, which is where JS makes it very easy to shoot yourself in the foot with this approach to scoping.
- vazhifarer 9y ago> Scoping rules are inherited from JS, meaning that you can declare variables inside blocks, but their scope is always the enclosing function That's not still the case with `const` and `let` in Javascript, is it? Lexical scoping still exists, but Block scoping is default now in JS
- ateevchopra 9y ago77 Million were rescued by the white hackers and stored. https://etherscan.io/address/0x1dba1131000664b884a1ba238464159892252d3a https://etherscan.io/address/0x1dba1131000664b884a1ba2384641...
- thecrazyone 9y agothe link seems to be down. Did we DDoS it ?
- e79 9y agoThe vulnerability was extremely simple, as suggested by the three keyword-long patch. I've written about this and other Solidity/EVM bugs from a technical perspective, if anybody is curious: - https://ericrafaloff.com/parity-multi-sig-contract-vulnerability/ https://ericrafaloff.com/parity-multi-sig-contract-vulnerabi... - https://ericrafaloff.com/analyzing-the-erc20-short-address-attack/ https://ericrafaloff.com/analyzing-the-erc20-short-address-a... I think at least a big part of the solution to these security problems is two-fold: - More secure conventions. All of the gotchas in Solidity make for a bad time. Even non-security bugs create a bad developer experience. Opting into private functions by default - More code review. Engineers need to be diligent or hire security professionals who are (I'm one).
- viach 9y agoLooks like a good motivation to start learning Solidity.
- pietrofmaggi 9y agoThis is the most useful explanation I've found about the vulnerability so far: https://blog.zeppelin.solutions/on-the-parity-wallet-multisig-hack-405a8c12e8f7 https://blog.zeppelin.solutions/on-the-parity-wallet-multisi... The explanation is a bit scary about what actually ended up in parity code: The wallet contract forwards all unmatched function calls to the library using delegate call... This causes all public functions from the library to be callable by anyone, including initWallet, which can change the contract’s owners. Edit: formatting
- hohenheim 9y agoI wonder, why the black hat didn't drain all the money and left it for the white hat group?
- sleepychu 9y agoMaybe they estimated that this was the proportion that would protect their gains from a hard fork
- richardknop 9y agoI agree. Probably game theory reasons. Don't steal so much it will cause the community to unite and hard fork. 30 million is enough to retire and probably not enough to cause hard fork and rollback of txs. They played it safe.
- mullen 9y agoI think this is what happened and it makes sense if you think about it. If they steal enough to get rich but not enough to force a rollback, then they can keep their ill gotten gains. 30 million is enough for a small group of hackers to live comfortably for the rest of their lives.
- gus_massa 9y agoMy guess is that they didn't expect it to be so easy, and were surprised by the success, and started to party on, and forget (or were too drunk) to take the rest of the money that was on the table. Anyway, your theory is much better than mine.
- djhworld 9y agoOn the parity website they state the following > Every single line in our codebase is fully reviewed by at least one expert developer (and routinely two or more) before being placed in the main repository. We strive for excellence; static code checking is used on every compile to cut out bad idioms. Style is enforced before any alteration may be made to the main repository. Continuous integration guarantees our codebase always compiles and tests always pass.
- 5chdn 9y agoConfirming this always was and still is the case. (Working for Parity.) However, this does not guarantee that such mistakes happen.
- sparky_ 9y agoDidn't they fork the project a while ago due to theft?
- qwertyuiop85 9y ago0x2ee4899d44F086e8ee974399f404214de33F9b68 Please donate, I'll go full time auditing code from now on. WHG member.
- qwertyuiop85 9y ago0x2ee4899d44F086e8ee974399f404214de33F9b68 Please donate, I'm going full bug hunting from today on your behalf. WHG dev. S.
- joeblau 9y agoIt's being put back: https://news.ycombinator.com/item?id=14811534 https://news.ycombinator.com/item?id=14811534 Edit: Without Vitalik or a hard fork.
- redm 9y agoI'm not sure why everyone is piling on Solidity. At the end of the day, bugs happen in all languages, to all programmers eventually, and if you want to point the finger, it has to be at Parity. If anything, it shows there needs to be a better process for peer review and some defaults in Solidity should be changed for security.
- bigdubs 9y agoIt's because even creating Solidity was a choice; why not use a more established language with a well understood vm?
- okreallywtf 9y agoIn reading the comments I had forgotten what DSL stood for and had to look it up and it usually means something other than intended here, to save anyone else the trouble its Domain Specific Language. https://en.wikipedia.org/wiki/Domain-specific_language https://en.wikipedia.org/wiki/Domain-specific_language
- o- 9y agoI believe from looking at the fix [0] I was able to trace back the origin of the bug. This is my (unverified) theory. Can anybody familiar with serpent confirm? There is a catch-all [1] function in the public API (why???) of the wallet contract which uses delegatecall to delegate to the library class. "In a similar way, the function delegatecall can be used: the difference is that only the code of the given address is used, all other aspects (storage, balance, ...) are taken from the current contract." [2] (again, WHY???) So calling through this catch-all function the "internal" modifier on "initMultiowned" does apparently not prevent it from being called, since the delegation happens from a function inside Wallet. So the "attack" is to just tell the wallet to reset its owners to myself. This would be so embarrassingly trivial, that it's more like picking the money up from the floor, than a "heist". This wallet contract is insane and the programming language too. Why would a language for such a critical application have such super unsafe constructs? This can't be true. Please, serpent community, talk to your local PL people! [0] https://github.com/paritytech/parity/pull/6103/files https://github.com/paritytech/parity/pull/6103/files [1] https://github.com/paritytech/parity/blob/02d462e2636f1898df3e7556364260c594b112e6/js/src/contracts/snippets/enhanced-wallet.sol#L426 https://github.com/paritytech/parity/blob/02d462e2636f1898df... [2] https://solidity.readthedocs.io/en/develop/types.html#address https://solidity.readthedocs.io/en/develop/types.html#addres... [3] https://github.com/paritytech/parity/blob/02d462e2636f1898df3e7556364260c594b112e6/js/src/contracts/snippets/enhanced-wallet.sol#L107 https://github.com/paritytech/parity/blob/02d462e2636f1898df...
- ericfrederich 9y agoIs this even illegal? Or just frowned upon? It seems this is just one big game, you find the weakness and you profit.
- eqmvii 9y agoTheft of property is illegal in almost all jurisdictions in a very general sense. It doesn't matter what the property is, and the law doesn't try to anticipate every possible thing a person could own to specifically prohibit misappropriating it. The practical challenges to tracking hackers or 'hackers' stealing digital currency mean you don't see regular prosecutions, but the ease of getting away with it shouldn't imply legality.