51 ms·
A hacker stole $31M of Ether – how it happened, and what it means for Ethereum
- icelancer 9y ago>"It’s important to understand that this exploit was not a vulnerability in Ethereum or in Parity itself." I mean.... I guess. It's a feature of Ethereum, if we're going to weasel around.
- formula1 9y agoI think most developers know not to eval() Why would you execute arbitrary text in any other languages?
- pipermerriam 9y agoYour parallel is not an accurate one. One of the key and powerful features of the Ethereum Virtual Machine or, EVM, is the ability to delegate execution to external libraries. You can think of this much the same way you think of installing 3rd party libraries in your favorite programming language of choice. In the EVM you can write a "library" which performs some common functionality such as manipulation of date-time objects much like the `datetime` library in Python. Any other contract may then make use of this code simply by delegating execution to the deployed library address. This has inherent risks that every Ethereum developer should understand fully, but with that risk comes some incredible power and potential. There currently is no "Standard Library" for the EVM but it is looking very likely that it will be comprised of this type of contract. Slowly, overtime, these library contracts will be written and deployed to the network. There is work being done on using theorem solvers to mathematically prove that a contract satisfies certain properties which opens the door to a "provably correct" standard library. I know of no other computing environment or packaging system that has these properties. For me, it has been an enlightening subject and I feel like we've only just scratched the surface.
- int_19h 9y agoA serious question: are the benefits really worth it? How much overhead would it be to just include the library code directly into the contracts instead (so that the whole thing can be verified as a single black box)?
- buttershakes 9y agoIts not really worth it. Very over complicated. Really they just need to do code/data deduplication on chain somehow and forget about using contracts as libraries in this way.
- pipermerriam 9y agoI think the answer to that question is extremely contextual and going to be very different for different applications. I also think that I'd like to point out that the idea of including the library code within the contract is untennable at a certain level as contracts currently have an upper limit on size which is determined by the block gas limit. It also doesn't make it any safer because it's still functionally the same as executing external code because it's the same code being executed.
- bvrmn 9y agoThe parallel is totally damn right. eval with an unverified user input. > _walletLibrary.delegatecall(msg.data) Dunno how much contracts in the wild have such brilliant feature.
- lowpro 9y agoI know I'm this situation the dev made a simple mistake, but I wonder if Ethereum is safe as a system assuming developers will make many mistakes, and those mistakes will happen more often as more complicated contracts are written. At some point I wonder if the idea of smart contracts is better than a traditional system, since they seem prone to developer error due to complexity.
- icelancer 9y ago>At some point I wonder if the idea of smart contracts is better than a traditional system, since they seem prone to developer error due to complexity. The idea is incredible. Groundbreaking. Honestly super interesting to me. The execution of them as law is... well, going about as expected. This is why the law doesn't actually work this way.
- hn_throwaway_99 9y ago> I know I'm this situation the dev made a simple mistake, but I wonder if Ethereum is safe as a system assuming developers will make many mistakes, and those mistakes will happen more often as more complicated contracts are written. This will probably come off as being assholish, but I honestly don't mean it to be: you should read the rest of the article. It actually covers this topic in depth and has good thoughts on this fundamental issue with smart contracts.
- lowpro 9y agoHonestly I read the comments first, I enjoy and learn from HN comments often more than the original article. Thanks for pointing out I was missing context.
- bastawhiz 9y agoThe rest of the article amounts to a few points: - Humans make mistakes, the tools should have been better - The technology to make Ethereum safe doesn't really exist - We should work to make that technology exist - We should be happy this happened since it raises awareness about the problem > In the end, attacks like this are good for the community. They call you to your senses and force you to keep your eyes open. What?! Listen, just because Valgrind exists doesn't mean you can't accidentally write a C program with memory errors. Just because Rust protects against race conditions doesn't mean you can't have bugs in your threading code. We're not even close to a world where tools can offer amazing protection. > The developer here was Gavin Wood, one of the co-creators of Ethereum, and the inventor of Solidity, the smart contract programming language. The code was also reviewed by other Parity contributors. This is basically the highest standard of programming that exists in the Ethereum ecosystem. This was an error made by the best of the best, reviewed by the best of the best. The tools that will save us from this madness don't exist. What does this mean for Joe Developer? It means he's not going to build something that he keeps anything of value on. The author's cheery "we'll be stronger for this!" attitude completely neglects the obvious chilling effect that this is having. If the guy that invented the damn thing can't protect his $31 million dollars, why would I even try to build something that could manage even hundreds of dollars? And to that end, is it really better than a traditional system?
- formula1 9y agoThe developer shouldn't have executed arbitrary text. Hopefully we can just fork, blacklist the stolen transactions and pretend this didn't happen.
- fatbird 9y agoThus proving that "code is law" is a meaningless slogan.
- dmcy22 9y agoDon't think it'll happen. From the article: A hard fork would be impractical–what do you do about all of the transactions that occur downstream? What about the people who innocently traded assets with the attacker? Once the ether they’ve stolen gets laundered and enters general circulation, it’s like counterfeit bills circulating in the economy — it’s easy to stop when it’s all in one briefcase, but once everyone’s potentially holding a counterfeit bill, you can’t really turn back the clock anymore. Also, a tweet from Vitalik: https://twitter.com/VitalikButerin/status/887782650026631168 https://twitter.com/VitalikButerin/status/887782650026631168
- pmoriarty 9y ago"smart contracts can also do things that normal contracts can’t, such as enforce a set of rules entirely through unbreakable cryptography." Isn't "unbreakable" a bit of a dirty word in the security community? Is there really such a thing as "unbreakable cryptography"?
- CydeWeys 9y agoOne time pad encryption is unbreakable given integrity of the pad material itself.
- InclinedPlane 9y agoAnd, how do you build one time pad encryption into ethereum?
- dsacco 9y agoYou can't. Or, well, you can, but it's redundant. One-time pads make sense in the Cold War, Vernam Square era of cryptography. But now that we have the internet and public key cryptography, a one-time pad implemented in Ethereum would be inane and frivolous. Take Alice and Bob, who want to communicate confidentially. Alice doesn't know Bob personally, so she can't securely communicate the one-time pad to Bob in person. Ethereum implements public-key cryptography, so she uses Bob's public key to send him the one-time pad's key. But now we're at the chicken and egg problem: we've just witnessed secure communication, so why do we want to use a one-time pad in the first place? Alice and Bob might respond, "so we can have perfect secrecy at some point in the future!" Which...alright, sure, let's go with it. So now to implement the one-time pad in Ethereum, Alice needs to feed a source of true randomness as a seed for a secret key which is as long as the plaintext. This is not only a genuinely hard problem, but it's grossly inefficient to encrypt something using a secret key as long as the plaintext itself. But wait - for every new plaintext, Alice has to do this true random seed song and dance each time to generate a new secret key. And every secret key ever used needs to be kept perfectly secret as well. You really just don't want to do this. One-time pads barely made sense in pre-modern cryptography; they don't solve any practical problems in modern cryptography, and their demands require steep usability sacrifices that are quite easy to screw up.
- EdSharkey 9y agoStories like this make me consider whether programmers that engage in commerce should be forced (yes, by law) into guilds that have rigid journeyman and apprenticeship stages before the programmer gets to touch the production environment. Specialized, official, bonded developer roles need to be established. Our community cannot continue operating in the hacker mode wherever money is involved.
- esaym 9y agoThat just makes the price of a "programmer" go up. And the normal people responsible for putting together said requirements know that in the end it would just make their IT costs go up, so therefore they don't (which is fine with me)
- EdSharkey 9y agoDarn right, it's costly! But how else will we rope in foolish devs from doing foolish things like eval() in the context of a user's wallet except by policing our community? You can expect businesses to do it...
- EdSharkey 9y agoMeant to say can't there, darn phone keyboard...
- LoSboccacc 9y agoOr work move to countries without red tape around the job. Unlike masonry, software is easily shipped.
- deleted 9y ago[deleted]
- eximius 9y agoIt is a very interesting thought. Any Germans care to comment? They have the closest systems, I would think.
- gciruelos 9y agoNothing was stolen. All I see is a programmer abiding by the contracts.
- LoSboccacc 9y ago.. and this wasn't even the first time. And this is all by design.
- 13of40 9y agoFrom Intel's perspective, everything went perfectly.
- onion2k 9y agoIn legal terms you'd need to make the argument that the programmer abided by the letter of the contract rather than the spirit of the contract. That might well be a reasonable defence in the case of smart contracts, but it'd need to be tested in a court.
- isolli 9y agoHas a contract been signed in any legal sense?
- Fej 9y agoIf a smart contract is also a binding, legal contract, then normal contract law applies - and intent matters here in the real world. Therefore, it's theft. I am most certainly not a lawyer.
- learc83 9y agoMost likely true. But if intent matters and the smart contract isn't actually the final arbitar, then smart contracts are fatally flawed. Unless courts recognize the ability to sign away your rights through some kind of disclaimer that makes the smart contract the equivalent of binding arbitration.
- BadBougie 9y ago"Ethereum is a descendant of the Bitcoin protocol, and improves on Bitcoin’s design" Misleading statement
- esseti 9y agoBut now, how can the hacker spend it or transoform to USD? To spend them if on online stuff is rather ok, execpt the fact that the items (if are a phisical objects) needs to be sent to an address. If he's going to transoform them to USD or BTC or whatever they need to use a platform, which asks for ids and co. so, how can he get rich without getting caught?
- theWatcher37 9y agoNice try thief! Hey guys I found him!
- mullen 9y agoThey already have converted some of the ETH to other coins. There are services out there that are completely anonymous that you can use Tor to access and exchange coins. The problem that this hacker has is that they need to convert a lot of coins.
- kanzure 9y agoprevious discussion: https://news.ycombinator.com/item?id=14807779 https://news.ycombinator.com/item?id=14807779
- Steeeve 9y ago> In the end, attacks like this are good for the community. I'm sorry, but what a bunch of baloney.
- catherinezng 9y agoGreat read. Thanks!
- shadowmint 9y agoThis is a very pro-Ether take on what happened, but ultimately it comes to the right conclusion: > The problem is that his programming toolchain allowed him to make these mistakes. Damn straight. The problem is that the model of 'public by default, opt in for security' is fundamentally daft in this context. There's quite a good read on that particular topic here too http://hackingdistributed.com/2017/07/20/parity-wallet-not-alone/ http://hackingdistributed.com/2017/07/20/parity-wallet-not-a.... ...but hey, if this ends up making Ethereum better, more secure and more robust as a result, then that's a good thing; it probably does need a different better language to express code in. Just remember... > certainly you should not store any money in a hot wallet that you’re not comfortable losing.
- jumbosuno 9y agowill Tezos help with Ocaml to make better contracts? I think that is the whole point of Tezos!
- pdkl95 9y ago> the model of 'public by default, opt in for security' is fundamentally daft in this context. It's daft in most contexts, and is one of the largest sources of security problems. If your design requires enumerating badness[1], you're doing it wrong. > from: http://hackingdistributed.com/2017/07/20/parity-wallet-not-alone/ http://hackingdistributed.com/2017/07/20/parity-wallet-not-a... >> Just about every ICO, trust and company used the Parity multisig wallet, and that code was considered well-tested. -sigh- This is, unfortunately, a common problem. "It worked ok the last N times" and "It passed a lot of tests" do not mean it's bug-free and safe to use. Richard Feynman was right during the Challenger investigation when he called this a childish attitude. (He was also right in not wanting to assign blame, instead asking "How do we educate the child?"[2]) [1] http://www.ranum.com/security/computer_security/editorials/dumb/ http://www.ranum.com/security/computer_security/editorials/d... [2] https://www.youtube.com/watch?v=4kpDg7MjHps#t=150 https://www.youtube.com/watch?v=4kpDg7MjHps#t=150
- SingletonIface 9y agoThe page you linked mentioned "SafeMath". Is this that? https://github.com/nemequ/portable-snippets/blob/master/safe-math/README.md https://github.com/nemequ/portable-snippets/blob/master/safe...
- nodesocket 9y agoDo we have any idea if the wallets that were stolen from were individuals, companies? How angry would you be if you lost millions and there was nothing you can do.
- DennisP 9y agoIt was three ICOs. They've all issued public statements saying they have enough funds in alternate storage to stay in business.
- owenversteeg 9y agoI think the fundamental problem here is an economic one. Make three assumptions: 1) most contracts worth implementing in Ethereum are fairly complex 2) even given great developers, bugs are inevitable in complex code 3) the budget of the contract-makers' security team MUST be smaller than that of the hackers You quickly see that if the chance of a bug is nonzero, "smart contracts" don't make economic sense. If you have a $100k contract, and you spend $5k on security (which would absolutely destroy most companies' margins by the way) you'll be facing hackers that are EACH willing to spend up to $90k or so. Let's say all the experts in this example world are $200/hr. You spent 25 expert-hours on security. But you're being hacked by people who spent 450 expert-hours on hacking you. With that in mind, would YOU want to use a smart contract? Spend 5% of the contract value instantly on security, and risk losing 105%? This isn't a normal loss by the way, where you can prosecute someone or sue somebody. No, this is the instant, digital theft of the entire value of the contract, to an anonymous digital address where it will be quickly blended in with hundreds of millions of dollars of similar thefts a month.
- HaseebQ 9y agoI grant your point, but disagree with your framing of the problem. I think a good analogy here is to compare to American settlers. You're going to have a few waves: the explorers who move into totally uncharted territory and take on significant risk by using smart contracts. These are kinda crazy people who love the innovation, and I'd argue this is the majority of people in the space right now. Eventually there will be the settlers, who start finding early uses for this technology that can significantly lower costs. Basically collecting on low-hanging fruit. J.P. Morgan, many finance companies, some savvy governments will step in to capitalize on easy wins. Then there will be the long tail of normal uses. By the time the average company invests in smart contracts, there will be very well-understood battle-tested templates and toolchains for creating smart contracts, as well as consulting firms that are specialized in writing them for you with provable security guarantees. Right now it's early. Your average company should not use smart contracts, that's a no-brainer. But someday the economics are going to make it a no-brainer for certain things, like incorporation, or issuing shares, or doing payroll, or complying with import/export regulations, or doing corporate taxes, or whatever it is that ends up more efficient through blockchains.
- PhilWright 9y agoIs it possible to track where the money goes from the hackers account onwards? Or is then opaque? How easy will it be for the hacker to move the funds around so it cannot be traced back to the theft?
- nileshtrivedi 9y agoA transaction can have multiple inputs and multiple outputs. And there are contracts that do the mixing up of transactions to provide privacy to users. So, like counterfeit notes, these funds will eventually be untraceable.
- davidgerard 9y agoIt is, but it turns out exchanges don't actually care. Bitcoins from the Bitfinex hack are slowly being dumped on exchanges, for example. It's like someone rocked up to a bank with a big duffelbag full of dye-stained notes known to have been stolen from another bank, and went "no worries lol".
- shawabawa3 9y agoWell, it's unlikely the coins when straight from the hack accounts to the exchange accounts (they might have, i'm not sure in this case) The coins just have to go through a single intermediate account for there to be doubt that the hacker still owns them
- davidgerard 9y agoyeah. Cryptocurrencies are prosecution futures, but only if law enforcement actually cares to do the considerable tedious legwork.
- andretti1977 9y agoHow did the white hats understood the vulnerability? I don't know anything about ethereum so i'm honestly asking. Is there a public log of the method invocations so they could see the hacker was exploiting that exact vulnerability and decided to replicate it?
- nileshtrivedi 9y agoThe article links to the initWallet() call on etherscan.io
- mpeg 9y agoYep, if you saw the attack done it was really easy to replicate it as all transactions are public. In fact, it's a testament to the poor technical capability of most people involved in Ethereum that the whitehat was even able to do this, in any other environment you'd have had other blackhats clean out the remaining $90m within minutes, all it took was to fire up a web3 console (ethereum's javascript interface) and call the initWallet method with your own address on it. Then you could drain the contract at will.
- Oras 9y agoand if there is a group of white-hat hackers supporting and monitoring, how come they didn't find that before and fixed it?
- mdekkers 9y agoAs an aside, every time I see a headline with "Hacker" and an image of a hoodie with binary and mostly dark colour tones, my expectation of the quality of content to follow drops significantly. Having said that, the actual article is pretty good...
- deleted 9y ago[deleted]
- JohnJamesRambo 9y agoAs an Ethereum investor, this hack has shaken my belief in Ethereum ever making sense as an ecosystem. Smart contracts which will always be fallible plus irreversible blockchain transactions seems like a peanut butter and tuna fish sandwich. I moved my money out of Ethereum for now.
- seanwilson 9y agoHmm, so don't most courts consider the spirit of a law/contract as opposed to the exact wording to get around people finding obscure loopholes in the phrasing? That's one area a computer is not going to be forgiving about. Obviously in this case, reassigning the wallet owner is completely against the spirit of the smart contract. What solutions are there to this? All I can think of is for contract coders to use a language that allows contract constraints to be specified more easily (e.g. "owners cannot be reassigned") and have it verified by the language. Maybe this is a good application of formally verified code but the language being used doesn't seem built with that in mind.
- jlebar 9y ago"It’s going to take a lot of work to develop the training and discipline to treat smart contracts the way that banks treat their ATM software." https://web.archive.org/web/20160406115607/https://www.bloomberg.com/news/articles/2014-01-16/atms-face-deadline-to-upgrade-from-windows-xp https://web.archive.org/web/20160406115607/https://www.bloom... ATMs are not secure because of their software. They are secure despite their software. Maybe eth will reach the point where the police will come after people who try heists like this. That seems much harder than coming after someone who stole $30m from a series of ATMs, though.
- ckastner 9y ago> Having sounded the alarm bells, a group of benevolent white-hat hackers from the Ethereum community rapidly organized. They analyzed the attack and realized that there was no way to reverse the thefts, yet many more wallets were vulnerable. Time was of the essence, so they saw only one available option: hack the remaining wallets before the attacker did. > By exploiting the same vulnerability, the white-hats hacked all of the remaining at-risk wallets and drained their accounts, effectively preventing the attacker from reaching any of the remaining $77,000,000. > To prevent the hacker from robbing any more banks, the white-hats wrote software to rob all of the remaining banks in the world. [...] One argument I keep hearing in favor of cryptocurrencies is that they are beyond the control of individual governments and their regulation through legislation and law enforcement. Next time, I'm going to use this case as a counterexample, because when the solution to the problem of "hackers robbing banks" is "vigilantes robbing the remaining banks", something is very wrong with your system, and it is certainly not something for the general public.
- AsyncAwait 9y ago> Next time, I'm going to use this case as a counterexample, because when the solution to the problem of "hackers robbing banks" is "vigilantes robbing the remaining banks", something is very wrong with your system I can see what you're saying, but I don't think that this is a problem with cryptocurrencies specifically, it's a problem with buggy software, yes, but it's something that is the case with every dangerous exploit being actively taken advantage of in the wild, Heartbleed would be an example that doesn't involve cryptocurrencies, but I give you that the Ether-based ecosystem seems to be a particularly buggy collection of software, probably because of too much ambition, (a Turing-complete VM), being written by people with too little experience and applied for very sensitive (monetary) transactions, which seems like a recipe for disaster.
- kahnpro 9y agoThis is a problem that everybody seems to skip over with cryptocurrencies. Cryptocurrencies are being sold as eliminating trust and allow us to rely on the cold certainty of mathematics. Only trust hasn't been eliminated from the system, it's just been shifted from a central bank to the authors of the software client you're using. To the majority of the miners in the network. The awful politics, lies, greed, corruption, are still here in all their glory.
- GrumpyNl 9y agoThe keep telling me Crypto's are safe.Everybody controls them. I haven't heard of any banks that have been robbed several times this year from these amounts of money. Sounds like me that crypto coins are the easiest hackable sources right now.
- richardknop 9y agoSo many Ethereum related posts on front page every day lately. Is this some sort of marketing campaign or the sudden increase is just because of the hack?
- bmon 9y agoIt's a hot topic right now just like when Bitcoin was first booming. Although today and yesterday especially so because of this hack.
- richardknop 9y agoBut Ethereum is not booming. Isn't it a consensus that it is mostly speculative and most of these ICOs are money grabs and no working products ever get released other than prototypes to raise money? Yes the price has increased by 4000% in couple of months this year but most reasonable people agree it is a pure speculation / gambling.
- DennisP 9y agoI'd say that's a matter of opinion, not consensus. Plenty of us have a different opinion, including people from some large corporations in the Enterprise Ethereum Alliance, who say they hope to put applications on the public Ethereum chain after scalability improves.
- dawidloubser 9y agoAs long as Ethereum apps are powered by a deeply-flawed programming language (Solidity) and VM (EVM), this will happen over and over again. Writing provable, secure software is difficult, and highly unlikely if your environment doesn't force the correct mindset. Solidity (poorly named) was made with the primary goal of being easy for JavaScript / Node hackers to use. The cost of this is now illustrated through the repeat 'hacks' of bad 'smart contracts'.
- antouank 9y agoExactly. I'm amazed that so much of the web today is still based on "easy" scripting languages like JS or Python, which are fragile and error prone. Once I transitioned to Elm and Haskell, I saw bugs almost disappear. I didn't improve as a dev, I just used a safer language. Especially when money is involved, correctness and safety should be the number 1 priority.
- josefx 9y ago> Exactly. I'm amazed that so much of the web today is still based on "easy" scripting languages like JS or Python You can put any script kiddy in front of them and get a "working" program. > Once I transitioned to Elm and Haskell, My first question when I heard of Haskells main features: "What does a planet from Star Wars have to do with programming?". Haskell is not a source of cheap programmers. > Especially when money is involved, correctness and safety should be the number 1 priority. When money is involved the first priority is a cost/risk evaluation. Generally the people involved in that evaluation don't have much of a personal risk so the number 1 priority is to reduce the cost.
- peter303 9y agoJust like the Hans Christian Andersen story:"The emporer has no clothes"
- Cakez0r 9y agoI have to expect that some bug like this has surely happened with a traditional bank too, causing them to lose a bunch of money. Humans inevitably write buggy software regardless of the platform. The difference with blockchain-based currencies is that their failures are forced to happen in public. I'd be interested to know what banks do when they discover that something doesn't add up in their ledger. I can't believe that it has never happened and never will.
- PMan74 9y agoI'm sure it has happened but at least with banks they have the option of following the chain of the money to wherever/whomever it ends. And with ever more stringent ID requirements to open an account that person should be identifiable. Generally banks will freeze funds if there's a claim of fraud from another bank. Far from perfect (fake ID, assumes the issue is spotted promptly, etc.) but better in this case.
- dboreham 9y agoIt happens all the time but banks just call up the counterparty and ask for their money back.
- bitcoinmoney 9y agoLol. The author really knows how to make click-bait articles. Same guy here: https://www.highstakesdb.com/2375-haseeb-qureshi-admits-to-chip-dumping-quits-poker.aspx https://www.highstakesdb.com/2375-haseeb-qureshi-admits-to-c...
- thinkloop 9y agoWhat's the fairest distribution of the recovered white-hat funds: - return them exactly as they were, with the unlucky people completely losing funds - distribute them back among everyone based on the % of total funds that were in their wallets
- dynjo 9y agoCriminals stole $40m USD http://www.telegraph.co.uk/news/2017/04/25/brazilian-bandits-stage-brazen-40-million-heist-paraguay/ http://www.telegraph.co.uk/news/2017/04/25/brazilian-bandits... What does it mean for the dollar? Answer: Nothing, but people improved their security so it doesn't happen again.
- heliumcraft 9y agoAgain, Gavin Wood did NOT write the change that caused this, he wasn't even the reviewer.
- HaseebQ 9y agoThanks for pointing this out. I assume because he pushed the fix that he was the developer, my mistake! Have amended the article.
- vasilipupkin 9y agoMaybe I'm wrong, but people seem to view smart contracts as theoretically infallible replacement for normal contracts. They to me are nothing of the sort, just some code that makes certain money transfers and disbursements more efficient than if implemented differently. So, of course there will be technical problems and hacks, just like when regular corporations get hacked in the non crypto world
- verytrivial 9y agoI'm sort of confused[1] that formal proofs are not mandatory tools in this space. There's some Herculean effort underway[2] to create verified HTTPS stack. The failure mode in that case is maybe, sort of data leakage or server control that might be worth something to someone. In the Etherium case, they just walk away with cash. It takes a sort of hubris (or is it foolishness?) to think you can just be very very careful and it will all work out okay. [1] Actually, its more schadenfreude, partly with the audacity of the speculator and system market makers, and partly at the mindless waste these proof of work/stake systems require. [2] https://project-everest.github.io/ https://project-everest.github.io/
- throwawayjava 9y ago> that formal proofs are not mandatory tools in this space The stakes are extraordinarily low relative to situations where formal proofs are mandatory. For references, the list price of a single new 737 runs in the 50 million range, and the cost of the software for the 737 is amortized across many thousands of planes. 1. That's actual hard money. Real US dollars you can use to buy yachts and houses and avocado toast. Given the level of hype and amount of speculation, the true value of all the ether in the world is obviously considerably less than Ethereum's market cap. The hacker stole $30M 'worth' of ether, not 30M actual dollars 2. The cost of a plane crash is easily 10x the price of the plane, and of course you can't put a price on the lost souls.
- staticelf 9y agoI am a programmer and I don't understand Ethereum. Sure I haven't really read up on it but if I don't understand it, how will the common man? I have little faith in this kind of system. Could anyone here explain to a noob how Eth would be any better than Bitcoin?
- joeyspn 9y ago> a hacker pulled off the second biggest heist in the history of digital currencies. This is not accurate... the MtGox hack was ~$100M, Bitfinex ~$60M, the DAO $50M, so this would be the 4th, not 2nd.
- seanalltogether 9y agoThere's a quote from John Carmack that heavily influences my take on OOP and DRY programming in general. "A large fraction of the flaws in software development are due to programmers not fully understanding all the possible states their code may execute in." http://www.gamasutra.com/view/news/169296/Indepth_Functional_programming_in_C.php http://www.gamasutra.com/view/news/169296/Indepth_Functional... As long as ethereum contracts support stateful OO contracts, they are bound to run into these kinds of bugs.
- artursapek 9y agoYou gotta love the hooded figure with overlay of CSS + HTML snippets. Hackers give me the chills!
- e79 9y agoManual code review would have likely helped. A tool like this maybe? https://ericrafaloff.com/introducing-the-solidity-function-profiler/ https://ericrafaloff.com/introducing-the-solidity-function-p...
- Temasik 9y agoanother hardfork? ethereum oldskool?
- khana 9y agoThe code nay the language (solidity) is obscenely too complex and rich to serve as the basis for tendering money transactions in a block chain that executes 'code contracts'. gotta dumb it down.
- kovacs_x 9y agoWhat I'd like to know as a developer- what was the "great" idea with the "call forwarding" in specific contract function?! What would be the valid use case, why author decided he should put it there beforehand?
- DennisP 9y agoWhen you deploy a contract you pay for every byte of code storage. So they decided to save people a little money by putting some of that code in a library contract that all the wallets would share.
- Dowwie 9y agoThe world's most expensive security audit...
- gspetr 9y agoOnly in recent history. I'm sure you would agree that by this definition any cyberheist can be called an "unsolicited 3rd party security audit".
- mholmes680 9y agoI know very little of Ethereum aside from the articles that pop up here, but I'm trying to compare this event to my existing currency. I have cash under my bed, i have it in 10+ accounts in financial institutions, and most of it is insured by the FDIC... so I've reduced my risk profile greatly. Does ethereum/ether allow me offline wallets? Can i have multiple accounts/wallets and easily administrate them? Is any agency insuring this yet? If so, then isn't this also user-error here? Don't allow a wallet of $X size that you can't afford to have disappear?
- gnidan 9y agoYou can use a securely hidden private key mnemonic (12-word, high entropy phrase) on a piece of paper, along with an offline "airgapped" computer, to sign transactions, then transfer the signed transactions to a device with internet access to publish it to the network. That's probably the most secure method of managing keys yourself, assuming access to physical security. A good approximation of this solution is the use of a hardware wallet, which keeps the private key behind a secure enclave (USB interface, transaction signing occurs within the enclave) There's no insurance or anything like that, either privately offered or via government regulation. The crypto market is still immature, so I wouldn't be surprised to see protections emerge in the coming decade. In the meantime, there is no equivalent to a bank for crypto assets—the best practice is currently to manage offline wallets oneself. Certainly be careful, though, user error is a big risk!
- gspetr 9y ago"There is no avoiding war; it can only be postponed to the advantage of others." -- Niccolo Machiavelli If he was alive today, perhaps he would have said: "There is no avoiding professional security audit; it can only be postponed to the advantage of cybercriminals." Their statement is the biggest joke[0]: "This body of code continues to have no known security issues." This reminds me of: "Beware of bugs in the above code; I have only proved it correct, not tried it." - Donald Knuth [0] https://blog.ethcore.io/the-multi-sig-hack-a-postmortem/ https://blog.ethcore.io/the-multi-sig-hack-a-postmortem/
- bitmapbrother 9y agoI don't get why the author keeps referring to the stolen ether as "counterfeit". It's not counterfeit, it's just stolen ether that will be reintroduced into the economy just as stolen bills are.
- bitmapbrother 9y agoWould it make sense to introduce some sort of escrow service into smart contracts to prevent such thefts in the future?
- deleted 9y ago[deleted]
- didibus 9y agoDefinitely it seems defensive measures should be built into the programming toolchain of Ethereum. Like it probably shouldn't allow eval at all. That said, any form of eval should also be a red flag for security. It seems like in this case cost won over security. And that is fundamentally the biggest threat to security.
- Businessmen 9y agoA great summary of recent events and recommendations for the future.
- pm24601 9y agoAnd this is reason #457, why I will not use a digital currency. No protection or recourse from fraud or theft.