20 ms·
Missing line in a smart contract leads to $10M hack
- nathias 5y agoThis just means smart-contracts are missing an extra layer as there is not correspondence between intention and code.
- Barrin92 5y agoI wonder when people will realize that the complexity inherent in human financial transactions will not go away just because you write code instead of natural language and 'decentralized finance' will reinvent everything it tried to get rid off (but shoddily) because nobody likes to lose their live savings because they missed a semicolon.
- seibelj 5y agoThere are plenty of Defi protocols that have not been hacked with many billions locked in them. Among them are Uniswap, Compound, Aave, and Synthetix. And in the traditional finance world plenty of mistakes have been made, like when Knight Capital accidentally ran their unit test algos in production and lost $500mil https://en.m.wikipedia.org/wiki/Knight_Capital_Group https://en.m.wikipedia.org/wiki/Knight_Capital_Group
- paulpauper 5y agothose are somewhat different. these are intermediaries when doing a hack. the hackers target smaller defi protocols with flash loans for example
- shoto_io 5y agoI think you have point. And, a key advantage I can imagine is that "checklists" could be implemented into code over time and that is potentially superior to natural language. I am not a crypto expert though.
- qeternity 5y agoIf it were this easy, software would not have bugs.
- terenia 5y agoStark reminder on the importance of quality control and checking the work twice. I think people sometimes become complacent with work completed in the virtual environment vs the physical world.
- shoto_io 5y agoyes. Reminds me of something a friend said a while ago: "You know how I became a great coder after 3 years? By being a bad coder for 3 years."
- LightG 5y agoExcept checklists often ... just get checked. c.f. people checking t&c's becuase they can't be bothered to read them (/sympathetic).
- redis_mlc 5y agoIt's an autistic thing, especially visible on HN. You get the same argument for eliminating airline pilots, yet when an engine explodes, I want pilots to deal with the emergency.
- chriswait 5y agoDoes anyone else feel like replacing all the legacy finance infrastructure with decentralised code is going to produce a worrying number of stories like this? Most of the examples I've seen so far it's happening to someone who works in tech, has disposable income, and is generally a proponent of cryptocurrency. I haven't written a lot of decentralised code in production, but I get the impression there is generally more to consider, and a fun new class of failure modes to worry about.
- dnautics 5y agoHow would exactly the same argument not be applicable to any sort of public code repo?
- deleted 5y ago[deleted]
- jollybean 5y agoIt's worse than that. Contracts are not code. It's a complete misunderstanding to posit them as such. Contracts depend first and foremost upon the legal regime in which they are valid. Every jurisdiction has rules, precedence, language means specific things. There is quite a bit of variability in this stuff, which is why we have lawyers. And Judges. Putting a contract into a crypto ... is basically pointless. There's possibly more transparency, akin to publishing contracts on the web or something like that. And of course, there is a 'narrow range of agreement possibilities' that could take place on crypto contracts, for example, things like stock options etc.. But generally speaking, even the contract cryptos are 'technologies looking for application'. We don't want to 'nay say' new, dreamy ideas, but these new dreamy ideas, combined with a bit of hubris, arrogance, greed, lack of self awareness can create problems.
- crooked-v 5y agoThe most obvious example for 'contracts are not code': the most airtight contract in the world can get quickly voided in court if it turns out one of the parties was actually a minor at the time of signing, even if they hid that fact or didn't actually know it.
- tshaddox 5y agoBut also, surely the traditional legal system will still handle disputes over smart contracts just like it does with traditional contracts. I can’t imagine that a missing line of code (intentional or not) would be treated any differently by the legal system than a vaguely-worded clause in a traditional contract. The legal system almost certainly will not say “your contract was just code and the code executed properly according to its technical specifications and therefore the outcome stands.”
- arilotter 5y agoIt's not necessarily true that a smart contract is controlled or operated by an individual or corporation. Once deployed, many have no provisions for administration or ownership tools. If you're using one of these contracts and there's a bug, suing the creator would be like suing someone because they put a random legal contract template online & you didn't proofread it well enough.
- lottin 5y agoI'm pretty sure a "smart contract" isn't a legally-binding contract. A smart contract is a piece of software code, like a text editor or a web browser.
- tshaddox 5y agoYes, and if you use a smart contract to hire someone to build a deck on your house, I suspect any resulting legal disputes would be treated by the courts the same as if you had used a traditional contract.
- vladimirralev 5y agoThere is place for both systems. Most crypto people have made peace with the fact that they can lose it all. People overestimate conventional finance. Conventional finance is incredibly flimsy if you dig into it. Leveraged beyond repair, ductaping one unprecedented monetary experiment after another. No conventional currency has preserved substantial purchasing power over a span of say 100 years maximum. The mathematical proof of supply limits alone is an unbeatable feature. Myself, not a crypto fan at all, I am sure crypto will be banned at some point, but just on the merit it's as good as anything.
- paulpauper 5y agoconventional finance has ways of insuring money and getting back stolen funds. it also is more idiot proof. nothing like that exists with cryto. crypto way less forgiving of errors..
- vladimirralev 5y agoNot quite accurate. The insurance you are talking about is for the custodial services of financial institutions. You can get custodial service for crypto with insurance too (https://custody.coinbase.com/faq https://custody.coinbase.com/faq). Outside of your narrowly worded agreement you don't have anything except perhaps the justice system which rarely works out in these cases. $20B were stollen in phone scams alone in the US last year, not recovered or insured, outside the insurance terms.
- TimJRobinson 5y agoBecause crypto is the first layer. It's like dealing with paper money and trades while living >200 years ago. Eventually "Trusted Institutions" will come along with insurance to keep your crypto safe for those with less risk tolerance. The advantage then is that you get to choose how much control you want to give up for safety. Unlike the current system where you have to use these institutions to participate.
- lottin 5y agoI think you're confusing "money" with "finance". Finance is about lending resources to carry out projects, whereas money is a means of exchanging things.
- duxup 5y agoFirst thing I do when changing or creating a thing. Try to figure out WHY things are the way they are and run through some scenarios. It's not a bullet proof system, I don't always do it well... but it can help having to re-invent some of the more obvious aspects of the wheel. The whole blockchain ecosystem seems like a long drawn out lesson as to why at least some systems we have are kinda big, bulky, involve a lot of checking / overhead ... and why some rules and regulations exist. Every new blockchain company that posts a blog and complains about "Why can't we just..." often has me thinking "Well yeah you shouldn't... wtf"
- ZephyrBlu 5y agoThis reminds me of Chesterton's Fence: https://fs.blog/2020/03/chestertons-fence/ https://fs.blog/2020/03/chestertons-fence/.
- duxup 5y agoTY I hadn't read this before, but it is worded way better than I did.
- alkonaut 5y ago> First thing I do when changing or creating a thing. Try to figure out WHY things are the way they are and run through some scenarios. As a developer I often stumble across code and systems that are superficially idiotic. I just think "Why isn't this doing X instead?". Here there are two approaches 1) blindly change the thing to make it better 2) Try to understand why it is wrong, and what led to the legacy design. The sensible thing might be 2, but its also soul-crushingly boring. So I obviously always do 1. After ripping out some code and replacing it with shiny new code, you invariably find the edge cases that led to the legacy design. They will show up as bugs, or edge cases missing. After a while, you will have iterated so that your solution might look something like the original (hopefully slightly better) but the important thing is you now have a system you understand fundamentally. You basically traded a few regressions for fundamental understanding of a system
- JadeNB 5y ago> 'decentralized finance' will reinvent everything it tried to get rid off Matt Levine wrote about exactly this in a recent Money Stuff column: https://www.bloomberg.com/news/newsletters/2021-05-11/money-stuff-crypto-markets-are-where-the-fun-is https://www.bloomberg.com/news/newsletters/2021-05-11/money-... . First paragraph: > A model that I often use for cryptocurrency is that it is rediscovering traditional finance: In its early days, crypto was a brand-new financial system, unsullied by the old evils of central banking, leverage, regulation, etc.; eventually people realized that some of those things were good, and started reinventing them. One way to reinvent finance is for idealistic crypto technologists to invent banking, leverage, regulation, etc., from first principles, with cursory or no knowledge of how the traditional financial system addressed these issues or why it rejected other solutions. You would expect this to lead to flawed but interesting results, whole new ways of doing things that might blow up horribly but that might instead point the way to a better future.
- ZephyrBlu 5y agoI find the fact that crypto is re-inventing finance from first principles to be really interesting. As he says, "You would expect this to lead to flawed but interesting results, whole new ways of doing things that might blow up horribly but that might instead point the way to a better future".
- Consultant32452 5y agoCompanies have canned contracts, like when you buy a house your mortgage company just plugs in a few variables and voila, contact. Commonly used smart contracts will converge in a similar way before they make it into common usage.
- agumonkey 5y ago> will reinvent everything it tried to get rid off I started to have this feel already. DeFi projects creates projects that create projects .. it's gonna be a potential spaghetti bowl of intermediate layers. Either the mass is gonna make it survive on the side or it's gonna fade off xml style.
- sva_ 5y ago> because nobody likes to lose their live savings because they missed a semicolon. Yeah, but shouldn't it be possible that these things will be avoided by confirming the validity of the code with theorem provers such as Coq, Lean, or something similar, at some point in the not too distant future? That's what I've been wondering, without currently having any stakes in the game (and probably not until there's compelling mathematical proof of security)
- Daishiman 5y agoTheorem provers require code for defining what you want to prove and the method through which you reach said proof. Proofs and theorems can have bugs.
- sva_ 5y agoBut aren't proofs exact in what they state? So it wouldn't be the proof that would be faulty. It'd be the interpretation of what somebody thinks the proof means to them, and that'd be something you could entirely objectively reason/work on.
- astrange 5y agoProofs are programs and programs are proofs of themselves. The ways proofs might help you show that a program is "correct" (what you meant to say) are 1. the effect of writing it twice in different languages 2. that proofs may be more abstract and you can refine the program from them. But a proof/formal methods can't actually prevent you from being wrong because you can be wrong at any meta level.
- astrange 5y ago> "correct" (what you meant to say) Oh, this is a definition of "correct", it's not me correcting the OP.
- Daishiman 5y agoBut the human world is not exact and full of context. Even mathematical.proofs exist within a context of an axiomatic system, known proofs, and various domain assumptions. I remember that in my computability theory class, defining the right proof was by far the most difficult task. And this was in very small, closed systems.
- pm90 5y agoCode won't make the complexity go away but it can definitely inform humans of various little things that would be too tedious or expensive to do manually. There's a reason we don't have lawyers review every ecommerce or in-store purchase that's made: the process of shopping has been standardized to such an extent that most parties (merchants and buyers) don't need to sign a bespoke agreement for every transaction. If we can get more complex agreements automatically hammered out, it represents not just large cost savings, but potentially creating more business for smaller players easily.
- anonytrary 5y agoAt least a smart contract can be unit tested thoroughly, whereas a 20 page legal document cannot be.
- masklinn 5y agoThat’s not actually useful, thorough unit testing can not prove the absence of bugs in the contract.
- paulpauper 5y agoWhy do ransomware when you can just find exploit and get away without having tainted crypto and also make much more $ too. Defi is such a big gift to hackers. Probably $100 million stolen total in past 2 year. These protocols and contracts are so complicated that such hacks are inevitable and more to come.
- lottin 5y agoMoreover the "hacker" is simply doing something that is allowed by the contract so it's hard to argue that these hacks are even unlawful.
- hhvn 5y agoYou could argue all hacking is just doing something that is (accidentally) allowed by the target system.
- ethanbond 5y agoNot really, because the entire premise of smart contracts is that the code IS the only representation of the contract. In normal software systems there’s an intent and then an implementation. There’s no explicit guarantee they are identical, which is exactly why there are subsystems to allow e.g. refunds or transaction invalidations.
- alisonkisk 5y agoThat's just ignoring the intent part.
- PeterisP 5y agoThat premise is clear, proponents of smart contracts would like it to become true, but as of now that premise is simply not true anywhere in the world. There may be obvious practical difficulties in identifying the counterparty and enforcing a judgement in them, but if that becomes possible (and if $10m is at stake, perhaps it might become possible, bounties, etc) then the argument that "code is the only representation, and this is what the code said, so this was lawful" is not valid, as it contradicts both contract law and fraud statutes.
- just-ok 5y agoBank error in your favor, collect ~~$200~~ $10M.
- barbegal 5y agoThis also shows how little security probing is performed on cryptocurrencies and smart contracts. It took over a month and a huge bounty to find the bug in this contract. The likelihood of finding bugs in other currencies and contracts is extremely high despite millions of dollars of value relying on it. Most cryptocurrencies and smart contracts are copy and paste with little analysis of the underlying code. To the creators the incentive is to create something fast and without expending any extra effort. The losers are always the users who put their trust in the creators. An ideal open source decentralised system should allow the users to verify the claims of the creators but the reality is that the code and the systems around it are far too complex for any single person to be able to verify quickly. Does anyone know of any organisations that can vet smart contracts and provide insurance in case they get hacked or fail in other ways?
- paulpauper 5y agoeven pro coders get hacked and make mistakes. normally, mistakes are inevitable and survivable, but crypto makes the stakes so much higher.
- paulpauper 5y agoWhen so much $ at stake and no wya to get it back, it makes it necessasry to have perfect code
- ctur 5y agoSomeday some engineer working on these kinds of contracts will realize they can make a lot more money illegally by “accidentally” adding such bugs to the ecosystem then colluding with whoever exploits them. Actually it’s probably already happening.
- bombcar 5y agoThere’s been at least one smart contract with a “typo” of zero for O that allowed an “exit event”.
- s5300 5y agoYeah, this is the case for this specific contract. Could dump a large amount of proof but don't exactly need too much attention brought my way.
- fastball 5y agoAs with the rest of the industry, mostly the solution here is just better vetting and static checking etc.
- paulpauper 5y agoMakes you wonder how many incidents are inside jobs. Probably more than one would assume.
- yborg 5y agoNot sure I follow the 'illegal' part. Code is law here, right?
- naikrovek 5y agoAfter reading a bit, not knowing WTH is being talked about, I did some searching. Because the author(s) of this article forgot what makes hypertext so powerful. (In fact, I think a lot of people have forgotten that. Don't be afraid to link things, people. Linking to something literally saves you the trouble of explaining it yourself. LINK MORE, PLEASE. I will click.) So this is apparently about some stock market for cryptocurrencies, looks like? I think so. The first few paragraphs of the analysis of the post-mortem contain so many new terms that I am never likely to trust anyone that pushes any type of cryptocurrency, ever. This is pretty clearly "The New Scam" type that is fashionable. People are regularly getting busted for the old fashioned pyramid scheme, so I guess something else needed to be invented. This stuff is unregulated, prices are easily swayed by a few famous individuals or sometimes a lot of unknown people, en masse, and you can earn and lose real money by trading the stuff. Hard pass. This article just reinforces to me that my decision about that is correct. I do not like telling people that their interests are bad, because I'm sure in some ways blockchain stuff is at least semi-useful. I mean there are other ways to provably make ledgers read-only, but whatever. I'm not trying to stir anyone up, is what I'm trying to say. Cryptocurrency is just so clearly not "on the level" in my eyes. Sorry. :(
- Arnavion 5y ago>Because the author(s) of this article forgot what makes hypertext so powerful. (In fact, I think a lot of people have forgotten that. Don't be afraid to link things, people. Linking to something literally saves you the trouble of explaining it yourself. LINK MORE, PLEASE. I will click.) This is a fine sentiment, but [you] [don't] [link] [every] [word] [in] [your] [sentence] to a dictionary website either, because you expect the reader to know English. In the same way it's perfectly fine to write an article with a target audience that understands the concepts being discussed. Not everything needs to be written for a general audience; this website is exclusively about cryptocurrency, and particularly dense with jargon and slang at that.
- alextheparrot 5y agoThis is actually a bit amusing, because one of my favorite reading features on iPad is being able to click and hold on an arbitrary word to look it up. Sure, the UI/UX of a traditional link isn't desirable, but I do want every word to be linkable to the dictionary.
- _pdp_ 5y agoThese kind of mistakes should not be possible in smart contracts if they are to become more mainstream. There has to be layers upon layers of defence built in to protect against common pitfalls. It is crazy that a single line can cause so much damage.
- tankenmate 5y agoCrypto pen testers will become a thing; plenty of central banks are making noises about starting blockchains.
- ethanbond 5y agoMaybe we could create a system to adjudicate such failures? ;)
- jacoblambda 5y agoThere are better tools for this, they just aren't in common use unfortunately. Had this been written in Glow, both this bug and the bug that followed where another 7M was stolen would have been compile errors. This is just the consequence of people developing code in languages that provide little to no protection against their various footguns. At the very least we should expect to see some additional tool on top of the language that can reason about the correction of the code.
- ZephyrBlu 5y agoHow would those bugs have been compile errors in Glow? I'm unfamiliar with it, but that sounds interesting.
- jacoblambda 5y agoHad this contract been written in idiomatic glow, it would have been structured as a state machine and transitions would be forced to be explicit. You could specify invariants on the states as well as constrain the behaviour of the transitions. In this case the transition would have moved the SM out of the initialised state which would have precluded the ability to re-initialise the contract/state machine. Attempting to invoke said re-initialisation would cause a compile error. You could write the contract in such a way that would still allow this however it would be evident that something is amiss as it would be incredibly un-idiomatic and awkward. In the other case, the function had an implicit constraint that the value was within a certain bounds. The contract made no effort to check these bounds. With Glow you would have specified the constraints on the inputs and the interaction with the contract would be denied if the input for the function was outside those constrained bounds. This would be a compile error and possibly also a runtime check in the case of malicious actors ignoring bounds. I'm not sure how necessary the runtime check would be (as I'd have to check how the smart contract generation is set up) but at the very least the exploit would not have been able to occur.
- latchkey 5y agoAnother one _just_ happened... $10m. This time using the wrong variable. https://bearn-defi.medium.com/bvaults-busd-alpaca-strategy-exploit-post-mortem-and-bearn-s-compensation-plan-b0b38c3b5540 https://bearn-defi.medium.com/bvaults-busd-alpaca-strategy-e...
- yaitsyaboi 5y agoWhat is the purpose of Solidity? Why did there need to be a new language for interacting with the Ethereum Virtual Machine? This really couldn't be accomplished by a python SDK?
- kamyarg 5y agoNot an expert in solidity but from my limited experience EVM and smart contracts have really different approach when it comes to computation. two things that come to my mind: - There is really no random() function due to need for determinism - Space vs. Time complexity is distorted, the gas you pay for instruction vs. byte is really different economics compared to AWS EC2 instance/hour etc.
- yaitsyaboi 5y agoInteresting, do you suggest any sources to read more about this?
- kamyarg 5y agoNot sure about articles but I can recommend Crypto Kittens Tutorial[1]. It has been some time since I did it(Late 2018 I think), but was really informative to get the mindset and different constraints people deal with in smart contract world. [1] https://www.cryptokitties.co/kitten-class/breeding/introduction https://www.cryptokitties.co/kitten-class/breeding/introduct...
- splintercell 5y agoSolidity is a DSL. DSLs have their purposes and this happened to be a correct purpose. It just also happens to be that Solidity is a terribly designed language.
- geocrasher 5y agoCan somebody explain to a non-coder who doesn't have anything to do with cryptocurrency what happened here? I find the article itself to be unreadable.
- latchkey 5y agoThe bank got robbed.
- yojo 5y agoAs I understand it: Value DeFi is a company that provides infrastructure for some kind of lending. Money (in this case cryptocurrency) is locked up in a “smart contract” that acts as a sort of bank account. If all is working correctly, the owner of that money can dispense it to borrowers by sending specially crafted and authenticated messages. In this case it looks like the way it was supposed to work is: create the contract, send an “initialize” message to declare yourself the owner, then fund it and otherwise control the money. The intent was that “initialize” could only ever happen once, so the owner could not change. In practice, there was a bug where someone could initialize again, thereby declaring themself the owner of the contract and funds. Someone did this to a contract funded got with $10M, then promptly sent it all to their own account.
- geocrasher 5y agoThank you. After some coffee and a re-read, this is the conclusion I came to also.
- latchkey 5y agoThis was REKT2. There is a REKT1 AND REKT3 as well. https://www.rekt.news/value-rekt3/ https://www.rekt.news/value-rekt3/ Anyone heavily participating in DeFi considers this a cost of doing business in the cutting edge of new finance (which is a very debatable way of saying things).
- s5300 5y agoOh, Value DeFi is just a long-haul grifting scam in general lmao. Wasn't a "missing" line, "dev" team just set it up lol. I have a boatload of screenshots sent from one of their team members I'd been talking with for a few months that was internally profiting off the grift but then went rogue. Shame this story is getting attention, especially on HN. YFV aka Value DeFi is just a long-haul rugpull/scam lol.
- koolba 5y agoSerious question for people familiar with this space. Would you encourage an ambitious expert programmer with a substantial finance background to avoid this space entirely, or enter it as a creator, a contractor, or black hat?
- hiq 5y agoWhat's your goal? I don't think committing crimes as an expert programmer is a rational choice with most utility functions. Do you really want to make 10x or 100x as much in exchange of your peace of mind? Given that you're probably a top earner already? And that's already taking it from a purely selfish point of view.
- koolba 5y agoI’m wondering which would be the most lucrative one, five, or ten years out. Plus the legal status of interacting with a smart contract per its “code is law” API has not been tested. Have you broken any law or even civil contract?
- jazzyjackson 5y agoWell at least take a look around and see if it's interesting to you. I've been enjoying a playlist of blockchain lectures by Gary Gensler, current chair of the SEC. Lecture 6 is smart contracts with Lawrence Lessig guest speaking. [0]/[1] I've been avoiding smart contracts since hearing about hacks like these (similar to the Multisig Parity Bug years ago, neglected to initialize, let someone else become the owner and kill the contract) - but I've been educating myself the past week and find that there are really cool things that can be done, maybe cooler a year or 15 in the future when ETH finally gets its fees under control. As a programmer, you'd probably be interested to see the ethereum virtual machine's "assembly" language [2], I'm pretty impressed with how little code underlies all these ERC20 tokens. [0] https://ocw.mit.edu/courses/sloan-school-of-management/15-s12-blockchain-and-money-fall-2018/video-lectures/ https://ocw.mit.edu/courses/sloan-school-of-management/15-s1... [1] https://www.youtube.com/watch?v=EH6vE97qIP4&list=PLUl4u3cNGP63UUkfL0onkxF6MYgVa04Fn https://www.youtube.com/watch?v=EH6vE97qIP4&list=PLUl4u3cNGP... [2] https://docs.soliditylang.org/en/v0.8.4/yul.html https://docs.soliditylang.org/en/v0.8.4/yul.html
- IG_Semmelweiss 5y agoThere's an extremely strong case for Bitcoin as a public ledger of real estate transactions within a particular jurisdiction like a country, but that would necessitate a lot of interested parties losing power that it would be a political 3rd rail. Outside of that is there any s interesting use cases that have emerged?
- hiq 5y agoMany people are asking what happened, because the article does not go much into detail. The code is there (linked in the article): https://bscscan.com/address/0x7a8ac384d3a9086afcc13eb58e90916f17affc89#code https://bscscan.com/address/0x7a8ac384d3a9086afcc13eb58e9091... After spending 2min on it and using this hint from the article: > The affected pool contract had an initialize() function that should have been activated after deployment. > The line: initialized = true; is missing from the function. That's really the crux of the issue. Have a look at the `initialize()` function. It's meant to be called only once (that's why it uses the modifier `notInitialized`), right after the smart contract is deployed, and never again. But the `initialized` variable is never set to true, meaning that it can be called again, and it seems that's what the attacker did. ...so for those who expected something fancy and technically advanced, that's not for you.
- andrewfromx 5y agoso where does one draw the line between theft and just doing what the code allows? I wonder in the future crypto courts is the defense, "your honor, the code allowed me to call initialize again, they specifically didn't set it to true." going to fly? Or will you have to prove that the 10 mil you now have was intended to be given to you and your "victim" isn't a victim at all.
- paulpauper 5y agoif it went to court, i am guessing presuambly under a plea deal the hacker would be required give back all or most of the crpyto to rectify the 'mistake;' if not, it would prove intent to steal . For example, there is the 2005 Sammy MySpace XSS incident. Technically, his code was interpreted by Myspace as valid CSS/html, but was still guilty due to intent.
- deleted 5y ago[deleted]
- cosmodisk 5y agoIt may depend on a legal system in a country but I think 'Or will you have to prove that the 10 mil you now have was intended to be given to you and your "victim" isn't a victim at all' is more likely. For instance there were cases,where ATMs dispensed stupid amounts of money because of some error. People would normally be found guilty if they take the money that technically isn't theirs.
- deleted 5y ago[deleted]
- exdsq 5y agoInteresting to see that those with audits are still vulnerable. I question the quality of companies like Certik which basically just run a home-brewed static analysis tool and charge a crap ton.
- coreyoconnor 5y agoFor fun I've been analyzing the contracts posted to r/CryptoMoonShots. Out of 20 posts 16 of them used the same contract; modulo names. This contract blocks everyone from removing funds but the owner. How? Is it some complex chunk of code that requires a delicate hack? No, not at all. There is literally a function with code, more or less, like: "If owner then OK here's all the funds". Anybody can check this in the contract. Yet people are dumping funds into these contracts. Even tho these contracts tend to only attract a few thousand dollars each. Well, costs next to nothing to create and spam. A more detailed analysis of a similar contract to the one I've seen: https://cryptot3ddybear.gitlab.io/blog/posts/scam-explained-bsc-stealthy-lp-block-howto/ https://cryptot3ddybear.gitlab.io/blog/posts/scam-explained-...
- twobuy 5y agoTypically the small amount of volume is by the contract owner attempting to pick up attention from momentum trading bots. This type of contract made a killing a few months ago. Basically miners trade by sandwiching orders in the mempool. You can search the 'salmonella' contract for more info.
- moozilla 5y agohttps://github.com/Defi-Cartel/salmonella https://github.com/Defi-Cartel/salmonella Link for the lazy, super interesting read.
- sneak 5y agoThen it moves the security breach incentive to compromising the owner's keys, which is also usually pretty straightforward.
- KETpXDDzR 5y agoI see a market for static code analyzers for smart contracts. And virus scanners!
- doopy1 5y agoYes, it's a very lucrative field for those that are good at it.
- deleted 5y ago[deleted]
- tylersmith 5y agoIt's a rapidly growing, and fun, market. Anyone interested, feel free to contact me about working in this field.
- jtsiskin 5y agoThe story doesn’t end there. After they converted to BTC at https://www.blockchain.com/btc/address/1Cm6WGvXQ9EgvvWX5dRsBxE2NvxFjfbcVF https://www.blockchain.com/btc/address/1Cm6WGvXQ9EgvvWX5dRsB..., where does the money go?
- paulpauper 5y agothat is presumably to prevent the $ from ever being frozen. in some instances, devs will freeze defi tokens. very uncommon and controversial but it happened after kcuoin hack
- dj_mc_merlin 5y agoIs it weird that this kind of excites me? It's like in that videogame Uplink, where you would hack into a bank and redirect cash to yourself. Except in real life. A new wild west?
- shiado 5y agoThere's no such thing as hacking a smart contract. The code is the law.
- cblconfederate 5y agoThis is why Defi wins: people realize early that their contracts have to be space-proof and nuclear-proof, or else the punishment can be more than fatal. But the bigger win is there s no bailout or stimulus. Insurance is an additional level on top of the chain
- distribot 5y agoI find the cyber noir nature of this rekt.news to be really delightful
- PaulHoule 5y agoI went to a conference years ago in NYC and was shocked that Etherium didn't have a security story at the application level.
- reilly3000 5y agoThis makes me think that the next generation may have a new profession of hybrid lawyer-programmers that are engaged to ensure the validity of smart contracts, both negotiating and formally verifying these boilerplate transaction machines. While this was clearly a technical oversight, there are also legal frameworks and traditions that need to be programmed into future contracts. That along with insurance, escrow, title, and other professions will need to evolve with web 3 paradigms.
- PostThisTooFast 5y agoWhat a pile of jargon and zero explanation. Shit article.
- mrfusion 5y agoI’d bet missing lines of software have done way worse than this.
- sireat 5y agoLooks like there are plenty of more DeFi hacks/internal fraud/incompetence https://www.rekt.news/leaderboard/ https://www.rekt.news/leaderboard/ Setting aside the hacks, what good is DeFi anyhow for those outside crypto space? Seems DeFi currently serve two main functions. 1. Crypto backed loans - main purpose being crypto speculation / possibly some dubious tax benefits 2. Decentralized exchanges - nice for those into crypto but not for Joe Sixpack.
- TimJRobinson 5y agoYou could have said similar about the internet in 1990. It was an easily hackable network used only by geeks to share research papers and chat. Technologies start to help small niches and grow over time. The DeFi space could eventually grow to replace any firm that acts as a middleman for digital trades: Robinhood, Wealth front etc.
- drdrey 5y agoIf you specifically want to avoid speculation, you could also provide liquidity with stablecoins and collect fees from people trading against your liquidity. For people outside the US, they could also get price exposure to US stocks with things like sAAPL, sGOOG, etc (synthetic assets that represent an underlying equity)
- uh_uh 5y agoHow do these synthetic assets implement tracking the original asset price? Are the assets still subject to the swings of the general crypto industry (e.g. BTC crashing pulls sGOOG down as well even though Google's real stock appreciates)?
- drdrey 5y agoFor a protocol like Synthetix, I believe it uses price feeds provided by Chainlink. In principle, you can always redeem a token like sGOOG for the current price of GOOG on the regular stock market. In practice, there is some risk that an asset could lose its peg. https://docs.synthetix.io/litepaper/#synth-pegging-mechanism https://docs.synthetix.io/litepaper/#synth-pegging-mechanism
- TazeTSchnitzel 5y agoIt is surprising that people would entrust large amounts of money to Turing complete C-like programming languages in an environment where mistakes are irreversible. Surely you would want to use a language that makes it harder to accidentally introduce common vulnerabilities? For example, considering contracts are likely to be state machines (and the error in this case is a state machine issue), maybe an explicitly state machine-oriented language design would be good? I'm not familiar with academic research in this area but I have used a real-world one before, Linden Scripting Language, which incidentally is also used for what you could call “smart contracts” involving money, albeit not in a cryptocurrency environment.
- Paradigma11 5y agoThere is: https://archetype-lang.org/ https://archetype-lang.org/ with an explicit https://docs.archetype-lang.org/archetype-language/state-machine https://docs.archetype-lang.org/archetype-language/state-mac... feature.
- jl2718 5y agoWhy is this only on tezos? Is there some technical reason why tezos can use it but others can’t. I know tezos was basically born from theDao fallout, but, seems like maybe eth should think about standardization and verification too.
- Paradigma11 5y agoI dont know how hard it would be to port it to other platforms. Different Virtual machine. Tezos uses a human readable stack based language as a low level represenation that is suited for formal proofs: https://tezos.gitlab.io/008/michelson.html https://tezos.gitlab.io/008/michelson.html If archetype depends on that then its going to be hard to port but i dont think it does. Another interesting project in development is https://juvix.org/ https://juvix.org/ which targets more backends beside michelson like llvm and wasm. Might run on eth2/Ewasm. There are also blockchain specific features like: https://medium.com/tqtezos/tickets-on-tezos-part-1-a7cad8cc71cd https://medium.com/tqtezos/tickets-on-tezos-part-1-a7cad8cc7...
- cryptica 5y agoI never understood the point of smart contracts. Why not just launch a new blockchain or decentralized application by forking code and launching nodes? That way you don't need to pay Ethereum fees and you get a lot more flexibility - Also, your project will not be constrained by Ethereum's scalability limits and you won't have to pay fees to subsidize the popularity of other projects which are running on the same platform... Ethereum seems to facilitate mostly short term scams. Projects launch, raise a ton of money, then when people try to actually use the new project, they realize they have to pay $20 per transaction. This quickly kills the project; now onto the next scam. What kind of brand new project can justify making their users pay $20 per transaction? I struggle to think of any genuine use case.
- bouncycastle 5y agoBecause contracts can call other contracts in the same transaction if they are on the same chain. This is what is known as "composition", and it's very handy for building powerful apps on existing proven primitives (such as aggregators, decentralized exchanges, lending protocols). Also, once you launch a contract on Ethereum, it's accessible to millions who already have an Ethereum wallet with ETH loaded. On-boarding to a new chain would be more of an uphill battle. If you're worried about tx fees, there are already plenty of L2 solutions available and more coming online soon!
- quadcore 5y agoThere might be something deeply interesting in that news actually. 'initialised = true' is obviously a bad pattern, now people cant argue about it anymore. Why is it bad? Obviously, if you forgot the line then... BOOM. So instead I check whatever main variable the initialisation initialised before the initialisation starts - even when it looks a bit awkward cause it does sometimes. Also, the whole concept of initialisation is a bad pattern. You dont want to have an initialisation whenever you can avoid it, you want to perform the whole calculation every time. 'initialisation' implies a state machine. You dont want state machines, you want stateless machines, as much as possible. So yeah, 'initialisation' is a good optimisation some of the time and most of it a bad compulsive-caching habit. 'initialised = true' just costed people $10M. I really like those DeFi things cause at first glance.. I think they might actually teach people how to code!
- meowface 5y ago>So instead I check whatever main variable the initialisation initialised before the initialisation starts - even when it looks a bit awkward cause it does sometimes. Also, the whole concept of initialisation is a bad pattern. You dont want to have an initialisation whenever you can avoid it, you want to perform the whole calculation every time. 'initialisation' implies a state machine. You dont want state machines, you want stateless machines, as much as possible. So yeah, 'initialisation' is a good optimisation some of the time and most of it a bad compulsive-caching habit. One issue is that every operation in Ethereum smart contracts costs some gas, with differing gas costs for different kinds of operations. I'm not sure to what degree it applies in this case, if at all, but anything you can do to reduce the number of operations (and minimize costly operations) helps reduce gas costs.
- intricatedetail 5y agoThis actually looks like core wars but for money...
- paulpauper 5y agomake that $8.5million. bitcoin fallen a lot
- raldi 5y agoAnd that is why after typing “if not initialized:” you must as muscle memory immediately type “initialized=True” as the very next line of code.
- ddingus 5y agoTwo things bother me: One is we put terms into contracts for when either party has to act in ways neither party may be happy about. This also helps to plan for risks. Shit happens. That is what terms are for. Missing a line = missing a term. Where that happens, one can totally expect the other party to make good use of the terms as agreed. Now comes the other major bother: When employing written contracts, unless one is rolling their own, we have a body of law and language fairly well debugged and mutually understood. Starting all that shit again as if code is law is going to be ultra painful! There was plenty of pain to establish the law we have today. This all will be no different. And still there will be law, so what is the point, unless the scope of terms is a subset of those allowed by law anyway?
- leifg 5y agoWhenever I read guides on best practices for smart contracts there is always a line in there that says “consider all possible edge cases when developing…” That sounds like smart advice but is also incredibly naive. If humans were able to foresee all possible inputs of any function we wouldn’t have spaceships exploding because of human errors. I’m not sure how the smart contract dev community actually thinks of themselves but I personally don’t think I would ever be able to guarantee that my program works for all possible inputs (I’m a software engineer for more than 12 years). So I am never surprised when a smart contract goes rogue and burns millions of dollars.
- perryizgr8 5y agoSo are they forking the chain again like they did the last time: https://www.coindesk.com/hard-fork-ethereum-dao https://www.coindesk.com/hard-fork-ethereum-dao It was a similarly silly coding mistake the last time too.
- jgilias 5y agoThis may be a silly and naive question, but what happens next? The BTC address that received the stolen funds is known and can be monitored. How do you convert it to fiat or use it without revealing yourself?