14 ms·
In simple words, he should have called a smart contract's function which would withdraw his tokens and send real ETH to his address. Instead, he sent tokens to
by afidrya 5y ago
In simple words, he should have called a smart contract's function which would withdraw his tokens and send real ETH to his address. Instead, he sent tokens to smart contract's address and they will stay there forever, not associated with any account.
This complexity should be abstracted away by wallet's UI. Users don't have to call APIs directly.
Also, this whole situation could be prevented by trying to send a smaller amount first.
- noduerme 5y agoI've written middleware APIs for accepting currency in carts and casinos that interfaced with / polled bitcoind and other daemons. Why on earth would this person be calling APIs directly, and why would the daemon not just reject the transaction if it's an unexpected kind of token? Or if he added funds to the contract why not be able to remove them to the same address? I never dealt with smart contracts but even allowing this to happen without an error seems like a crazy, terrible design.
- jazzyjackson 5y agofrom the reddit comments, similar question, apparently every instruction adds gas fees to running the contract, so if you're going to use the contract a lot, you leave out any kind of validation. >> Wow why didn't the contract creators think this through and block requests to the contract > Because adding that check would increase the cost of every user transaction. All AMM swaps would be done with WETH so it’s the right call to not have it in there
- XorNot 5y agoI really can't think of an expression other then "lol" to sum up my response here for just how incredibly stupid this is, as a "platform of the future". A design which actively discourages robust programming and error handling in financial software. Wow.
- ljm 5y agoIt's like a libertarian utopia. Literally everything is an individual responsibility with no wider recourse. Want validation? Other people don't want to pay for stuff they're not validating... so it's on you to be careful. Accidentally fuck up? Not our problem, that's on you for not calling the right API. Want your money back? We're not paying money to cover for other people's mistakes. You're on your own bud.
- skinnymuch 5y agoWhat about the Eth DAO forks? How was that individual responsibility?
- optimalsolver 5y agoAll smart contracts are immutable, but some are more mutable than others.
- ericmay 5y agoOk… but then if you’re going to throw out these cases you should also address how markets can fix these issues, such as great customer service: “when I fucked up they helped me out, they’ll get more of my business”, or maybe insurance, or just better products that don’t have these issues. Idk why people conflate libertarianism with this hyper-individualist stuff. It really isn’t the case.
- ljm 5y agoDo ethereum and smart contracts currently have excellent customer service, such that the guy in TFA can get his 500k back?
- spookthesunset 5y agoWhy should this person get anything back? Code is law. And if code is law all bugs are also law. The half million was a fair and just transfer. Whoever is the recipient is fully deserving both morally and ethically of their new-found wealth. If I was on the receiving end of this transaction, I’d thank the sender for the money and move on with my life. Of course I’d never be in the position to receive the funds because I’m not stupid enough to play this game—odds are very good I would be the one who sent half a million dollars by mistake! I mean, I think I’m joking but not really. If you want to practice “code is law” and really mean it, this is the kinds of stuff that will happen.
- noduerme 5y agoBack in the day or at least when I ran my own bitcoin node, any call against the blockchain was free. This sounds like someone charging for hitting the API on a rented node, as opposed to an actual cost imposed by the currency to consult the blockchain (?) But maybe the contract-generators aren't even running their own node, just piggybacking on someone else's API. Sure. Cheaper.
- riffraff 5y agoAFAIU, smart contracts on the ethereum VM can be arbitrarily complex, so you pay the network to execute them, or a random user with an infinite loop would bring down the network. You are indeed renting a machine to run some code, and if you want many people to use your code you want to make it cheap. There's a trade off. You can fuck up things on the BTC blockchain too, "burning" crypto by sending it to a dead address has been a thing for a long time. It always seemed stupid to me that it was possible, compared to sending money to an invalid IBAN, but I'm not a crypto enthusiast so I may be biased.
- noduerme 5y agoOn BTC, you could send things to the wrong address, yes. But you can't send the wrong type of currency or send it to a nonexistent address. In this case it seems like the contract has created the black hole (not the Ethereum blockchain itself), but that's even more absurd since someone ultimately should have control over everything that was put into the contract, regardless of the source.
- axiosgunnar 5y ago> But you can't send the wrong type of currency or send it to a nonexistent address Of course you can do both things, which is why catastrophic financial ruin is a daily fear when dealing with cryptocurrencies. https://www.quora.com/How-can-I-find-my-Bitcoin-cash-that-I-accidentally-sent-to-a-Bitcoin-address-through-Coinbase-The-transaction-shows-completed-but-it-never-got-there https://www.quora.com/How-can-I-find-my-Bitcoin-cash-that-I-...
- kwertyoowiyop 5y ago“Premature optimization is the root of all evil.” And now in a whole new way!
- dTal 5y agoThere are, of course, other industries with financial incentives against safety features. We usually regulate them. We can point and laugh at this one person, but according to the reddit thread they're the 265th person to make this mistake, and more than half of the money in the inaccessible account is not theirs.
- noduerme 5y agoI hadn't even thought about this. With BTC early on, the only party to really benefit from lost coins would be "Satoshi", but his coins weren't worth anything until the currency took off anyway, so it was more important and long-term profitable to build a system that didn't lead to user anger than one that would lose coins to deflate what was already a deflationary currency. It really does show how slimy the whole cryptocurrency world has become.
- GaylordTuring 5y agoAnd that's just for this particular token. You can go to just about any token contract and see how numerous people have sent their tokens to the contract address itself.
- ddingus 5y agoGood grief, this is like machine language for money
- mox1 5y agoexactly, with no-do overs. Everyone hand codes their assembly correctly on the first try right!?!!
- capableweb 5y agoThere are plenty of do-overs, it's called the "development phase" and involves testing things on your local computer with the team. No one gets everything right the first time, but with a lot of testing, you can actually write software that does exactly what you think it will do, and you can achieve pretty cool stuff. Remember that humans wrote the software that took humanity to the moon!
- UncleMeat 5y agoAs we know, no software has had bugs caught once launched to prod. The existence of some software that worked under this model is not evidence that it is a good model. "Just test prior to release" is not a complete solution.
- mox1 5y agoYes, and that code had bugs. https://www.forbes.com/sites/lanceeliot/2019/07/16/apollo-11s-infamous-landing-error-code-1202-offers-earthly-lessons-for-self-driving-cars/?sh=4934e30734bc https://www.forbes.com/sites/lanceeliot/2019/07/16/apollo-11... There are 0 do-overs on smart contracts in production. No stopping the network for a minute to triage, no rolling back a minute, no circuit breakers. No "Error 1202, do you want to continue?" pop-up messages.
- ddingus 5y agoIn this case, not really. User was calling a "ROM" What you describe are dry runs.
- BatteryMountain 5y agoIt truly is laughable. Ever heard of "Return to Sender" in case of invalid events/transactions?
- SwiftyBug 5y agoYES. Weren't these supposed to be SMART contracts? My email provider is smarter than that.
- capableweb 5y agoFirst time I hear about IMAP/POP3 provider being able to "undo" emails after being sent. What provider are you using and how does that work behind the scenes? And no, gmails fake "we don't actually send it until you close the tab/wait 30 seconds so you can undo it" doesn't count.
- oefrha 5y agoI’m sure you’ve heard of it, but in case you haven’t, it’s called bouncing when there’s no valid inbox on the other end. Before you object, yes, you can set up a catch-all incinerator, but that’s not the default as is the case here, you have to explicitly set it up.
- capableweb 5y ago"Bouncing" can happen in cryptocurrency world as well, it's called "sending to an invalid address". It just happens to be that the address-space is so big you don't really know what address has a real physical person behind it or not, or yet even. Try sending cryptocurrency to an invalid address and you'll see that the wallet will reject sending it, just like email bouncing.
- oefrha 5y agoMost people setting up mailservers don’t consider a catch-all forwarding to /dev/null a valid inbox. And no sane mailserver software forwards to /dev/null by default if you don’t explicitly tell it what to do when it receives email it isn’t supposed to receive. A “valid” address locking up funds sent to it without recourse is /dev/null.
- sanderjd 5y agoIt was a really bad design decision to have smart contracts have this "send to the address" capability, rather than requiring clients call a method that is explicitly defined.
- Maursault 5y ago> he sent tokens to smart contract's address and they will stay there forever, not associated with any account. Wait... so the tokens are really still there, just inaccessible? In what way do the tokens still exist? What makes them inaccessible? Is there really no possibility of restoring the tokens? No possibility of cleverly hacking them out with the assumed myriad of unpublished security flaws?
- pie_flavor 5y agoThe tokens are a number in a hash-map of user to balance in the weth program. Any eth program ("smart contract") can be a user. All the smart contract that owns the tokens has to do is tell the weth smart contract to transfer them, or approve mister redditor to transfer them on the contract's behalf. But that contract wasn't built to do such a thing. And now that it's published, it also can't be updated to do such a thing. A new contract could be uploaded, but that new contract won't be the same user. So they're just gone for good. Hope that cleared things up.
- triangleman 5y agoSo, could the Ethereum community get together and agree to rewrite the blockchain and undo this transaction? Perhaps they could vote on it and have a hearing of the facts. Of course that introduces its own tyranny but is it possible?
- monktastic1 5y agoThe chain is by nature append only, so you'd have to fork it, which they sure as hell are not going to do for a "little guy," to put it mildly. At least, that's my layman's understanding.
- shadowgovt 5y agoYep. Little users can still get screwed, but players too big to fall get to make up new rules. ... Reminds me of another financial infrastructure I know.
- bigtex88 5y agoIn simple words, he should have done what everyone else does and used Uniswap or Zapper or Sushi or ANY exchange and swapped WETH for ETH that way. This is just a dumbass user doing dumbass things. This is basic-level stuff right here. Don't interact with contracts directly unless you 100% know what you're doing.
- UncleMeat 5y agoBut people are allowed to interact with smart contracts. To obtain the WETH he needed to do that. This is a "why do we even have that lever" kind of situation. If my brokerage had a "permanently burn all of your money" button then it wouldn't be reasonable to just say "well, people shouldn't push that button." We can even see this with the criticism of wire fraud. Wire fraud is a huge fucking mess that occasionally costs people their life savings. The entire setup is rightly criticized (heck, even by the crypto community) for having users interact with a highly error-prone system with huge consequences.
- emteycz 5y agoPeople are allowed to login as root and delete their systems too. Yes, today's software doesn't make it easy - and the same can be said about this wallet/token; this was a complex sequence of steps in the wrong direction, not a missclick.