11 ms·
Best description of the hack I have found yet. The hack is on the solana side not the ethereum side of the bridge https://twitter.com/kelvinfichter/status/14890
by cdiddy2 5y ago
Best description of the hack I have found yet. The hack is on the solana side not the ethereum side of the bridge https://twitter.com/kelvinfichter/status/1489041221947375616 https://twitter.com/kelvinfichter/status/1489041221947375616
*edit: another good thread https://twitter.com/samczsun/status/1489044939732406275 https://twitter.com/samczsun/status/1489044939732406275
- lostmsu 5y agoBoth cut short for me.
- deleted 5y ago[deleted]
- encoderer 5y agoEvery one of these attacks reads more like a chemical process than a hack. “First, synthesize o2 by borrowing an oxygen molecule…”
- ZephyrBlu 5y agoExploit is a more apt description than hack.
- btown 5y agoFrom the first thread: > A commit was made ~9 hours ago replacing usage of load_instruction_at with load_instruction_at_checked, which actually confirms that the program being executed is the system program. It's interesting that this commit was made ~9 hours ago and the exploit happened a few hours after that. Possible that an attacker was keeping an eye on the repository and looking out for suspicious commits. Could be that the Wormhole team spotted the bug, patched it, but the attacker got to it before the patch could be rolled out. Super important to keep these sort of patches lowkey and to try to stuff them into larger commits. > It looks like maybe Wormhole tried to do this by including the change in a much larger and unassuming commit called "Update Solana to 1.9.4". Not sure exactly what happened here, but a clear lesson to try to deploy before making any patch details public, if you can afford to do that. Of course this ends up being at odds with Web3 ideals, so not always clear how to best handle these sort of things. One thing that would be healthy for the larger ecosystem would be for chains to build in regular "maintenance windows" where trades are halted by contract, at which time sensitive security patches can be rolled out to the codebase and then to the network by the maintaining team. Of course, this requires a lot of foresight. But the alternative is something like this. Also - why would you ever set up a system where the majority of its assets can be drained by a single transaction, whether legitimate or not? Just because it's not centralized doesn't mean every transaction is made equal; one could require timeout periods for transactions above a certain amount, or any size of transactions could trigger a halt once a certain amount has been bled in aggregate, that requires supermajority consensus to "unlock" the chain. That this wasn't built in, in an ecosystem where hacking is rampant, by a team focused on creating a cross-chain transmission utility, is surprising, to say the least. There are far, far worse things than a halt on trading. There are many domains where unsupervised 100% uptime on systems with access to a substantial portion of an organization's assets is ideal; finance, whether centralized or decentralized, is rarely one of them.
- rr808 5y agoThis is why multi day settlement is a feature not a bug. For big money it really does not need to be instantaneous.
- 101011 5y agoWhich is funny because you always hear how fast crypto transactions are. What everybody seems to leave out is that fully settling on the blockchain is slow and costly.
- SkyMarshal 5y ago> fully settling on the blockchain is slow and costly. That depends on which blockchain you're fully settling on. There's more than one, Ethereum != "the blockchain".
- yvdriess 5y agoFundamentally, the more popular the chain, the more expensive transactions are going to be.
- spopejoy 5y agoNot if the chain can scale -- ie not "fast finality" but being able to throw more resources at the problem as adoption increases (unlike Bitcoin, Ethereum and most single-chain POS systems however). Gas' true function is to stop griefing, the fact that it sends tx costs through the roof is because immature tech.
- oblio 5y agoHow can they ever solve the fundamental problem of slow worldwide, globalized, decentralized consensus? Have I missed some Turing Award discoveries while I was away?
- basicallybones 5y ago
- X6S1x6Okd1st 5y agoFor those not following the space, solana has a smart contract language (a DSL in rust) that is new. Ethereum's primary smart contract language is solidity which has iterated many times & has linters and auditors that have learned their lessons through plenty of bugs in the past. (e.g. the DAO hack that split ETH into Ethereum and Ethereum classic) was a bug of the type "re-entry", it still crops up. The new language & platform will likely need to learn the classes of bugs that can crop up through a similarly painful process, although this one was using something that was unknown to be unsafe :shrug:
- archseer 5y ago> something that was unknown to be unsafe The call they were using was deprecated and marked unsafe a while ago: https://github.com/solana-labs/solana/blob/7ba57e7a7c87fca96917a773ed944270178368c9/sdk/program/src/sysvar/instructions.rs#L180-L188 https://github.com/solana-labs/solana/blob/7ba57e7a7c87fca96...
- tasha0663 5y ago> smart contract They need a new name for these things that better communicates the risk level. Right now calling these "smart contracts" is like calling dynamite a "lovely candle". There's nothing smart about something that lets you screw up this badly.
- spookthesunset 5y agoIf they didn’t formally verify the smart contract in a way that covers all edge cases including known “exploits” they kinda deserve to have their ethereum transferred to its new holder. Code is law.
- lottin 5y agoAccording to contract theory, it may not be possible, in practice, to write "complete contracts", that is contracts that specify what is to be done in every possible contingency. See https://en.wikipedia.org/wiki/Complete_contract https://en.wikipedia.org/wiki/Complete_contract
- chrononaut 5y agoWow! This was the most surprising to me in the thread: > It's interesting that this commit was made ~9 hours ago and the exploit happened a few hours after that. Possible that an attacker was keeping an eye on the repository and looking out for suspicious commits. https://twitter.com/kelvinfichter/status/1489050921938132996 https://twitter.com/kelvinfichter/status/1489050921938132996 > Could be that the Wormhole team spotted the bug, patched it, but the attacker got to it before the patch could be rolled out. Super important to keep these sort of patches lowkey and to try to stuff them into larger commits. https://twitter.com/kelvinfichter/status/1489051698329014273 https://twitter.com/kelvinfichter/status/1489051698329014273 Is this something inherent in the cryptocurrency space? Where monitoring for security patches and exploiting them before they are rolled out results in an instant multi-million dollar payday? Is this a common risk? If so, that seems crazy. Vendors already struggle rolling patches in closed source environments.
- mdoms 5y agoI thought these contracts lived on an immutable blockchain, how can they even be patched?
- danielvf 5y agoThis bug was on the Solana blockchain. Solana has built in support for updating code. Even on Ethereum, with it's mostly immutable contracts/programs, there is a super common pattern of a tiny shim contract that forwards all calls on to another contract that does all the work. By changing a storage variable which changes the contract the shim points to, you can effectively upgrade the code.
- dralley 5y agoAnd therein lies my biggest frustration with crypto evangelism. Almost every theoretical benefit that gets trotted out is such a detriment in practice that the ecosystem tosses it aside. While still proclaiming it as a virtue.
- 5y ago
- mdaniel 5y agohttps://threadreaderapp.com/thread/1489041221947375616.html https://threadreaderapp.com/thread/1489041221947375616.html https://threadreaderapp.com/thread/1489044939732406275.html https://threadreaderapp.com/thread/1489044939732406275.html It's unfortunate that the images don't load in that view, but it's still better than the twitter UI
- bitcharmer 5y agoThanks for sharing but I immediately drop stories that are sliced into a million twits instead of being put in a single blog post. I hate modern internet.
- kwertyoowiyop 5y ago“Code is law”? No, VM implementation is law!