4 ms·
As a part of the hack the attacker did transfer 320M million worth of previously existing coins to themselves. That was the payoff for the hack, and the entire
by danielvf 5y ago
As a part of the hack the attacker did transfer 320M million worth of previously existing coins to themselves. That was the payoff for the hack, and the entire point of doing the hack. The minting part was just a stepping stone to that.
Also, the attacker definitely exceeded authorization - it was literally the authorization component of the code that the attacker bypassed by substituting part of it with their own ringer code.
- cwkoss 5y agoHow is this different from a bitcoin miner minting coins, trading them for another coin, and withdrawing? If code is law, attacker was playing by the rules. I don't think this is clear-cut illegal. It looks illegal-ish, but I think a good lawyer could argue it isnt. Does Solana/Wormhole have ToS that (in the courts eyes) overrides the state of the blockchain? If they did, doesn't that kind of defeat the purpose of a decentralized blockchain?
- TameAntelope 5y agoCode isn't law, is the point. No matter how many times people try to claim that, the legal system does not, to my understanding, actually work that way. It would depend entirely on what a judge and a jury think about how the law ends up getting applied, were this tried in US courts.
- cwkoss 5y agoIf code isn't law, could a crypto holder sue a crypto miner for inflating the market supply and reducing the value of their holdings? What is the legal distinction between mining (which is intent of the protocol) and this attack (presumably not the intent of wormhole)? Do blockchain services need to create ToS's which can legally supercede in the case of bugs in order for courts to punish attackers? Would blockchain users accept a service with such a delegation of state?
- TameAntelope 5y agoYou can sue anyone for anything in my country (USA), but I don't know if you'd win, for so, so many reasons.
- PretzelPirate 5y agoInterestingly enough, the only people I see saying “code is law” nowadays are people who are accusing the blockchain community of being the ones pushing that idea.
- shinryuu 5y agoAn exploit is technically always following the rules of a system. Take for example a sql injection. The system allowed a sql injection, you told the system to execute the sql code of your choice and bam you got what you wanted at the expense of the counterparty. This would still be considered illegal. code is code, code isn't law. Even if you try to call it 'smart contracts'.
- Youden 5y agoAh, I wasn't aware of the previously existing coins. This being DeFi though, was it clear who owned those particular coins or were they "owned" by the program? I'd actually be interested to know if crypto can, from a legal perspective, be owned. Has crypto theft been successfully prosecuted before? As for exceeding authorisation, yes, true, but IIUC, CFAA only makes illegal the unauthorised access to a _computer_. Since this is a crypto program, is there an identifiable computer that was accessed without consent? To be clear, I'm not making any moral judgements here, I'm just curious how our current laws and moral positions apply to crypto.
- danielvf 5y agoYes, people have gone to jail for stealing Bitcoins - In fact a US DEA agent and a US Secret Service agent did a few years ago. See https://www.justice.gov/sites/default/files/opa/press-releases/attachments/2015/03/30/criminal_complaint_forcev2.pdf https://www.justice.gov/sites/default/files/opa/press-releas... for the initial criminal complaint, which is well worth reading.