17 ms·
White hat hacker awarded $2M for fixing ETH-creation bug
- hbbio 5y agoIt's not just any white hat hacker, it's saurik who was behind the original jailbreaking tools for iOS and the creator of Cydia, the unofficial app store back then. He is also now the "CTO" (if the term applies) of a well-known blockchain-based VPN, Orchid. Edit: He has a great write-up about the vulnerability and its discovery on his blog: https://www.saurik.com/optimism.html https://www.saurik.com/optimism.html (which was on HN a couple days ago)
- aerique 5y agoA jailbroken iPhone 3GS is the phone I've had the longest (nearing 5 years I think) and it was a joy to use, so thanks saurik and enjoy the bounty!
- andrewmcwatters 5y agoCXO titles in organizations do not exist without a board of directors. Businesses otherwise simply have members, managers, employees, contractors or vendors, or volunteers. You can pretend you're a CEO/CTO, but if you answer to no board, you're not.
- CRConrad 5y ago> Businesses otherwise simply have members, managers, employees, contractors or vendors, or volunteers. Clubs have members; businesses have employees. I think I'll take my lessons on business terminology from someone else, if it's all the same to you.
- andrewmcwatters 5y ago> Owners of an LLC are called members. Most states do not restrict ownership, so members may include individuals, corporations, other LLCs and foreign entities. There is no maximum number of members. Most states also permit “single-member” LLCs, those having only one owner.[1] [1]: https://www.irs.gov/businesses/small-businesses-self-employed/limited-liability-company-llc https://www.irs.gov/businesses/small-businesses-self-employe...
- CRConrad 5y agoTIL, thanks. I would have assumed those are called "owners", so thought you meant "members" in the fake sense of employees, as ISTR some large American corporates (Walmart, Amazon?) using it. Though I notice now that you actually mentioned employees, too, explicitly; I must have totally missed that.
- cowsandmilk 5y agoOrchid is a Delaware C corp with SEC filings for its offering. Do you think it lacks a board of directors?
- andrewmcwatters 5y ago> (if the term applies) I'm responding to whether the term applies.
- saurik 5y ago> For Orchid, while I have no official/ratified title, I am "in charge of technology".
- sfoley 5y agoWtf is a “blockchain-based VPN”?
- xur17 5y agoI think the simplest explanation is that it's a VPN system with a "blockchain based" payment system such that anyone can be a user or a provider without have a central intermediary. I haven't dug into the specifics yet, but that's my high level understanding.
- saurik 5y agoPrior discussion of this incident (and the $2M bounty) here on Hacker News: https://news.ycombinator.com/item?id=30289240 https://news.ycombinator.com/item?id=30289240 My (I'm the hacker) article / post-mortem this blog post is referring to: https://www.saurik.com/optimism.html https://www.saurik.com/optimism.html At the time of this last getting traction a few days ago, some people were sad that the title of my article and the discussion that resulted focused more on the bug instead of the bounty (which my article gets into near the end as part of some high-level thoughts on ethics), which is maybe why I am suddenly seeing this appear here again this morning (as this news article is instead focussing on the bounty angle)? FWIW, the $2M bounty--which was actually listed as $2,000,042 (as they wanted it to sort higher on the list at Immenufi, lol)--was potentially (none of us realized this at the time I "won", and I am honestly still not 100% sure of it now, though I haven't yet come across any counter-examples) the largest single bug bounty payout ever (...though, by only $42 ;P).
- gus_massa 5y agoCongratulations. I'm not sure if this was discussed in the previous thread, but does the bug allow the creation of real ETH coins, or it just increase the counter in the Optimism database (or whatever system they are using)?
- saurik 5y agoOptimism is a blockchain quite a bit like Ethereum, so the "database" mental model might be a bit confusing for a frame here (as it isn't like they are some centralized service), but no: this doesn't let you directly create ETH (which would be much much more devastating); it only lets you create something we might call "OETH", which is Optimism-specific. The native currency on Optimism (used to pay gas, like ETH is used on Ethereum) is effectively ETH; but, as it isn't Ethereum, that ETH on Optimism has to actually live on Ethereum: it gets locked into a contract there which acts as a repository/reserve for all of the ETH being used on Optimism. When you deposit ETH in this reserve on Ethereum you get credited the same amount on Optimism in the form of cryptocurrency IOUs (which we might call "OETH"), and you can later withdraw that money back to Ethereum, whereupon the OETH is destroyed and ETH is unlocked from the reserve contract. The bug here (which I go into detail in in my post-mortem, along with another / different description of how these "bridges" work) was in the VM used for the smart contract behaviors on Optimism, which would mean you could arbitrarily replicate OETH (the IOUs for ETH). For avoidance of any doubt: you couldn't use this bug to create an arbitrary amount of ETH/Ether, but the issue is that a lot of people call the money on Optimism--which is normally backed 1:1 with ETH--"ETH". (There is a discussion about what it should be called in the Ethereum chains database; I personally think what we need is a terminology for describing the full path whenever you have "ETH via an indirect path".)
- baobabKoodaa 5y agoTitle is misleading, since the bug doesn't actually allow creating ETH.
- jollybean 5y agoIn other words: ETH was an insecure blockchain and once compromised, there is no legal or operational recourse, with the implication that issues could indeed exist today. House of Cards.
- VectorLock 5y agoEthereum has forked to roll-back hacks in the past, likely for something as big as making ETH from thin air they'd do the same with even less hesitation.
- jollybean 5y agoYes, and they can do it for whatever reason they want. One might argue therefore that ETH is centrally controlled, and with considerably less oversight and reasonable oversight than, for example, most central banks.
- SparkyMcUnicorn 5y agoAnyone can fork ETH, and a fork is only successful if there's consensus.
- CRConrad 5y agoFunny how that "consensus" seems to be defined as "among those who have the most". So how is that any more decentralised, any less of an oligarchy, than the old system?
- berkes 5y agoNo. This was neither ETH, nor the Ethereum blockchain. Nor does this imply more issues indeed exist today.
- jollybean 5y agoFrom the bounty: "The Summary On 2/2/2022, I reported a critical security issue to Optimism—an "L2 scaling solution" for Ethereum—that would allow an attacker to replicate money on any chain using their "OVM 2.0" fork of go-ethereum (which they call l2geth)." No - sorry - ETH doesn't get a 'pass' on this. The 'Rest Of The World' is tired of the Crypto Scam Delusion masquerading as something reasonable and watching these critical failures getting swept under the rug. This issue demonstrates that critical failures will exist in the wild (and it's wrong to suggest that they won't come up in the future - they will) creating an existential flaw for systems in which there is no intrinsic remedy. Forks by 'completely arbitrary central powers' entirely defeat the purpose. Just last week we had the FBI arrest criminals laundering literally billions in Crypto. It's a tiring fraud absorbing enormous amounts of attention and energy for no apparent benefit but entertainment. The concept is currently fundamentally flawed, it belongs in 'side project' territory for now, not in the mainstream.
- colesantiago 5y agoThis just proves how insecure the blockchain / web3 / cryptocurrency space is. It's good to see white hat hackers in this space trying to fix what is already broken. But sorry to be that person, just a timely reminder of the truth: All cryptocurrencies and 'DeFi projects' are ponzi scams including Orchid.
- __MatrixMan__ 5y agoDo you think that a bank or a government would've handled fixing such a flaw as well has optimism did? All tokenization schemes are ponzi scams including USD, it's just that some use violence to stay relevant, and other use bug bounties.
- jollybean 5y ago"Do you think that a bank or a government would've handled fixing such a flaw as well has optimism did?" It's irrelevant. We don't use 'algorithms as ownership' in the real world. We use social agreements like contract law to undo problems. "All tokenization schemes are ponzi scams including USD, it's just that some use violence to stay relevant, and other use bug bounties." We use the law to maintain civil infrastructure. Yes, if someone wants to murder you or someone else, or launder billions, we'll use violence to stop them. An algorithm that is effectively used as a Pyramid Scheme is not going to save your from anything.
- __MatrixMan__ 5y agoIt can take years for contract law to get in front of a judge and be enforced, often the damage that can be done in that interval is significant. So I think they timeliness is indeed relevant. As for your murder comment, I'm not saying that violence is strictly unnecessary, just that the coincidence of "we have the guns" with "we issue the ponzi tokens" is probably not the only way to enforce the law.
- CRConrad 5y ago> the coincidence of "we have the guns" with "we issue the ponzi tokens" is probably not the only way to enforce the law. Not "the only way", perhaps, but AFAICS the only way that makes sense. Sure, "the law is an ass" and "the querns of law grind exceedingly slow" and all that... But still, it's the worst alternative except for having no law, right? So if you want the rule of law, the law needs to have the biggest guns. And why would anyone want anyone but the law to issue the tokens of lawful commerce?
- vinnymac 5y ago> Had the issue not been promptly resolved, malicious users on the chain could have exploited the flaw. This means a cyber actor could have gained access to the unlimited generation of fresh ETH tokens. I am curious, would it be easy to detect an individual who was exploiting this vulnerability?
- saurik 5y agoIn my post-mortem I go into this a bit: someone had actually triggered the bug (on accident while debugging the Etherscan block explorer) but it hadn't been noticed by anyone (and the person at Etherscan didn't realize the ramifications). I believe, due to the atypical mechanism used to store the account balance state on Optimism (which is discussed in detail in my post-mortem as this is also what I claim to be the root cause of the bug), it would have taken quite a long time to notice someone taking advantage of this issue if they weren't being egregiously ostentatious with it (and even then it would have taken "too long" before tons of extremely-difficult-or-arguably-even-impossible-to-unwind economic confusion and damage would have resulted as the whole ecosystem is so heavily automated).
- vinnymac 5y agoThanks, I only read the article linked and had not yet dug any further. I appreciate how much work you put into this! For anyone who may have missed the link in the article or thread, this is it: https://www.saurik.com/optimism.html https://www.saurik.com/optimism.html
- SodiumMerchant0 5y ago
- ForHackernews 5y agoHow much did he give up by not exploiting it? Whatever happened to 'code is law'? How sad to see web3 rehashing the failures of webs 1 through two.
- rrjjww 5y agoThere is some discussion about this above, but I'm curious - does the $2M reward count as ordinary income? Would persons on work visas (i.e. H1B) be able to collect without jeopardizing their immigration status? Could you employer consider it moonlighting?
- m4tthumphrey 5y agoWas it paid cash or in ETH?
- saurik 5y agoThe bounty amount was denominated in USD and is being paid in USDC (a stable coin, which is means it is intended to map effectively 1:1 with--in this case--USD).
- devoutsalsa 5y agoAt the moment, USDC is the only stable coin I’m comfortable holding. Are there are any other stable coins that are like backed by hard assets?
- sammyq 5y agoWhat’s the reason of holding USDC, isn’t that same as holding cash in bank?
- sfe22 5y agoThe problem is other stable coins are not transparent, and are very likely not fully funded so they can collapse any time. USDC is by coinbase and a little more transparent, thus less likely to collapse in case of mass withdrawal.
- koolba 5y agoKeeping your money on chain but not subject to price fluctuations. There’s also pro and anti arguments for being in control of your assets.
- pmlamotte 5y agoIt can be used in smart contracts, DeFi (such as a decentralized crypto exchange or earning interest), and can be used for very fast transfers between centralized exchanges/services that might not allow actual USD deposits/withdrawals or that require waiting for an ACH transfer to go through. Several cryptocurrencies are good for transferring between centralized services, but USDC will be price stable in comparison. Fees can be a problem though.
- dboreham 5y agoHeadline is misleading. Creation of wrapped ETH tokens on Optimism, thereby allowing _theft_ of ETH from contract escrowed funds.
- evv 5y agoThanks. As somebody with a very basic understanding of ETH, it seemed super unlikely that a L2 would be able to able to mint arbitrary ETH. (That would obviously be vulnerability in the L1)
- vmception 5y agoRight, this kind of exploit is in vogue right now. Minting supply inflation bugs happen all the time, but not usually for something redeemable for something so liquid and valuable. The bridges are a new unique target.
- dylanz 5y agoI remember walking down the main street in my hometown on my way to drink at a bar and seeing saurik and some friends at a bars all with their laptops out and hacking on something. What caught my eye was a terminal open and a Vim session. I walked up and we all chatted for a bit. Back in the day you didn't run into that very often where we lived so it was pretty cool to see. That boosted my conviction for my choice of IDE and I started bringing my laptop out to the bars in the evenings as well. Years later my friend and I built a business and pretty much all the code was written in the evenings at one of those bars. You can be social and code at the same time it turns out, and coding prevented me from drinking too much while I was out. No real morale to the story, just an anecdote I wanted to share. That said, congrats on the bounty saurik!
- quickthrower2 5y agoWow the only time i have seen anything like that in a bar was the bar everyone went to after a functional programming conference! The only geeky things ive seen “in the wild” are swag (like AWS T-shirts)
- 4pkjai 5y agoIt's cool seeing people coding 'in the wild'. I was on a train in Sydney once, and I saw an older man writing some VBA for a Microsoft Access database. "What are you coding there?" "Oh, I'm writing an application to manage patients at my dental practice" "You're a dentist?" "Yup"
- phist_mcgee 5y agoI started my devops career path in 2017 by looking over the shoulder of a woman working on her laptop on the train. She had a tmux session on one side of the window, and a doc page open for something called kubernetes on the other. I googled it, and here I am now. Funny how it all works.
- eanc 5y ago
- everfree 5y agoThe title isn't really accurate. It wasn't a bug to create ETH, it was a bug to steal ETH from the Optimism contract.
- ThrustVectoring 5y agoThat's not exactly accurate either - if I understand the situation correctly, it's a bug that allows counterfeiting of the contract's outputs. This could be a higher magnitude event if the counterfeiters could generate more purported liabilities than the contract can cover.
- deleted 5y ago[deleted]
- tomas789 5y agoJay Freeman is the man who found the bug. He is also author of the infamous Cydia - tool to install software on jailbroken iOS devices.
- VectorLock 5y agoI feel like this title should more accurately reflect this wasn't a bug with Etherum and real ETH couldn't be created.
- pests 5y agoSame, understand it now was a DeFi bridge which is more of "the floor is floor". Love crypto, bad rep currently.
- system2 5y agoI wonder when we are going to see a full Bitcoin crash due to a major hack. These type of news make people trust centralized currencies even more.
- AviationAtom 5y agoWhy is there such hostility towards crypto? I can understand the anger at Proof-of-Work cryptos, or perhaps the current somewhat "wild west" state of them, where fly-by-night operations work to separate people from their money, but ultimately I see them as the wave of the future. Ultimately I think the cryptos that see the most success will likely be those that can be better regulated, which is somewhat at odds with why crypto came about, but without some protection it would be like an unregulated stock market.
- CRConrad 5y ago
- stjohnswarts 5y agoIf it's "regulated" what good is it? It seems imminent that both the US and China will have highly regulated digital currency soon so that they can retain control and track citizens' cashflow. I think at that point crypto with the possible exception of bitcoin as a sort of "digital gold" will go into a death spiral. Certainly blockchain might survive though.
- balefrost 5y agoIn case you hadn't seen it, there's a rather well-received video called "Line Goes Up - The Problem With NFTs" (https://www.youtube.com/watch?v=YQ_xWvX1n9g https://www.youtube.com/watch?v=YQ_xWvX1n9g). It really covers crypto in general and treats NFTs as a crypto offshoot. It's 2 hours long but still feels rushed. Dan's general attitude is that crypto isn't revolutionary and isn't really trying to be. It's not trying to democratize money. It's trying to build a system with the same power dynamics as the current system, but with different people at the top of that power structure. His take is that crypto doesn't solve any of the problems with the existing systems and just creates a bunch of new ones. My recollection is that he doesn't spend much time on the energy use (he touches on it but IIRC doesn't dwell on it). He does go deep into the "wild west" state of them. His attitude seems to be "wild west" isn't a transitory phase; it's the end state of crypto. I don't think he says it in that video, but in a subsequent interview, Dan pointed out a danger with this and all deflationary currencies - they reward early adopters and people with a lot of capital. People who buy in late (either by choice or because they were simply born later) have a compounded difficulty in "catching up". He says he's worried about a future where crypto isn't an option and everybody needs to use it to some extent in day-to-day life. Moms and dads - or toddlers - who didn't "get in early" will be at a significant disadvantage. --- Personally, my main concern is with PoW. It's fine to say that PoS will eventually replace PoW, but that's not the situation right now. PoW is wasteful by design, and that just rubs me the wrong way. It's great that miners tend to use more renewable sources on average than the average utility customer, but they're still using an awful lot of nonrenewable sources as well. I guess I just think about all the other things we could do with that electricity and it seems like such a waste. My secondary concern is with the hype machine in overdrive. It feels a lot like the dotcom bubble to me - people making all kinds of wild claims about crypto, NFTs, web3.0, etc. Everybody so desperately wants it to be the next big thing because they smell an opportunity to make a buck. But it feels very cart-before-horse to me. It's not clear to me, for the kinds of problems that crypto is trying to solve, that crypto is the best solution to those problems. How many use cases really call for a decentralized, trustless ledger? This article (https://thecorrespondent.com/655/blockchain-the-amazing-solution-for-almost-nothing https://thecorrespondent.com/655/blockchain-the-amazing-solu...) mentioned a couple of projects that got greenlit due to blockchain hype, yet either don't have anything to do with blockchain or else use blockchain in pointless ways - such as having a small, fixed pool of trusted mining nodes controlled by one entity.
- TheRealNGenius 5y agoI don't believe jailbreaking qualifies as white hat.
- saurik 5y agoIt doesn't: it is what we call "grey hat". The article title is presumably referring to my role in this hack, not previous work.
- OOPMan 5y agoDid he get paid in real money or monopoly money?
- ineedasername 5y agoAnd it will probably be a lot easier to spend that $2M than $100M of exploited ETH that might have to be laundered clean, and still have some risk attached.
- kordlessagain 5y ago> So, as of now, Optimism and other related Ethereum projects are bug-proof. Just wait until AI gets its mittens on it.