15 ms·
Beanstalk cryptocurrency loses $182M of reserves in flash ‘attack’
- b0sk 4y agoweb3 is going great! (https://web3isgoinggreat.com/ https://web3isgoinggreat.com/)
- sgt101 4y agoThe sad thing is the folks still buying into it, speculating that it'll be repegged even when the founder has explained that it's dead in the water. I remember people buying Lehman shares post liquidation on the basis that they would get retrospectively bailed out. Guess what?
- bombcar 4y agoIt's always amusing to me how "decentralized" becomes "FBI FIX THIS" as soon as it falls to some attack. At least they've sped up the normal leveraged buyout and corporate looting from months to mere seconds.
- SkipperCat 4y agoThis is also known as "privatized profits", "socialized risks". The same thing happened after the financial crash of 2008. Banks demanded to be bailed out because of the systemic risk to the American financial system. But when people started to demand that banks claw back the bonuses paid out, the banks said no. They claimed that would be government overreach. Ah, the irony....
- solumos 4y agohow many of these decentralized protocols has the FBI fixed?
- danans 4y agoI could be mistaken, but I think they meant "FBI go find and arrest the thief and compel them to return the funds", not "FBI go fix the protocol".
- optimalsolver 4y agoIf code is law, then the exploiter was perfectly within their rights to do this and they're entitled to the money. Not their fault that they read the contract more carefully than the contract writers did.
- TekMol 4y agoArticles should also be read carefully. This was not related to the contract behaving in unexpected ways.
- anamexis 4y agoIt certainly doesn't seem like they expected this.
- bena 4y agoNo, they didn't. They figured human nature would keep them safe. And that no one who could muster the capital to perform this action would want to, and anyone that would want to wouldn't be able to muster the capital. Technically, the risk of borrowing that amount of money is high. As is the risk of investing that amount of money into one coin. They figured anyone that would even begin to attempt something like that would operate in good faith. No way they'd tank the coin, because they have so much skin in the game. Well, that doesn't matter when you can take your skin and go home. Not to mention the skins of everyone else, wearing them Hannibal Lecter style.
- whimsicalism 4y agoIt was expected that it would be possible to take $182 million in reserves easily with a flash loan?
- bilbo0s 4y agoNo, it was expected that people with more skin in could decide to take any action they liked. Including, "take $182 million in reserves easily with a flash loan".
- PaulHoule 4y agoIsn't that what proof of stake is all about?
- narrator 4y agoYeah, they said whoever has the most beans has control. So these guys got a loan to get beans, took control, and left with the money. They didn't even hack it. They fell for the Proof of Stake / Ayn Rand fallacy which is the assumption that anyone with a lot of money is a good person. Btw, that's why proof of stake is so complex. They have to do all these complicated hacks to get stakers to be good.
- PaulHoule 4y agoI hear people saying that Ethereum is finally going to make that proof-of-stake transition and not be so energy intensive anymore but I wouldn't be surprised if bad actors have accumulated a knowledge base of vulnerabilities they haven't shared and if within 48 hours to a month there is no more Ethereum.
- makomk 4y agoNo. Generally speaking, proof of stake doesn't let someone transfer other people's funds to themselves just through owning a large proportion of whatever cryptocurrency - that's a really bad idea in terms of incentives and also not necessary for it to work - and has time locks in order to try and ensure that funds are actually at stake, which would prevent flash attacks like this one. This was just really badly designed. Letting someone with a mere instantaneous supermajority of money committed decide where to transfer all the invested funds to in a system with flash loans available pretty much guarantees something like this will happen.
- pfraze 4y agoBasically somebody borrowed a bunch of crypto, bought controlling “shares” (tokens) in the DAO, and voted the treasury into their own wallet. I’m curious why controlling levels of the token were on the market, and I have to assume that’s what the creators didn’t account for: the possibility that the people who were supposed to manage this thing would be buyable at a realistic price. I’d also ask why there wasn’t some kind of time delay on important decisions like that? It’s pretty bizarre. It doesn’t help that smart contracts are just not super easy to build. They’re just easy enough for you to think you can, but when I’ve dug into the actual complexities, it’s been pretty rough. It’s especially hard when each op costs gas, so you’re having to focus on security and efficiency at the same time. I have to imagine it disincentivizes more complex business logic around managing a DAO, like you’d expect for something like this.
- trhr 4y agoWhen you're shifting around $80m to net $182m, you set your own gas price.
- mcintyre1994 4y ago> I’m curious why controlling levels of the token were on the market, and I have to assume that’s what the creators didn’t account for: the possibility that the people who were supposed to manage this thing would be buyable at a realistic price. From the article: > A still-unidentified attacker had borrowed $80m in cryptocurrency and deposited it in the project’s silo, gaining enough voting rights in exchange to be able to pass any proposal instantly. I’m not sure but my guess is that they basically had an uncapped token that mints in exchange for deposits, and that’s used for voting. So you didn’t need to buy off existing holders, just deposit more than everyone else put together and mint more tokens than have previously existed.
- pfraze 4y agoAh. Oof. That's a bummer of a mistake.
- trhr 4y ago> However, on Monday the stablecoin’s value had not hit zero and was around $0.12, since some traders were voluntarily buying beans, betting that some rescue package would arrive to rebuild the project’s treasury and restore the peg. Well, that rescue package better be at least $500 million this time, or the guy's already written the code to do the same thing again, but $182m richer...
- mrwh 4y agoThis is bizarre and example of how I don't understand the crypto world at all. Shouldn't a stable coin that is manifestly no longer stable be worthless? Is it known whether the hacker managed to translate their coins into something else before the price crashed, or did they also lose most of what they captured?
- xur17 4y agoI think people are betting that it might come back, or get bailed out by some investor. Wormhole, which lost hundreds of millions was bailed out by a VC within a day or 2, so there is definitely a non-zero chance it could happen.
- blueprint 4y ago"The lightning hostile takeover raises fresh questions about the unregulated nature of digital currencies and the lack of protections for investors." People worth their salt have known proof of stake has been broken for many years. Question 1. Why do people trust the founders of these scams? Question 2. Why do we refer to them still in mainstream discourse as systems that even qualify as cryptocurrencies?
- 7steps2much 4y ago> Question 2. Why do we refer to them still in mainstream discourse as systems that even qualify as cryptocurrencies? Because a sizeable part of the population that doesn't care about cryptocurrency but cares about climate change has been sold on the idea of it. They were told that PoS can get by without the energy waste of PoW. Marketing for PoS was pretty good.
- kayamon 4y agoPoS is the bus that goes faster if it doesn't have to stop to pick up passengers.
- 3np 4y agoThis has nothing to do with PoS. Q2: Agreed - this does not qualify as "cryptocurrency".
- paulpauper 4y ago$0 recovered, no arrests despite many hacks and billions stolen. goood luck with that. these hackers are likely in Eastern Europe, far from reach of FBI. There is no information to go on.
- paulpauper 4y agoThere must be entire teams going through these smart contracts looking for exploits. Imagine making 10-100mm in a day just with some code. You would have to work for 100-s1000s of years to make that much.
- exdsq 4y agoI do testing in the blockchain space and it’s really crazy just how thorough one has to be to catch these issues, when there are so many adversaries.
- xur17 4y agoI will say, it does give me some confidence in the platforms that have been around for a while, and have billions of dollars deposited.
- bastawhiz 4y ago> A still-unidentified attacker had borrowed $80m in cryptocurrency and deposited it in the project’s silo, gaining enough voting rights in exchange to be able to pass any proposal instantly. With that power, they voted to transfer the contents of the treasury to themselves, then returned the voting rights, withdrew their money, and repaid the loan – all in a matter of seconds. Sounds like when I was a kid and my brother would make up a game with vague rules, but when I'd pay it in a way he didn't expect, he'd say, "no not like that!" and call our mom. Congrats to whoever found the loophole and made nine figures!
- BaseballPhysics 4y agoThis isn't even a loophole. Beanstalk apparently set up what amounts to staking system for votes. More money == more votes. Have enough money? Well, then you have the majority of votes and can do whatever you want. This is precisely how the system was designed to work. They just didn't foresee someone building up a large enough stake to amass the voting power needed to undermine the system. And that is simply a failure of imagination and goes to show how naive these folks were. The way this works in the real world is you have a limited number of shares that give individuals some number of votes, and those shares change hands. In order to build up a large enough position to control a company, you have to convince existing owners to give up their stake or vote with you. But if every dollar contributed to a "silo" creates a new vote, then yeah, you're basically saying: If you're rich enough you can take control of the project by simply amassing a large enough fortune in the project. There's probably things they could've done to reduce the likelihood of an event like this--e.g. requiring supermajority or unanimous voting for certain types of changes, for example--but they didn't, so here we are. The system worked as intended. And yes, I really mean "intended". They intended for people with more money to have more of a voice. And this is the (extremely obvious) consequence of that choice.
- machiste77 4y agoThe thing about a flash attack is that you don't need to be rich to buy that many tokens. You can borrow funds, buy the tokens with borrowed funds, execute your vote, sell the tokens, and then return the funds all in the same transaction. The only money you would need is the cost of gas.
- snvzz 4y agoInvesting in shitcoins, in a nutshell. There was a Simpsons skit about that: https://www.youtube.com/watch?v=-DT7bX-B1Mg https://www.youtube.com/watch?v=-DT7bX-B1Mg
- m348e912 4y agoYou linked to a south park clip that is about the banking system not cryptocurrency. I get your point though, it is a funny bit.
- snvzz 4y agoPoint was being roped into bad (gambling-tier) investments. How funny, I somehow wrote Simpsons rather than South Park; There's no such thing as enough sleep in spring weather.
- CryptoPunk 4y agoCryptocurrency is the largest bug bounty in the world, by a huge margin.
- 3np 4y agoDetailed analysis: https://scribe.rip/@omniscia.io/beanstalk-farms-post-mortem-analysis-a0667ee0ca9d https://scribe.rip/@omniscia.io/beanstalk-farms-post-mortem-... TL;DR: Beanstalk violated several commonly known best-practices and are now suffering the consequences. This kind of economic vulnerability can barely be called an attack - certainly does not clarify as a "hack" and it's several years since the community learned from bzx and similar almost identical incidents what happens when you make irreversible decisions based on on-chain price oracles like Curve (which is jot the fault of Curve - they should just not be used this way!) Hopefully the FBI recognizes this. If anything, Beanstalk promoters are responsible for irresponsible marketing and shifting blame. > The lightning hostile takeover raises fresh questions about the unregulated nature of digital currencies and the lack of protections for investors. No it doesn't. It's quite clear that there weren't any protection mechanisms at all. The kind of investors who put funds into contracts that can have those funds transferred out at the whim of a threshold of governance votes that are tradable on the public market must be aware of these risks - in particular sine it's the umpteenth time that in principle identical scenarios have played out over several years now.
- cuteboy19 4y agoIf beanstalk was so egregiously bad why didn't everyone (or anyone) call them out on it before?
- 3np 4y agoAs for me; first time I hear of them.
- whomst 4y agoI've been running a SIGECOM chapter at UIUC and the main theme over the past four/five months is people meme-ing about Beanstalk and how its such a shit show. My original concern had to do with the stability lever only working to decrease the value, so it inherently requires a "distinct triangular shape" to keep itself running. I didn't take it seriously enough to do a deeper analysis (mostly because I'd find something like this, but I can't really do anything with it legally) but there's about $10k invested in the ecosystem as LPs/bond-owners within my group of friends.
- peteradio 4y agoWhat an unbelievable scam. Is this just money laundering? Lost money ain't taxed the same.
- baobabKoodaa 4y ago> Is this just money laundering? Lost money ain't taxed the same. No. How would that even work? Did all the beanholders conspire together to frame this hack? Even if they did, what they'd end up with is transforming a bunch of clean money into a bunch of dirty money. The point of money laundering is usually to do that thing in the other direction.
- peteradio 4y agoWhat is the point of stealing this money then? Presumably the "thief" thinks they will be able to cash in on it in some way. Can these "losses" be used to avert taxes on the part of the "investor"? If the pain of the laundering is less than the potential tax avoidance then you might have a profitable laundry outfit.
- baobabKoodaa 4y ago> What is the point of stealing this money then? Presumably the "thief" thinks they will be able to cash in on it in some way. Yes, exactly, and that is distinctly different from your earlier hypothesis that the whole thing may have been a conspiracy to money launder on behalf of the people who lost money. > Can these "losses" be used to avert taxes on the part of the "investor"? If the pain of the laundering is less than the potential tax avoidance then you might have a profitable laundry outfit. Look, if this was a single person who claimed to have lost a bunch of crypto to a hack, then you might plausibly weave this story, but it's not a single person. It's a bunch of random people. This bunch of random people didn't collude together to fake a hack to create tax losses to offset their realized capital gains from somewhere else. And even if they did do that, that wouldn't be called "money laundering", money laundering is something they would have to do later, to hide the origin off their newly-ill-gotten wealth.
- hn_throwaway_99 4y agoIs there any site somewhere that lists the running total of all publicly acknowledged cryptocurrency heists? $650 million here and $182 million there, and at some point you're talking about real money...
- gerry_shaw 4y agohttps://web3isgoinggreat.com https://web3isgoinggreat.com
- mrep 4y agoI like rekts leaderboard: https://rekt.news/leaderboard/ https://rekt.news/leaderboard/
- wbeckler 4y agoI checked the leaderboard and it's missing Mt Gox, one of the few I'd heard of. $460M at the time, and about $29B in today's money if it were still bitcoins.
- carmen_sandiego 4y agoI don't think they typically include theft by those who have the private keys.
- hn_throwaway_99 4y agoThanks very much for this. I had seen this before but I somehow missed the "grift counter" in the lower righthand corner, which is just what I was looking for.
- iamben 4y agoNot sure if you're asking seriously, but: https://web3isgoinggreat.com/ https://web3isgoinggreat.com/
- boh 4y ago$182M of theoretical value that is. Until the "attacker" actually trades it for real money the value of this (yet another) random currency is zero. The pricing of widely known crypto is pretty dubious as it is. Pricing for off-brand cryptos is more marketing than fact.
- mcintyre1994 4y agoFrom the article: > Others were encouraged to deposit cryptocurrencies such as ether into a “silo” to build up the stablecoin’s reserves in exchange for voting rights over the operation of the organisation. I’m not sure exactly what their reserves consisted of, but it could be mostly ether and similarly liquid currencies, rather than random ones. It sounds like the thing they stole was their non-random-currencies reserves that were supposed to be able to maintain the peg.
- TrapLord_Rhodo 4y agoHe stole all the Eth backing the reserve. eth's 24 hour volume is 19.3B. They could easily trade that in a day without a major correction.
- colinmhayes 4y agoWell the problem is laundering it all. THe attacker can't just send the eth to an exchange, they need to mix it first.
- space_rock 4y agoI would say most shitcoin hacks are inside jobs. Skip the pump and dump and more to stealing from token holders
- lreeves 4y agoThe loan part is really bizarre to me; how does one borrow 80m without the lender knowing who you are, why would a lender lend 80m without knowing the borrower, and if you're anonymous enough to steal the money from Beanstalk then why would you even pay the loan back? There are so many layers of insanity here.
- drcode 4y agoThat's the cool part: everything is part in one transaction, so the lender is paid back instantly with interest. Zero risk for the lender.
- carmen_sandiego 4y agoThe loan is zero-risk for the lender because it's taken out and repaid within the same transaction (sort of like a database transaction). If the borrower fails to repay, the entire transaction fails/reverts and the money is never lent out. Now, the borrower doesn't only have to put the borrow and repay calls into that one transaction. They can put anything in between, for example interacting with Beanstalk.
- koboll 4y agoI'm not much for regulation of crypto/DeFi in general, but instant lending like this should absolutely, 100% be illegal. It's exclusively useful for exploits and MEV vampirism, and for nothing else.
- nathias 4y agoPeople need to learn that in a DAO tokenomics is part of security.
- joshu 4y agoremember beenz? maybe flooz is next.
- legaloslotr 4y agoFunny to see the DeFi space speedrun through 100s of years worth of financial rules, regulations and crime!
- kristjansson 4y agoThere's a 'steal all the money' DAO analogue of 'fire the missiles' for decentralized behavior. If someone achieves control, they can do _anything_ the system is authorized to do. Either the system can't fire the missiles, or it has to ensure the 'wrong' people can't achieve control, or that the cost of achieving control exceeds the value of the assets a controlling stake can direct. Even a reasonable cost incentive may not be sufficient if enough of the controlling stake is available to borrow, or there's enough liquidity to allow someone to buy, exploit, and resell a controlling stake within a single transaction. That aspect is unclear in this scenario. Did the attacker repay the flash loan with stolen funds (netting ~$100m) or were they able to resell (unwind? return?) the controlling stake within the single transaction? If the former, shouldn't there be $80m floating around (former) holders of 'beans' to at least partially recover? If the latter, how was there enough liquidity to buy + resell a controlling stake's worth of tokens?
- crismigo 4y ago
- crismigo 4y ago
- kristjansson 4y agoA more granular analysis[0] of how this attack was executed via W3IGG[1] [0]: https://medium.com/@omniscia.io/beanstalk-farms-post-mortem-analysis-a0667ee0ca9d https://medium.com/@omniscia.io/beanstalk-farms-post-mortem-... [1]: https://web3isgoinggreat.com/?id=beanstalk-farms-stablecoin-project-loses-182-million-to-exploit https://web3isgoinggreat.com/?id=beanstalk-farms-stablecoin-...
- Geee 4y agoThis is one of the problems with proof-of-stake, although the attack manifests differently and is much slower. Someone can borrow money, and pay higher yield than the normal staking yield, to buy staking power and change the rules to their favor. It's already happening and most people are staking through exchanges, instead of running their own staking nodes. It's a fundamental failure in the PoS incentive structure, and that's why it's inherently more risky than a proof-of-work system.
- deleted 4y ago[deleted]
- formerkrogemp 4y ago
- danans 4y agoI'm wondering about the demographics of the victims of a $182M heist like this. Is this more like 182 very wealthy people (i.e. worth $10s to $100s of millions) losing $1M each, or is it more like 1820 people losing their $100K life savings into this?
- lkrubner 4y agoI have a life long interest in the phenomena where someone makes mistake after mistake, yet they retain 100% confidence in their decision making process. The terrible results of their previous mistakes never dent their certainty that they are smarter than others. And this maladaptive process, which I've noticed in certain individuals, now seems to play out in group-based way, among enthusiasts of cryptocurrency. It is curious that, at this point, political science offers decades of careful study of different kinds of voting systems, their strengths and weaknesses, as well as game-theory models to help with scenario planning for contingencies and pathological cases, and yet, instead of working all of this out in a simulation, crypto enthusiasts prefer to run these experiments using real money, often millions of dollars. This is simply irrational, in a straightforward way. One has to assume some kind of gambling addiction has taken hold among these people, since gambling addicts are the only group we know of who demonstrate this particular kind of irrationality. Or are we looking at some new kind of mental pathology?