7 ms·
I write MEV bots for a living. I can tell you that the Beanstalk "hack" was evidence of extremely poor design. One of the key security aspects of designing a D
by downandout 4y ago
I write MEV bots for a living. I can tell you that the Beanstalk "hack" was evidence of extremely poor design. One of the key security aspects of designing a DAO is that you are not supposed to let the results of a vote take effect in the same transaction or even the same block. This was entirely on the designers of that protocol. It's so negligent and downright stupid that I would be quite surprised if it weren't an inside job. The fact that it took more than a day for anyone to notice this is truly shocking.
- bushbaba 4y agoreentrancy attacks are also well known. Yet many DEFI projects continually get hacked from them.
- vmception 4y agoWas this a reentrancy attack though I don’t think it counts as one, I was thinking that needs the governance contract to either recursively call itself or call an external unrelated contract
- downandout 4y agoCorrect, the Beanstalk thing was not a reentrancy attack. That was a governance attack on the world's most insecure DAO. The Rari Capital exploit was a reentrancy attack. https://twitter.com/BTCTN/status/1520425720631156736?s=20&t=eyF7NEWua4335xtCxhThAw https://twitter.com/BTCTN/status/1520425720631156736?s=20&t=...
- pru567 4y agoIs there a list of common attacks with names? This is the first time I've heard the term "reentrancy attack", there's probably a dozen other terms I've never heard of, but would like to read about.
- anony23 4y agoSearch for ethernaut for a good overview of exploitable solidity bugs.
- mik3y 4y agoI’m not remotely in DeFi but your comment suggests there’s a world of design rules & patterns within it, which are always somewhat interesting to learn about. Where would you go to learn this stuff (other than as a practitioner eg with access to mentors)?
- forum_ghost 4y agoone way would be to review https://rekt.news https://rekt.news on how NOT to do things?
- downandout 4y agoAt this point, alot of this stuff floats around Twitter and substack. It's still a bit of a dark art. If you'd like to read some stuff about MEV, start here: https://twitter.com/bertcmiller/status/1402665992422047747?s=20&t=SiFfBpb2P0AfH5SyR2bGHQ https://twitter.com/bertcmiller/status/1402665992422047747?s... and here https://twitter.com/0xmisaka/status/1525964196181057537?s=20&t=RlRxabL2YJU8ajVPW4xhpg https://twitter.com/0xmisaka/status/1525964196181057537?s=20... You can go pretty far down the rabbit hole on crypto twitter. This was also a cool event, there is 7 hours of video and slides, which have more of the kind of info I think you're looking for...discussions about protocol flaws and design etc. https://flashbots.notion.site/flashbots/mev-day-836f88806995412dabc1c7bb7ce4e830 https://flashbots.notion.site/flashbots/mev-day-836f88806995...
- UncleMeat 4y agoHow can something both be a dark art with no actual organized space for best practices and also have it be extreme negligence and stupidity for somebody to fail to follow these best practices? I'm not aware of any other area of software engineering where best practices are only just floating around on twitter.
- downandout 4y agoFair point. I probably should have directed him to: https://www.openzeppelin.com/contracts https://www.openzeppelin.com/contracts That’s the closest thing to a collection of standard contracts for protocol builders to use that I am aware of. I’m more on the MEV side - I try to profit from protocols rather than build them. So it wasn’t my first thought.
- forum_ghost 4y agowhat are the best designed DAOs from your experience as MEV'er?
- hsuduebc2 4y agoHow people make money with mev bots these days? I find it hardly possible even a year back.
- downandout 4y agoOn the ETH chain, Flashbots [1] has decimated profits, by turning MEV into a race to the bottom, where miners wind up with most of the profits that bots ("searchers") create. On other chains there is much more profit to be had. People are making large amounts of money, as you can see here [2] (check out BSC on there, most of those profits go to the actual bot owners). It's gotten incredibly competitive, and there has been quite a bit of consolidation. You used to be able to make a bot that could just make a few thousand dollars per day. Now you're either making 6 figures per day as part of a team, or a few hundred dollars per day on your own. One of the reasons you need a team and financing is that much of it is infrastructure based - being right next to miners/validators in the same server rack, etc. It takes significant resources to have nodes exactly where you need to have them, in various parts of the world. It's also feast or famine. Sometimes, you'll wake up with hundreds of thousands of dollars from thin air. Here [3] is a loan liquidation using a flash loan from last week that netted the person that submitted it $366K (that was the value at the time) - in a few milliseconds. The only money they had to have to do this tx was the $1.50 transaction fee. The ~$8 million necessary for the liquidation was flash borrowed from a Pancakeswap pair. [1] https://docs.flashbots.net/ https://docs.flashbots.net/ [2] https://eigenphi.io/ https://eigenphi.io/ [3] https://bscscan.com/tx/0x73d37b728ebd55088d0d7ccd3f82a485ac31035a957ba0ad9f2258ef556e62c1 https://bscscan.com/tx/0x73d37b728ebd55088d0d7ccd3f82a485ac3...
- ge96 4y agoEverytime I read these seems too good to be true. $1.50 -> $366K? Who doesn't want that.
- downandout 4y agoIt is and it isn't. Getting to the point where you were the one bot fast enough to get into the right position to snag that liquidation involves writing the bot itself, writing the smart contract, understanding the lending protocol and how their liquidations work, understanding how oracle transactions work, working out the math such that every input and output is precisely correct to 18 decimal places, having your server in the right rack in the right datacenter to beat the others, and on and on, are not easy tasks. But yes, once you do all of that...it actually is a money printing machine that will never end as long as markets have volatility. It's a bit like living in the movie Ready Player One...once you are clever enough to run the gauntlet, riches are yours.