59 ms·
The math prodigy whose hack upended DeFi won’t return funds
- blakesterz 4y agoThis was an interesting read. The case is now in limbo until authorities can locate Medjedovic or he decides to appear. “I did not steal anyone's private keys. I interacted with the smart contract according to its very own publicly available rules. The people who lost internet tokens in this trade were other people seeking to use the smart contract to their own advantage and taking on risky trading positions that they, apparently, did not fully understand.”
- dehrmann 4y agoReminds me of the standard advice of "don't roll your own cryptography." There are a lot of subtle nuances that make it hard to get right. When you have well-funded teams of absolute novices writing rules for complex games with money on the line, this is what happens. Rather than just having user accounts taken over and having to do a mea culpa, the reward isn't lolz or dark web money, it's actual money, and a lot of it.
- Gordonjcp 4y agoI read a thing where someone called cryptocoins "Dunning-Krugerrand" and that has stuck with me for years.
- hartator 4y ago> I did not steal anyone's private keys. I interacted with the smart contract according to its very own publicly available rules. Yes, it's a little disingenuous to claim "code is law" until it doesn't suit you anymore.
- moistly 4y agoIt’s a heck of a catch-22! Reject the judiciary system and shun government interfere… or open the door to continually expanding government oversight. Remain the primary target for big “crime” hacks and lose trust and value… or join the current system and lose value?
- ummonk 4y agoWhere did Indexed Finance claim "code is law"?
- antishatter 4y agoWhat’d he do that was illegal? Seems like he didn’t cheat and insider trading laws don’t seem to apply. Oops crypto is a unregulated market.
- davidweatherall 4y agoStop regulating crypto! (Unless I've been hacked, then we need to regulate it)
- rnk 4y agoI'd tend to agree with you. People with money and power will push for laws that protect them though. But this situation is why I'm skeptical of these kinds of contracts - too much potential for problems.
- onepointsixC 4y agoIt's an exploit no matter how you look at it.
- postalrat 4y agoWould it be an exploit if I discover the math to move all bitcoin in existence to whatever address I want then do so?
- deleted 4y ago[deleted]
- tediousdemise 4y ago
- jakear 4y ago> His profile on one social network included a quote from Kurt Vonnegut's Cat's Cradle about the futility of humanity's quest for knowledge: “Tiger got to hunt, bird got to fly; Man got to sit and wonder ‘why, why, why?' Tiger got to sleep, bird got to land; Man got to tell himself he understand.” Hey! He’s just like me. > But did Medjedovic do this, or did the algorithm? Barry Sookman, a lawyer in Toronto specializing in information technology, says it's a distinction without a difference: “Individuals are responsible for the activities of technologies they control.” This of course goes both ways — aren’t the index fund creators responsible for their technologies too?
- DangitBobby 4y agoIf I write code that can be exploited with a buffer overflow and you exploit it, who is the law going to punish more harshly?
- TremendousJudge 4y agoIf code is law, you.
- shadowgovt 4y agoBut the entire raison d'etre of most of crypto is to get out from under the thumb of existing national and legal entanglements. So the question becomes "Who's law?"
- ummonk 4y agoThat's not the position taken by Indexed Finance's creators: "When Kellar and his co-founders created Indexed, they imagined it as a step forward for DeFi, or decentralized finance, a blockchain-based movement that purports to offer a more automated, less intermediated version of borrowing and lending, asset trading, and portfolio management. Some proponents take a utilitarian view of DeFi, considering it an improved version of traditional finance, with its fee-taking middlemen and sluggish human decision-making. Others are more libertarian, seeing DeFi as an escape from the existing system, a way of circumventing the rules and restrictions imposed by governments or corporations. Then there are the skeptics, who think it’s all a grift. Kellar, who describes himself as “very progressive,” fits squarely into the utilitarian camp."
- omarhaneef 4y agoWhat is interesting to me is how it shines a light on the regulatory framework of the non-crypto economy. If you read up on edge cases, there is a lot of people deciding if something is "fair", and my notions of fair and a particular judges notions of fair are often at odds. To steal from Frank Zappa: Legal isn't the same as allowed, allowed isn't the same as fair, fair isn't the same as just, and just isn't music.
- lbriner 4y agoA judge is not deciding whether something is "fair" they are deciding whether it is illegal to the letter and/or spirit of the law. The reason this is at odds with us is that many things are legal that are not "fair". The specific danger here legally is trying to apply general laws into an unregulated market. It's a bit like borrowing money from your mate and then trying to take him to court because he's asking for too much interest.
- omarhaneef 4y agoWell, this is going to send us down a rabbit hole but the reverse is also true: there are multiple interpretations of a given law and the judge tries to use their judgement to square the law with the facts. (Rabbit hole because I sense this is a debate lawyers have all through law school, and there are various schools of thoughts about the nature of the law etc)
- Brian_K_White 4y agoRight? There probably is not agreement on fundamentals like the root purpose of law.
- Brian_K_White 4y ago"many things are legal that are not "fair"." They are, or at least purport to be, fair at some level or through some mechanism most people may not immediately percieve. When something really isn't fair, even by some indirect means or when accounting for some other imperative like geneneral societal necessity, then they are at least understood to be failures not successes. This story though... it actually provides a good example of indirect fairness. Well yes and no, there's a point and also a counter to that point, net result throw up my hands glad I'm not in crypto: Point, it's fair: You got robbed and think it's unfair that there's no recourse. That downside is just the fair price of being in that game at all, which you pay in trade for not having to deal with the traditional system and "the man". You have to absorb the occasional loss from a mistake as just a feature of the environment like the risk of your shipping boat sinking because the ocean is not a safe place. The only protection possible is pay an insurer or maintain your own emergency escrow or something, not any kind of police or rule-daddy. Point, it's not fair: They are not in fact free of the man, and so they are not really getting the true freedom they are paying for by assuming all responsibility for their own risk.
- thawaya3113 4y agoCode is law.
- curiousgal 4y agoA common misconception about law/contracts is that they are static. You can technically "not break" any laws and still be held accountable by a court of law.
- BitwiseFool 4y ago>"Code is law." I agree, but with the caveat that code is the letter of the law only. As it currently stands, there is no way to resolve a dispute, ambiguity, or unintended consequence with smart contracts in the same way that a court of law would handle such issues with a conventional contract. There is no room for interpretation and all smart contracts must be understood as such.
- turtledove 4y agoThe people who genuinely believe "code is law" are stunned to learn that: a) humans won't act "rationally", b) regulations exist for a reason, and c) no, the law is law, code is brittle.
- shadowgovt 4y ago"Code is law" really seems to me to be a philosophical position that can only be held by people who haven't fully internalized Gödel's incompleteness theorems.
- vmception 4y agod) I genuinely believe that Medjedovic should show up in court to test that theory. The only thing interesting about this case is how incompetent he was, while having his entire brand and identity be based on intellectual superiority. He should have used a virgin address and Tornado cash. He should have not needed to risk any funds for failure, as he should have tested the transaction in a localhost staging environment for free. Him getting doxxed is the only thing that allows this theory to be tested, whether he, or we, believe it was legal, it is now unnecessary liability. Instead, everyone knows who he is, that he's spiraling mentally, a judge in his hometown jurisdiction froze his addresses and the funds within it (which is a legal abstraction that does not freeze the funds but makes it illegal to move them until the order is lifted, in his favor or not). Just piling on the liability. I think “code is law” is a decent crux of a more fleshed out defense, I think the Canadian attorney for the project founders is grasping but I’m not as familiar with the direction courts go there, I would prefer to see something similar play out in US federal appeals court (which is sadly after the drama of trials court and how opinions calcify throughout). It would be great and beneficial to see a transcript of how the “Sushi flooding” is argued the context of a broad computer access abuse law.
- richbell 4y ago> The only thing interesting about this case is how incompetent he was I'm astonished at how poor his OPSEC was. He could have taken any number of precautions to shield his identity -- did he really think that deleting the messages on Discord would be sufficient?
- turtledove 4y agoYou love to see it. Love to see crypto taking Ls.
- onepointsixC 4y agoNo I don't think I'll love to see a person who "written the N-word into the code itself, 16 times." to steal 16 Million.
- turtledove 4y agoThe white supremacist who did this is not a hero. I'm not cheering for that asshole.
- gaze 4y agoyeah the ideal thing to happen here is for that money to be sent to a nonexistent address and for everyone involved to be arrested.
- meroes 4y agoIf only so it lessens some of the bad behavior I’ve witnessed. My cousin has been investing most of his paycheck in Bitcoin for several years. He also thinks Tesla Wall Batteries will mine crypto soon and “broke into” a private event Elon was at and made a TikTok of it. I want him to have a successful future is all.
- Brian_K_White 4y agoI feel this, but you know in a case like that, Elon and Bitcoin don't actually matter. If it weren't those, it would be whatever else existed to fixate on. I have a friend or two like that and I know that if I could fix Bitcoin it would not clear up their life or make them safe.
- randomhodler84 4y ago“Love to see your retirement 401k investments lose, eating away at your life’s labor and rendering it worthless.” This is a nasty position to take. You should never take joy at others losses.
- vmception 4y ago> Medjedovic added that he'd taken on “substantial risk” in pursuing this strategy. If he'd failed he would have lost “a pretty large chunk of my portfolio.” (The 3 ETH he stood to lose in fees was worth about $11,000 at the time.) This is misleading, either intentionally or due to Medjedovic's incompetence. You can fork the current head of the mainnet blockchain to localhost and try infinite permutations for free to see what the next state of the blockchain will be. And then if you like that state, you can then pay to send the working transaction to the mainnet to make that same state occur, in a sure bet. (nearly sure fire bet as in some cases, someone could replace the mainnet transaction in route, but they wouldn't necessarily know what to look for or change if its a distinct kind of transaction) Medjedovic either didn't know this, because his skills didn't translate as well as he thinks, or Medjedovic knows this and hasn't come up with a stronger argument to support his actions yet (of which there are plenty) and actually is relying on public sympathy to support his actions. Either way, there is an opportunity for broader education on how these exploits can be cooked in something akin to a "hyperbolic time chamber" or quantum reality without anyone's knowledge, ready to hop back into our dimension fine tuned and ready to cause maximum effect, all within the ~15 seconds between blocks if necessary, as the state changes per block.
- MockObject 4y ago> You can fork the current head of the mainnet blockchain to localhost and try infinite permutations for free to see what the next state of the blockchain will be. And then if you like that state, you can then pay to send the working transaction to the mainnet to make that same state occur, in a sure bet. You have described mining.
- vmception 4y agoYeah good observation. But instead of arbitrarily hashing a algorithm used in consensus to find a block, this would be hammering specifically constructed bytecode at a smart contract’s ABI endpoints to see how many other things get effected.
- drcode 4y ago> And then if you like that state, you can then pay to send the working transaction to the mainnet to make that same state occur, in a sure bet. That often isn't true anymore, see https://ethereum.org/en/developers/docs/mev/ https://ethereum.org/en/developers/docs/mev/
- rvz 4y agoGood for the hacker then and well played. If you really hate crypto projects so much, rather than complain all day long about the crypto-bros getting rich off of their tokens, just hack the smart contracts themselves and the project should offer a bounty if not beg for a negotiation for that and once the project creators fix the bug, you keep the rest. Job done, until the regulators come.
- paulpauper 4y agoeasier said than done. you can be sure that when news breaks of a contract being hacked it was only after maybe dozens, if not hundreds, of contracts had been tried and failed, by many hackers all over the world. Also, likely illegal: Code may be law but the judge may not see it that way.
- trasz 4y agoI find it disturbing that Medjedovic was prosecuted in the first place. If anyone is guilty of this situation, it's Kellar and Day.
- DangitBobby 4y agoAbsolutely. They are guilty of writing vulnerable code, being hacked, and stolen from.
- deleted 4y ago[deleted]
- trasz 4y agoThey are guilty of implementing a mechanism that was broken by design, and wasting customers' money. They hadn't been hacked or stolen from - the "attacker" didn't need to hack any particular security mechanism, he was just smarter at how their market worked than the owners.
- Handytinge 4y agoIf _they_ are not treating it as seriously as actual regulated finance, why should the courts be treating the attacker in that way?
- glerk 4y agoAbsolutely, they are guilty, but they won't take any responsibility. When you deploy a smart contract on a permissionless blockchain, you don't own the smart contract or the funds that it controls. These developers are hypocrites who don't believe in the basic premises of this technology. It is easy to preach the virtues of decentralization when it makes you money and run back in the arms of daddy government when things don't play out in your favor.
- qgin 4y agoHey, code is law right? He is the rightful owner now.
- postalrat 4y agoUntil someone finds a way to calculate another key to move his eth.
- Overtonwindow 4y agoThis was fascinating to read, but I think the guy is ultimately innocent. He executed a series of speculative trades using the platform's rules and mechanisms. It reminds me of the 2013 case of some guys who took advantage of a software bug in a video poker game. “All these guys did is simply push a sequence of buttons that they were legally entitled to push.” This sounds very much like the same thing, and since digital currency is not heavily regulated, some might say at all, I think the outcome, while unfortunate, is not illegal. Sadly Day & Keller and others will likely haunt this poor kid with lawsuits and frivolous attacks, but in my book he did not break the law. https://www.wired.com/2013/11/video-poker-case/ https://www.wired.com/2013/11/video-poker-case/
- paulpauper 4y agoYeah, the attacker resides in Canada, so even if found guilty he's looking at easy jail time at the worst. All he has to do is wait a few years and the $ is his. not like in the US in which feds hand out decade+ sentences like candy on Halloween.
- moneywoes 4y agoCan’t he be extradited
- retrac 4y agoMaybe. That actually raises some interesting questions, come to think. A key factor in an offence is the location of the offence, which usually determines jurisdiction and the relevant laws. In the classic example of hacking an American bank from Canada, the offence occurs on the American bank's servers in the United States. That's relatively clean and simple, legally. With an Ethereum smart contract ... I'm not even sure where to begin. Where does the offence even occur, legally speaking? What aspect of fraud by a non-American, against an American resident by executing an adverse smart contract, occurs under the jurisdiction of the United States, if any?
- liminal 4y agoThe fact that Ethereum code is public seems to weigh in favor of allowing him to get away with his "hack". For any other financial instrument, we rely on verbal descriptions of how it will be conducted and behave. With Ethereum, the code speaks for itself -- for better or worse. This leads to a rather absolutist dog-eat-dog rationality that I don't much like, but also don't see how to avoid.
- cbm-vic-20 4y ago> For any other financial instrument, we rely on verbal descriptions of how it will be conducted and behave. My brokerage sends me plenty of prospectuses and other documentation that I don't read that describes exactly that. I depend on the regulators and the lawyers of other clients that have a lot more to lose than I do to make sure they stick to the rules.
- npollock 4y agosource: https://www.bloomberg.com/news/features/2022-05-19/crypto-platform-hack-rocks-blockchain-community https://www.bloomberg.com/news/features/2022-05-19/crypto-pl...
- SamBam 4y ago> But in our email exchanges, he argued that he'd executed a perfectly legal series of trades. In real finance, there is an understanding that technical loopholes can exist, since not every outcome can be foreseen when writing laws, but the legal system can frequently prosecute against a series of actions which are, individually, legal, but which together are taken in order to achieve something illegal. That is, modern finance and the law also attempt to deal with intent. But in the Ethereum smart contracts world isn't the whole premise that the code is the law? That we don't need any of these pesky courts or banks or auditors or anything: the code is the law, and the decentralized blockchain will enforce it. With this worldview, if the attacker simply exploited poorly-written code to find a loophole, how do the owners of Index have a leg to stand on?
- miltondts 4y ago> That is, modern finance and the law also attempt to deal with intent. It does? Maybe for the poor, but certainly not for the rich/corporations.[1] [1] - https://www.imf.org/external/pubs/ft/fandd/2019/09/tackling-global-tax-havens-shaxon.htm https://www.imf.org/external/pubs/ft/fandd/2019/09/tackling-...
- kmlx 4y agoso called “tax havens” actually have a role to play in the world economy. but on your main point regarding “modern finance and law”: 2021: https://member.fintech.global/2022/01/05/the-top-five-compliance-failure-fines-of-2021/ https://member.fintech.global/2022/01/05/the-top-five-compli... https://www.kyckr.com/aml-fines-2021/ https://www.kyckr.com/aml-fines-2021/ tldr fines amount to billions in total and sometimes criminal proceedings are brought forward.
- throw_m239339 4y ago> so called “tax havens” actually have a role to play in the world economy. So does the mafia and the child slaves corporations like Nestlé profit from, they all have "a role to play in the world economy". But it's about the morals and ethics and the hypocrisy of western institutions that allow these loopholes for the super rich in order for them to protect their wealth from taxation.
- tzs 4y ago> It would take weeks to figure out precisely what had happened, but it appeared that the platform had been fooled into severely undervaluing tokens that belonged to its users and selling them to the attacker at an extreme discount. Q: is the programming language these things are written in powerful enough and have sufficient data access for the developers to include sanity checks that would halt trading automatically if something is happening too far out of the norm such as an unusually high volume of attempted night discount sales? Or maybe that would just block extreme discount sales if there have been too many of those recently?
- meetups323 4y agoThe language could represent that, but you pay per operation so checks tend to get thrown out the window.
- isolli 4y agoThis part seems relevant: > It also saved on costs by limiting the number of interactions between the platform and outside entities. For example, when Indexed needed to calculate the total value held within a pool, instead of checking token prices on an exchange such as Uniswap, it sometimes extrapolated from the value and weight of the largest token within the pool, called the “benchmark” token. > This way, it reduced the fees it paid for transactions on the Ethereum blockchain. This cost-saving mechanism ultimately allowed the hack to take place.
- hiq 4y agoSee this very good comment about Solidity, the main language used to write software on Ethereum: https://news.ycombinator.com/item?id=14691212 https://news.ycombinator.com/item?id=14691212 More to your point, you can always have more logging, slow things down to make them safer and allow communities to react in a timely manner, but it's far from trivial. The real problem is that any mistake can be fatal from the defender's point of view.
- motohagiography 4y agoThis isn't a hack, it was straight arbitrage. I distinguish them because there was at no time a transfer of administrative power or control over the contract or targets infrastructure to Medjedovic. In a smart contract, I'd make a legal distinction between syntactic parsing and calculation, which has to do with the purity of functions and data. An arbitrage would be fair game if it levered an unanticipated calculation, whereas a recent example where the contract was only checking the last several bytes of a destination address key would be a parsing exploit. Medjedovic's arbitrage as described appears to be a pure calculation advantage, and not exploiting a parsing error, and so this is very reasonably fair game. He used logic endogenous to the contracts, with no exogenous control of the systems running the contracts. When you exploit a buffer overflow, you are breaking through (sabotaging) a parser as a means to manipulate the raw memory and machine - whereas this arbitrage is closer to something that lies somewhere between clicking on a link someone provided but had some unspoken intention about you not using it, and a SQL injection or other evaluation error that yields an index. (edit: Actually, it's more like saying something really funny and unexpected on a platform that hasn't banned that kind of humor yet, and they're just mad about the consequences. we could even see a future where the distinction between a hack and arbitrage will be the complexity class of the algorithm and whether it represented a scheme that was Turing complete) Unfortunately, in Canada they'll go after him just as a fugitive now, and there is no shortage of political actors who will want to make him the perfect example villain for their hysterical policy objectives. This is one of those increasingly classic situations where a really smart kid gets system-involved and can't comprehend how insane it is because the legal system and politics are not subject to mere reason. If he has the money, fleeing before charges were laid was probably even rational, as there is no reason to expect the legal system is equipped to deliver justice in something so new.
- meetups323 4y ago> If he has the money, fleeing before charges were laid was probably even rational, as there is no reason to expect the legal system is equipped to deliver justice in something so new. Except what's next? Live in hiding in a foreign country? Craft a new identity and find new chains to exploit? I suppose 18 years old is a good time to learn that you can have all the money in the world, but it won't do shit for you if you can't spend time with the people you want to. I'd wager this individual could get much more satisfaction out of developing novel, interesting mathematics that do actual good for humanity, surrounded by a group of like minded high performing individuals. But he seems to have thrown hopes of that out the window. It's sad, really. But I'm perhaps projecting.
- TameAntelope 4y agoFor all the people shouting "Way to go!" and "The money is his!" I think you should remember he's currently a fugitive, and would need to spend the rest of his life living this way. If that's what it takes to live the "code is law" dream, count me out.
- silentsea90 4y agoI like the very web3 middle ground where the attacker negotiates with the company and returns a part of the money, the rest being the lawful reward for reporting the vulnerability.
- knorker 4y agoDo you mean "like" as in you're amused by it's absolute absurdity, or that you think this is a good standard practice?
- silentsea90 4y agoSorry, I should make it clear - it is very very absurd. Can't edit comments after some time sadly.
- silentsea90 4y agoTo make my stance very clear - this is an absurd and hilarious practice and feels similar to ransom, with the hacked entity putting "white hat hackery" on the table as an option to get some of their money back.
- wang_li 4y agoPlus his family aren’t choosing to live their lives in hiding. What part of the smart contract is going to prevent acts of violence against them? Seems like he was relying on maintaining anonymity and now that that’s out the window his family is on real danger. $16-17 million is a lot of dough and it would cost a lot less than that to hire some kidnapping & ransom specialists to visit his family.
- shockeychap 4y ago"But passivity also created risk. If there was a problem with the code, someone could exploit it directly, without needing to bypass any human safeguards. And limiting blockchain interactions to cut costs entailed a trade-off: When a smart contract—a script that executes automatically when certain criteria are met—has fewer steps, it can leave more room for security vulnerabilities." So much of this reminds me of Chesterton's Fence, where "innovative" solutions are deployed by people who never put forth the time and effort to fully understand how the existing system came to be the way that it was - and the problems that it had to deal with and solve along the way. I'm not trying to sing the praises of finance and banking; there's much there that is broken. (I'm also not a fan of crypto or NFTs.) But I am saying that many of the "old" ways came about in response to a litany of problems that are neither obvious nor intuitive, and you need to understand why it works the way it does before putting out a new solution.
- RcouF1uZ4gsC 4y agoI have a compromise. Allow hacks of cryptocurrency to be prosecuted, but when they are, the also prosecute the creators of the cryptocurrency for making unregistered securities and for any fraudulent marketing of the cryptocurrency, or any failure to disclose risks, or for not following financial regulations. This is another example of make risks public and reward private. They are arbitraging the financial system and trying to have the freedom of cryptocurrency, but when things go bad, want law enforcement to come fix it.
- kristjansson 4y agoThis is an outright copy of https://www.bloomberg.com/news/features/2022-05-19/crypto-platform-hack-rocks-blockchain-community https://www.bloomberg.com/news/features/2022-05-19/crypto-pl.... e: missed at the end of the article: > (Except for the headline, this story has not been edited by NDTV staff and is published from a syndicated feed.) So perhaps this is reproduced under a legit syndication deal?
- Brian_K_White 4y agoIt says "(c) 2022 Bloomberg Christopher Beam, Bloomberg Businessweek" right in it.
- deleted 4y ago[deleted]
- ummonk 4y agoYeah and "(Except for the headline, this story has not been edited by NDTV staff and is published from a syndicated feed.)"
- dang 4y agoOk, we've changed to that from https://www.ndtv.com/business/the-math-prodigy-whose-hack-upended-a-crypto-platform-wont-return-funds-2992987 https://www.ndtv.com/business/the-math-prodigy-whose-hack-up... above. Thanks!
- knorker 4y ago> Once cyberattackers have been identified, they often return funds in exchange for a face-saving bounty and credit for being a “white hat” hacker. Jesus, this whole cryptocurrency racket is a joke.
- kristjansson 4y agoThere's something delicious in a critical part of the arb relying on a mechanism the contract authors included to reduce gas fees. Not only are we enshrining code as law, we're playing code golf with it first!
- dimator 4y agoI'm getting strong Neuromancer vibes from this. It's so interesting that we're now officially cyberpunk in some corners of our world.
- __turbobrew__ 4y agoFor all of those involved: play stupid games, win stupid prizes.
- WhitneyLand 4y agoSome insight as to what this guy is made of: The Ethereum address Medjedovic used for the attack included the number “1488”—shorthand for a neo-Nazi slogan—and he'd written the N-word into the code itself, 16 times. A Twitter user called him the “Dylan [sic] Roof of Balancer Pools,” a reference to the mass shooter who killed nine Black people at a church in Charleston, S.C., in 2015. Medjedovic liked the tweet. Completely counter to every experience I’ve had working with Waterloo people. My sample group always seemed smart, interesting, kind.
- Imnimo 4y agoI think of this like if you empty the 'take a penny, leave a penny' tray into your pocket. It's clearly allowed by the terms to take the pennies, but it's also clearly immoral.
- sib 4y agoIs it? Or is taking a penny allowed, but not taking all the pennies (which feels more code-is-lawish...)
- bix6 4y agoCan someone explain how you can take out a ~$150m flash loan? (Did he post $300m collateral?) Did he only need 3 ETH for that or were the ETH only used for the transaction fees?
- colinmhayes 4y agoSo flash loans must be repaid before the next block is mined, so you don't need to post any collateral, just the interest. If the loan isn't repaid in time it automatically unwinds and you lose the interest payment.
- bix6 4y agoThank you
- yobananaboy 4y agoThe 3 ETH was the gas fees for the transactions. (Some went to deploying the attacking contract, some went to contract interactions afterwards.) With a flash loan, the funds must be returned by the end of the transaction, or the transaction fails. This makes the completion of the transaction the collateral, as if it fails at any point, all transactions (including the loan) get reverted.
- bix6 4y agoThank you
- zecken 4y agoI feel like the fact this person, per the article, is a white supremacist who used the n-word in his code repeatedly is under-discussed here. Folks here jumping through hoops to rationalize why what he did is actually demonstrative of either flaws in crypto or the purity of arbitrage come off seeming very tone deaf.
- antiterra 4y agoWhat exactly are you proposing here? That we have a different set of financial and legal rules for despicable people? Or that the financial and legal rules everyone is subject to should be based on how they impact a specific despicable person? If a despicable bigot is facing the death penalty for stealing a bag of chips, would it be ‘tone deaf’ to say that’s an unfair punishment?
- Handytinge 4y agoSomeone can be a white supremecist and you can be impressed with their (non bigotry) actions. People aren't that black and white (sorry).
- JackFr 4y agoAs I understand it, Indexed behaved as a sort of ETF for crypto, that had automated their creation/redemption mechanism. Importantly they had automated the creation/redemption mechanism poorly. Here's the operative passage: By eliminating human managers, Indexed could forgo management fees like the 0.95% its bigger rival, Index Coop, charged for simply holding its most popular index token. (Indexed would charge a fee for burning tokens and swapping assets within a pool, but those only applied to a small fraction of users.) It also saved on costs by limiting the number of interactions between the platform and outside entities. For example, when Indexed needed to calculate the total value held within a pool, instead of checking token prices on an exchange such as Uniswap, it sometimes extrapolated from the value and weight of the largest token within the pool, called the “benchmark” token. This way, it reduced the fees it paid for transactions on the Ethereum blockchain. Kellar saw full passivity as a “natural extension of the way index funds already operate.” Kellar was wrong. In bringing down the costs, they eliminated the very thing that might have prevented the transactions that cost them all the money. The trades were legitimate, just unfortunate for the holders and to ask the courts to reward the incompetence of the management of indexed is to ask the courts too much.
- yobananaboy 4y agoThey were holding $17m in funds and only paid 2 unnamed security auditors? Yes, getting a proper audit for a Defi Protocol is expensive (probably 8 person weeks at $20-30k/week or ~$200k), and every good audit firm has a 3-6 month waiting period. But when you’ve got 100x that to lose, it’s a drop in the bucket.
- deleted 4y ago[deleted]
- neonate 4y agohttps://archive.ph/ZG3rP https://archive.ph/ZG3rP
- vfclists 4y agoWhy did this link land me on the Indian site ntdv.com?
- vfclists 4y agoThis sounds like https://www.theguardian.com/business/2020/jan/28/navinder-sarao-flash-crash-trader-sentencing https://www.theguardian.com/business/2020/jan/28/navinder-sa..., Navinder Sarao, the British Indian trader who was blamed for the "flash crash" of 2010. It looks like if you fall foul of big merchant banks and stock traders you can have the full force of the DOJ land on you, but crypto is not important enough.
- bobsmooth 4y ago"They discovered that the Ethereum wallet used to transfer tokens during the attack was connected to another wallet used to collect winnings in a recent hacking contest by a participant who sometimes identified himself as UmbralUpsilon. Pulling up the participant’s registration, they saw that it linked to a profile on the collaborative coding platform GitHub." Opsec really isn't that difficult, you just have to give it some thought.
- caymanjim 4y agoForget about the exploit itself. Why are people trusting two young nobodies (Day and Kellar of Indexed Finance) with so much money in the first place? Ok, so Day has some decent academic credentials, but he's just one person. Who was doing risk analysis? Which independent experts analyzed their algorithms? Which accounting firm audited them? Where's the oversight? These two guys whipped something up, threw it out in the wild, and the masses fed tens or hundreds of millions of dollars into it without a care in the world. This is how crypto operates. Buyer beware.
- pohl 4y agoHaven't people who are attracted to crypto, for the most part, already decided that oversight is bad because something something decentralization?
- Red_Leaves_Flyy 4y agoIt’s the Libertarian fantasy. Crypto bros, many VCs, angels, and other mini napoleons think they can solve the world’s problems without addressing any of their personal problems, studying history, taking responsibility for their actions, engaging in community building, or hiring people with spines. Which is why crypto and ilk keep reinventing every scam and repeating the mistakes of the past that directly led to regulation.
- fron 4y ago"Libertarians are like house cats: absolutely convinced of their fierce independence while utterly dependent on a system they don't appreciate or understand." No idea who said this originally but it continues to be true. Abandon the system, and they find it was there for a reason.
- xur17 4y agoBecause people want to and decided the risk was worth it to them? If a consenting adult wants to deposit their money into a system that they have full visibility into, why should we stop them? > This is how crypto operates. Buyer beware. This statement rings very true for me, and perhaps is the bit we agree on. With crypto there is no "oversight" that blocks you from depositing your funds into unsafe contracts, etc. It's up to you as the user to do your own research before depositing funds. There are many projects within crypto that ARE well built, and have been carefully tested, analyzed, slowly released to the public, etc. I like having the ability to make this choice myself instead of relying on some gatekeeper to decide what I can do with my money (cough "accredited investor rules").
- henning 4y agoWeb 3 is going great!
- Jon_Lowtek 4y ago-- EDIT -- i found the address and i take everything back and declare the opposite, that address is not random at all. -- original post -- > The Ethereum address used for the attack included the number ... shorthand for ... So Bloomberg thinks people choose the numbers in their wallet addresses and are responsible for any perceived numerological meaning. Are they for real? Sure the guy could have sat there recreating addresses until one includes this number, but i consider it more likely this is the result of searching randomness for patterns they want to find. Someone noticed the pattern in the randomness and Bloomberg includes it, as it makes the antagonist more evil and the story more interesting.
- buzzy_hacker 4y agoI’ll give the full quote: > The Ethereum address Medjedovic used for the attack included the number “1488”—shorthand for a neo-Nazi slogan—and he’d written the N-word into the code itself, 16 times. A Twitter user called him the “Dylan [sic] Roof of Balancer Pools,” a reference to the mass shooter who killed nine Black people at a church in Charleston, S.C., in 2015. Medjedovic liked the tweet. Here’s another: > Medjedovic apparently flirted with extremist ideas: The classmate says he heard him speak favorably about White supremacy and eugenics. He is clearly a white supremacist, how is this “searching randomness for patterns they want to find”? This is speculation, but it wouldn’t surprise me if this guy generated lots of addresses until he got one that did have 1488 in it.
- deleted 4y ago[deleted]
- JKCalhoun 4y agoParents, don't rush your kids.
- anonu 4y agoAre there any good resources someone can point to on getting into the code and mechanics of this? The article was a nice read, but probably distills the real stuff behind some journalistic simplification.
- Graziano_M 4y agoethernauts is particularly good intro that has you work through a lot of the common security issues.
- viksit 4y agoSmart contracts are badly named lambda functions. They need the same regulation as any other code, the difference being, the regulation can come in the form of more lambda functions. The judiciary could write the latter any time they got the right technical input. The question really is - what’s worth putting in the effort right now? And those answers are coming soon. But we shouldn’t conflate smart contracts with legal contracts in discussions.
- jrm4 4y agoI'll keep saying it -- a "smart contract" is nothing nothing nothing at all like a real contract, it's a stupid little piece of vending machine code that just operates. If we're going to argue the ridiculously dumb idea that smart contracts are, in fact, legal contracts -- congrats to the kid because he is 100% entitled to that money.
- eftychis 4y agoGood luck to the judge. Commodities laws still apply so this will be interesting to follow. They had to sue or they would be sued themselves (which they might regardless), but there is no law restricting you actually from inflating the market value of an item (or a security). Their advantage is that he doesn't have a lawyer (or claims to) -- which is a stupid move; and that they froze his gains (another stupid move). If a hack is actually involved under Canadian law we shall see but a civil lawsuit is not unlikely to dictate that. He misled their market maker, not the holders. Of course without reading the case one can not say anything and has an incomplete view, but they are trying to shift blame here. There is precedent of course, when Oil futures went negative and in the end brokers paid the difference -- as their software wouldn't allow people to trade non-negative ranges. tl;dr: I think they are still on the hook for the lost funds back in the E.U./U.K.
- giantg2 4y ago"In their complaint, lawyers for Kellar and Day argued that two particular steps of the attack violated statutes against market manipulation and computer hacking." So now they want crypto to be treated as regulated securities, but let me guess, only when it benefits them...
- QuantumGood 4y agoMost want the law to benefit them if they suffer harm, even if it can be argued to be self-harm. Most pay little attention to the law if no harm is taking place... unless the law will cause harm. This isn't unique to DeFi
- malermeister 4y agoWhat's unique to DeFi is that they're trying to circumvent there laws trying to prevent harm to others, while still wanting to be protected themselves.
- smk_ 4y ago
- deleted 4y ago[deleted]
- snickerbockers 4y ago"code is law" until you suddenly realize you suck at coding and come crying to the actual law.
- darepublic 4y agoGood for the hacker I say. Enjoy it in health.
- pcj-github 4y agoIndexed gets no sympathy from me; guy exploits a bug in the code. Awfully predictable that these would-be DeFi fanboys go crying to a centralized legal authority when things don't go their way.
- QuantumGood 4y agoThe philosophical wishes of those protected under the law does not change the law. What if someone wishes for full protection of the law and publicly asks for it beforehand, but then gets involved crypto/DeFi — would they then "deserve" the law's protections while others involved in crypto/DeFi do not?
- jazzythom 4y agoCode is law. He deserves every cent, because it’s all as worthless as the rest of the crypto sector will be in a few months. He deserves the money because he illuminated the true state of crypto by example in a sea of fraud.
- SergeAx 4y agoAll DeFis are just very expensive bug bounty programs.