3 ms·
> An attacker accessing a staking node can, on purpose, double vote or surround vote to get the ETH slashed. What is the incentive for them to do that? If the
by whatisweb3 4y ago
> An attacker accessing a staking node can, on purpose, double vote or surround vote to get the ETH slashed.
What is the incentive for them to do that? If the node is secured physically they would need to break into a person's house and decrypt whatever security setup they might have in place. The whistleblower reward is typically fairly small, probably not worth the criminal behavior.
- TacticalCoder 4y ago> What is the incentive for them to do that? They could be short trading ETH. They could just want to create havoc. Why did people deface websites long before online ransoms were a thing? I don't think bad people need many incentives to do bad things. I may be wrong of course. > If the node is secured physically they would need to break into a person's house and decrypt whatever security setup they might have in place. But that's not how most exploit work. Most exploits, and by very far, are 100% software. I mean: it's for the very reason that computers aren't devices to be trusted that many are protecting their coins using hardware wallets. I don't know what software is needed to stake Ethereum but I'm pretty sure it involves a huge software stack. Seriously: I don't understand how, on one hand, there are people holding the keys to move their ETHs on hardware wallets who are, on the other hand, staking these ETHs on a purely software stack. It makes approximately zero sense to me. If you're certain your node can be trusted to safely stake your ETHs (as in: there's not risk of your ETHs getting slashed in two), why bother with a hardware wallet? Just keep the private keys that allows to move your ETHs on your node too, because you consider it's safe anyway? I don't know: I may be all wrong on this but it sure makes no sense to me.
- whatisweb3 4y agoIn Eth2 PoS the validator has two keys: signing key, and withdrawal key. They are derived from the same mnemonic seed phrase that can be kept in cold storage. The signing key must be stored on the device doing the staking, but the withdrawal key does not need to be, it is only secured by cold storage.
- Vecr 4y agoRight, but OP is not talking about theft, OP is talking about someone (with possible short interest) creating havoc by causing people's staking nodes to behave in a bad way caused them to be slashed. You can't get the money they lost (it's gone for good), but you might be able to profit of a short position, or with a more sophisticated scheme, a resulting fork.
- whatisweb3 4y agoI see - I am sure those sort of attacks will happen. If you secure thousands of ETH in a single validator and are tied with something that could be shorted - such as a company and its stock or token - then your situation is just as vulnerable to attack as keeping your cold wallet in your home's safe. Somebody could break into your house and either coerce you to provide the staking keys, or crack the device, or find another vulnerability if your opsec is not effective enough. If you're staking in the cloud with Amazon you are probabbly even more vulnerable. But isn't this the whole idea? By staking, you are placing your capital at risk in order to help secure the network. This is how staking is often described by Ethereum developers. > or with a more sophisticated scheme, a resulting fork I'm not following this.
- Vecr 4y agoYou might be able to create enough havoc in the staking system to cause a fork, and you might be able to preposition buy and sell orders (selling very early on the fork you don't favor, not selling on the one you do favor, and using the money you made by selling to buy more in the fork you favor as soon as possible, possibly from an automatic market that springs up within minutes. You would then use your position to make money as the price of the fork rises, closing out all positions before the whole thing goes down again.)