12 ms·
Hackers drain $100M off Solana-based DeFi platform Mango Markets
- mardoik 4y agoThis time it's one of Solana's largest DeFi protocols. Are these guys asleep at the wheel? I wonder if these hacks can ever be fully prevented.
- DemeterFarm 4y agoThey are 100% preventable, by using cryptocurrency.
- yieldcrv 4y agowho is they? the people that don't architect their systems for oracle manipulations? the way people talk around here reminds me of people in the 90s ‘that dun undastand dem puters with their viruses”, interestingly the folly and new problems presented by computers never went away, consumer and developer behavior improved
- renewiltord 4y agoYeah, you can solve this with the Blockchain
- tbrownaw 4y agoThe usual way to fix this sort of thing is with a human-in-the-loop retroactive fix process. But that's called "regulation" and "lawsuits", and the cryptocoin crowd trends to not like those.
- randomerer 4y agoNot sure this is the case in this hack but many of these hacks are related to human error.
- mmastrac 4y agoIf there's every a use for provably correct programs, it should be in crypto.
- nl 4y agoHey Matt! There is some interesting work done in this area. For example https://reach.sh/ https://reach.sh/ lets you write formally verified smart contracts. I guess this is helpful with some classes of bugs. But I'm not sure it would with most. For example it is unclear if it would have caught this problem since (from the vague description!) it appears it would have needed some economic modelling to catch.
- RHSeeger 4y agoFrom what I'm seeing here, all the individual things that were done _were_ correct. It just so happens that the system was setup with rules that allow for this type of thing. A probably correct program would not have helped here.
- dfcowell 4y agoThis is the difference between correctness and fitness for purpose.
- threeseed 4y agoThe problem is that you can't predict ahead of time every use case. That's why today's financial system has the ability to manually revert back to a previous state if something gets wrong e.g. undo transactions, government bailouts etc.
- formerkrogemp 4y agoCrypto will be seen during the current tech bubble as a sign of market mania similar to the craziest notions of the .com bubble.
- Taniwha 4y agoI'm kicking myself for not creating a large series of tulip NFTs a year ago
- formerkrogemp 4y agoI'm sure that would have done well in Holland..
- uptownfunk 4y agoFeels like the 90s again
- cryptoanon 4y agoA lot of people seem to think that this was an inside job. I’m getting tired of this. So much money has been siphoned away from the market it’s not funny anymore.
- nradov 4y ago
- cryptoanon 4y agoWhy are you so cruel?
- worthless-trash 4y agoThe world is a cruel place, sometimes being direct is the only way to get a message across. The world has been treating adults like children.
- worthless-trash 4y agoSee my votes at -1, can't even tell people what I think. Silenced by a sensitive minority.
- dfcowell 4y agoI think a lot of this sentiment comes from the fact that people buy into and hype up an ecosystem that is very up-front about how much responsibility lies with the individual (all of it!) and those same people get upset when they get taken for a ride and lose their shirts. Play with fire, get burned. If you don’t want these things to happen, stay in the regulated financial system where guard rails exist against market manipulation. Personally, I’ve done my due diligence and decided that the crypto community is a raging dumpster fire that is speedrunning the last 200 years of centralized financial fraud and somehow failing to learn any of the lessons along the way. For that reason (and because I lack the time to exhaustively vet every project that looks interesting,) I’m staying out of it.
- 4y ago
- sinerath 4y agoi never read this one but watch ravencoin be next
- nl 4y agoThis attack was interesting because it's an economic, not software hack. https://twitter.com/joshua_j_lim/status/1579987648546246658?s=20 https://twitter.com/joshua_j_lim/status/1579987648546246658?... is the source overview. The software all worked as expected, and it's difficult to see exactly which step you'd go "no, the person shouldn't have done that". Arguably the fault is with the loan protocols that valued collateral at the instant spot price rather than some kind of time-averaged price.
- datalopers 4y ago> valued at the instant spot price The entire cryptocurrency hype machine is predicated upon quoting market capitalization based on instantaneous spot prices. Nobody thinks about liquidity until it's gone.
- piva00 4y agoThe person shouldn't be able to wash trades, that's the core of this "hack".
- nl 4y agoYes, this is true.
- mewse 4y agoNB: This article is about the $115 million Mango Markets hack of a few days ago, not about the $127 million exploit of Binance's blockchain from last week or the $160 million Wintermute hack from last month or the $1.2 billion-with-a-'b' Acala hack from the month before, or...
- deleted 4y ago[deleted]
- cowtools 4y agoWhen will they learn? When will they learn... THAT THEIR ACTIONS HAVE CONSEQUENCES
- quickthrower2 4y agoCrypto being public might mean more hacks get reported whereas a 100 private businesses getting phished out of a million wont register even if the information is available to a reporter.
- Retr0id 4y agoAnd?
- yieldcrv 4y agoits a statement to focus on the system design of the organizations that got hacked instead of the asset/platform they happen to use, just like we do with non-crypto organizations
- qeternity 4y agoThe platform that an organization uses is a critical piece of the design of an organization. If a bank gets hacked because they’re running Windows 95, would don’t turn around and absolve them of liability. And if an organization uses an anonymous, immutable platform that makes it vulnerable to manipulation and theft, well then they deserve every bit of criticism.
- Animats 4y ago"According to Lim, the hacker funded the main account (account A) and offered 483mm units of $MNGO perps on the order book. The attacker then funded a second account (account B) with 5mm $USDC collateral. Then, he/she used the funds to buy the 483mm units of $MNGO perps (at a price of $0.0382 per unit). The perpetrator’s actions made $MNGO’s spot market price, reaching as high as $0.91. $MNGO/USD price of $0.91 per unit, account B was in the money by 483mm times ($0.91 – $0.03298) = $423mm. That was enough unrealized P&L to take out a loan of $116mm across a bunch of tokens. This left mango and left the protocol at a deficit,” Lim stated." Is this a "hack", or a legitimate financial transaction? Nothing above looks illegal. In regulated markets, if something went from $0.03 to $0.91 in a short space of time, trading would be shut down. Nobody would sell you a loan on something that had just had a giant change in price. But the crypto sector doesn't want exchange regulation, so they don't have the "circuit breakers" that, say, the CBOE does. Web3isgoinggreat[1] tracks total losses in the cryptocurrency sector. Their total counter just advanced to $11 billion. [1] https://web3isgoinggreat.com/ https://web3isgoinggreat.com/
- mattwilsonn888 4y agoMore of a financial exploit, but don't conflate popular crypto sentiment from Twitter with what's possible. There is no reason regulation is required to prevent this on a automatic protocol level - but no surprise in the DeFi space if preventing this type of exploit isn't an active area of development.
- cuteboy19 4y agoMany of the recent bridge hacks were easily preventable. Unfortunately when the dev himself is the hacker, no amount of active development would fix these issues
- mattwilsonn888 4y agoI'm not sure if this has much specific relation to the Mango hack, but you raise an interesting point mentioning the possibility of a developer hacking his own network (who would be more qualified to do so?) - my broader point is this: there is a lot of incentive to get these platforms up and running, and not always a lot to build them safely and even less to truly audit them. Often the developers make their money up front - in a way that's all that has to be said for the diligence developers of these protocols might have across longer time scales. People are so concerned with making a quick buck they forget about subtleties like developer token lock up, third party audits, patience in general. But that's how markets go - fast money is more valuable than slow money and the price you pay is risk. What the average Joe need to know is that DeFi, while capable of producing huge gains, also comes with a lot of risk both market-wise and protocol safety-wise.
- dainiusse 4y agoThis just tells why crypto is nowhere near anything except casino...
- bouncycastle 4y agoHate to be that guy, but someone has to say it... In this case the code worked as expected and the "attacker" played within the rules of the game. Except they "won" too much. That's not supposed to happen.
- randomfool 4y agoWe’re laughing at the game creators. They’re the ones who decided to rewrite the rules, often with little understanding of economics.
- quickthrower2 4y agoCreating and selling worthless tokens = Entrepreneur Obtaining someone elses tokens because code had flaw = Hack
- UncleMeat 4y ago"As expected" is doing a lot of lifting here. In some sense, this is true for all hacks. The code is just doing what you told it to do when it returns to some gadget in libc after the return address is smashed. All exploits are making a program do what it says it does but where that behavior is different than what the developers hoped it would do.
- SilasX 4y agoNot quite. Per this other comment[1], there's a difference between correctness vs fitness for purpose. The code was correct -- if, previously you had walked through the logic of the attack with them, the coders would have said, "yep, that's what we want it to do -- lend that much, based on those oracles' prices". They just didn't realize that there are dangers of using a price oracle for collateral valuation that has recently shown a sharp upward movement. (Which fals under "fitness for purpose".) So the code correctly lent to someone at Mango's current valuation, it just didn't require the optimal-in-hindsight collateral ratio for such a volatile asset. [1] https://news.ycombinator.com/item?id=33173028 https://news.ycombinator.com/item?id=33173028
- e63f67dd-065b 4y agoCode is law working out real well over here. The code said that we should value MNGO at the current spot price, so that's what the code did, and poof went the entire network. In the real world we have things like leverage ratios, anti-manipulation laws, circuit breakers, etc. Some of this is regulatory, and others are just things we figured out were good ideas many years ago. I think there's a sense of hubris in the new code is law advocates. As a programmer, code is law scares me because I know code is nothing if not buggy, whereas law has real mechanisms where the case is presented in front of humans that generally speaking have reasonable thoughts. Yes law is flawed, judges can be biased, lawyers are expensive, but throwing all of that away in favour of code on the internet seems much worse. Judges can issue injunctions that say "freeze everything until we sort it out in court", whereas code just runs whether you want it to or not. Courts can say "reverse all the transactions related to x", and blockchain is, by design, immutable.
- groestl 4y agoPlaying devil's advocate here, since I'm generally of your opinion: there is nothing that prevents more code being written covering more unintended uses of the technology, including injuctions and reversals. If at all, there is a hubris that complex problems can be solved with clean, minimal code and simple concepts. After all, when rendering their decisions, human courts are also solely refering to rules written before the fact (in my home country at least).
- lmm 4y ago> After all, when rendering their decisions, human courts are also solely refering to rules written before the fact (in my home country at least). They don't though. Courts dream new meanings into existing laws, create new duties where none existed before, and while the extent to which they should do so is controversial, few serious people think they should avoid doing so entirely.
- groestl 4y agoI agree with you, and IMHO that does not necessarily conflict with what I've written before. It's true that there is broad catch all logic at the top level of policies, and when deriving lower level decisions courts inherently create policy too. But I believe it's not completely unrealistic to have such functionality baked into a conflict resolution protocol for crypto as well. Although the decisions and policies it derives might not be explainable for humans. Generally though, I use the arguments in this discussion the other way round: in convincing lawyers (German speaking lawyers that is) that the value of law is mostly in being readable by common people. And less in being unequivocal to courts. We have code for unambiguity, but in essence, code bears the same problems as complicated laws when communicating policy and what's socially accepted to society.
- zeronine 4y agowHeN wIll they LEarn?
- squeaky-clean 4y ago"Then, he/she used the funds to buy the 483mm units of $MNGO perps (at a price of $0.0382 per unit). The perpetrator’s actions made $MNGO’s spot market price, reaching as high as $0.91" Is the second sentence sentence missing some words? Or is there something specific about Mango that makes this make sense? If 483mm units were bought for $0.0382 per unit (is that the average price, a fixed price?), why did the spot price suddenly increase 30x, was there that big of a spread in the order book? Also how does that add up to $5mm USDC? Isn't $0.0382 x 483mm = $18.4506mm?
- anonymoushn 4y agoFirst question: yes, the missing part is that the attacker also had to buy a bunch of spot mango tokens on centralized exchanges to drive the price up after establishing the large position. Second question: Mango Markets lets you trade perpetual futures with leverage, so you don't need collateral equal to the notional value of the contracts you buy.
- squeaky-clean 4y agoThank you! It makes sense now, and also... wow.
- strangattractor 4y agoTo you maybe:)
- salawat 4y agoOkay, let me see of I got this right. User acquires an/a set of in perpetuity futures contracts. (A future without an expiry date, effectively, what? A pin I guess?) Idea being, this order indicates intent to swap at volume $MNGO to $USDC at $RATE. Centralized exchanges sees the futures order, and starts cranking up the price of $MNGO due to the increased interest in swapping based on the presence of the Futures. The Futures contracts are leveraged, but require no collateral, because there is no expiry date on the Future (no intended date of delivery). So the order volume (spot token purchases) induced upward price movement and... What? Caused other uninvolved investors to buy his acquired tokens at a peak, and he just takes the money and cashes out never intending to actually honor or settle up the perps, which won't margin call, because they're still "good" but will never mature? I'm failing to see an exfil path for ill-gotten gains/financial chicanery beyond the seemingly obvious wash trading. If anyone can help detangle this, I'd be much obliged. This kind of market weirdness is interesting, but inscrutable at times, when there's usually like 6 pieces of networked jargon needed to render something that doesn't tend to line up to anything tangible in the conventional sense.
- senko 4y agoPSA: In normal, regulated, markets, this kind of "economic hack" is called "fraud" and gets you in trouble (fine and/or jail).
- strangattractor 4y agoEvery time I have dis'd crypto in comments on HN they always loose karma. This is the first discussion with people that agree with me. I have found my tribe:)
- strangattractor 4y agoVery funny:)
- cercatrova 4y agoAnother day, another cryptocurrency exploit. But I thought code were law?
- stevebmark 4y agoWhy do crypto hack announcements sound like AI generated text? They're things like "Krupto's Flifty ICO Exploited by Etherium's $SCRIM"
- beardyw 4y agoI have a feed from: https://web3isgoinggreat.com https://web3isgoinggreat.com Multiple scams and failures every day.
- deleted 4y ago[deleted]
- SilverBirch 4y agoI think the really great thing about this hack, is this platform is governed by a DAO. Apparently, the person who pulled this heist ended up with enough governance tokens that they could propose something to do the DAO along the lines of "I'll send you a bit of money back if you say you won't call the cops" and was able to vote for it themselves with 32million votes. https://dao-beta.mango.markets/dao/MNGO/proposal/3WZ5DpZXDvNAK4JwPS1HDPzSinEJUGpBC4XXx9vPtnVS https://dao-beta.mango.markets/dao/MNGO/proposal/3WZ5DpZXDvN...
- janef0421 4y agoSeeing that contemporary crypto essential operates like bearer bonds, it is hardly surprising this would happen.