22 ms·
Proof of solvency and beyond
- sillysaurusx 4y ago> But it's worth getting to the fundamental issue with the right half of this design space: dealing with user errors. By far the most important type of error is: what if a user forgets their password, loses their devices, gets hacked, or otherwise loses access to their account? > Exchanges can solve this problem: first e-mail recovery, and if even that fails, more complicated forms of recovery through KYC. But to be able to solve such problems, the exchange needs to actually have control over the coins. In order to have the ability to recover user accounts' funds for good reasons, exchanges need to have power that could also be used to steal user accounts' funds for bad reasons. This is an unavoidable tradeoff. > The ideal long-term solution is to rely on self-custody, in a future where users have easy access to technologies such as multisig and social recovery wallets to help deal with emergency situations. Not to dismiss this out of hand, but isn’t that the central problem? Users want to use Coinbase for convenience as much as for any other reason. Saying “we’ll make it easier to host your own coins” is a bit like saying “we’ll solve the #1 problem with mass crypto adoption”.
- x-complexity 4y ago> Users want to use Coinbase for convenience as much as for any other reason. > Saying “we’ll make it easier to host your own coins” is a bit like saying “we’ll solve the #1 problem with mass crypto adoption”. That's the point: Coinbase & CEXes have it easy because they can centralize - Their development efforts can be honed in more effectively. The ultimate long-term goal is to remove the need for such entities in the first place, and make it easier/safer/cheaper with the use of rollups, on-chain insurances, social recovery wallets, DEXes, & integrated crowdsourced filter/allow lists.
- baxtr 4y ago>The ultimate long-term goal is to remove the need for such entities But replace with what? With people like Vitalik? He seems to be an influential figure and calling the shots. How is this in any way different than a "normal" company with a CEO and a board?
- x-complexity 4y ago> But replace with what? Ideally, open-sourced & audited smart contracts that are ERC-compliant & developed by the general public, with the internal mechanisms made viewable to anyone that wants to learn how such mechanisms work. > With people like Vitalik? He seems to be an influential figure and calling the shots. Vitalik can point at where focus could be targeted at, but the decision is ultimately up to the developers themselves. In fact, as far as I can remember, most of the efforts mentioned in the post & image below are not publicly mentioned at all, with other developers leading the charge on that front. (Danksharding being one example, with the development efforts led by Dankrad Feist, hence the name.) https://twitter.com/VitalikButerin/status/1588669782471368704 https://twitter.com/VitalikButerin/status/158866978247136870... https://pbs.twimg.com/media/FgwVhUjaAAEx_Bb?format=jpg&name=large https://pbs.twimg.com/media/FgwVhUjaAAEx_Bb?format=jpg&name=... > How is this in any way different than a "normal" company with a CEO and a board? The main difference is that development is not wholly left to one party: Anyone can choose to develop the applications that they want to see & deploy them onto the platform. Even if you're external from the main development efforts, you can still contribute to the overall ecosystem with code contributions towards one of the various nodes of the entire system. This stands in contrast with a standard company, where external development's forbidden outside of a special area designated for the general public to interact with.
- jsemrau 4y agoIf your only business is being an exchange you might not run into any issues if you consider all the decentralized exchanges that are still operating. The problem arises if you add market maker, trading house, hedge fund, market research, and learn2earn to the mix. #greedisgood.
- lottin 4y agoDecentralised exchanges only deal with virtual tokens. Centralised exchanges are needed because people need to be able to trade these tokens for real assets.
- chrisco255 4y ago> Saying “we’ll make it easier to host your own coins” is a bit like saying “we’ll solve the #1 problem with mass crypto adoption”. Sure, I mean, we're still in the "dial-up era" of crypto and a big part of that is wallet UX. But if you're following the space closely, you can see there's been some solid efforts on that front. Rainbow Wallet (https://rainbow.me/ https://rainbow.me/) is an iOS & Android wallet that backs up your private keys to iCloud/Google cloud. I think for smaller sums of money and valuables, this is a pretty good solution. Argent (https://www.argent.xyz/ https://www.argent.xyz/) is a smart contract wallet that has a "social recovery" feature that allows you to delegate account recovery to a circle of trusted parties. Gnosis Safe (https://gnosis-safe.io/ https://gnosis-safe.io/) is another smart contract wallet that many DAOs use for treasury management, which allows for arbitrary multisig settings to be configured (like requiring 3 out of 5 signers or what have you). Some of these still need work on UX, but the core tech is there. Another factor is blockchain fees. Layer 2s like Arbitrum (https://arbitrum.io/ https://arbitrum.io/) and Starkware (https://starkware.co/ https://starkware.co/) have already dramatically reduced fees (by as much as 10-20x and will likely get to 1000x reduction by the end of the decade). Once the layer 2s and layer 3s are more mature, it's conceivable that a Coinbase or Kraken could run their own auditable rollup, even if the order book was run on a centralized server, at least the net balances would be held on-chain (Dydx https://dydx.exchange/ https://dydx.exchange/ works like this currently).
- DSingularity 4y agoWell maybe we should accept crypto isn’t for the masses. Maybe banks are good enough for that use-case (users who want convenience because they can’t be bothered to learn how to manage their own coins). Maybe vitalik should focus on preserving decentralization instead. As far as I can see it the biggest flaw in cryptocurrencies — including Bitcoin - is when you look hard enough you realize the decentralization is a facade.
- theCrowing 4y agoBanks are better.
- vouwfietsman 4y agoIsn't this the same problem though, nobody wants to manage their coins -> platforms manage coins for users -> centralization.
- bergenty 4y agoThe difference here is people physically cannot manage and protect a large amount of cash and not having it in banks means you gradually lose money over time. This isn’t the case with crypto where you can carry potentially all the wealth in the world on a single flash drive. I think more can be done. An entity with a mobile app like Coinbase that seamlessly carries out transactions and then deposits your coins in your own personal wallet but manages your keys in an encrypted manner so all of the account management is hidden behind a single password. They should charge a monthly subscription for it.
- flakeoil 4y agoBut what's the point? Having Coinbase or some exchange like that handle your money or having a bank handle your money. Wherein lies the difference? You prefer to have an encrypted number in your pocket which only Coinbase can access over an encrypted number at a regular bank's server?
- 4y ago
- ragebol 4y agoCertainly reads like an instance of 'If all you want to use is a hammer, everything looks like a nail'.
- Closi 4y agoYep! Proof of solvency can be done now - just allow a reputable financial audit company in and get them to publish your financials.
- birracerveza 4y agoThe entire point is not having to trust "reputable" financial audit company, as we've been shown time and time again that they can, and will, be corrupted.
- ForHackernews 4y agoMeh. As an outsider, you're not going to be able to reliably audit some incomprehensible smart contracts, either. You'll have to trust somebody: either Deloitte, or @ShibaMuskMoonSecure.eth Evidence: https://old.reddit.com/r/Buttcoin/comments/we8514/nomad_hack_smart_contract_auditors_outlined_the/ https://old.reddit.com/r/Buttcoin/comments/we8514/nomad_hack...
- siftrics 4y agoYou can easily audit total assets though. Just look at one number on the chain.
- ForHackernews 4y agoI assume you have to install software to do that? Software written by some author(s) that you have to trust? That you have to download and install from trusted sources? It's not like I can verify "one number on the chain" with my own human eyes and no third parties involved. There's always trust somewhere in the system, you're just making that trust relationship more obscure and opaque.
- joosters 4y agoQuick way to summarise a Vitalik blog post: Here's a social problem, tech will solve this!
- smcl 4y agoThis looks like "Here's a crypto problem, more crypto will solve this!"
- firasd 4y agoI think the speed and low-fees required in (some types of) financial trading just can't happen fully on chain. So that's another reason for centralization in exchanges Also it's interesting to note that in regular finance, exchanges and brokerage firms are separate entities .. meanwhile eg FTX was both the exchange and the 'broker' Edit: just searched twitter and came across someone asking SBF this exact question about the conflict of interest in being both the exchange and broker (of course he was also trading with client funds on top of that..) https://twitter.com/dwarkesh_sp/status/1593243104114458627 https://twitter.com/dwarkesh_sp/status/1593243104114458627
- x-complexity 4y ago> I think the speed and low-fees required in (some types of) financial trading just can't happen fully on chain. So that's another reason for centralization in exchanges That's currently being resolved with the implementation & adoption of rollups: There're currently multiple efforts towards developing zk-based rollups, with everyone (Polygon, zkSync, Scroll) taking a different approach towards providing it. Right now, optimistic rollups are the dominant rollup strategy right now, with improvements & decentralization already undergoing development & deployment. Most still have guardrails in place, but it's publicly known & already being worked on. https://l2beat.com/scaling/risk https://l2beat.com/scaling/risk
- tromp 4y ago> I think the speed and low-fees required in (some types of) financial trading just can't happen fully on chain. So that's another reason for centralization in exchanges You could have an exchange whose users have 2nd-layer channels open to it for all the currencies they trade. Trading can then happen near-instantly with 0 fees. While still centralized, it doesn't need to take custody of any user's funds.
- etchalon 4y agoIt feels like there would be a way to construct the tree in a manner that would drop the likelihood a negative balance was detected to an acceptably small number.
- big_red 4y ago
- deleted 4y ago[deleted]
- choppaface 4y ago> If you prove that customers' deposits equal X ("proof of liabilities"), and prove ownership of the private keys of X coins ("proof of assets"), then you have a proof of solvency: you've proven the exchange has the funds to pay back all of its depositors. But what if your private keys are actually owned by Alameda, who lent you them for the purpose of demonstrating solvency but then oops options blew up and they're gone now? But what if most of your deposits were gold- or USD-backed assets and your assets are all shitecoin and a 51% attack happens to shitecoin and everybody wants their gold back? But what if you do all this and you prove solvency, but your assets are all rated by S&P and oh crap just like in 2007 they rated everything triple-A but it's actually junk? I mean the technical ideas in the piece are sound, but there's nothing here to fundamentally rebuild trust in crypto. Also: the title "having a safe CEX" -- cute, but underscores how crypto is such a sausage fest.
- siftrics 4y ago> But what if your private keys are actually owned by Alameda, who lent you them for the purpose of demonstrating solvency but then oops options blew up and they're gone now? You don't understand public key cryptography. If someone else has the private key to your assets, the assets are not yours. This is not a failure of cryptography. Don't blame crypto.
- lottin 4y agoIt shows how easy it is to fool this cryptographic 'proof' of solvency. I think most people would regard this is a failure.
- siftrics 4y agoIt would be impossible for any entity to fraudulently post proof of on-chain reserves today. Sure, the fraud might fool some subset of extremely uninformed people initially, but someone is bound to find the fraud when they check the chain with one of the hundreds of different open source clients that exist today. Immediately, they would post this astonishing finding on Twitter. Immediately, Twitter would blow up and out them as frauds. Immediately, all of the people who were initially fooled would know that this company is a fraud.
- voz_ 4y agoAnd... still no real world use for crypto.
- spencerchubb 4y agohow about all of the people who don't have banking infrastructure, but do have smartphones
- nprateem 4y agoYes excellent. Exactly what those people who live on $2 per day need is to have their $2 fluctuate wildly from 2c to $6 on an hourly basis.
- siftrics 4y agoStablecoins pegged to the dollar and various other currencies of the "real world" have existed for many years now. Stop acting in bad faith.
- Zanfa 4y agoWith the number of collapsed stablecoins this year and the biggest one of them all being a complete fraud, I'm not sure they're any safer. Also, every fiat-backed stablecoin is by definition 100% centralized to a single legal entity.
- siftrics 4y agoWhat is your point? My point is anyone with an internet connection can give their savings 100% exposure to any centralized fiat currency, _if they so choose._ I'm not saying you should or you have to. I'm just saying this gives people the option to do that. What's bad about that? What's wrong with that? Should only US citizens be allowed to save US dollars?
- codetrotter 4y agoUntil the peg is lost, like what happened with UST (now USTC). https://jumpcrypto.com/the-depegging-of-ust/ https://jumpcrypto.com/the-depegging-of-ust/ That coin was supposed to be pegged to $1 USD.
- panic 4y agoAre there any applications of zk-SNARKS outside cryptocurrency?
- siftrics 4y agoYes, absolutely. In a fully public voting ledger, you could manually verify each vote is associated to a unique national identifier without revealing it. E.g., this vote corresponds to an SSN that hasn't cast any other vote, without revealing the SSN in question.
- unintendedcons 4y agoLooking forward to trying this! Any implementations?
- ricochet11 4y agozk'ing machine learning. hide the inputs for privacy. https://0xparc.org/blog https://0xparc.org/blog have a bunch of cool things like https://www.heyanon.xyz/ https://www.heyanon.xyz/ also the S part being succinct is useful without the zk parts too!
- web3isgoing 4y agoVerifiable computation. See Pinnochio and RISC Zero. https://eprint.iacr.org/2013/279.pdf https://eprint.iacr.org/2013/279.pdf https://www.risczero.com/ https://www.risczero.com/
- baxtr 4y agoSo what I really don't get about the decentralized fans: They repeatedly say, our goal is to replace entities like DEX. But replace with what? With people like Vitalik? He seems to be an influential figure and calling the shots. How is this in any way different than a "normal" company with a CEO and a board.
- web3isgoing 4y agoVitalik isn’t running any DEXes, he is not in a position where he can steal or move user funds locked into a DeFi contract. He could suggest a change that might do something malicious at protocol level, but the rest of the developer community would reject it.
- Yizahi 4y agoCEO of a bank can't do that too. The board can though. And of course customers can reject that decision and switch bank. But in reality that won't happen both in the bank case and in the tokenbro case. We have already saw how Vitalik stole lawful tokens from the receiver of The DAO program (code is law after all), and everyone has supported him. Exactly the same as banks can do, only without outlandish claims.
- chrisco255 4y agoA fork is not a theft. The code allows for forking, doesn't it?
- EiZei 4y agoMost people don't even understand asymmetric cryptography 101, how is piling on more math is going to help?
- web3isgoing 4y agoThis math is not for end users of an exchange, it’s for developers and researchers building new exchanges. The UX does not need to feel that different than any regular app.
- squokko 4y agoI feel bad for Vitalik because I think that he's a well-meaning 200IQ guy whose talents are being used to help scammers fleece ordinary people of their life's savings.
- robjan 4y agoHe's choosing to use his talents this way
- rabite 4y agoYour assumption of his naiveté is quite charitable. Before becoming the mouthpiece/patsy for ETH he was doing a quantum computing scam. He claimed he was going to compute NP problems in P time by simulating a quantum computer in software. Absolute hogwash obviously https://davidgerard.co.uk/blockchain/buterins-quantum-quest/ https://davidgerard.co.uk/blockchain/buterins-quantum-quest/ A more cogent explanation is that Vitalik finally found the right way to pull a con.
- squokko 4y agoHuh, interesting. But in 2013 he was 19 years old. I'm not willing to ascribe such malice to a 19 year old for something like this.
- lottin 4y agoRidiculous argument. Are you saying children are incapable of malice?
- pa7x1 4y agoPerhaps they are not capable of understanding why you cannot simulate a quantum computer with a classical computer. Sometimes even smart people are wrong about stuff, that doesn't make them necessarily malicious: https://en.wikipedia.org/wiki/Isaac_Newton#Alchemy https://en.wikipedia.org/wiki/Isaac_Newton#Alchemy
- squokko 4y ago
- bArray 4y agoFrom my understanding, this only solves one issue - exchanges holding crypto assets. I would expect an exchange to also hold traditional liquid money, which currently couldn't be captured by this. If you could get the US financial system onboard, maybe you could get them to maintain a 1:1 representation of a digital coin, but I don't see why they would be motivated to do so. The next problem then is that you can't diversify your holdings beyond that of crypto, so you are completely trapped by the relatively unstable nature of crypto. One day you hold a billion meme coins worth one billion dollars, the next day it is worth zero.
- web3isgoing 4y agoFiat assets was addressed in the post. Stablecoins can be used to avoid price volatility, and work within the framework Vitalik is suggesting.
- aww_dang 4y agoBacked tokens are still a trust liability with the issuing party. They have a place and are interesting, but it would make sense to limit the scope of exposure.
- chrisco255 4y agoYes, that's why there's a spectrum of stable coins with varying levels of centralized control, governance, risk, etc. Stable-ish coins like RAI and LUSD are backed by ETH only, but they do not have a hard peg, they allow for some small wiggle room (typically <10%) that allows the protocols to catch up with dramatic supply/demand imbalances when they occur.
- bArray 4y agoExactly. Take Tether for example. Every time BTC starts to dip, USDT starts to de-peg. They are not at all uncoupled. Tether doesn't have the market cap to cash out all of the BTC, and never will. The amount of apparent value in the crypto market heavily outweighs any possibility of cashing it all out. And that doesn't even begin to touch the questionable liquid assets held by stable coins. Tether claim to be holding 82% of "extremely liquid" assets [1], but I'm unsure it's proven or tested. From the report [2]: > The valuation of the assets of the Group is based on normal trading conditions and does not reflect unexpected and extraordinary market conditions, or the case of key custodians or counterparties experiencing substantial illiquidity, which may result in delayed realisable values. No provision for expected credit losses was identified by management at the reporting date. Substantial liquidity could be caused by, say, global inflation or recession conditions. But that surely won't happen... [1] https://tether.to/en/tether-proves-resilience-of-reserves-in-latest-attestation/ https://tether.to/en/tether-proves-resilience-of-reserves-in... [2] https://assets.ctfassets.net/vyse88cgwfbl/1Xfu4398CIoMiuKjPhvnHM/6d1608c90bb775d2d432b7b24264da28/ESO.02_Std_ISAE_3000R_Opinion_30-9-2022_RC134792022BD0548.pdf https://assets.ctfassets.net/vyse88cgwfbl/1Xfu4398CIoMiuKjPh...
- beefield 4y agoI admit, I did not read that in detail. Can someone explain how the "proof of liabilities" is proving that it contains all liabilites of an exchange? for example the electricity bill that is coming to be paid next week or the off-book loan of x billion cryptocoin from your fellow exchange that you need to pay back also next week? Awfully lot of trust you seem to need in this fancy world of trustless money of the future.
- Yizahi 4y agoIf you close your eyes and ears, then it is possible to imagine that such filthy thing as offchain liabilities doesn't exist. At least when Kraken posts about their "proof of liabilities" without actual audit of offline liabilities on Reddit r/cc, they readily eat that claim, no one challenges it. And then in every single post about this new trend, they will write that Kraken is somehow solvent due to this. I guess this was the point - if people already believe in something, it doesn't need to be real :) .
- capableweb 4y agoAll benefits of cryptocurrencies goes out the window when you introduce centralized exchanges. "trustless" is referring to the protocols, not the ecosystems.
- darawk 4y agoThe idea is that the exchange publishes a sum of their liabilities, and each individual user can check that their balance was uniquely included in the sum, cryptographically.
- beefield 4y agoUnfortunately this does not prove in any way that the exchange has included all liabilities in the sum, it only proves your deposit is included. A very, very different thing.
- darawk 4y agoOf course. But it lets every individual check this, which means if any individual's balance is not included, they can publish that. It is a vast improvement over the current state.
- c7b 4y agoIt's easy to be dismissive of everything crypto-related after the FTX crash, but we should remember that the problem of fraudulent business practices isn't specific to crypto at all. It's yet to be seen whether proof-of-holdings is practicable for crypto assets, let alone for real world assets. But it is an interesting use case for zero knowledge protocols that could tackle some very real problems. Yes, we have auditors in the real world, and I'm not thinking of replacing them, but it could improve audits. As one example, not too long ago there was a crash of a German payments provider of a scale not much smaller than FTX (Wirecard) that was audited by one of the major firms (EY), who missed a fake $2bn bank deposit claim.
- hef19898 4y agoAnd Wirecard was a clear fraud. They didn't steal customers deposits so. And, all in all, Wirecards accounting was lightyears better than FTXs, Wirecard held bank liscenses which requires proper book keeping of assets and deposits.
- ramraj07 4y agoMany of us were dismissive of everything cryptorelated even when many others became millionaires or billionaires believing into it. If you needed something as pathetic as the FTX fiasco to change your mind, you’re right, that’s unreasonable for sure.
- arkh 4y ago> many others became millionaires or billionaires believing into it Yeah, being first in a Ponzi scheme tend to work well for some people. For every winner in cryptocurrency there are losers as cryptocurrencies are a zero-sum game.
- jnsaff2 4y agodecidedly negative sum as a lot of energy has been wasted to redistribute wealth
- 4y ago
- JoachimS 4y agoReading the Vitalik posting made me think of this, also on HN right now: https://annasofia.xyz/2022/11/05/criticizing-computers.html https://annasofia.xyz/2022/11/05/criticizing-computers.html Every problem, issue with crypto-tech seems to be solved with yet another layer of crypto-tech. Every criticism of the tech is deflected by pointing at yet another project that is claimed to fix what is being criticized.
- darawk 4y agoHumans have been solving the problems of existing technology with more technology for quite a while now. This comment is like criticizing database indexes as a mere technical band-aid over the fundamental problem of having too much data.
- short_sells_poo 4y agoThe problem is that databases solve a real world problem: businesses and people need to store data, and the database is literally the solution for that. Cryptocurrencies have so far not resulted in a compelling use case. All that we are seeing is a questionable solution looking to solve some as yet undiscovered problem. The parent comment is a bit flippant, but I agree with the thought. The entire crypto industry is rapidly becoming a bizarre and convoluted rube goldberg machine that is completely impenetrable to anyone but the most ardent zealots. Even more, as an outsider it seems like everyone is in this echo chamber of back patting and "with just this one more buzzword bingo sounding feature, we'll have unlocked the true potential of crypto".
- PubliusMI 4y ago
- web3isgoing 4y agoOne failure of FTX and BlockFi is that users had no way to ensure that the centralized custodian was not running off with their on-chain deposits by directing them into unsound deposits. Vitalik is suggesting a cryptographic mechanism here that would provide better transparency as to on-chain activity of a CEX. Day traders want to trade, no matter how much you try to tell them their trades are fictional or "have no use cases."
- braingenious 4y agoThis is so funny. Self-styled geniuses inventing infinitely iterable levels of complexity to invent infinite levels of why they should have infinite governance around the concept of digital money is probably the best grift in generations. Don’t get me wrong, I think it’s great. In the US, it’s mostly the worst folks actually losing to this game and I’m overall entertained. edit: I should maybe clarify that my crypto holdings are now about $20, entirely from folks losing bets to me.
- trophycase 4y agoCool story bro
- braingenious 4y agoThanks!
- KaiserPro 4y agoPremise: proving that you are solvent using cryptographic means Answer: let's re-invent accounting. Look the problem is this, as an "exchange", to be profitable you either need to charge fees, or do some sort of fractional reserve, using deposited value as capital for your Exchange's investments. If you go for option one, then you will be undercut by someone doing option two. The tradeoff being, number two is more likely to loose all your customer's cash. The value of something is more often than not irrational. This means that there is subjectivity in the value of assets. You can't technology your way out of that. This means that its perfectly possible to prove that you have liquid assets that will cover your present position. However thats expensive to maintain. So you start buying longer term more illiquid assets (think property, commodities, companies, etc) some of these are liquid in a day, others months. Worse still the value of them depends on how and when you sell them. So sure you can have assets that cover all your liabilities one day, then due to a re-valuation, not have enough. Thats not the same as solvent though. But, all of this neatly misses the point of crypto. If its a practical payment system, rather than an investment, you wouldn't hold your crypto at an exchange. You hold it your self and move it when you need to convert/liquidate.
- dmak 4y agoSerious question. Why didn't accounting help discover the solvency issues for FTX?
- edf13 4y agoBecause they had no accounts... their record keeping was not there. They didn't know where funds were, who was using them and what for.
- hef19898 4y agoIn short, they didn't have accounting. Nor where their books audited. FTX is a great example of ehy banks, and every other company, has regular audits of their books. As is Wirecard, but they didn't steal customers money. Just compare the "balance sheets" SBF prepares to a proper audited one, and the differences are clear as day. One can grab any audoted balance sheet from any publicly traded US company of the SEC website, I'd pick one from a financial insitution.
- rojeee 4y ago"Proof of reserves" including Vitalik's heath robinson crypto schemes, provide minimal assurance to exchange users. Why? It's what one would call a "limited assurance engagement" in audit parlance. In other words, it provides assurance over a small subset of the balance sheet of an exchange - only the customer deposits and the exchange liabilities pertaining to said customers. However, there are a few red flags which no-one seems to raise: 1) The customer deposits should be off balance sheet if they actually were held in custody. If deposits are not off balance sheet then customer assets cannot be held in custody. Instead, the customers are a creditor of the exchange. 2) From the terms and conditions I've read for various exchanges, customers are typically not treated as a preferential creditor. 3) In the event of an insolvency, customers are treated pari passu with other creditors. 4) To get sufficient assurance that the exchanges can honour their customer liabilities, we need to see ALL of the liabilities, not just the subset relating only to customer deposits. E.g. Who else is money owned to? Did they issue debt? Did they borrow from a bank? Are there any legal provisions? Etc... 5) Given the legal treatment of customers as unsecured creditors, without entire visibility of the balance sheet, the "proof of reserves" report is pretty much useless.
- mnadkvlb 4y ago2 and 3 will make sure no incubator will invest :)
- blitzar 4y ago4) ... this is why tradfi ringfences. One legal entity for the deposits one legal entity for the business. The entity for the deposits has only liabilities to customers + assets from customers.
- oldgradstudent 4y ago> provide minimal assurance to exchange users Worse, it provides false assurance that allows the operators of the exchange to loot the exchange more easily.
- Mvandenbergh 4y agoIn fact, on (2) this isn't even something an exchange can do through their Ts&Cs. Local law will decide creditor priority so in the absence of a regulatory framework that treats exchanges as "bank-like" and makes, as a minimum, customer balances "special" in some way, this simply isn't possible.
- tphyahoo 4y ago
- shaunregenbaum 4y agoNone of this addresses the consumer issue. You need to display this information to users and they need to both understand it and trust it. That is what the current system has.
- highwaylights 4y ago> Rather than relying solely on "fiat" methods like government licenses, auditors and examining the corporate governance and the backgrounds of the individuals running the exchange, exchanges could create cryptographic proofs that show that the funds they hold on-chain are enough to cover their liabilities to their users. So... use crypto to prove that you hold enough crypto to cover the losses if crypto crashes and you can't pay people back without crypto. This only works to prove that you hold enough Trashcoin to pay back people's Trashcoin that you're supposed to have - but why have their Trashcoin at all if you need to make it available to them? You can't do anything with it that would make you money while still guaranteeing availability to it's owner, so then you're just providing a free custody service for someone that's worse than them just holding it themselves. Also, if you're able to cryptographically guarantee Trashcoin holdings then you don't need the exchange anymore. Guarantees + DEX + off-chain transactions replaces your exchange for low fees in that case. Leaving all that aside though - It's a suggestion to optimise away protections as a problem to be solved when the solution being proposed has time-and-again proven itself unfit for purpose with catastrophic consequences. Regulating financial systems and making them safe is hard, because it's more complicated than anyone who's approached this in crypto seems willing to acknowledge. Honestly, I think regulators should be approaching this whole space with a view of "we'll get involved to stop criminals that have the potential for non-crypto victims, but we'll not spend time or resources to help anyone that get's ripped off after choosing to put their money in this". (i.e. The state has a duty to protect it's citizens, but I don't see what burden the state has to protect money that was wilfully removed from the protections of the regulated financial system. If anything, the state has a duty to not waste resources pursuing lost funds in those instances as they have no mandate to do so.) I have sympathy for people that lost out with FTX and Celsius - I genuinely do - but there were so many warnings that you would have had to dismiss before ending up in that situation and it's hard to believe that people that put money into these platforms (or tokens in general) didn't realise what they were getting into. There's a massive amount of historical experience to draw on - these aren't new schemes.
- autotune 4y agoI am just so exhausted with all of this nonsense. Why can't we go back to talking about how to get rich slowly over like 10-20 years with real money? Yeah you are not going to become a millionaire over night, but maybe you'll have enough to buy a house before retirement. You'd have better luck trusting a casino with getting a return on your money than crypto at this point.
- deleted 4y ago[deleted]
- candiodari 4y ago... and how does this prove that the "solvent" exchange doesn't have liabilities (I believe FTX was on the hook for real-world mortgages for private homes of their management) It doesn't.
- lrvick 4y agoIMO a universal and easier to reason about solution is you have a threshold signing wallet created across a series of remotely attestable cloud enclaves like Google/Azure Confidential VMs, AWS Nitro Enclaves, and even TPM2.0 enabled baremetal. Deploy an open source, deterministically buildable, stateless, and immutable, unikernel OS to all platforms that enforces strict signing policies on a multisig wallet address signed and owned by whoever requested that wallet to be created. End users will not need to trust the custodian as they will have access the remote attestation interface to prove systems they pay for are running expected binaries and thus obey the rules. A user then asks those systems to generate a wallet with a policy that grants the custodian the ability to transact only specific maximum amounts per day, with an automatic dead-mans-switch that always signs/exports an updated escape-hatch transaction sweeping all funds that a user can publish at any time. It is possible, per the above, to create custodians with no raw access to key material that are provably bound to the terms a user agreed to on deposit. This accountable computing setup ends up looking a lot like off-chain smart contracts. It could be used to ensure any type of user owned cryptographic key material can only be used by a SaaS according to user defined policies. I am working with several custodians on implementing this type of accountability right now. Anyone that fails to have a good proof-of-funds solution is going to become irrelevant in the medium term and hopefully illegal in the long term.
- DebtDeflation 4y agoThe article seems to be more about proving reserves rather than proving "solvency". There's more to assets and liabilities than just customer deposits and coins held. How does a Merkle tree help when customer deposits are used as collateral for some off chain loan and then the value of the exchange's equity drops below the value of these off chain liabilities?
- cynusx 4y agoWell, it's the first time I see crypto trying to tackle real-world financial issues such as counterparty risk. Crypto's real future is in machine-readable accounting imo
- jmull 4y agoThat's just another thing that doesn't require crypto at all.
- mr90210 4y agoScientism! This guy lives in a bubble.
- skee8383 4y agoWho cares. crypto is finished.