4 ms·
The big difference is DeFi apps are immutable, humans are not. If someone has deployed a DeFi app that can't be changed and hasn't been hacked in a few months,
by TimJRobinson 4y ago
The big difference is DeFi apps are immutable, humans are not.
If someone has deployed a DeFi app that can't be changed and hasn't been hacked in a few months, I'm fairly confident it's safe. With an exchange it doesn't matter if it's been running 10 years, it could start stealing money tomorrow.
- kkielhofner 4y agoCode generally is but the target size and scope here completely changes the game. When an iOS zero day is discovered (as one example) exploiting it often still takes multiple steps, i.e. some action each individual target needs to take. In most cases (rarer and rarer with the exception of log4j, etc) this limits exposure until it can be discovered and patched. Even in the case of things like log4j you can patch your instance before someone gets around to exploiting your instance. It's widely known that governments, people like the NSO, hacking groups, etc sit on zero days for as long as possible waiting for an opportune moment with the highest return and biggest impact. Hacking groups, governments, etc have been known to sit in compromised networks for years before striking. Point here is they can be remarkably patient and with smart contracts by the time the issue is discovered there's no point - the smart contract is now at $0 and the attackers have disappeared into the night. When smart contracts are deployed they sit at an address. If an equivalent "zero day" is discovered it's just there there waiting for someone to exploit it with global/universal impact. No action on the part of any users, no need to deploy target by target. I'm sure I could phrase that better but early-morning HN is what I do between waking up and the caffeine kicking in for real work :). Point here is, I don't quite understand your "it's been around growing for a few months and $10m (or whatever) is there so it's probably safe". Why strike a buggy contract when it's received some amount of traction and is still early stages? Why grab $10m when you can grab $100m (or more)? As I noted there have been several cases (arguably most) where I'm pretty sure the attackers did just this. Or, in the case of Axie Infinity, you can steal $620m the "good old fashioned way" by targeting and manipulating one of the people behind it. So, in practice, in many cases, humans are still involved. This also doesn't get to my other points involving the challenge of securing your own wallet, etc. If you peruse around Discord, Reddit, etc where crypto people of higher than average knowledge, skill, and sophistication are reporting daily wallet hacks you'll see just how hard this is. The equivalent being there's a reason why (for example) the United States keeps gold reserves in places like Fort Knox where there is a literal army of 26,0000 soldiers securing it. Most people don't have that ability and even though this comparison is a little tired I think it applies quite well to the difference between keeping gold in your house vs securing it in a bank vault (for example). That said, you have a point about centralized exchanges but there's a reason why banks don't run off or gamble (FTX) with customer funds - regulation. I think it's clear from the FTX situation something closer to "bank-ish" regulations are coming to centralized exchanges which only tips the calculus further here towards centralization. So, as is often noted, crypto in general is marching closer and closer towards centralization and consolidation which history has demonstrated is almost always naturally the case.