More than 10 percent of $3.7B raised in ICOs has been stolen
reuters.com
reuters.com
Edit: Assuming the underlying ICO transaction happened in Bitcoin or similar. If the funds were wired in say, USD, it would not be able to be rolled back after 3 days or so.
No -- well, kinda. This is unintentionally hilarious because, of course, Ethereum has done just that once before. By creating a new network that picked up from just before the "fradulent" activity.
The part that might be confusing to some folks is that in order to operate a truly trustless and decentralized cryptocoin ecosystem, we have no way of distinguishing between "fraudulent transactions" and legitimate ones. They're all legitimate otherwise they'd have been rejected by the network.
I can't quite tell whether you're trying to underscore a point about cryptocoins' benefits or if you're misunderstanding the conversation.
Just in case it's the latter -- I was probably a bit too fast n loose with the quotes around "fraudulent" so I will explain in more detail.
From the article:
> Phishing was the most widely used hacking technique for ICOs, with hackers stealing up to $1.5 million in ICO proceeds per month, according to the report.
This is a kind of "fraud" which cryptocoins are not designed to thwart. If you steal someone's keys and take their money, it can't be returned to them unless the thief decides to return it. This is very much like cash.
The problem comes from decentralization. In the Real World, we usually defer to authorities when it comes to crime and restitution. The authorities come to a determination and publish their decree. This is very much centralized. Cryptocoins are decentralized and are simple automata. There's no authority that we can appeal to in order to reverse a transaction that was executed in bad faith. Part of the problem is that there's no way for the automaton to trust this authority without destabilizing the entire system.
To clarify, the network would basically be agreeing to honor the possibly already spent coins... and that isn't really going to happen at this point.
I thought they just created a new transaction that moved all the stolen funds to a new smart contract?
That's why, from what I remember, when etheruem was hardforked created a transaction from the thief's wallet to a new smart contract, and everyone agreed to validate that transaction even though it wasn't signed by a private key.
But in general the answer is no because once they have your bitcoin and cash out to cash who are you going to ask the money from? The person that just disappeared?
Since these ICOs are all running on top of some existing coin/blockchain, unless there is a native mechanism for undoing a transaction (I don't believe any mainstream coin/blockchain supports this), the only option would be a hard fork.
Side note: You'd also be impacting other transactions which have occurred after the transaction that you want to roll back. Considering how blocks incorporate the identity of previous blocks, all of the block-minters would have to participate in the roll back.
By the way, how would you verify that ICO tokens were actually stolen? In the modern world, that is normally done using a police report, but not everyone in the world is going to trust that.
And even with a police report, if the police are unable to get the stolen good back, then you're stuck. That's why people commonly take out insurance on their possessions, and why (in the United States) most cash deposits are insured by the NCUA or the FDIC (up to certain limits).
IPOs are regulated, so there isn't that much of a mess around them, and it's more difficult for people who shouldn't be investing to play that game. That's on purpose, and it came to be through some hard-learned lessons.
> If our monetary system was so good we wouldn't be in 19 trillion in debt
National / international debt is, first and foremost, a tool, and it doesn't work the same way the "regular" debt does.
> and cryptocurrencies would have no reason to be adopted
They still don't. They live as long as they get to be financial wild-west, where it's easy to get rich off fools.
> there is a reason why Bitcoin debuted in 2009 after the 2008 Recession...
Yes, because it was developed around then.
> When the government does bailouts and Quantitative Easing, this can be seen as a scam to some
Maybe, but then again taxes are seen as theft by some. We can talk about ideologies all day, but in the real world, the "traditional" system still remains somewhat suitable for running a technological civilization, whereas cryptocurrencies are not, and will not because they don't scale well.
It's too early to say anything about the economics of ICOs, apart from that people are being oblivious to their risks. Until we see a business redeeming tokens for goods or services which which cannot otherwise be procured and are improved by virtue of their tokenization, ICOs will remain closer to moonshots than investments.
Name three.
Honest question. Is there a single ICO where one can use the tokens to redeem a good or service which cannot otherwise be procured and which is improved by way of using a token to purchase it instead of cash?
I say potential case, because while the goal seems noble, so far I don't see the tokens available, and it seems the project is still knee-deep in some mathematical and technological issues around the coin itself.
Was Ethereum a scam?
Furthermore the Ethereum foundation itself has been spending a lot of its reserves on research grants and other activities that directly benefit the members without providing much benefit to the public at large. Under Swiss law it should be audited regularly however no audit had been published publicly.
So what, many early adopters and sellers of Bitcoin have done the same - and heaven forbid Satoshi decides to cash in, that person / group alone is a billionaire (on paper though).
The impression I got from the headline was that "More than 10 percent of the $3.7B raised in ICOs came from stolen funds".
"10% was stolen. The rest was spent foolishly."
On the flip side, basically this means that if you're willing to accept a 10% risk of total loss, ICOs are not a bad investment -- knowing that going in.
One solution I've been kicking around is something like an escrow + shareholder voting. It would play out as follows:
1. Devs come up with an idea, decide they want to ICO to fund it.
2. Devs come up with game plan including set of milestones with timelines.
3. Devs reach out to escrow who arranges an ICO. ICO occurs, all ether besides a starting amount is held by the third party.
4. When devs hit first milestone, they show work to holders of ICO coin who then vote on whether the milestone has been achieved. Devs have to report any coins they previously mined or held so that they can't vote for themselves and agree to not purchase any further coins in a contract with the escrow. They also have to identify their relationships with any early coin buyers for the same reason. If they get approval from their shareholders, the next batch of money is released so that the work for the next milestone can be complete. If not, no money is released or the coins are voided and all monies are returned to the investors.
The third party company would take a management fee, purchase insurance to protect against theft of the assets, and be a registered US corporation so legal action could be taken if they committed fraud.
An added benefit is that if you are early to market you could help SEC shape ICO policy (assuming it's not too late) potentially becoming a mandated gold standard.
[1] https://en.wikipedia.org/wiki/Vitalik_Buterin
[2] https://en.wikipedia.org/wiki/Decentralized_autonomous_organ...
In other words, you could come up with this really complicated scheme to verify trust with your ICO in order to win over savvy investors. Or you could just hack together a buggy, insecure ICO in a few weeks and get flooded with retail investors clamoring to get their dumb money into any crypto they can lay their hands on. Barely computer literate friends and relatives have asked me recently how they could get into crypto. There's virtually an army of these woefully uninformed "investors" to get money from in an ICO. Why the heck would anyone lose months (at a minimum) of development time to build some trust that nobody cares about anyway?
Doesn't that basically mean your ICO is subject to US law, essentially eliminating the main benefit of a "trustless transaction"?
The idea that you can have large investments and crypto backed companies without someone in the financial chain being subject to external governance is completely unrealistic. No rational investor would participate in that. Large numbers of people will inevitably commit fraud, and they have, as noted by the article.
So how is having an escrow that is subject to US law an answer to "I want to have a trustless network with no government intervention"?
At the end of the day it depends on what the goal is. Is the goal to lower the barrier to entry for new companies to raise money, or is it to create some idealistic free market? The former is possible and useful, the latter is not.
There are many other ways that an ICO could result in total loss to you. Just as a back of the napkin estimate, it used to be conventional wisdom that 90% of startups fail. I'd say that's a more reasonable lower bound than 10%.
Edit: Obviously a world without scammers would be ideal. However, I'd rather have an unregulated market than one with gatekeepers.
And for ICOs, fraud is fraud. If someone promises one thing and instead runs off with your money, the gov't will prosecute that.
What we need is a framework for users so that they can make informed decisions about what to invest in. And we need laws that make it completely legal.
Wall Street is the 1%'s point of control over the 99% and it's going down hard. Their power seemed strong in the old world but is absolutely meaningless in the face of a large scale citizen uprising.
Trying to fight this new technology will do nothing but accelerate the process, as it did on a smaller scale with P2P file sharing.