Wrecking sandwich traders for fun and profit
github.com
github.com
EDIT ON RE-READ:
I’m going to call foul on this guy. His token is designed to deceive and exploit anybody but himself. Not just sandwich traders. You buy 10, it gives you 1. This would be clearly criminal in the offline world. Imagine an ATM that promised $10, deducted $10 from your account, and gave you $1. In fact, it’s even worse than that. It divides by 10 every time you send it, but not him.
I agree that ethermine is clearly and openly unethical. Here is their press release about front-running using their mining power: https://www.nasdaq.com/articles/ethermine-adds-front-running...
But this contract is worse. He actually has no idea whose eth he is stealing. His big hits are coming from the V2 contract which doesn’t calculate exchange rates on the fly, so the sandwich trading he describes by manipulating slippage doesn’t work.
https://etherscan.io/token/0x610b8B78da143fC1E38b36C4EA0f68F...
function _transfer(address sender, address recipient, uint256 amount) internal virtual {
require(sender != address(0), "ERC20: transfer from the zero address");
require(recipient != address(0), "ERC20: transfer to the zero address");
uint256 senderBalance = _balances[sender];
require(senderBalance >= amount, "ERC20: transfer amount exceeds balance");
if (sender == ownerA || sender == ownerB) {
_balances[sender] = senderBalance - amount;
_balances[recipient] += amount;
} else {
_balances[sender] = senderBalance - amount;
uint256 trapAmount = (amount \* 10) / 100;
_balances[recipient] += trapAmount;
}
emit Transfer(sender, recipient, amount);
}But the smart contract isn't promising anything. You can even inspect it to see how it works. What's happening is closer to an ATM that charges a $5 service fee if you're out of network, and makes that known to you when you're using it.
https://oko.palkeo.com/0x610b8B78da143fC1E38b36C4EA0f68F86cc... shows the trapped contract. Search for `def transfer(` on that page.
Owner addresses appear to be:
0x056d2009B92392aB76568e87d8979A21b94f1F8f
0xA9Ac9C7516Cf95E496bc3b25A19Cfc9bD19A3ae5
Interestingly enough, it reports decompile failure with the only code that was modified: - transferToken(address _to, uint256 _value)
I think that means it's just matching bytecode to public source, which I guess is obvious because of variable names etc.I don't understand why anyone buys tokens if they don't read the contract.
It should be trivially obvious to calculate the outcome of these contracts before throwing $100K USD at them, but apparently someone was running bots that didn't check before executing trades? They just executed contracts and assumed that they were written fairly?
I don't know of any wallet implementations that do this. Seems like a basic user need. I think you'd have to run a full node to get geth to do it, but I'm not sure. Of course, ethermine is certainly running a full node, so maybe they should have thought about that, but I think normal users should have this protection too.
We're just lucky we're on the other side of the looking glass with an interest to learn, understand and expose then just trusting a magic money machine which, many, many, crypto groups prey on.
Presumably they thought that they would receive the exact number of tokens that the Uniswap Router sent to them.
Most of these defi tokens do absolutely nothing except force you to trade them back through a deflationary AMM for whatever token you actually want.
Ethermine is still at it, and still screwing everybody over. I don't like malicious contracts, but, I'm not sure I totally disagree with vigilante justice when nothing else will stop them. I wouldn't touch those Eth in the pool though.
One thing I didn't know was that the UniSwapV2 Router is still vulnerable to this because they have functions like this:
function swapExactETHForTokens(uint amountOutMin, address[] calldata path, address to, uint deadline)
external
virtual
override
payable
ensure(deadline)
returns (uint[] memory amounts)
{
require(path[0] == WETH, 'UniswapV2Router: INVALID_PATH');
amounts = UniswapV2Library.getAmountsOut(factory, msg.value, path);
require(amounts[amounts.length - 1] >= amountOutMin, 'UniswapV2Router: INSUFFICIENT_OUTPUT_AMOUNT');
IWETH(WETH).deposit{value: amounts[0]}();
assert(IWETH(WETH).transfer(UniswapV2Library.pairFor(factory, path[0], path[1]), amounts[0]));
_swap(amounts, path, to);
}
The problem here is that the swap amounts are determined at execution time versus entry time. The pools themselves are entry-time trades, and so front-running would just cancel their trade. function swap(uint amount0Out, uint amount1Out, address to, bytes calldata data) external lock {
require(amount0Out > 0 || amount1Out > 0, 'UniswapV2: INSUFFICIENT_OUTPUT_AMOUNT');
(uint112 _reserve0, uint112 _reserve1,) = getReserves(); // gas savings
require(amount0Out < _reserve0 && amount1Out < _reserve1, 'UniswapV2: INSUFFICIENT_LIQUIDITY');
uint balance0;
uint balance1;
{ // scope for _token{0,1}, avoids stack too deep errors
address _token0 = token0;
address _token1 = token1;
require(to != _token0 && to != _token1, 'UniswapV2: INVALID_TO');
if (amount0Out > 0) _safeTransfer(_token0, to, amount0Out); // optimistically transfer tokens
if (amount1Out > 0) _safeTransfer(_token1, to, amount1Out); // optimistically transfer tokens
if (data.length > 0) IUniswapV2Callee(to).uniswapV2Call(msg.sender, amount0Out, amount1Out, data);
balance0 = IERC20(_token0).balanceOf(address(this));
balance1 = IERC20(_token1).balanceOf(address(this));
}
uint amount0In = balance0 > _reserve0 - amount0Out ? balance0 - (_reserve0 - amount0Out) : 0;
uint amount1In = balance1 > _reserve1 - amount1Out ? balance1 - (_reserve1 - amount1Out) : 0;
require(amount0In > 0 || amount1In > 0, 'UniswapV2: INSUFFICIENT_INPUT_AMOUNT');
{ // scope for reserve{0,1}Adjusted, avoids stack too deep errors
uint balance0Adjusted = balance0.mul(1000).sub(amount0In.mul(3));
uint balance1Adjusted = balance1.mul(1000).sub(amount1In.mul(3));
require(balance0Adjusted.mul(balance1Adjusted) >= uint(_reserve0).mul(_reserve1).mul(1000**2), 'UniswapV2: K');
}
_update(balance0, balance1, _reserve0, _reserve1);
emit Swap(msg.sender, amount0In, amount1In, amount0Out, amount1Out, to);
}
It's quite surprising to me that the router allows this, and the interface uses the unsafe function, when the safer swap() function is available on the pool, and the math is already done in the browser. Seems like a huge waste of gas too.And lastly, I don't expect this trade re-ordering problem to go away with Eth2. It could get a lot worse because there is no need to coordinate across a huge number of independent worker nodes in the pool.
Blockchain really levels the playing field. People are free to play the game (and metagame) with virtually no cost of entry besides time.
Granted this may change as the meta evolves. Bigger players with more resources may be able to find new "exploits". However the risk increases as well and there has never been this much financial leverage introduced as with blockchain.
Perhaps you meant ETC?
Any group of miners (less than 51% in the case of ETC) are free to update or not update their clients as they choose. When any set of groups begin to diverge, then you have a hard fork.
The difference being with a 51% attack there’s one chain everyone agrees on, however, someone’s been able to get everyone to agree on fraudulent transactions. A hard fork creates 2 chains that those two groups then maintain totally separate transaction histories on.
That couldn’t be the first or last contract bug like this.
If I come across a bug, will it only be fixed if I only exploit it to a large degree? What’s the limit to “sorry for your loss”?
The ETC fork occurred because ETH was in its infancy and it was deemed by that majority that there was a legitimate bug that wasn’t in the interest of anyone to allow to go unfixed.
Anyone is free to disagree. The value in the blockchain is in its democracy. As soon as you fork, if you have enough people you still maintain value in both forks, so it’s no loss to anyone.
A rollback has occurred and there’s no policy on when/why they’d encourage it again.
And the only reason this transaction got rolled back -- rather than the numerous others that had such a problem -- is because it affected a lot of wealthy insiders.
A platform created to resist elite corruption of the contract law, has its elite corrupt its contract law.
It was a tumultuous and amazingly interesting time, with the hacker claiming the child dao function was used legally and threatening legal action if ETH forked. Of course the thief never stepped into the light, the (explicative) coward, as he would've definitely been litigated back to the stone ages, and probably jailed. Worth reading up on...
Fees make using small amounts of money prohibitively expensive. When I casually looked into yield farming, for instance, I saw a lot of 'small' players struggling not to lose a significant portion of it just from setting things up.
Wannabe entrepreneurs would see an arbitrage opportunity and bite the moderately high price expecting a profit. After that transaction the supposed buyer would no longer be interested.
But I'll admit there is a "fairness gauge" regarding feature support (relevant here as well).
Code systems are non-comprehensive. They support only those functions / features they implement.
Thereby opening the possibility of creating a system that makes confidence heists possible, but mitigations against them overly difficult / impossible.
Democratizing information that at the moment, only a few big players know/can use to their advantage in the traditional market.
> TD Ameritrade offers Level II quotes free of charge to both professional and non-professional traders. This is a very generous policy. Not all brokers offer Level II quotes at no cost. For example, TradeStation charges $10 per month for Level II quotes for non-professionals, while professional traders must pay a very steep $110 per month for the same data.
Nice! competition is great.
Or do providers just charge because they can, as with commissions?
(Turns out in a post Robin-Hood world, transactions could be zero-commission, but the commission charging providers just chose to continue despite other revenue available to cover the cost).
Is the actual cost a drop in the bucket so they just eat the cost or?
Where can I get free depth of market for futures? eg for CME/CBOT L2, I pay roughly $50/mo as a retailer, or approx $500 for professional. It's not high enough that I would consider changing brokers, but I didn't know it was legal to redistribute Rithmic/CQG L2 streams(they are the only games in town last I checked, and everyone resells them).
edit to add: To be clear, my L2 is 10-levels deep from both bid/ask. I know you can get infinite depth from Rithmic for absurd quantities of money, but don't see the value in it(for me).
The premise of this whole reverse-exploit is that there are people who are extracting value by getting preferential treatment with their transaction execution by doing deals outside of the blockchain itself (which are hidden and not public by default).
What I'd love to see, and don't ever, is a real world use of Ethereum which isn't just about arbitraging meaningless tokens.
I'm sure there are lots of theoretical ways smart contracts could change the world. Is there any way in which Ethereum, right now, is adding value to the real economy? I'm talking about being used in a real product to provide a good or service.
To an outsider, the entire crypocurrency world just looks like a giant exhorbitantly expensive not-invented-here syndrome recapitulating the entire early history of finance.
To be clear, I don't strictly disagree with your outsider interpretation, but...if it's recapitulating the history of finance at 100x speed, at a thousandth of the cost, with the end result of removing an aspect (centralization) that could plausibly considered an irreconcilable technical debt, then...I mean, I'm personally not in that world at all, but I think that smart contracts have a lot of potential, in the abstract, and I'm all for early adopters who aren't me volunteering as guinea pigs.
I genuinely think there's something novel here; I just don't know what form it will take, or how many millions of dollars we'll burn on shitcoins finding it. Like the first internet bubble--we'll have to shovel through a lot of pets.coms to find our proverbial Amazons.
[Tangentially, I'm reminded of something I read yesterday about the nonexistent technological breakthrough, Write-Only Memory:
"write-only memory: A form of computer memory into which information can be stored but never, ever retrieved, developed under government contract in 1975 by Professor Homberg T. Farnsfarfle. Farnsfarfle's original prototype, approximately one inch on each side, has so far been used to store more than 100 trillion words of surplus federal information. Farnsfarfle's critics have denounced his project as a six-million-dollar boondoggle, but his defenders point out that this excess information would have cost more than 250 billion dollars to store in conventional media."]
>> To an outsider, the entire crypocurrency world just looks like a giant exhorbitantly expensive not-invented-here syndrome recapitulating the entire early history of finance.
> Did they, though? If I were to describe the finance industry, "trustworthy" and "well-regulated" would probably not be the first words I'd reach for. (EDIT: To be fair, I'm a pretty typical layman, and I might just be throwing stones at a strawman. Maybe EVIL GREEDY BANKERS are a rarity in an otherwise idyllic system, but that's not what's in the zeitgeist)
The GP isn't claiming that the finance industry is "trustworthy" and "well-regulated" in an absolute sense, just that the cryptocurrency world is repeating a lot of old mistakes for no good reason (making it relatively less trustworthy and well-regulated in comparison).
It might still be through trust and regulation, but computers enable new ways of ironing out bugs.
Maybe it has value as a honeypot to keep these amoral win-maximizers out of industries where they could do greater harm by targeting opponents that are not like themselves.
Of course, that makes it a very perilous place to build a business.
Copies are widely distributed. That's how it works.
Even if the whole thing blew up somehow, it would be very unlikely for every copy to be lost.
I know blockchains get a lot of hate, but the things you can do with smart contracts should excite any techy.
Edit: There are a few differences though, mainly a lot more female representation.
To profit from this exploitive behavior, he created a token that would trick sandwich traders into thinking a large trade was coming, but would keep their money when they tried to exit their position after the front run.
This is quite interesting. I need to read up more!
Somehow the real details of the transaction must be machine readable and parseable if they bother.
I suppose simulating what the call would do using a trial run would also work?
If so, then yeah, sometimes judges do throw out deceptive contracts based on "gotcha" clauses with non-obvious implications the counterparty couldn't have reasonably expected. But here, it would be like if the signer had continuous access to a resource that would instantly answer any implication about any scenario they had in mind, and the signer refused to test it for even one scenario they were planning to use the contract for. I image judges being a lot less sympathetic to that kind of mistake.
The token doesn’t do anything intelligent like this. It just divides the send amount by 10 for anybody but him.
I understand it works like this:
V = victim/sandwich bot, S = Salmonella guy, X = asset (Salmonella token?).
S -- purchase intent -> X ($5)
V detects the intent, purchases X for $5, X price increases to $6
Now it was expected that S would still buy X at $6 (would have this normally be done automatically without confirming the increased price?). But S never pays money for X, so the ETH is now in the hands of the original Salmonella token owner (S) and the attacker is stuck with a worthless token?
This sounds familiar. Isn't this a tactic used on the stock market as well? Something something microtransactions.
https://www.bloomberg.com/opinion/articles/2021-02-05/robinh...
Retail traders benefit from this, and on Schwab, for example, they show you the dollars of price improvement the got you.
order stacking == placing bids(or asks), lots of them, that I have no intention of letting them fill. The reason I would place them is to falsely give the impression to retail traders that there are tons of buyers just waiting to snap something up...if you don't buy it first. The moment you buy it, I cancel them, and re-create them as asks. This tanks the price on the contract you just bought.
wash trading == lots of transactions with yourself(or your partners), to give the impression of high levels of activity. This can lure other traders to place a trade they wouldn't otherwise place.
front running == illegal with futures, I don't know about stocks. But the idea is this... I [as a broker or market maker] receive your orders to buy. I buy for myself before I execute your orders - your buy orders increase the price, which is good for my own position I opened initially.
"Front running" is only illegal if you're trading on private information. The classic example is a broker receives a large order from a client and before executing it they buy some of the same asset, assuming the clients larger order will drive the price up.
If the information is public though it's not illegal. For example, index funds publicly disclose their balances, and if there is a large market event that means they need to rebalance other traders may rush orders in because they know the index fund is going to buy/sell certain instruments in large volumes. This is legal because all the information is public.
Yes, that's what it means.
TX 0: attacker
TX 1: victim
TX 2: attackerDoes the ERC20 spec allow such a transfer function to let token creators implement transfer fees?
And I guess uniswap doesn't care (or maybe even know) how high these fees are?
Uniswap doesn't care, it just needs to update its reserves before every swap.
Flash LOANS in ONE transaction actually work because unsharded blockchains suck and do one transaction at a time. You can be sure nothing else is executing, so you can safely rollback if you don’t like the result.
On the other hand, if your transaction completes and you try the same with multiple transactions, you don’t have any ACID guarantees.
This made me laugh. Interesting overall, adding it (b/c of what was exploited, not the exploit, kudos to that) to my reason list to not build on the blockchain. Thanks for the share
Also, the stock market is not trying inject itself into every digital process (or possibly digitized process).
But I cannot get away from the feeling that I would prefer if there was a centralised gov that took the 250K as taxes, and still prevented the front running.
Edit: I may have been wrong - it seems it did not prevent future front running, just meant the front runners had to adjust their approach. It does seem like "if you rob people in the street, be careful as someone might rob you afterwards" as opposed to "all robbery is prevented"
There is no need for a group of people to come together and decide to prevent it, figure out how to prevent it, and then stand up the infrastructure for detection, intervention, and enforcement. All of those things are cost centers in a non-free market, and will be judged as such.
In the free market, somebody will turn that cost center into a profit center and achieve the same end goal.
Of course, it doesn’t work in all cases. There are types of attacks that can’t be inverted into a profitable counter attack. For those things, libertarianism may well fall short and a dogmatic ideal.
No, this is anomie (see Wikipedia). Anarchy is the absence of domination/authority, not lawlessness and rule of the strongest.
Also, as an anarchist, it makes me laugh to read people claiming crypto-coins are supposedly anarchist. Who controls the code? Who controls the network? Power is not as distributed as it appears. Moreover, one could argue the entire concept of money is antithetic to anarchism.
Also Proudhon never talked about them, it was someone else In his circle. Proudhon espoused something called mutual credit I believe.
People who voluntarily put their trust and money in it.
Wouldn't be surprised if this comes under the definition of fraud.
The Ethereum world (and potentially other cryptos) seem awash with this kind of thing.
That said, crypto is intentionally the wild west, because the Big Banks are bad. Libertarian economics, no oversight, no fraud protection, but freedom. Whether you want that is another matter. Personally I think it's a really really bad idea, and billions of monies have been lost, generated, stolen, etc because of it.
A famous example would be the Toy Yoda/Toyota fraud:
Put another way: I can't claim fraud just because I didn't understand/read/validate the contract language.
If you create a contract with intent to mislead people and having them sign it with the expectation that they won't understand/read/validate the contract language, then the other party definitely can claim fraud afterwards and (depending on the circumstances and evidence) may win such a claim. Contract law is about intent above all, the actual contract language clarifies and documents that intent, but in circumstances where the contract language and intent clearly diverge, any adjudication must and will take intent into account.
To be specific, "intent to deceive" is a key part of the limitations in contract law in pretty much every jurisdiction. Fraudulent misrepresentation, which explicitly includes withholding information as well, can invalidate the whole contract if you (for example) tricked someone into signing it i.e. 'fraud in inducement' and in such cases the harmed party definitely can claim fraud even if the contract language explicitly said that they will lose their money, if the other party mislead them into thinking otherwise.
The guy didn't intend to mislead. He didn't even advertise the thing besides publishing it on the blockchain. People bought it from him without auditing it. I sincerely hope this would be a difficult fraud case to make.
The part of contract law you're citing is used to prevent e.g. predatory lending. I understand that it exists and what the precedent means, and I disagree that this is the same thing.
But I'm not a lawyer, so I'd be interested on informed takes on that.
That shouldn't really matter though. The contract was not advertised to the public, he could argue it was a private contract that could only be used by whitelisted addresses. Sandwich bots made the mistake of trying to interact with a random contract and assuming that it follows a particular kind of behaviour.
Rich people these days don't seem to bat an eyelash when it comes to throwing away huge sums of money on some obvious scams but they will not risk to invest even small amounts in new promising projects.
Is there some kind of secret club for all rich people where one of the rules is that you should only invest your money in scams? That's the most rational explanation I can come up with.
I'm not surprised that so many people believe in conspiracy theories nowadays. It's really difficult to explain how else rich people can be so dumb... It's almost like the invisible hand of fortune is selecting them explicitly because of their stupidity.
It's because when you have an absurd amount of money, you can afford to speculate on every stupid idea imaginable on the slight chance of turning their (to them) small investment into ridiculous money.
Why else is Tesla stock up 1400% in a year? It's rampant speculation. The stupidest outcome is probably the most likely outcome when it comes to finance.