SafeDollar ‘stablecoin’ drops to $0 following DeFi exploit on Polygon
cryptoslate.com
cryptoslate.com
I simply don't think it's possible for human beings to write good enough software for smart contracts.
Although neither of these things will actually help if your contract gets exploited before you can push a fix.
You can make powerful systems with simple correct independent components. You can not make complex secure monolithic systems. It gets even worse when you look at contracts with delegation.
The problem with most "smart" contracts is they have abstractions, delegation and scope creep.
You'll potentially have less of a chance for contracts to be exploited (at least compared to what we have now).
That said, you can't protect against infrastructure exploits as easily, mathematically flawless program or not.
My former professor (RIP) oversaw the formal verification of the F-16 computer software and it still had significant bugs in the end where the specification itself was incomplete or in error. And that was a multi-year, team-scale effort. No one is doing that for smart contracts.
The key is that the contracts need to be minimal and analyzable, so its ~100 lines of code you can manually analyze. Documented separately all the edge cases, or ideally removed through good design so they simply don't exist. A bunch of problems I've seen in the real world of crypto are annoying edge cases that you can fix with an if statement, or ideally change the design to remove them completely. It's actually a surprisingly hard space because you're trying to make terse, complete and secure code.
In normal web/systems programming you have layers of security; internal services, external services, firewalls, access controls, vpns, security by obscurity, etc etc etc. In crypto you have none of that. Everything is 100% public, the code probably should be published, or else it is trivially decompiled. If there is a problem someone will find it if there is value in finding it.
I have a lot more trust in that kind of product than in a product where contracts are subject to interpretations by humans which may or may not be reliable. It's one of the reasons why people incorporate their companies in Delaware, there are well known case law, so you know in advance what to expect from the justice system. Predictability is an important part of a contract, I trust a well inspected and battle tested smart contract much more than a human enforced contract. That said, not everything is suited to smart contracts, but many financial applications are.
It's a fair point that any easy-to-find bugs in large, time-tested contracts will have been found. Any medium- or hard-to-find bugs also will probably have been found. But there might still be a very-hard-to-find bug lurking; and given the value of finding such a bug, people might look hard enough to find it.
In other words, the same scale that ensures there is no low-hanging fruit, also provides the incentive to pick high-hanging fruit.
> I have a lot more trust in that kind of product than in a product where contracts are subject to interpretations by humans which may or may not be reliable.
This is a valid concern, but it's also extremely well-understood at this point; we have centuries of global-scale experience with traditional financial and legal systems. They're certainly not flawless, but it's rare for gigantic new flaws to emerge. An important point is the existence of mechanisms for rolling back bad transactions and challenging / appealing flawed decisions.
The core issue is the inherent asymmetry where 1 person finding 1 bug can destabilize giant systems. Even if these systems where hundreds of years old that doesn’t actually mean much.
They all are until they aren't.
I'm doing ICO next week, if anyone wants in.
The collective is incentivized to continue being fair because if they weren't, nobody would use their coin, and the rewards issued to fair lawyers would be worthless.
Everything involving code has bugs. Bugs aren’t a reason not to use code. Bitcoin isn’t a problem for the very small fraction of the population that use it. Bitcoin users are super rich tech workers and finance guys, by and large.
The people hurt most by Bitcoin are all the people who don’t use it. It benefits the ultra-rich at great expense to the other 99% of humanity.
Unless you don't believe the narrative that Bitcoin stores/grows wealth very well, in that case...poor people can simply not use it.
Perhaps you mean to say that the distribution of coins is uneven. That's true, but not a problem Bitcoin aims to solve or can solve. Bitcoin is fair, the same rules apply to everyone. If a billionaire has a 1,000 Bitcoin and I have 0.1 Bitcoin, we both win or lose based on price action equally, relatively speaking. That's as fair as it gets. With Bitcoin, having lots of coins doesn't give you any new free coins, unlike fiat money.
The environmental destruction is overstated and rapidly changing as we speak. Soon the vast majority of mining happens based on renewables with a specific focus on stranded energy. And this isn't a vague promise, some 60/70% of the hashrate from China, which include most coal-based mining, is being wiped out in just a few weeks.
Fiat money doesn't give your free money either. You have to invest in something - and there's plenty of fee-limited options in the cryptocurrency world as well.
> And this isn't a vague promise, some 60/70% of the hashrate from China, which include most coal-based mining, is being wiped out in just a few weeks.
Because the price is so low, not because they want to help the environment. At the next peak everyone will be happy to burn whatever fuel is cheaper than the payout again.
The impacts of climate change, which Bitcoin unquestionably contributes to, skew significantly towards poorer countries.
And the consumer protections built into the regulations around fiat currencies are there to protect people who can't afford teams of accountants and lawyers.
Ethereum is working on moving to proof-of-stake within the next year, which completely removes its need for energy-intensive proof-of-work mining.
> “One of the biggest problems I’ve found with our project is not the technical problems, it’s problems related with people”. - Buterin
https://tokenist.com/buterin-explains-why-ethereum-2-0-upgra...
Given that the reasons are political rather than engineering in nature, there's no way to put a timeline on them.
Edit: might have the details confused about above point, but the general thrust of things is pretty clear. https://foreignpolicy.com/2019/03/19/neo-nazis-banked-on-bit...
I also don't think it matters and there is no consensus to do the same thing any longer.
The explanation for why they did it was because the transaction would have a very large percentage of Ether in the hands of one actor who would eventually be able to alter control of the future Proof of Stake network. If it was any other asset they wouldn't have bothered, and now much larger $ values are captured from people without any notice or fanfare. They didn't know it would be 7-9 years before Sharded Proof of Stake or the Beacon Chain would exist, and its likely that the means did justify the ends at that point in time as many of their supporters and institutional supporters had their funds in that contract.
Without that I think the best you could do is model your program in some other formal verification system and then convince yourself that your model matches the actual contract.
It's massively more expensive, so you'll see it used in aerospace, railway signalling, some vehicles (trains, components of some cars), power generation and distribution, industrial processes.
Sometimes also in consumer products that have long warranties and are extremely expensive to recall/repair, like washing machines.
Just yesterday was a post on a formally-verified C compiler, used by Airbus (and others) [2]
This may interest you: https://en.wikipedia.org/wiki/Rice's_theorem
Sure. And if you look at sufficiently small-scale pieces of software, there is probably a lot. As scope of a software system increases, the probability of bugs rapidly approaches unity, though.
Ensuring your requirements are correct is possible, but often hard. Ensuring your software meets the requirements is possible, but often hard, especially if you need to consider hardware failure or defects.
Only in academia
The mechanics of stable coins is really trivial and thusly should be trivial to implement and validate. Unfortunately it is not, and it is sad that the hype and investment rush inside the broader crypto field does not foster languages and platforms that actually are suitable for the few realworld use cases that exists inside crypto.
Ethereum is pretty unstoppable, but unless you use a contract proxy, your contracts are immutable and bugs that can be exploited will be exploited.
I think he was going to college for computer science and then switched to law. Last I heard from him, he was running for a judgeship.
Point is not whether my bank is malicious, but just that there's bugs everywhere and we'll have a few big "rug pulls" as this defi stuff is in prototype phase, but it will eventually grow mature. A flaw in Windows can lead to incredible losses too, but we've grown past that.
2. We have a general AI exception handler called a pilot.
3. Many of those systems have hardware redundancies, so even if there is a bug, hardware can stop it. A fuse might blow instead.
And you get a refund for your plane ticket if you reach your destination, but if you don't, whoever figured out the trick to crash the internet-connected plane gets to keep all the ticket money. And that could be the same person who wrote the plane's software.
The incentives to break those other pieces of software are different.
Very few people are incentivized to hack planes to crash and kill people. Even fewer are incentivized to hack the space shuttle. Not to mention those pieces are rarely exposed on the public internet, or have connectivity at all.
But massive amounts of nigh-untraceable free money? Ton's of people are incentivized to go for that.
It's hardware with no joysticks for humans to adjust. It just happens to be hardware that's implemented in code.
The trade offs in functional languages seem to well suited for the world of smart contracts, that I almost think of smart contracts as the retro-active problem that functional programming solves. Granted, I appreciate functional programming and good code enough where I wish all code met the standards required for FP, but the real world is much messier; when large amounts of money are so directly on the line though I think its obvious the compromise is worth it.
Smart contracts are like launching a rocket - you don't optimize for development time. FP forces a bit more safety.
What you do get in contract disputes where specific wording matters is in edge cases where you might reasonably assert that both parties wanted (and agreed) A or not-A for some specific situation as part of the negotiation, disputing where exactly some boundary lies - but not for the core parts or complete reversal. On the other hand, automatically enforced "smart contracts" don't make such a distinction and any typo can reverse the core meaning of the contract as well.
Contracts have always had a healthy dose of manual debugging that have allowed them to function.
[1] The idea of "a reasonable person" is used heavily in the US legal system and has problems but it also has upsides.
Not a lawyer here but I’m guessing.
Not all legal loopholes automatically deprive you of all your savings. Intentional loop holes only go so far before consumer protection or other entities overwrite it. And if both parties are in agreement and in good standing you can figure out a way to find a reasonable compromise.
With a smart contract, there can be no negotiation and attempt at reconciliation. The price here will never recover from $0, so at a single point in time $248,000 was transferred from bag holders to beneficiaries.
I agree, but think it's fixable. I believe we have missed a natural platform in between binary notation and computer languages.
I believe there is a 2-D dimensional binary. Simply using a grid (with an array of cells forming a line, and lines stacked on top of each other—a spreadsheet basically), we can drop *all* syntax characters. The only thing you have is your cells and your semantic words.
Not only does this make tooling and languages much simpler (which will have big network effects), but you gain new fundamental complexity metrics which may turn out to be incredibly important in designing simple, bug free systems.
I personally really like crypto but it's not one of my main interests. I have been working with some folks in the space on using these ideas to build a new type of blockchain from the ground up. I bet that the biggest blockchain in the future will be a higher dimensional one, based on Tree Notation or derivatives of the core ideas.
I fail to see how this helps.
The reason why bugs crop up all the time in software isn't because syntax is confusing. It's also not because semantics is confusing--plenty of bugs have perfectly clear, well-understood bugs. The problem is that we as programmers don't think about how our software could fail. We don't ask ourselves "could this multiplication overflow?" frequently enough. We don't look at code and ask "who made sure this pointer points to valid data?" We believe that there's no way the price of an affiliated token could ever reach exactly $0, so we assert that it can't happen.
The way you avoid these bugs is to just simply make it impossible for the system to get into certain states. It's already the case with statically-typed languages that it's impossible to pass a string to a function that expected an int. If you design your API right, you can make it impossible to get an index into an array that is out-of-range (although this is way too rarely done). But, even then, you will still find people who will confidently use the escape hatch to say "this string is clearly UTF-8, I know it is from outside experience, so don't bother checking."
Now if dai, usdc or usdt had failed, that would be a big deal.
The fact that some people think a $250,000 heist followed by the collapse of a half a million dollar stablecoin is "not news" underscores how ridiculous the cryptocurrency space is right now.
Title of leaderboard, REKT.
It is interesting that these exploits still happen.
The “Dai” peg did break — both in early 2020 [1], and a few days after launching. DAI’s now 60% backed by Tether like instruments. It’s basically a strictly worse version of Facebook’s Libra, assuming Libra weren’t crippled by state regulators (Libra is now Diem).
Every major algorithmic stablecoin has imploded at least once in times of market volatility. Preston Byrne has written a wonderful article explaining why the concept is clearly unsound and theoretically flawed [2]:
When you make a “coin” which is in form and substance a repackaged
exposure to another underlying cryptocurrency, as Dai is simply
repackaged Ether, and Basecoin is simply an abstraction of demand
for “Base bonds,” and peg that exposure to some meatspace asset
like an ounce of gold or a U.S. dollar, a sudden move against the
underlying collateral – in this case, 12% – can trigger a sell-off
that breaks that peg, and breaks it hard.
It’s perhaps a testament to the frothiness of the cryptocurrency markets — or the sheer number of low information investors — that this concept doesn’t die. No matter how many times the “stablecoin” peg breaks, no matter how many times it costs investors millions of dollars in losses, it just refuses to die. If there were any justice in this world, the concept would’ve been fundamentally discredited years ago.Unfortunately, when stablecoins break, they get propped up by biased investors in closely linked pseudo equities who limp the imploded stablecoin along by injecting more capital and then powering on the hype machine.
[1]: https://blog.makerdao.com/the-market-collapse-of-march-12-20...
It's valid, healthy and even recommended to have significant skepticism regarding crypto. I think that's fair game, as about 90% (or more) of coins are pump-and-dump schemes. Further, almost everything "Defi" is supremely risky, as they are completely unregulated, not insured, often lack liquidity, and can go down the drain at moment's notice.
Fine. However, there's a general anti-crypto stance here largely based on outdated mainstream narratives that if you truly would be literate about crypto, could only laugh at.
So this community is not "very literate", it doesn't even past the basic smell test.
Can you be specific about the narratives you're seeing on here that you are laughing at?
https://bitfinexed.medium.com/tether-is-setting-a-new-standa...
And if you believe USDT has been 1:1 backed by us dollars for its full history - dream on. If you believed they would actually get audited when they said they would - hahah.
Nothing of value is backed in our world. If a mere 7% of bank account holders go to the bank to collect their money, the bank collapses. They don't have your money, it's not there.
If all owners of gold (gold value papers) today claim their physical gold, it can't be done. There's 400% more value paper compared to the total supply above ground.
If all owners of Apple stock today decide to sell their stock all at the exact same moment, they won't get out the full market cap. Because the entire thing crashed before that. But that won't happen, because the exchange will simply stop the trade.
Which is the same thing crypto exchanges do when things get too heated.
Meanwhile on boomer news
> A single web server caught fire somewhere in Bolivia, is social media over? (+20000 points)
(Though I think it's obvious that USDT is a scam.)
If there are any appropriate places on the internet for news about a new collapsed piece of DeFi tech, HN is unquestionably on that list.
How is there no discussion about FRAX, Maker's DAI, USDC, CRV's 3pool token, Liquity's LUSD, and so many other interesting projects?
The interesting stuff happens when they fail.
And you're missing projects that aren't pegged to the dollar, but instead have dampened volatility floating price targets — like Reflexer and OlympusDAO.
It's a rich, beautiful corner of a rapidly growing space.
Some are via reserve dollars, some via collateral based on an oracle, some via collateral not based on an oracle, some are tightly coupled, and some are a bit looser.
Some are more centralized than others. Some rely on governance more than others. Some allow themselves to drift further from the peg than others. Some are more complex (and therefore more at risk of failure). There's actually quite a lot going on, and I personally find it pretty interesting, but yeah, at the surface, it's a bunch of coins that trade fairly close to $1.
You find stablecoin's failures interesting. Crypto enthusiasts (which admittedly are a tiny fraction of the people holding cryptocurrencies) do too, while at the same time finding the pegging mechanisms interesting as well
What else can you suggest in order not to prompt this response?
These artificial stablecoins that attempt to get clever with algorithmic finance and smart contracts are interesting because they inevitably collapse when someone pokes the system enough to make it unstable. The strangest part is how it happens over and over again yet people still put money into these flawed algorithmic stablecoins anyway.
- In some countries, swapping crypto to stablecoin (another crypto) has no tax implications whilst swapping to fiat does have consequences.
- For big account holders (not me), stablecoins are the only way to put gains on "dry land". If you win big on exchanges, you can't take it out at once, there's withdrawal limits. It can takes months to get it out, years if really rich. During all this time, your gain may finish if you'd hold it in the original coin, so stablecoins secure your profit in the meanwhile.
Fascinating? No, but definitely important.
Now do MakerDAO.
DAI is not in this category. It is backed by over collateralized loans in multiple currencies, and maintains peg by creating and burning coins in a smart contract.
Even going with your analogy, it makes no sense that this was #1 on HN. Unless it's also true that HN is just weirdly out of sync with crypto.
The hype drives the coins but the only people getting rich are those in early then motivated to tell people to buy. It's a decentralized pyramid scheme and even those work some of the time.
Until the next financial crisis maybe?
It's a thing to accept and be entertained by I guess. The stunning lack of self awareness over here is legendary though.
People come with their Argentina and Venezuela inflation and capital control stories and I fully agree with them but it feels like that is in no way justifying the hype around cryptocurrencies. Average people just want the MLM fueled number go up speculation and that is about it.
Within the larger space of crypto are the "degenerates" and "ape investors". That's what they call themselves. They're fully self-aware of their unhinged choices and behavior. They embrace it and laugh at it.
This is important to understand. They aren't uninformed or gullible. They know they're crossing a field of land mines and decide to go for it anyway.
I'd like to figure out how to build a cryptocurrency that is useful for conducting actual business but toxic to investors.
An economy that lacked parasitic middle men would be a good thing for the status quo to have to compete with.
Yes, perhaps a currency that you could trade quickly and cheaply all over the world, with 2-3% reduction in its purchasing power each year so that no one has a reason to hoard it or speculate. I wish we had the technology to create such a currency./s
USDC is a stablecoin, and there are plenty of others out there.
Are you talking about selling USDC to another baghholder? Thats not 'redeeming' that's trading.
Much more likely a smart contract somewhere fails than USDC/Gemini (the only two I know that do full audits to ensure 1:1 dollar backing, ignoring USDT). There just isn't much risk there, hence there not being much (any) profit trading stablecoin.
That peg could certainly fail, and you could certainly argue that there's something not quite right about the practice, but it was made up to legitimize tokens long before crypto.
I do agree that some stablecoins are scammy in nature, but others serve an important purpose and that purpose is to allow individuals and enterprises to navigate doing business in crypto despite crypto's high volatility. Where is the deception in that?
An extreme anti-establishment view is driving most crypto enthusiasts into opting for tech that isn't going to remain in everyone's interest for too long. These lessons started with DAO.
It's almost like a sort of willful ignorance of division of labour and the concept of pooling risk.
If you are working a w2 job and paying taxes and paying your mortgage / auto loan... crypto doesn't really help you.
Blackmail? Awesome. Buying illegal substances? Awesome. Gambling? You got it...
Sure, the vast potential of reward justifies the added risk. But I'm also not in the US, I'm not rabidly anti-government, and I don't want to store my money under my floorboards. Good, old-fashioned, regulated banks serve a valuable purpose.
Some of crypto's loudest voices are young, college-aged people who've recently read Atlas Shrugged or Catcher in the Rye and are certain that they will never be the ones to lose their keys.
Having a middle man doesn’t ensure safety. It just means that you have someone to blame if it all goes wrong. And even if you blame them, they most likely won’t see any negative repercussions anyway.
With billions being syphened from African countries, it's hard to make the case that crypto microloans are a net good for the continent.
Sure it does: moving gold and commodities between countries in non-mutually-friendly regimes, very much resembles crypto.
Fiat finance is a system of contract law built on top of a de-facto "state of nature" of irreversible no-arbitrator commodity transfers. It exists in places where people can agree on who the arbitrating party should be. It does not exist outside of those places. It especially does not exist between powers that are actively at war.
Cryptocurrency platforms are, at a base layer, a digital equivalent to the commodities-transfer "state of nature." Many crypto platforms also have the mechanisms within them to build fiat finance systems atop them. (The keyword to search here is "security tokens".)
I personally think that's for the best. Build something that can simulate all the kinds of finance the real world operates on, rather than only some.
Most people, most of the time, if they touch crypto at all, should be doing so using one of the fiat "layers" on top of crypto, rather than the commodities-transfer base layer. Just like people should be buying things using credit cards, rather than by sending gold bullion in the mail.
But if the fiat layer were the only layer, then you'd have a system that only worked where contract law works, which would be no better than the existing fiat ecosystem, in the sense that it wouldn't enable many of the use-cases that cryptocurrency enables. Chief among those use-cases being securely transferring commodities to people in countries that your own fiat regime's financial infrastructure refuses to deal with, for them to then convert to local fiat money. (See e.g. the saga of this YouTuber https://www.youtube.com/channel/UCAPrhJwVweWZA8GEPoClSdw trying to pay his employees/contractors in Nigeria, Liberia, etc. for their work.)
Ah, the "I want to break laws" use case for cryptocurrencies.
> Sure it does: moving gold and commodities between countries in non-mutually-friendly regimes, very much resembles crypto.
Parent is talking about a legal framework and yet your counter-example is a transaction between two jurisdictions/parties/legal entities that are in less-than-legal agreement with each other. Apples to oranges.
Also, I'm quite certain you and parent interpret "the world" differently. You seem to interpret it in the sense of a pre-formalized economic framework society. Whereas parent (with whom I side with), use the term "the world" to refer to that sector of society with a codified economic framework.
> Many crypto platforms also have the mechanisms within them to build fiat finance systems atop them. (The keyword to search here is "security tokens".)
That might very well be the case but parent's argument is that our legal economic system is not purely algorithmic. Crypto might have features that are analogous to our current fiat systems but those features do not describe the whole fiat system; it misses some features (or "bugs", depending on how you look at it).
To paraphrase parent's statement, having someone able to override transactions is a feature of our existing systems, for better and for worse. Conversely, a system without this arbitrator has pros and cons too. You pick your poison.
Unless the things have been destroyed, the trade can be undone
The parent comment's real point was that the world isn't run algorithmically. An enterprise which tries to smuggle goods may not be able to reverse transactions if they transfer too much, but they should be able to react to an overcharge and shut down operations before they lose everything. Or they should be able to stop a shipment before it reaches the border. Or they should be able to change the rules of their trade if government rules change in between.
That's the kind of stuff smart contracts tend to ignore or forget about. They have little flexibility in them in a world that's constantly in flux.
The existence of flawed software does not mean that it’s impossible to make reliable or trustworthy software. If you’ll never trust your money to a smart contract no matter how vetted, then I’d recommend you never fly a plane or store personal data in the cloud.
I think you're missing the parent's point, which is around the world running on legal contracts.
It's that legal disputes are settled non-algorithmically. If someone harms you through fraud or other illegal action, a judge can order a transaction reversed, etc.
None of this has anything to do with algorithmic trading, or using algorithms in finance generally for efficiency.
It also doesn't mean that it is economically feasible to make 100% reliable or trustworthy software.
> If you’ll never trust your money to a smart contract no matter how vetted, then I’d recommend you never fly a plane or store personal data in the cloud.
Isn't vetting of contracts the opposite of having a no human touch algorithmically run world?
And who does the vetting of the code? Who does the vetting of the people the vet the code? Who does the vetting of the people that run the code?
To have your money in smart contracts right now is tantamount to seeing those 737 max plane crashes in the past, then plugging your ears with your fingers and saying I can't wait to fly on a 737 max tomorrow. It's kind of a mess out there right now [1].
[1] https://cryptoslate.com/binance-smart-chain-sounds-alarm-ove...
Algorithmic stablecoins are mostly in category "c" so far. There is no human failsafe and there is no predetermined process that can shape the algorithm.
Nope. Regulations require human supervision, in some way, of that trading.
Furthermore, those trades have exactly the kind of non-algorithmic softness that omk talks about: if an algorithm makes a trade which is obviously incorrect, you can ask the exchange to bust it.
... but when that stuff goes wrong, which it does, we don't just say "geez that's too bad, the code is the code".
Look at the 2010 flash crash: something like 20,000 trades were broken after discussion between FINRA and the exchanges based on how far they were from the reference price.
Similarly, I don't end up eating the entire loss if my bank's anti-fraud system mistakenly approves a transaction on a stolen credit card, because I have 60 days from the statement date to report the problem under the FCBA.
The point is that in most cases where physics is not involved (e.g. flight control systems), the real-time behavior of the systems is backstopped by processes to deal with exceptions in a slower, more considered way.
In the exceptionally rare case that something is exploited within a cryptocurrency, there is no recourse for the victim.
Are we perhaps better off for many — maybe even all — of our status quo legal contracts not working like software programs? Sure.
Is there a class of legal contracts — either already in existence, or made possible by crypto — that’d make much more sense if ran like software (with different requirements/constraints than the error tolerance you described)? I don’t see why not, and why this would be mutually exclusive with the first premise.
The whole point of crypto-like contracts is that the terms of the contract are defined solely by code. Ambiguity is, by definition, impossible.
If you remove that, why not just use a regular contract?
The execution of a contract seems distinct from is legal validation.
Think of smart contracts rather as vending machines for financial transactions. For example: You enter some crypto coins, maybe select an option and the machine returns a receipt for redeeming your investment plus some interest later.
If the machine is well designed it will forever do the same thing and, hence, be reliable and convenient. Of course, bugs can happen. But like with vending machines, you test and audit its code before deploying it everywhere.
In the same way a "smart speaker" allows for interactive and sensitivity to its environment compared to a "dumb speaker", a "legal contract" allows for arguing and bugfixing and sensitivity to its environment compared to an block chain "contract".
They should call them "strict contracts" or "inflexible contracts" or "software-enforced contracts". The smarts have been taken out on purpose.
So, is it that much of a stretch to assume that some day a significant fraction of contracts will be more algorithmic? "The best way to predict future is to create it" - unatributed.
The rest of the world doesn't want to lose millions due to an exceptional condition in a contract that wasn't apparent on audit.
That isn't how the law works, and that's a good thing.
When it comes to contract disputes you ultimately wind up before a human with hopefully decades of experience trained by a system with centuries of experience which can deploy some level of nuance.
Which is not how geeks think the legal system works. Or if they do understand it works that way they feel that it is flawed. That isn't a flaw, that's a feature.
Sometimes it goes wrong. But if you're ever the beneficiary of a judge going "yeah that contract term was always bullshit. you think you're clever, but i wasn't born yesterday. nullified." then you'll appreciate it.
Crypto enthusiasts want to defect from the system of democratic law in favor of algorithmic law.
And just because you're using a smart contract, doesn't mean that the legal system of the jurisdiction you're in no longer has an opinion or the ability to make judgements against you.
So, I agree, some of these things are features not bugs to normal humans, but to most cryptocurrency enthusiasts they are anathema. Ultimately we'll need systems that are a bit more friendly to error. It's early days though, and the technology is flexible enough to incorporate nearly any kind of system you want.
Not everyone agrees with that. Everyone using smart contracts is opting in to code-as-law - nobody who doesn't want that needs to use or touch them.
Maybe we have a similar phenomenon with blockchains nowadays... Of course there will be errors in the source code somewhere, it is software written by humans!? It is just a matter of creating another level of abstraction as a safeguard in the smart contract, maybe even with 4 eye principles...
This is a good news aggregator for rugs (exit scams), bugs & more: https://www.rekt.news/
Would be an useful reference in this ever-changing landscape, though I would pity the maintainers.
Nonetheless, I feel bad both for the people who worked hard to create this failed cryptocurrency and for the victims who suffered these sudden losses.
It's hard to write bug-free code. One way to help prevent bugs is to make languages less powerful. In hindsight, it seems that Satoshi Nakamoto's decision not to make Bitcoin's scripting language Turing complete, making all sorts of bugs impossible, will prove to be a smart choice over time. It forces applications of Bitcoin that require control flow to be executed off the main chain.
Any defi project can all themselves a stablecoin. It is false advertising to say that you will maintain the peg to a dollar if you cannot meet that promise.
If you are just experimenting or trying to get something for nothing (synthetics- created out of thin air 'backing' your stablecoin), then don't make claims that it will be a dollar.
Also, selling unregistered securities is illegal. Operating a money exchange business is a crime without license.
A week ago they had another issue.
Is it theoretically (or in practice) possible to reverse / mitigate these kinds of token transfers? How would we even think about that?
[Mr. Burns looks through a portfolio of his old stocks]
Mr. Burns:
Hmm, let's see..."Confederated Slave holdings." How's that one holding up?
Blue Haired Lawyer:
It's, uh, steady.Digital goods, meanwhile, can just be transferred permanently "into the void" (i.e. to an account without an associated key.)
So people who "agree" with the change can just insta-exchange their cash, and those who don't can keep their cash on version 1. Then you don't have bugs like this as easily anymore.
This whole thing will no go very far without something like an update system. The old C programmers would laugh their ass of at a code-once-and-hope mentality.
EDIT: And by rewrite I mean like how OTA updates "rewrite" things, have a coin-bootloader or something that takes care of it.
In fiat world, if big industry or finance makes a mistake, the taxpayers are forced to bail them out instead of allowing them to fail, because of some perceived “systemic risk” that could take down the entire national economy.
Probably not in this case as one wouldn't "liquidate" the stablecoin at merely $250k of assets ... but wouldn't this be a viable (albeit, nefarious) mechanism to defraud crypto investors ?
Not very helpful.
[1] https://safedollar.medium.com/safedollar-post-mortem-analysi...
There was a lot of talk about how secure Polygon is.
[1] https://softwareengineeringdaily.com/2021/06/02/polygon-conn...
I'm so tired of people manipulating others and telling them to throw their savings into "Stablecoins" for 5-12% APR. Pure insanity.
AMA I guess?
/S
The problem of course, is that once these contracts are published onto the network to create your new cryptocurrency token, it's very difficult (perhaps impossible?) to update them. And of course, if someone finds a vulnerability in one of the contracts and exploits it, it's game over. There's no reversing the transfer of tokens.
So to give a more explicit answer to your question, it's not a problem with Ethereum, but a problem with the contracts people are writing on the Ethereum network.
Polygon is a little different, due to its proof of stake system, where there is no "winner" and the validators (Heimdall instances) "check" the work of the actual block producers (Bor instances). It also has a slasher-like element where only one Heimdall instance needs to prove that a block is incorrectly executed for it to be rejected, so a malicious actor would need to compromise all active Heimdall instances to be able to lie.