$600M taken in largest DeFi hack to date
blockworks.co
blockworks.co
Nothing has really changed at all. Innovation seems more about inventing a way to do an old thing that feels new enough to avoid legal scrutiny until a company gets large enough and the public angry enough that laws create regulatory capture.
I'm not sure if I am reading your comment correctly.
Regulatory capture doesn't sound like a desirable thing, and wouldn't do the desired regulating. What did/do you believe the definition is?
It's not a desirable thing for the public - plenty desirable for industry...
It worked out pretty well with Ajit Patel and the FCC... Or the CRTC and it's board members and adhoc meetings in bars/pubs with the telecom industry.
The stock market, oil/gas, telecommunications are all examples of industries that started as innovative with no regulation. Once established, they were regulated. The stock market got consumer protections. Oil/gas faced environment & safety regulations. Telecommunications face many regulations around zoning and providing rural and not always profitable access. In return, this regulation raised the startup costs so significantly that only the pre-existing large companies could adapt and new entrants effectively ceased to exist.
It's a bit of a tradeoff. As consumers, we get some benefits and the company gets their existence & rent guaranteed indefinitely. The same will happen with digital advertising and the gig economy. The public is already getting tired of the wild west and calling for regulation. This regulation will be twisted and controlled by the companies it impacts to secure their future.
You have misunderstood regulatory capture. Regulatory capture occurs when the regulator puts the interests of those in the industry ahead of consumers.
> In return, this regulation raised the startup costs so significantly that only the pre-existing large companies could adapt and new entrants effectively ceased to exist.
This isn't regulatory capture. Regulatory capture is things like making laws that it is only possible for incumbents to be licensed to do specific jobs.
For industries emerging from the innovation stage to the regulatory capture state, usually the first regulations increase the startup cost to some extremely high level that only the incumbents can support. Only in the advanced stages to governments grant monopolies to specific companies.
That's a very specific term with a specific meaning.
And if I might say so, for a tech forum, there seems to be a remarkable number of luddites who sit mighty high on their horses as they sing the praises of Chesterton's fence while simultaneously baying over the stagnation of housing, transportation, and their flavor-of-the-week, dead-on-arrival revolution, etc.
Should we never have used GPS because a good map won't lead you into a desert? Should we stop using phones because a one-to-one conversation may end up as dead an art as Latin is a language? Not everything that was done before was done for the right reason. Not now or even then. They were done mainly because there was no other given choice or someone on a high chair said so and signed his name on a piece of paper declaring it as law.
I'd say it's beneficial that those regulations have been circumvented even if I don't necessarily cheer on the particular actors who do the circumventing or what they do afterwards. Innovation is about finding novel ways to get from A to B as speedily, efficiently, and effectively as possible. And if regulations create a roadblock to it, all the more reason to invent around them. After all, there wouldn't a modern desktop if it wasn't for Compaq engineers reverse-engineering and reimplementing IBM's BIOS.
The theme appears to be that innovation brings many benefits and great risks. I would advise appreciation of nuance and thoughtfulness. As we become a Kardashev Type I civilization, we could carefully consider the way we organize our society and the existential risks we create for ourselves. For the first time in our history, we have the ability to pretty much completely annihilate ourselves and we're only creating more ways to do it. Maybe some caution is due.
(1) https://daily.jstor.org/an-affordable-radio-brought-nazi-pro....
What is that supposed to be? It’s not a known concept. If you think it means something you should define it.
As a lawyer, it’s perfectly legal to circumvent a law by designing around it. Crypto does that perfectly. So does everybody else. Heck, the whole open source movement does it.
If instead you are saying that it’s good to find loopholes in laws that violate the spirit of the law, but not the letter of the law … well, you just explained why smart contracts are stupid and will never work.
Edit: by your definition, this “hack” was just innovation designed around the “law” of the smart contracts ;)
Weirdly, online advertising is in some cases more restricted than traditional broadcasting. I've never seen a movie pause half-way through so someone can go "By the way, Microsoft paid us $5,000,000 to feature this extremely close-up shot of a Surface with the branding visible", but that's a legal requirement for YouTube videos containing sponsored content.
Ethereum has had lots of these hacks, due to bugs in the smart contracts provided.
You don't see these types of (protocol level) hacks in bitcoin, litecoin, or monero.
Blockchains don't need to be turing complete, for reasons like the contents of this article.
Code is law, bro. These aren't hacks or bugs. They are inert chunks of code that all play by. Even "bugs" in the execution engine are fair game when code is law...
The fine folks who carefully investigated the DAO smart contract and transferred lots of its value to their possession are just as entitled to that wealth as the people who possessed it in the first place. There was no hacking and no thievery. The smart contract was executing exactly as it was written. I argue the only people playing in bad faith were the makers of ethereum and the DAO, who rolled back the blockchain and stole the funds back into their hands.
Now this argument sounds silly, but I stand by it. Code is law is a horrible idea. But if you want to live in that world... all "bugs" are just as much of the "law" as the stuff that isn't a "bug".
Going to think about this while I walk. That is a tough argument to counter.
Still, last time they called it a bug and rolled back the chain.
Wait, what is crypto about again? I can’t figure it out.
It used to be about decentralized peer-to-peer money that is highly resistant to censorship.
Then that got blown to bit because satoshi didn’t possess enough foresight to realize that one day it will get owned by a handful of people who will leverage the artificial scarcity to conduct endless pump-and-dumps to enrich themselves at the expense of the poor.
How do you think Satoshi would have reacted to the current state of affairs? You think he would see this “cryptocurrency” space as the path to solving the problem of money and corruption in finance?
You can’t fix fundamental problems in modern economics by fixating on the properties of money which can be altered (presumably for the better) through technology?
To save some comments; Yes, they do have the potentials to create their own closed-circle economic ecosystems, but for the retail banking services to work (eg overdrafts, mortgages etc) you will end-up with centralised players as these kind of services need to be backed by wealth (it's not a tech-issue).
- leveling the playing field with an open interface that anyone can build on top of
- allowing true ownership of assets
What is ownership and how is it true? This is philosophically on the deep end, as the evil powers can seize your wallet just as easily and you may have no (legal) recourse, https://xkcd.com/538/
Seriously if I own a traditional asset within the current legal system (e.g. stocks, bonds, real estate), "the system" can help me protect and enforce my ownership rights, if you're in good social standing. In crypto "the system" cannot help you as much.
However if you are in bad social standing, the system can seize the wallet or the stocks easily.
The uncertainty inherent in the universe we understand today and in all human endeavors is difficult to contend with in code.
In the main, contracts serve to reduce uncertainty and to attempt to manage uncertainty that can't or shouldn't be reduced. Of necessity, contract law has developed a myriad of principles and rules in service of this aim. However, these principles and rules are themselves predominantly characterized by uncertainty. See, for example, the implied covenant of good faith and fair dealing.[0]
Humility — and a corollary respect for our ancestors — is a defining characteristic of my own study of the law.
---
https://en.wikipedia.org/wiki/Bangladesh_Bank_robbery
At a lower level, mortgage wire fraud is a serious problem in real estate closings, and once it happens it's very difficult to get your money back:
So it was originally about the same scale as this one.
Regulation S needs to be extended to all crypto trading. [1]
[1] https://www.dorsey.com/~/media/files/newsresources/publicati...
What I'm advocating is that all crypto trading by US persons be at SEC/CFTC/etc regulated exchanges.
Offshore appears to be where the chaos happens, see: Binance.
Bitcoin is not is a security. Neither is Etherium. I'm not an expert on this area but I don't believe the SEC has the power to regulate them, unless they stray into naughty territory.
New Initial Coin Offerings are something that it can evaluate and deem a security, requiring proper SEC listing as a security; but the existing established digital currencies are not securities and do not require trading through brokers just like trading cash (or exchanging one currency for another) does not require brokers.
The SEC hasn't declared them currencies but neither are they securities. They are assets that you can trade with anyone. That's my best understanding of the SEC's current stance.
Future ICOs could also being avoid classified as securities if the avoided matching the rules that the SEC uses to evaluate whether an offering is a security. There's a checklist of criteria, including whether the asset is being advertised as something that people can buy and expect to make money on.
Ethereum launched as a network where you could perform functional operations more complex than Bitcoin, and was a bit before the SEC got its evaluation rules together (from what I understand), and so may have slipped under the radar; but it certainly wasn't a pump-and-dump scheme like many other ICOs have been.
> The SEC hasn't declared them currencies but neither are they securities.
They are commodities and fall under the purview of the CFTC, and are subject to their regulation.
> Ethereum launched as a network where you could perform functional operations more complex than Bitcoin, and was a bit before the SEC got its evaluation rules together (from what I understand), and so may have slipped under the radar; but it certainly wasn't a pump-and-dump scheme like many other ICOs have been.
Nope, they failed the Howey test which is the legal standard for determining whether something is a security. This was because they raised capital in their ICO. It was at the SECs discretion not to treat them as securities. Just because something isn't a pump-and-dump doesn't mean it's not a security. In fact, one would expect most securities not to be given it's kind of illegal. [1]
I know it is today considered a commodity, however, it was always a security as determined by the Howey test. The SEC elected not to treat it as one at its discretion.
[1] https://bitcoinist.com/secs-gary-gensler-crumbles-when-asked...
> On Thursday, June 14, 2018, the U.S. Securities and Exchange Commission’s (SEC) Director of Corporate Finance, William Hinman (Hinman), announced that the commission would not be treating Ether or Bitcoin as securities. The SEC’s announcement is in line with the recent comments of SEC Chairman, Jay Clayton, who recently noted the difference between cryptocurrencies and digital tokens, saying that cryptocurrencies as “replacements for sovereign currencies” were not securities, while digital assets revolving around a venture are often securities.
https://cassels.com/insights/sec-declares-bitcoin-and-ether-....
Maybe you meant to say that it just escaped being classified as a security, but as far as I can tell it's a commodity at present.
Indeed it is today considered a commodity. This is broadly what I was getting at, yes.
I encourage you to review the Howey test however as it is the framework ordinarily used for making this determination. [1]
But, it did greatly improve the quality and availability of the service. Maybe crypto helps push banks the same direction.
* Banks
* Finance
* Insurance
* Building and fire codes
* Pharma
* Travel (airlines, trucks, and cars)
* Energy
Decentralized finance at its best - so decentralized that individuals and centralized companies can decide to block transactions by themselves.
At the end of the day, centralized assets on Ethereum are as legitimate as decentralized ones. The whole point of Ethereum is that it permissionless. If we celebrate Iranians or 16 year olds being able to build on top of it then certainly Goldman Sachs may do so as well.
[Edit: Following the incentives of the protocol is not collusion. In a crypto context I would define collusion as something like multiple parties working together against their own incentives (e.g. rejecting valid, fee-paying transactions).]
If a majority of banks and businesses agree to block transactions of a known terrorist, is it collusion or cooperation? I don't see a meaningful distinction at that point, other than the negative connotation of "collusion" poisoning the well. Which is why I referred to "cooperation" instead.
if they can pursue their own interests freely and if those interests they pursue align with the majority or the totality it does not negate their decentralized nature.
Humans are social creatures and collusion is the natural order. Humans will cooperate unless doing so is clearly to their detriment.
Initially the idea of crypto was that "Code is Law". The code sent the funds somewhere, correct? So by the "Code is Law" standards, this would have been just a legit transaction.
Now it is like in the old world. Whoever has the highest reputation is right.
This happens all the time in traditional written law. Legalese exists for this very reason.
Just because one side says so?
Because that side has a big brand name?
That is exactly what I mean with "Whoever has the highest reputation is right".
The initial promise of crypto was the opposite: That the little Joe has the same rights as the big guys. Because code is law. And code does not care about the budget of your legal department and your marketing department.
If you can't accurately predict the implications of the lines of code in a smart contract, then it's as good as saying "The laws of physics are laws. That ball ended in my garden following the laws of gravity and thermodynamics, asking for me to return it to you is breaching the initial promise of the physical world". This may change with better smart contract languages that can reconcile intent with effect[1], but while talking about complex Ethereum smart contracts, the "Code is law" argument has no value.
Furthermore, as long as you keep within the bounds of trustless cryptocurrency (unfortunately not a tautology these days), code is indeed law. The ETH this person acquired cannot be confiscated.
That's only because there's no ETH. All there is is a ledger. And ledgers can be "ammended", as they have been in the past, effectively stealing the hacker's ETH back.
Theoretically you could write more precise laws with code.
Maybe they should have let a group of contract lawyers proofread what the code does. Lawyers look for bugs, inconsistencies, errors, loopholes all the time.
Doesn’t stop people from arguing that no one could tell what the intent was, or the intent was actually what they did, or the law was so badly written that they are right because. And sometimes they win. But it’s rare.
It's like trying to fit a finite-term polynomial to a fractal - there's literally no way to make things match up everywhere. [1]
People complain because law/finance/whatever seem to be too complicated, so they try simpler, more "obviously correct" sets of rules that perform even worse in practice than what we already had because the world is still a fractal, and simpler rules just mean you're trying to use fewer points to fit that infinitely complicated curve. It's easy to look at existing law/finance/whatever from the outside and say "it's too complicated, we should refactor everything from first principles" but there's good reason to believe that is always a mistake [2].
Simple, obvious rules like "Transactions should be immutable once they are completed" seem like a good idea, but then they encounter incredibly common real world situations like "what if somebody made a mistake when they specified the amount of the transaction or the account number in the 'to' field?" Real world finance has ways to handle this - if nothing else, you can take it to court and ask a judge "does this seem reasonable?". "Code-is-law", like Procrustes "perfect bed", only has admonitions to be completely perfect yourself or suffer the consequences.
So IMO it's not just that most code is not well written, it's that the very idea that any finite amount of code, no matter how "perfect", can be a good fit for all the intricate needs of the actual lives of billions of people is fundamentally flawed.
And also, most of the code is not very well written :)
[1] as an alternate analogy, it's like trying to fix Godelian incompleteness in a formal system by adding a finite number of axioms.
[2] https://www.joelonsoftware.com/2000/04/06/things-you-should-...
That is until the Ethereum Core developers were massively affected by the hack and decided on an unprecedented rules rewrite to address the hack. (Which they haven't considered ever since, despite other hacks of the same type.)
EDIT: here's a pretty good write up of why you might think that ETC doesn't follow "Code is Law" either. In short after forking from ETH years ago because they had a stronger conviction that code is law they decided to break compatibility of existing code deployed on the chain to keep in sync with ETH development.
It is worth noting that they also have been subject to several 51% attacks [2].
[1] https://investorplace.com/2021/06/ethereum-classic-will-stan...
[2] https://ethereumclassic.org/knowledge/roadmap
[3] https://www.coindesk.com/ethereum-classic-blockchain-subject...
My feelings have now changed and IMO Ethereum will or already has overtaken bitcoin in importance. In general if you want to do "dapp" development you will write for the EVM, although you probably won't deploy on ETH L1 as your first place.
Ethereum has some very serious network effects building up behind it even if your favorite aspect of it was shed during the DAO hack.
I much prefer this interpretation. I think this should be considered ipso facto legitimate use of the contract.
The more frequent these contract "failures" become the more suspicious I am that the authors of the contract themselves are the ones exploiting them.
It's an obvious scam in this frothy market: introduce a contract with an intentional defect and then exploit it yourself.
Again, I am tempted to consider this a legitimate use of the contract.
But that isn't what The DAO was advertising. It was "code is law", which was supposed to remove the element of messy human judgement from things.
Of course, it was a spectacular failure because nobody actually really wants "code is law"... instead all they did was re-invent mob rule and those with the loudest voices decided what to do about the "theft".
IMO Ethereum did something that would be really nice to be able to do in the real world. A chain split, each participant got their resources on each side of the split (except the hacker) and each person got to choose which one to support, or both.
There was no need to bend to the "loudest voices" as to what to do with the theft, but rather to create two parallel chains and let each individual decide.
But the DAO contract specifically said, “we are bound by the results of this state machine, and it takes precedence over any human description of it”, and then wanted take-backsies as soon ask they didn’t like the result.
[0] https://twitter.com/Mudit__Gupta/status/1425115177771405312
So at least for the Ethereum Classic thing, the code was written in the way that just allowed such action and therefore you should not reverse the transaction. Note that the hack was still illegal, that's the fact, so you can (and should) go to the law enforcement to do something with it. But there was no bug in the code of the blockchain itself, it was working exactly as it was supposed to. There was a bug in the smart contract though, but it's not a part of the blockchain, so it's not a violation of principles/nature of blockchain ("code is law") but a 3rd party mistake.
Same here, no principles of the blockchain was broken. So the "code is law" stands. But the transaction is still illicit, and is a hack.
Best part of the article is how an anonymous person helped the hackers launder their money and got a tip for it.
18 U.S. Code § 3 defines an "Accessory after the fact" as "Whoever, knowing that an offense against the United States has been committed, receives, relieves, comforts or assists the offender in order to hinder or prevent his apprehension, trial or punishment, is an accessory after the fact." and states that it's worth half the jail time as the primary offense.
However, it could also be argued that hanashiro.eth is aiding someone in committing the crime of money laundering, not just helping them avoid being caught, in which case 18 U.S. Code § 2 says that planning, ordering, or knowingly helping commit a crime makes one eligible for the same full full punishment as the primary actor.
edit: this is also something different governments may take a different stance on. If the U.S. finds someone criminally liable, El Salvador may not. Also, it's contentious what the 'location' of the crime even is, as there are no physical servers which have been attacked; could the blockchain as a distributed database be considered to exist 'everywhere' or 'nowhere'?
binance charity and donations to archive.org, etherscan, infura.io, rekt... and Vitalik!
it was 13.37 Ethereum
https://etherscan.io/tx/0xdf3afc47c7914e06ddb1be19afcd769e55...
I am still waiting for Rekt to cover this one.
I’m still bullish on defi but there is a lot of incidents like this that need to happen before these systems become resilient.
"For safety, all transactions have to go through Dave" == "Free money to anyone who manages to hack/bribe/kidnap/etc Dave"
If it's not clear why, consider: what keeps defi from implementing gambling (or as it's known in the financial world, "options trading") on real-world data outcomes, like stock prices? Answer: that data isn't programmatically available on the blockchain. You can make a smart contract that depends on the closing price of ETH, but not AAPL.
So, what if it were? What if someone decided to publish AAPL's closing price to a ledger somewhere? Then people could make a smart contract that effectively implements options trading against AAPL stock, right? In theory, yes. But in practice, the people that trade options will say, "How can we trust that you won't screw up, get hacked, get bribed, go out of business, etc? Every dollar we entrust to a smart contract that relies on your data is a prize to be won by the first person to find a way to subvert your service's data integrity."
And they'll be right. There are lots of people trying to find fancy solutions to this problem, but to my knowledge we're no closer to a real solution than we were the day Ethereum went live.
If someone breaks into the fed and transfers a billion dollars to their account, it’s pretty pointless, because the next day or hour or whatever, it will be rolled back and except for them being in jail, it will be like it never happened.
For it to be worthwhile, you would need to avoid having any of the oversight mechanisms step in, AND get the cash out in a way that is independent of the system AND won’t leave a trail for the army of slow and methodical investigators. And that is waaay harder.
Providing an ability to do something criminal that will cause a non-reversible transfer of value? Ho boy. That raises the stakes a LOT - and it’s why you see so many bank robberies and why gold transports are guarded so heavily.
I prefer cryptographic fraud proofs.
Sometimes I feel like crypto doesn’t stop to ask if the institutions and processes they seek to deprecate exist for a reason?
I absolutely believe that blockchain/DLT have some very promising use cases. But so much in crypto land just screams out that people don’t truly understand the systems they oppose so strongly.
Tether just froze a bunch of funds. Like a bank. Or PayPal. One of the most repeated slams against TradFi is the “PayPal locked my funds! Money belongs to the people! Self sovereignty!” But we’ve seen time and time again with the ETH fork, Tether freezings (they’ve had multiple), that we end up right back at these processes. People will claim that if everyone in a decentralized network decides to do something (like hard fork), that doesn’t violate the decentralization. But what do you think society is? We’ve all come together and decided on a bunch of rules we want to live by. Hack by hack we are seeing these same functions replicated in crypto.
Tether is one of many assets on Ethereum, each with their own properties. Some are centralized, some are decentralized, some are stable, some aren't, etc. It's about choice at the end of the day, and crypto actually gives you this choice vs paypal or your bank.
And whatever those rules are, a minority has to accept the decisions made by others. When it comes to the rules for a financial system, you now have many choices.
https://twitter.com/mudit__gupta/status/1425150994778787841?...
https://blocksecteam.medium.com/the-initial-analysis-of-the-...
The article would have benefitted from an explanation of how operation of this code in a 'Code is Law' scenario can result in 'stolen' ledger entries. It's like complaining about an 'illegal' court judgment, after the appealing court says it wasn't illegal.
I know there's a fun semantic debate about smart contracts hacks, but at the moment this theft does not appear to be in that category.
But now a days it's hard for me to understand what's going on in crypto world. For example I couldn't even parse their statement:
"#PolyNetwork was attacked on @BinanceChain @ethereum and @0xPolygon Assets had been transferred to hacker's following addresses:"
Source: https://twitter.com/PolyNetwork2/status/1425073987164381196
Some more details here if you're curious: https://news.ycombinator.com/item?id=27812093
I'm getting CDO, CDO^2, Synthetic CDO vibes reading this.
eth peeps get rugpulled again! lest we not forget ETC ethereum classic is actually the real eth chain except they forked it to salvage the DAO debacle - except the internet has a short memory and no one remembers this any more.
inb4 ETH3 fork
Haha, smart contracts are as stupid as the average "intelligent home" only worse: They cannot be updated.
People writing smart contracts should be the ones coming from a firmware/embedded writing background, not "webdevs". Right now DeFi smart contracts look like the 90s web: Tons of "Defaced" website every week. Of course now there's a stronger incentive given that monetary value is involved.
This is an overly broad statement that doesn't accurately represent the entire space. There are a good number of projects with very experienced developers that use rigorous testing, multiple audits, etc. There are also teams that yolo smart contracts with very little testing. Assuming every project in the space is the latter is quite inaccurate.
Polygon is a protocol described as an 'Internet of blockchains' that is compatible with Ethereum and connects with other Ethereum-compatible blockchains.
They suffered an attack on its blockchain that affected other blockchains and the coins affected were sent to the hacker's address.
From my understanding:
Polygon (formerly MATIC) is a token related to (built off?) ethereum.
Poly Network was a bridge layer that spanned polygon and ethereum.
Polygon and Poly Network are distinct entities as far as I can tell, but they are all overlapping and using each other, so I don't fully understand the distinction.
The running joke, before all the nightmares cryptocurrency has spawned since it took off, was that he'd helped some drug lord fix their metaphorical printer, but not so funny now...
This is what I don’t understand... There is nothing that prevents something 10 times bigger to happen and cause many people to quit crypto en masse leavingg others holding the bag... this is going to embolden other hackers. It’s an awful lot of money!!
> DeFi has survived so many individual hacks and exploits that people are less scared of their assets going to zero as a result.
This is pretty amusing, if anything.
Whose money was stolen? PolyNet's? Random user? Someone "betting/buying" on a contract?
What is Curve.fi and why is transferring the proceeds there advantageous for the hacker?
I've never heard of poly.network but based on what I can see here, it seems likely that this was related to a cross-chain bridge. ie. they run their own network and the assets on that network were "bridged" in from other networks.
Bridged assets are really held in custody at the bridge while a "copy" of that asset goes off to the other networks and does things, eventually that "copy" comes back to the bridge and gets destroyed, then custody of the asset you bridged is released back to the original network.
In this case it seems like someone was essentially able to provide forged "custody papers" of bridged assets that came in from BSC and ETH mainnet and were floating around on Polygon and then was able to "unbridge" assets back to BSC and ETH mainnet. The people affected are presumably anyone who had used poly.network bridge to bridge assets from either ETH mainnet or BSC over to Polygon.
curve.fi can basically be thought of as a bank (or really a provider of interest earning bonds).
The really bizarre thing here is that the "hacker" doesn't even try to cover their tracks before putting money straight in the bank. The funds are dirty, we can only speculate that curve may not want to touch these coins and is possibly figuring out how to "quarantine" them as there's every possibility that other "big boys" may follow Tether on blocking redemption.
There are well-known methods of washing funds, so it's possible the "hacker" wasn't really all that experienced but somehow "stumbled" upon the keys to the vault, so to speak.
I guess is doesn't hurt to ask? Not usually how doing a crime works though.
https://mobile.twitter.com/Mudit__Gupta/status/1425150994778...
https://www.theblockcrypto.com/post/114189/poly-hack-attacke...
You could argue that paper money lacks the features of bitcoins so it's easier to lose your funds inadvertently with bitcoin.
Dogecoin for example has some config changes to block size that make transactions cheaper.
It's factually "better" as far as code goes.
Crypto/BitCoin currently delivers mostly on the last one "store of value". So the hackers keep them. Indefinitely.
Ethereum was created after Bitcoin. It was designed to be more of an open programming platform. It was designed to be Turing Complete and enabled the use of "smart contracts". The DeFi space runs on smart contracts and Ethereum kicked off DeFi. This is the Ethereum white paper [3]. Mastering Ethereum by Andreas M. Antonopoulos & Gavin Wood is another book you could check out [4].
Here are a couple of introductions to DeFi, as well [5][6].
The hack that everyone is discussing here was on Poly Network, which a layer 2 solution for Ethereum [7]. Layer 2 solutions were created due to lower the high gas fees on Ethereum, as well as increase transaction throughput. Ethereum itself is also working on moving to Ethereum 2.0 which would help address the issues that layer 2 solutions are trying to solve [7].
Edit: Poly Network actually appears to be more of a bridge between different networks (Ethereum, Polygon and Binance Smart Chain) [9], so it's worth noting that this wasn't a direct hack on Polygon, which is a layer 2 solution for Ethereum.
[1] https://bitcoin.org/bitcoin.pdf
[2] https://github.com/bitcoinbook/bitcoinbook
[3] https://ethereum.org/en/whitepaper/
[4] https://github.com/ethereumbook/ethereumbook
[5] https://ethereum.org/en/defi/
[6] https://blog.coinbase.com/a-beginners-guide-to-decentralized...
[7] https://www.gemini.com/cryptopedia/polygon-crypto-matic-netw...
[8] https://ethereum.org/en/eth2/
[9] https://www.reddit.com/r/CryptoCurrency/comments/p1qfdo/psa_...
It's not. Polygon != Poly Network. See this comment https://news.ycombinator.com/item?id=28132755
But also, insurance products exist, they pay out pretty reliably. Are there any DeFi insurance products that would be able to cover $600M yet?
edit: some people seem to misunderstand, DeFi insurance products exist, the policies are not too expensive and they pay out reliably and quickly. The math is easy because of the transparency of "semi-untraceable internet money" and the Defi sector being much larger than any of the hacks. There are a lot of competitors in the insurance space. It is easy to make and rely on a claim because the damage is easily seen and verified for the policy holder. There are several sectors in the Defi space, such as AMMs, oracles, lenders, and some of those sectors are driving sentiment and attention more than others. Insurance is one of those sectors. My question was whether any of the insurance systems would be able to cover $600M, right now, it wasn't to entertain out of touch people's pre-existing skepticism.
Truly, we live in the future.
I mean, thats what we are talking about here, products that already exist and are live right now and compete with each other. You can enter it though, there is room for differentiation.
> Hackers exploited Poly Network on DeFi exchanges Polygon, Ethereum and Binance Smart Chain
When even a website supposedly specializing on blockchain can't get their basic terminology right.
Legal action? By who? A central authority!? No way...
Also it seems the project was not very decentralised if everything was stolen with a single private key.
If the federal government mandates their citizens pay taxes on crypto, it most definitely should come with federal help in catching criminals.
The country you reside in may tax you non-state-currency assets, like selling a painting. But if a painting is stolen around the world at the same time, many governments may have collected taxes on part of that painting. Which government should be the government to persue the theft?
In a different way, if 600 million USD was stolen in cash in France. The US would work closely with the French government to close that case. The US would not be the one to foot the entire bill of solving the case.
Here no government has any real stake or harm to reputation to close the case.
Do the police get involved if someone steals your sword in WoW? Do they get involved if a bigger Twitter account "steals" your meme and reposts it without attribution?
Not necessarily. The OP is pretty light on details on what this "hack" was, but if this was the case of someone playing "code is law" games with a flawed smart contract, then I think it'd be totally legitimate for the government to require taxes be paid but not swoop in with law enforcement when someone made a bad deal (i.e. had their flawed contract exploited).
I'm not aware of any court that would, for example, jail a Chinese citizen who stole virtual money of a US citizen? Are you?
Ideally governance would also be done in a decentralized manner, but we’re not there yet.
Decentralized systems have different benefits for different people. For instance, some people like to trade 24 hours without corporate middlemen stopping you from trading at night. That's not the same as avoiding legal authority.
I remember when the crypto market tanked and the fine folks on r/cryptocurrency were demanding the SEC shut down Bitmex and arrest its CEO.
Seems that at any given time, rugged crypto individualists are 10 percentage point losses from begging Big Daddy Government to step in.
People are typically "rugged individualists" only so long as they feel they're winning from the system.
Hacker/insider got the private key. Simple as that.
Here is the 2015 Swift Network Hack resulting in $101M stolen from banks. https://en.wikipedia.org/wiki/2015%E2%80%932016_SWIFT_bankin...
Here is a catalog of financial cyber incidents: https://carnegieendowment.org/specialprojects/protectingfina...
Good ol' totally centralized inept Ethereum platform strikes again! Always good for some belly laughs.
It’s becoming apparent to me that the main innovation of crypto is a form of regulatory arbitrage. You or me cannot sell derivatives like Goldman Sachs but in crypto land you totally can from your home with a laptop.
You can start a gambling casino on ethereum and get away with not following any of the laws regarding gambling as long as you couch it in financial and blockchain buzzwords. Some people will make a lot of money doing legitimate work and some scamming others until all of this becomes big enough to become mainstream and regulated.
I don’t use or advocate for DeFi, but the weird smugness of random people defending the existing financial system is quite off putting and frankly hard to understand given the last few decades.
Confirmation bias plays a big role in the popularity of crypto, in unsettingly the same way as it does with people dreaming to become a famous soccer player... mostly through confirmation bias and very little value-add.
But, as with cryptocurrencies, it just doesn't make any sense. Maybe a boxer taking it on the chin round after round can derive some satisfaction from still being conscious. But they aren't making any progress and would be rather stupid to continue considering it a winning strategy.
Oh, wait.. maybe it does make sense.
For those with a longer history on Wall St, it was essentially a new asset class with all the easy money arbitrage opportunities that went away in equities 20+ years ago back again.
Always look for the chump at the table. If you can't spot them, you're the chump.
This is likely an issue of sophistication -- crypto hackers don't have decades of "best practices" knowledge to draw from, and may also feel a false sense of security.
Citation needed for such an extraordinary claim.
In the meantime, this article explains how and why that would be the case:
https://www.nytimes.com/2021/06/09/technology/bitcoin-untrac...
Basically the openness of the ledger allows law enforcement to skip some slow and difficult tracing and requesting of warrants.
On top of that, cybercriminals seem to make exploitable mistakes that have enabled stealing their private keys.
A person following the letter of a smart contract for their benefit, while not breaking the terms of any legally binding contract they've signed, has yet to be charged with a crime (to my knowledge)
I haven't seen news of anyone from DarkSide being arrested for that hack yet though.
[1] https://www.justice.gov/opa/pr/department-justice-seizes-23-...
I understand the whole point of crypto is the future bet that centralisation/regulation by state actors will eventually be _less_ trustable. This one hack means $600MM lost, but how much has been routinely lost to bad governance, inflation or corruption? How much value has been destroyed in the 2008 housing crisis?
In the long run, the crypto market can professionalize enough while remaining decentralised, such that the risk/reward is attractive compared to holding 100% fiat – this seems to be people's bet, not that crypto is inherently safe.
Which is the problem with that community: they seem to have these extremely naive yet cynical view of politicians just being "stupid", money being wasted, everyone being corrupt etc. And that, somehow, their funny little hashes are the silver bullet to solve these issues.
DINO, not defi
Coming soon.
The hacker can earn a bunch of Curve and treat this more like a larger flash loan. The market values Curve and this would either mint new Curve or distribute more Curve from the Curve organization's existing treasury.