DeFi protocol BadgerDAO exploited for $120M in front-end attack
theblockcrypto.com
theblockcrypto.com
Reminder also that you don't have to "hack etherum"; there are plenty of spots more vulnerable than the blockchain itself at which value can be stolen.
(I would however be interested to know where all this stolen value ends up, and how well it can ultimately be laundered into the real world, or if this is more like driving a truck into an ATM that causes far more loss than is actually successfully stolen)
> Is it possible to compromise the protocol and find out information about depositors? -- No, Tornado Cash is a decentralized protocol based on zero knowledge proofs. Its smart contracts are immutable, have no admins, and the proofs are based on strong cryptography. Only the user possessing the Note is able to link deposit and withdrawal.
That very much sounds like an impossibility statement like "Use Tornado Cash and no one will be able to trace your transaction".
OTOH, they also say that
> After depositing, users should wait some amount of time before withdrawing to improve their privacy.
and that
> To preserve privacy a relayer can be used to withdraw to an address with no ETH balance.
So it seems privacy is not a binary switch here and, instead, it can be "improved" and "preserved". But what is it then? Can deposit and withdrawal be linked or not? Are the privacy guarantees as absolute and strong as the FAQ make them out to be?
It obviously cannot prevent you from revealing your transaction via other means. For example, by publicly announcing it.
It might not be evidence that A and B are your addresses, but strong implications.
So, you put it into Tornado and wait days, weeks, or even months, so it could be a random transaction.
People generally like privacy when it comes to medium and large purchases, regardless of what it is that they are purchasing.
> People generally like privacy when it comes to medium and large purchases
The "war on money laundering" goes against this.
> But the recent Pandora Papers leak has revealed that U.K. properties worth nearly $5.5 billion, according to those who've analyzed the documents, have been purchased through offshore shell companies that hide the owners' identities.
> "Using a shell company means that no one need ever know that the asset is yours," said anti-corruption activist Duncan Hames, Director of Policy at Transparency International. "Indeed, the British government probably doesn't know."
People can simply crawl the blockchain for addresses that have a good amount of money and then check which of them they can relate to persons.
If they know you and how much your crypto net worth is, they might start to attack you in some kind of way to get your private key.
If you tornadoed that money in an address that can't be linked to other addresses anymore, the work to relate the address to you might be too big so people won't try.
Edit: HN destroyed formatting
So if there are N deposits then later N withdrawals, the only thing you know is that each withdrawal matches one of the deposits, but not which one.
As for privacy improvements:
- If you deposit then immediately withdraw, observers might suspect that you instantly withdrew your deposit.
- You need ETH for the withdrawal transaction, which has to come from somewhere (making it potentially traceable). With their relayers you can withdraw to an empty account while hiding the origin of the transaction fee.
If there were e.g. three deposits for 5.542, 3.799, and 10.4322 ETH, and someone withdrew 3.799 ETH, then it seems like you'd know which deposit they made.
Best case, you wait long enough and maybe someone else deposits 3.799 ETH.
If anything, I'd expect the output of such a service to be even worse than most inputs, as the money will be mixed with all the inputs, some of which would be associated with horrible crime beyond just fraud or theft.
Oh, you do. Not being able to prove the source of your funds puts you at serious risk of asset forfeiture.
If you the give them to someone, well then they need to explain where it came from.
Also, if you want to put them back into your account, you'd need to show provenance.
Since this costs money to use, most people are not going to use it unless they're trying to hide something so the big risk I'd worry about is similar to the risks of running a Tor exit node in your house. What happens when someone else using that service is investigated for some serious crime? Anyone who has transactions going to or from that pool is going to be under suspicion and it's really hard to _prove_ that you weren't knowingly helping them launder money when you have a public log of transactions involving the target.
In this specific case, you’re talking about a service people have to pay to use. That lowers the pool of people using it considerably which makes techniques like timing analysis easier and increases the odds that your transactions will be mixed in with someone else’s criminal activity.
Timing analysis is a real concern, that's why they warn you about it on the front page and ask to wait before you withdraw.
https://medium.com/@tornado.cash/how-to-stay-anonymous-with-...
Very few people are so ideologically committed that they're going to pay extra and live with those constraints, which is a major problem for a protocol which is critically dependent on volume to deliver privacy and repudiation.
> Plenty of people concerned with privacy use public blockchains - you don't need to dox yourself to use them, just need a private key. Unlike traditional finance, where you just have to hope that your PII data won't get leaked one day with all your transaction history.
This is confusing a number of things. Most PII breaches are not the banks but the merchants who collect things like addresses because they need them for shipping or to satisfy legal requirements, and paying with a blockchain won't change any of those needs.
Similarly, very few people have a way to generate and spend a significant amount of cryptocurrency entirely for anonymous online services and will thus need to identify themselves for most transactions — a cryptocurrency exchange isn't exempted from Know Your Customer, companies which have to deal with abuse are going to want to prevent sock puppets or shell accounts, airlines aren't going to lose interest in checking your identity, buying a house without showing where you got the funds is going to attract a lot of attention, etc.
That link to the real world is the common reason why these promises don't pan out. In general, ask yourself how a particular activity would go if you showed up with a suitcase full of cash and refused to say where it came from. Cryptocurrency will be exactly the same in all but a very few cases.
And I don't know why are you talking to a strawman about a suitcase full of cash, etc. I just said that Tornado.cash offers privacy and that privacy is not always used for evil things.
What a time to be alive as a criminal hacker!
What can DAOs do to prevent the single point of failure that is the web front end? Is there a reliable second level of security to ensure you are at the site you intended? The SSL certificate didn't work because Cloudflare was still terminating the SSL connection.
If you don't want to trust anyone at all, you can read the contract code and make individual judgement whether it does what it's supposed to do.
That's the definition of due diligence. It's not one thing and the specifics of what's involved vary depending upon the investment. At the end of the day, the onus is upon the user to determine if it's a fraud.
Being difficult or down right impossible for a non-technical person to audit a contract address or the contract code itself isn't a license for users to ignore that risk. It means they're accepting it in its entirety. Or they can defer to a trusted third party to make that determination for them. But even then, they're still on the hook for trusting that third party.
As to how they would know if it's the real smart contract: they would see what it was via their wallet after interacting with it the first time.
> As to how they would know if it's the real smart contract: they would see what it was via their wallet after interacting with it the first time.
In other words, the system is not safe to use. People will reliably be fooled into thinking that they're interacting with someone else — the difference is that if you go to amaz0n.com and enter your credit card info, your liability is capped at a low amount and will likely be zero because the regulated financial industry has a fraud handling mechanism better than “the people who profited from you buying their tokens will mock you for being phished”.
So a quick solution would be to run a job that checks your site every minute or so and compares the javascript against known hash values. Shut the site down if a hash has changed.
One defence is ENS. If your DAO's contract is registered for example as "BadgerDAO.eth", and your users wallet software shows that every time they make a transaction then it will be a red flag when the contract has been swapped out in the compromised front-end.
Unfortunately many wallets don't support ENS, and in those that do the experience could be better. So better wallets are part of the solution.
I disagree that this is an important detail. Even though the smart contract code wasn't exploited directly (this time), this type of massive theft is only possible because the smart contract ecosystem thrives on a lack of accountability.
I'm a software engineer but the idea of a "smart" contract working as an "organisation", none of which can be undone when there is an error seems like it has massive risk attached and little to no benefit.
It doesn't seem "decentralized" as there are still organised parties to write and deploy code and the tokens that inevitably belong with each DAO are usually majority held by the creators.
Currently I like the __idea__ of a DAO but see them massively overhyped and unable to describe or prove their actual value.
Please change my view.
of course, as a software engineer, you know that is a hellish nightmare because the code we write is fallible so this entire thing makes no sense whatsoever.
Let's imagine I'm creating a fresh business and choose to structure it as a DAO, does this mean that the ever understanding code is the CEO steering the company? Or is the DAO the product of the company itself? I don't understand the relationship here.
Following on from that, I am the party that writes the code for the DAO. Now I can claim that my code is perfect and we can trust the machines to execute it. But I'm still running the deployment of it and the weakness of corruptible man can still abuse the trust given to the code they create.
The DAO itself could have code that enables something like, "the code for this DAO can be updated as if 50% of token holders vote yes" and then 50% of token holders could vote yes to a code change that appoints a CEO who has absolute authority or they could vote to change the code so that no vote could ever take place in future, and the code becomes "stuck" forever.
The code for a DAO lives and runs on the blockchain, so the integrity of the DAO is linked to the integrity of the network on which it runs: although there's no absolutes, in the case of a network like Ethereum, it is for all intents and purposes, secure, so deployment and execution is not a network-level attack vector.
Does that help?
The reason DAOs are considered _the future_ by some is the implicit assumption that perfect code is possible to produce. Many non-software engineers believe that _if we have the integrity of the network to guarantee the code cannot be changed without consent, then we can have absolute faith in the code_... but of course, as software engineers, we know code is very fallible, whether it's unintended side effects or malicious backdoors or just an honest misunderstanding of what the code is meant to do, there's millions of ways for code to go wrong long before we need to worry about code integrity.
However, the most popular version of this DAO appears to be literal Ponzi schemes operating in the open. It seems people are more likely to trust the Ponzi scheme when they feel they have some degree of control over it.
Many of the high profile DAOs fail for exactly the reasons you highlighted: They’re sold as being built to buy or control off-chain assets (like a copy of the constitution or an NBA basketball team) but they lack any of the real-world contractual obligations that would actually link the DAO to the real-world asset. They’re relying entirely on the real-world volunteers to do what they claimed to do in agreement with what the DAO voted. This is why the constitution DAO had to make it clear that contributions were donations and tokens did not constitute actual ownership.
It’s possible that a future DAO will go through the trouble of setting up the appropriate real-world contracts and entities to make this all legally binding and an actual security, but at that point the legal entity is doing all of the heavy lifting and the DAO is just a very expensive donation and voting system where gas fees consume hundreds of dollars of every member’s interactions. Any breach of contract would still have to be handled in the real-world legal system, so the DAO wouldn’t really protect anything other than providing a record of who voted for what.
Nexus Mutual just told on Twitter that since it is not a smart contract attack, they're not going to pay.
Looks like they’re refusing to cover it because it was a supply chain attack.
I'm curious — how do you just "pause a smart contract"? Is that written into the code?
https://ethereum-blockchain-developer.com/022-pausing-destro...
They just move some speculation and crime there.
Among the clients nobody innocent gets hurt, as there is nobody innocent.
Now ransomware and such...
In terms of normal bank clients moving to a DAO bank or something silly like that, you're right, nobody in their right minds is doing this.
Depends how "innocent" someone is when they are blinded by greed, even if greed fueled by scammers.
Would that same person be culpable if they did as little due diligance before "investing" in more traditional organized crime, lured in by "you can't lose. It's a sure bet, 10x gains!"?
At best the innocents here "invested" in a lottery ticket, and lost in the same way that a non-winning lottery ticket loses.
Mix that with someone who's easily impressionable and anxious, and you get someone who'll likely make some very bad decisions.
And every smart contract is a self-funded hack bounty.
Smart contracts are a complete misunderstanding of what contracts are, and what the hard parts of the space of contracts are. They're simply changing the simple problem to be enormously complex, without making the hard problems any easier. In fact it makes the hard problems harder too.
causing great public interest and excitement.
> OP making sensational claims
Def 1. "causing great public interest and excitement"
Well, not really. This story is just "huh, another one". Brings to mind the meme "I'm shocked, shocked!, to see another one of the cryptocurrency LARPers topple over"
Def 2. "very good indeed; very impressive or attractive."
Thank you!
Take the first sentence on ethereum's intro to DeFi: "DeFi is an open and global financial system built for the internet age – an alternative to a system that's opaque, tightly controlled, and held together by decades-old infrastructure and processes. "
Lots of the slowness and beurocracy of old finance is scoffed at as being, in more words, "stupid bullshit".
Rule after rule, and obstacle after obstacle, is loudly ranted about how terrible it is.
So the solution, in these people's explicit methods, is to throw away everything and start green field.
Now, I'm a software engineer. I understand the allure of green field. Surely, "how hard could it be"?
So because the description of how stupid cryptocurrency is can fill books (and there are several), let's stick to a short summary of the outcome of DeFi so far:
It's barely newsworthy every time one of these LARP banks topple over, losing all the money.
It's almost a weekly occurance.
And not only is all the money stolen, it's also not reversible!
When one of the founders of the pirate bay hacked a (real) bank's mainframe, he didn't actually get away with much (a couple of hundred dollars, I think was all that his accomplices managed to withdraw from ATMs). The rest was transferred back. (also suddenly "lack of extradition treaty" became a non-problem)
Basically cryptocurrencies and DeFi is software engineers with no understanding of economics, law, or society, discovering why all of the rules, laws, and procedures currently in place exist.
Another example is that AML/KYC laws didn't fall from the sky. "Well what if we didn't have laws at all?" is not really a rational place to start.
That's not to say that traditional finance is perfect. Absolutely not. But the cure for bad laws is not "The Purge".
So yeah, it's not this event, so much as this happens all the fucking time.
Imagine if these people were selling cars, and complaining about how much pushback they're getting for putting them on public roads, while every day there's deaths all over from unregulated cars that have swords on them, chopping heads off of the drivers themselves, and innocent pedestrians.
Like, how do you not see why this is causing pushback and that your way of replacing the seatbelt with a potato is stupid, and that actually the law that says a seatbelt is not allowed to be a potato maybe has a valid point?
Especially since things are more subtle than that. A non-techie cannot tell the difference between a seatbelt and a potato, and that's why the law says your car needs to have actual seatbelts.
Code can almost always be exploited and broken in a way actual contracts can't. Giant corporations spend tons of money on various security features, only for them to be broken by some 15 year old that wants to play pirated games on his console.
Why would I possibly want to add that risk to my financial life?
> The front end to the BadgerDAO website was reportedly acccessed, according to comments in the project's Discord channel, and used to intercept transactions. One admin said it appears that an API key for Cloudflare was compromised.
> One user had around 900 bitcoin ($50.8 million) worth of tokens stolen in a single transaction. Another lost $5 million worth of tokens in one go.
Once that BTC is gone, it is gone. DAOs seem to have a lot of trust issues beyond a simple front-end attack and not even you should trust that they can keep their own websites secure. Where are the regulations, audits and security checks for this thing?Oh dear.
If consenting adults voluntarily went out of their way to get an unregulated product, without harming anyone but themselves, then why should they be stopped?
This is a disingenuous argument. FDA doesn't regulate only stuff that is not expected to be consumed by the buyer. GP could have said wine instead of baby milk.
Because not everyone would agree that governments should necessarily regulate everything that you consume. Especially when it's advertised as "consume at your own risk".
Yet alcohol is highly regulated, much more so than baby milk.
Sadly, some people are more than happy to force their worldview on others, "for their own sake".
And when people who want to kill people and have been free to kill people get told they are no longer allowed to, they have also been unhappy about it.
Like was this guy [1] right in what he did and his punishment was unfair?
At which point the blockchain becomes a hiderance.
Also, there are interesting advantages to the transaction authorization model that blockchains have whereby a message is valid only if signed by the sender, enforced down to the data layer.
Big companies ran payroll 100 years ago without IBM machines, but IBM made it easier for big companies to run payroll, so companies that bought IBM machines were able to scale.
Company budgets were done just fine on big sheets of paper 50 years ago before PCs loaded with VisiCalc or Excel deployed to every desktop. What company that still did it the old way survived the 1980s?
Credit card transactions even 30 years ago were still often done with a physical mechanical impression at the point-of-sale. That worked just fine, didn't it? Yeah, there was some fraud, but the people who were given credit cards were few enough that it wasn't unmanageable. But online POS systems now mean that almost everyone today makes payments with debit or credit cards most of the time.
Is "things are working just fine" a reason to not innovate?
Rockets: "The future of space travel" or "so unsafe you could die on launch". Pick one.
If you don't like DAOs or any experimental finance -- which I think is a totally sane thing to do -- then just don't use them. That's why traditional financial structures like banks exist.
Missing by design. It is telling that a currency dubbed "USD tether" which (let's pretend) is backed by USD 1:1 magically excuses you from all regulations you need to abide by if you process actual USD.
The alternative is to learn this lesson the hard way, like these people have.
So it could be just cost of doing business.
But a mix of snake-oil salesmen and nerds dreaming of utopia try to convince everybody that their approach is somehow magically better.
For instance, the Quebec Maple Syrup Heist is reported as both "3,000 tons of maple syrup" because, wow, that's a shit ton of maple syrup AND that the value of the heist was an "estimated $18.7 million".
DeFi: Decentralized Finance
DOA: decentralized autonomous organization; an organization represented by rules encoded as a computer program that is transparent
It's great at instantly losing all your money to a teenage hacker though.
DAOs are actually DOAs 'Dead on Arrivals' due to fundamental trust issues.