Finding a Creature in Ethereum's Dark Forest
bertcmiller.com
bertcmiller.com
Perhaps a transaction reusing a nonce made it to the mempool, but the attacker, watching the mempool, immediately submitted (or even cooperated with a mining pool to) a transaction emptying the sending account, using a much larger fee to push out the other transaction. That would leave no trace of the nonce reuse on chain.
So really R=k*G generates a new point R, where k is the nonce and G is a point that is part of the ECDSA standard. Then r is taken as the x-coordinate of R.
It is easy to derive k in b=k*a mod N if you know a and b, but nearly impossible to derive k in B=k*A if B is k self additions of A on an elliptic curve.
https://corecursive.com/064-ethereum-rescue-with-dan-robinso...
Dan: Maybe I’m like a predator in this environment where… In this case, I was a white hat hacker, but maybe I’m a black hat hacker. Maybe I’m trying to take money from a smart contract. And I think I’m so smart. Like I put a bunch of effort into figuring out this way to steal this money from it. And as soon as I go to do that, just this whale comes up from the deep and just devours me whole. I think I’m actually at the top of the food chain and I’m not even close.I mostly don't touch, like or welcome meme shitcoins. I think NFTs are as much a grift as ICOs were in 2017, etc. etc. I still love the tech. I still love the mindsets of the people I got to meet through crypto and while there is a lot of BS, there are also a lot of very smart people working to build things that give us a fighting chance to take back some of the control and privacy that we have surrendered to FAANG and co.
So, criticize away. Or just shit on it if you want, which is what some of HN is really doing. It changes nothing. I for one am grateful for everything constructive being said, because it paves the way to a future I and many others are hopeful and excited about.
If there is something I can recommend, it is not to define a "subculture", sector or movement by its most extreme outliers. Makes for a pretty bleak outlook on life.
> I bet it makes your subculture feel more important than others though.
That's how some people think no matter where you look, including startups and VC.
I'm just having fun, but I don't feel particularly important. Yeah, thinking there is some good to be done, some meaning in the things you spend time on is part of what makes them fun, but I could find that in a dozen other industries, too.
Currently, the US is the closest it's ever been to losing democracy, and the gun nuts are cheering on those who are destroying it. So not going to be expecting much out of them, I'm afraid.
Which gun nuts?
Conservatives? Or the Trumpists? Maybe you mean the Libertarians? Or is it the John Brown Gun Club? Or maybe NFAC?
"Gun nuts" is considerably more nuanced than presented.
You're the most reasonable crypto-enthusiast I think I've seen on this site but your position is tainted by this fact, for me.
I saw in a sibling comment that you suggest people not judge sub-cultures for their outliers - fair enough. Can I at least express concern for them? These people are getting scammed. Full stop. Not nearly enough is being done about it from within the crypto community and even from outside of it.
People holding a currency which depreciates, and their cost of living increases, are being scammed.
You're ready to keep trusting the people government has put in charge of the money? (Private corps, via lobbying and central banks, more)
> There are many crypto-enthusiasts for whom no level of rigor [counter to crypto] will ever satisfy them despite being obsessed with various "whitepapers" which are mostly marketing fluff. They endlessly defer to various whataboutism's until you find out they are taking an inherently political position (usually some sort of neo-libertarian) and hence the "merits" of the proposed currency _really_ only apply to people who are disenfranchised by existing economic systems. Usually, little is said of how to improve existing systems as that challenges the notion that the status quo is so flawed that it needs to be replaced wholesale. Any idea how to refute crypto to these folks?
Become similarly disenfranchised, or perhaps study the > $1.5T worth of users who are — instead of arguing, and telling them they're wrong (they don't care — why?).
That may help.
Is that money divided evenly amongst the users?
> they don't care — why?
The incumbents stand to make money by denying the existence of a scam, whether they are involved or not.
Can you elaborate on why this taints my position? It wasn't a statement of opinion or an endorsement of Bitcoin, or proof of work. I was just giving a timeline on how long I have been involved with crypto currencies.
Blog has since been wiped, most of my traffic was coming from China. I decided it was a bad idea to talk about money on the internet: see the first and second rule(s) of Fight Club. I should not enable mining bots with bash shell scripts on my blog.
We share some thoughts. The NFT's only make sense to me if you are using them inside of some meta-realm as a form of validation. ICOs were scams and the memecoins are scams and the Youtubers shilling this stuff are scammers as far as I'm concerned. I watched a video the other day of MrBeast and some other Youtubers laughing about shilling cryptopunks. Pretty sad life if you ask me.
If the market grows on its own and I didn't promote it or shill it, does that not mean it's legitimate?
I thought Ethereum was a pre-mine scam at first (kinda still do) but the market has spoken and all of these cryptos are just big pools of liquidity to swim in now. ETH has enabled and built some wild things like AAVE and AMM's but it's difficult to understand the value proposition in 2021/2022 - other than just big pools of liquidity. I think L2 scaling on Ethereum has huge potential.
I stayed off-market until 2017 and then I had to pay a few years worth of salary in taxes to the government because I got jiggy with the first ATH in 2017 as the knife was falling.
2021 has been interesting. A decade into this crypto thing, very little has stopped it. It's difficult to stop an idea once the genie is out of the bottle.
Yes, I believe Proof of Work is a race to the bottom; but it might just be the thing that fairly and accurately prices energy usage one day. I ran 16 GPUs sucking down nearly 3kW around the clock for ~24 months and then I had to shut down the operation because difficulty and I could no longer afford the electricity.
Am I destroying the planet? I don't know. I'm retired from proof of work mining. I'm a staker now ;-)
This hits home. I really refused to acknowledge Ethereum for a long time, because I thought smart contracts and their need for oracles were stupid. Shifting around trust, instead of eliminating it. Security by obscurity, but for trust, is how I thought of it.
I agree with and share the sentiment of the rest you're saying also. Bitcoin and PoW generally are no longer interesting or useful to me, but I also feel sometimes like I haven't really warmed up to the rest of the sector yet.
I only mined with my desktop GPU. While I considered it, I never took the plunge and scaled up - instead I just bought more Bitcoin and sat on them for a little while, before I transitioned to other coins and tokens completely.
For one, they don't rely on "number go up" to make money, they use strategies similar to those used by HFT firms to make money from market inefficiencies. They generally don't have loyalty to a particular crypto platform, they just go wherever they can find a competitive advantage. They also tend to be much less politically outspoken and often left-leaning, in contrast to the vocal libertarian views that permeate the rest of the field.
They also most certainly aren't "imagining" making money. Most of their strategies are essentially elaborate forms of arbitrage, which are risk-free sources of profit by nature (until out-competed). Their only losses come from fees paid for deploying strategies that turn out to be unsuccessful. Even fees for failed transactions are pretty much a non-issue these days because of Flashbots.
This is a minority of the people in tech and on HN. It's not taboo in general (as those groups only make up a tiny fraction of the population), nor even taboo for those specific groups - so I think that makes calling it a "taboo" at all a stretch.
There are various techniques people use for them: a careful counter, a precise timestamp, a hash of the rest of the data, or a random number. Often you can choose as the user... as long as you don't use the same value twice; alternatively, your choice of nonce might be verified by your counter-party (as with Ethereum's account nonces).
The consequences of using the same value twice will also differ: your request might be rejected/ignored, you might be penalized or cause an error, it might expose your identity to a system where you were otherwise anonymous, or it might allow someone to calculate your private key. The high-level idea is what matters, not the specifics.
People use some kind of "replace by fee" transactions all the time, as far as I know these broadcasted transactions, typically with higher fees, have the exact same nonce as the previous one.
If simply reusing the same nonce allowed someone to crack the private key, it'd be a much bigger issue than a few wallet emptied. It'd be a tremendous amount of wallets emptied, daily.
Can someone explain in more details?
How could reusing a nonce once lead to a full compromise?
Or is it only if the nonce is reused, but for the exact same transaction, with all the parameters identical, then signed using the same private key but some other random point?
Modern signature schemes such as EdDSA do not have this footgun as they specify a completely deterministic procedure for deriving a fresh nonce for each pair of (message, private key), simply by applying a cryptographic hash function to their concatenation. This is MUCH safer for the implementor, and also simpler to implement because one doesn't have to bother with maintaining a stateful PRNG
But...the interesting part. What happens when cross-chain asset movement is much simplified? I don't see there being any issue with legitimacy (original owners could still verify ownership, you couldn't). But if you flooded original chain with fakes, uh...
Talked myself out of it. nevermind
It is an interesting scenario to think through, in particular what happens with stablecoins etc. which would not be redeemable.
Ultimately, I predict such efforts to fail badly. The fact that e.g. Ethereum NFTs are copied will in fact work against such a fork getting traction.
So there would be very little reason to duplicate a chain for that. You can already get the free stuff and you can’t copy the rest because clubs will look at their register not yours.
*Would this actually work? Not a Ethereum/Bloclkchain guy myself.
2) Unless you are a malicious BTC\ETH mining node that got the future transaction (which uses the nonce again), it will be too late. You will learn about the re-use only after the blockchain update propagates.
It may assume some knowledge of things like etherscan and the EVM though.
It was a scam.
I wonder how it was done, Etherscan didn't show anything and compiling it led to a few bytes of difference between what was compiled and what was deployed.
[1]: Like this Unicode RLO exploit for instance: https://krebsonsecurity.com/2021/11/trojan-source-bug-threat...
[2]: https://tenderly.co or mainnet forking using hardhat are convenient ways to achieve this.
Fortunately, there are tools like Ganache, which you can run with `ganache-cli --fork` to reliably emulate locally what will happen when transactions are sent to mainnet. I would accept no substitute approach when dealing with suspect contracts.
That bot is doing pretty bad in such an active year
One thing to check about the other addresses is if they compromised themselves on other networks like public testnets or other blockchains