Beanstalk Farms stablecoin project loses $182M to exploit
web3isgoinggreat.com
web3isgoinggreat.com
How on earth can people just shake off a loss of $182MM? And is this one of those contracts? Have the courts ruled that code is law, and that a poorly implemented and exploitable contract is legal? There is so much wrong with this.
None of that happens with crypto, which has lost more money in scams than Wall Street has in a decade, despite being a fraction of the size of Wall Street.
Yes but that is irrelevant.
It is unfortunate this happened of course, proper security audits of your smart contracts is very important in cases like these.
I think both are "huge" news, but the "rebuttal" does not add any weight to the argument because they're not comparable.
Yes, they are. Things don’t have to be the same to be comparable. People compare them all the time and very reasonably so. “Should I put my money into traditional finance or defi? What are the pros/cons?”
An axis that should be compared when choosing a finance system is “how likely is my money to disappear?”. A single event where an amount of money that’s this fraction of the overall system and this much value is a newsworthy, meaningful, relevant, comparable event.
I have no issues with this question, because you want to compare the two and find out what properties suit your goals.
> An axis that should be compared when choosing a finance system is “how likely is my money to disappear?”.
This is not what was being discussed, but it is certainly an important question to ask if that is the choice one is making.
> A single event where an amount of money that’s this fraction of the overall system and this much value is a newsworthy, meaningful, relevant, comparable event.
We already agree that the two events are newsworthy. The thing we disagree on is the following: If 0.1% of traditional money is stolen is newsworthy, then this adds further evidence that 0.1% of DeFi money being stolen is newsworthy. I don't agree with that.
It's not better that there's actually a planet-changing volume elsewhere in similar jeopardy. We should be howling about the anti-features baked into these things that enable criminal enterprise.
Based on current US inflation rates, that’s about 4 days worth of inflation. So, you could probably blame the Fed for “stealing” that much in one swoop.
And how do you come to that conclusion?
Too bad nobody seems to care much about it because the numbers don't go up.
Visa's fees are 1.4%-2.5% for the merchant where Monero's median fee over the last 100 transactions was $0.002.
And what is the half life value before that money ends up disappearing because of a hack, wallet mismanagement, or a straight up scam, or ending up being seized by the FBI?
Considering the ridiculously large percentage of Bitcoin that belongs either to the FBI or Mt Gox scammers, and the massive number of other scams in crypto, I bet once you adjust for those factors the value will be minuscule.
Not sure how that's comparable to Visa, Visa doesn't handle conversations at all between different types of currencies (you can't convert USD to BTC with Visa for example). It all happens via 3rd parties, just like with cryptocurrencies, so it depends on the 3rd party more than anything else.
> And what is the half life value before that money ends up disappearing because of a hack, wallet mismanagement, or a straight up scam, or ending up being seized by the FBI?
Neither of those things have happened to Monero, and since the project is relatively old (for the cryptocurrency space at least), it seems safe to say that they generally know what they are doing, or we'd seen more hacks.
I think the original claim still seems right. Monero both settles faster and has lower fees (depending on the amount for the Visa transaction obviously, as it's percentage based, while Monero as a "flat fee" [based on network activity]).
The key step was: "Further, they deployed and voted for a fake BIP-18 that moved all funds from the protocol contract to the exploiter."
EDIT: More context here https://twitter.com/peckshield/status/1515692144190648322/ph...
The dissimilarity of pension funds & banks is present, and so there's no opposition to that objection.
> But it's a personal annecdote, so really it's up to you what made you lose faith in "the system".
I'll admit my pro-crypto stances upfront, but the anti-crypto stance of "Oh it's just your opinion that 'the system' messed up" is highly non-conducive when it comes to getting people out of crypto & trusting the current financial system once again.
To those people, their rightfully legitimate concerns of corruption, non-transparency, & failure to even partially repay the funds lost are dismissed as 'anecdotal', much like the concerns of every privacy-concerned individual before Snowden's leaks were made public.
To that end, verall, your dismissal of the parent's experiences as anecdotal will sour the opinions of the concerned & cause them to dig in their heels even further. It does not help alleviate their concerns, nor does it help in re-establishing trust.
With regards to the actual improvements that I would like to see implemented in the current financial system, the creation of a triple-ledger accounting system [1] where transactions are anonymized-but-traceable would help a long way in re-establishing trust in the current financial system. The 3rd party in this picture wouldn't even need to be a blockchain: It would just need to be a neutral 3rd party that would make transactions on the aforementioned ledger transparent to the general public.
I don't trust governments and I don't trust banks. I want an economy that's completely independent of them.
Brasil actually fixed their inflation problem with Plano Real (Cardozo was finance minister at the time) which is one of the all time great stories of government intervention in an economy.
I'm not impressed by their plan. They simply created yet another currency and duped the population into believing it was going to be different this time.
The inevitable fate of all inflationary currencies is irrelevance. Its value will drop to zero and it will be replaced by a new currency in order to restart the cycle. It's only a matter of time.
Personally, I'd rather trust a system which can't be controlled by any one individual (or even a small group of individuals), over a corporate pension fund.
$20k? No delay other than getting the transaction through the mining pools or whatever. $500k? Maybe an hour to settle. $1m+? That’s going to take a day (in which time big red warning lights can flash on your defi project wall boards).
You're missing the point though: these defi systems are mostly scams right out of the gate. They're designed to be exploitable by their creators.
They're also designed so that the exploits are plausibly denyable-- so while we can look at the long long list of anonymous created defi ponzis that vanish with everyone's funds via similar attacks we can conclude that many were intentionally designed that way-- attributing it for any specific one is challenging.
But there is something positive to say about crypto too.
The failings of crypto teach a lot of people about how and why societies work the way they do. And that no amount of tech can ever replace our institutions and human trust.
I'm 100% with Stephen Diehl on this one: the entire 100% of crypto needs to be burned down to the ground. It needs to go because of the enormous harm it does to people and our larger society, for no gains at all.
Regulation, once it comes, will help better protect retail investors.
Crypto is still in the early stages, the technology is revolutionary though and I think it's here to stay.
Sure, if you want to focus on the negative you can focus on the negative.
well you’ve convinced me
To me it’s a shame though, crypto as a concept is very interesting in many ways. Algorithmic money, defined by serverless programs, not COBOL behemoths. Massively distributed, yet consistent mutable database. A space where you can bootstrap an idea on a shoestring budget. A bit like internet vs cable TV and trad banks.
Except in this analogy, the “crypto” internet seems to have gone straight from Arpanet to nothing but ads, child porn, dark net and gambling, skipping past Wikipedia, Google, dotcoms (when they were plucky upstarts not to vil conglomerates). Shame.
The examples you give mean nothing to me. What real problem is being solved by any of your examples of 'interesting'?
We already have something that allows you to bootstrap an idea on a shoestring budget: the cloud.
Summary:
> flash-loan attack due to a flaw in its newly introduced Curve LP Silos that compromised the protocol’s governance mechanism, ultimately permitting the attacker to conduct an emergency execution of a malicious proposal siphoning project funds
It was a super basic flash loan oracle manipulation, which could have been done by anyone, so it probably was just another Waterloo kid finding their fortune, but really, who are these people who dumped millions of dollars into magic beans?