Beanstalk cryptocurrency loses $182M of reserves in flash ‘attack’
theguardian.com
theguardian.com
Sounds like when I was a kid and my brother would make up a game with vague rules, but when I'd pay it in a way he didn't expect, he'd say, "no not like that!" and call our mom.
Congrats to whoever found the loophole and made nine figures!
Beanstalk apparently set up what amounts to staking system for votes. More money == more votes. Have enough money? Well, then you have the majority of votes and can do whatever you want.
This is precisely how the system was designed to work. They just didn't foresee someone building up a large enough stake to amass the voting power needed to undermine the system. And that is simply a failure of imagination and goes to show how naive these folks were.
The way this works in the real world is you have a limited number of shares that give individuals some number of votes, and those shares change hands. In order to build up a large enough position to control a company, you have to convince existing owners to give up their stake or vote with you.
But if every dollar contributed to a "silo" creates a new vote, then yeah, you're basically saying: If you're rich enough you can take control of the project by simply amassing a large enough fortune in the project.
There's probably things they could've done to reduce the likelihood of an event like this--e.g. requiring supermajority or unanimous voting for certain types of changes, for example--but they didn't, so here we are. The system worked as intended.
And yes, I really mean "intended". They intended for people with more money to have more of a voice. And this is the (extremely obvious) consequence of that choice.
The only money you would need is the cost of gas.
flash_loan(int amount_borrowed, func arbitrary_trades)
1. give LOANEE_ADDRESS amount_borrowed
2. call arbitrary_trades()
3. give LOANER_ADDRESS (amount_borrowed + interest)
When 2. is executed, the loanee has the money. When 3. is complete, the loaner has the money back. If the loanee doesn't have the money to give, 3rd step fails. And since its atomic, the whole transaction fails.
A single atomic transaction does:
1) Borrow $80M 2) Use $80M however you want 3) Return $80M + loan fees (e.g. on Aave this would be 0.09%)
The lender is algorithmically guaranteed to get the money back and the borrower can potentially take advantage of large scale transient opportunities, or...just wreak havoc on a poorly secured system.
More info here: https://docs.aave.com/developers/guides/flash-loans
(I don't know what the second question means or what your mental model of a "real" currency is)
You're assuming that it wasn't intentionally designed that way.
The regularity of these events should makes it impossible to believe that they're all accidents... it's also not possible to figure out exactly which ones are and which aren't, which is itself no accident. (Or in which cases a third party exploited the vulnerability prematurely...)
Particularly so in that the advertised functionality of the system was obviously a non-sustatinable ponzi scheme... It was always going to explode, the only uncertainty would be how.
If that happens, and you used some kind of personal credibility to set it up, you've missed your shot.
Just a python script to avoid that artificial inefficiency entirely.
Also as the other user posted, gas fees would cripple you on Ethereum. Pretty sure I spent $50 sending some money somewhere earlier.
So then you need an identity verification system, or at least some practical difficulty in creating many accounts without getting caught.
A supermajority was required. The attacker purchased enough LP tokens to secure one. At the moment of the attack they held about 70% of voting power.
Unanimous voting wouldn't have been particularly useful because it would never be used. You can't ever convince every last investor to log in and pay gas to vote on a governance measure.
There was a protection in place, which was that the measure must be up for 24 hours before it can be passed. But the critical flaw was that the contents of a measure can be swapped out by a supermajority token holder, even after the 24 hour cooldown period. The attacker threw up 2 measures, one pointing to a nonexistent contract address, and another dummy measure as a diversion that would have transferred $250,000 to Ukraine and $10,000 to a wallet they owned. The diversion worked, and everyone spent the 24 hour period discussing why someone thought they could hoodwink the LP token holders into swindling $10,000 from them, and more or less ignored the second measure. Then, during the attack, the attacker deterministically created the treasury liquidation contract at the formerly blank address and used the flash loaned supermajority to pass it.
Second, I am curious:
> There was a protection in place, which was that the measure must be up for 24 hours before it can be passed.
So what happens after that 24 hours? The way you've described it here, it sounds like there's an up/down voting system after the cooldown period to either confirm or block the proposed measure, but it's not clear to me how that works. Who has control over that final decision?
>So what happens after that 24 hours? The way you've described it here, it sounds like there's an up/down voting system after the cooldown period to either confirm or block the proposed measure, but it's not clear to me how that works. Who has control over that final decision?
Anyone with at least 0.15% (IIRC) of voting power could propose a measure, at which point it would show up on the web app frontend with every LP token holder's vote defaulting to "No". It would have to accrue "Yes" votes from holders of >50% of LP tokens within a certain time period to pass. Alternatively, holders of >2/3rds of LP token could force pass a measure immediately, though this wasn't implemented on the web app frontend. But each of these was subject to a 24 hour period -- no measure that hadn't been proposed at least 24 hours ago could pass, even by supermajority.
And I assume the decoy proposal was just a means to ensure no one realized what was going on and themselves use a flash loan to reduce the attacker's voting power below the 50% level needed to pass the proposal?
My favorite take on crypto commodity is that “They’re recreating and failing to solve problems that have been solved in traditional banking for hundreds of years”.
Maybe there is some upside where this is just all growing pains, or maybe it’s all garbage all the way through, I don’t know.
But it’s clear to me that technically smart does not mean economically wise.
So how long until the crypto speedrun of financial crises reaches, and then surpasses, the regular financial system and we see financial crises that haven't even happened yet in the regular financial system (but are likely to happen at some point in the future)?
They also didn't do any research on why a mountain of legislature, regulation, and case law that protects minority shareholders exists.
By the time you're playing with nine figure sums, one would expect that to be something they should have looked into!
Well, no, because the assumption among crypto libertarians is those laws and regulations are a product of a government that's a) incompetent and/or b) corrupt.
If you take it as a first principle that the current system is the one that's broken and that you're part of a grand mission to reinvent it, of course you're not going to waste your time trying to learn from it.
What basis would they have for calling this theft?
The sad thing: These aren't just anonymous crypto bros on a beach losing their tokens through theft, rugpulls, crashes, or other vulnerabilities. A lot of ordinary people are burning up their savings on these schemes (enabled by platforms like Coinbase and OpenSea and even Venmo) even as they urge other suckers and family members to get in on it.
Not their fault that they read the contract more carefully than the contract writers did.
This was not related to the contract behaving in unexpected ways.
They figured human nature would keep them safe. And that no one who could muster the capital to perform this action would want to, and anyone that would want to wouldn't be able to muster the capital.
Technically, the risk of borrowing that amount of money is high. As is the risk of investing that amount of money into one coin. They figured anyone that would even begin to attempt something like that would operate in good faith. No way they'd tank the coin, because they have so much skin in the game.
Well, that doesn't matter when you can take your skin and go home. Not to mention the skins of everyone else, wearing them Hannibal Lecter style.
* Started with currencies that didn't allow flash loans. * Made a "we feel good about democracy of involvement" rule that supermajority could make any decisions with the funds "because we like people who invest in our work." * They added two currencies that supported flash loans. * Person or persons with currencies used flash loans to gain supermajority to transfer the funds out.
This is why banks are inefficient. There are (in theory) safeguards to transfers make it possible to stop or reverse activities. DeFi is forever going to be dealing with these issues after the fact.
Seems like in this case the outcomes were entirely predicted by the "attacker".
AFAIK but speculating every programming language has primitive recursive arithmetic.
There is no theory that says that there does not exist a program whose behavior can be predicted. We have just criminally underfunded research into formal verification; and somehow decided that even computationally limited, code is law programs handling millions of dollars don't need any type of formal verification
I don't really see how this is different.
Code is not law.
If you're not into the cryptocurrency mess, this reads like regular old hacking. "If code is law and your code allows me to execute arbitrary SQL queries, then this SQL injection is perfectly legal" doesn't hold up in court. The FBI will not let you go because technically you only asked the remote server to execute your request.
It does invalidate the "code is law" concept, but in the real world, code isn't law.
"Manipulating" doesn't seem like the right word here.
This is more like a billionaire buying up a popular social media platform and then once he owns the majority of it, deciding how it should operate.
Looking at the Terms and Conditions as well as the contract, this goes under "A fool and her money". There was no embezzlement at all, this contract literally said people with more money can potentially vote to take all the money. Which is madness, but people agreed to it.
Which is illegal, and will get you sued if you try it.
Code is not law, but this “attack” isn’t abusing the code so much as the basic premise of what the code is designed to do. This is the intended agreement
Here's the challenge, though: it is impossible to definitively say whether the functionality of a program is intended behavior or not. For a classical server that gets "hacked", the code is running on a server that someone owns and access to that server is defined by the owner. Similarly, the maintainer of the code decides whether the behavior of the code was intentional or not.
On a blockchain, there is no single server, the code is being executed on many machines. And you can't trust any individual, the author of the contract got their chance to clearly describe the intention of the code when they wrote it. There is literally no way to determine whether the contract was used as intended, or exploited. You can't go ask the author because they can just lie. The code is all you have.
But that doesn't mean "code is law". Consensus is law. The blockchain can be forked, the transaction reversed, and the contract amended.
> in the real world, code isn't law.
That hardly matters here.
No; the law is the law. What exactly do you intend the content of the statement 'consensus is law' to be? The world 'law' has a meaning, and it's distinct from the meaning of 'consensus'.
The whole idea that you'll replace the existing legal structures with some consensus of transaction miners is some apocalyptic nerdvana with no basis in the real world.
Cryptocurrencies claim to be something else. Something that isn't government by terms of service, laws, etc. How else could you create a worldwide decentralized currency without adopting a rule that code is law.
My main objection is calling it law: if you’re scammed while purchasing illicit substances on a darknet marketplace, you have no legal recourse, but the marketplace’s rules can’t be called “law”, either.
No, it's not.
At best, there is some kind of implied-in-fact legal contract related to to the code in the “smart contract”.
“Code is law” is an aspirational slogan repeated by people who fetishize the former and oppose the latter, usually without understanding it (or either.)
You can have a contract that both parties thinks says one thing, but they each have something different in mind. That's a failure of mutual assent. You can have contracts where the thing which is contracted on becomes impossible. One party can misrepresent the contract, either deliberately or innocently. The contract can be agreed to under duress; or be so uneven in its obligations that is manifestly unconscionable.
To a greater or lesser extent, all these scenarios can give rise to rescission of contracts or their avoidance in courts of law. The idea that code is an unambiguous statement of the contract and therefore definitively legal and perfectly binding is nonsense.
The question isn't, "once we get these people in a room, how do we (as a legislative body) decide who owns what and compel the parties into cooperating?" The question is, "these parties are assumed to retain perfect anonymity, and they operated according to the design of the consensus-based system that we (as miners) agree to; are we ok with the outcome? Should we come to a consensus on an adjustment to the design?"
Smart contracts are unambiguous by definition. What you're describing is PEBKAC at best.
It doesn't matter whether the contract is unambiguously written if you sign it with a gun in your mouth.
There's no way to do this in code. You need a judicial system to make determinations on them based on facts. There is no "adjustment to the design" other than incorporating some kind of arbitrary undoing capability into smart contracts that defers to a legal oracle that consumes decisions of courts and applies them into the chain.
From the little I know of this case it seems likely that this should have been governed under securities law and all participants should have been kyc'd. If that didn't happen then it looks like someone was committing securities fraud.
The only real question is whether the machines think one bullet to the head is most efficient use of resources, one bullet per organ, or an equivalent mass of non-depleted (they don't care about radiation, the biosphere is not their problem) uranium to the target biomass.
In the same way that a serial killer is a “psychopath is law” problem.
The problem with both descriptions is that both use “law” to mean “something that happens and has consequences” rather than, well, law in any more specific sense.
> Smart contracts should be considered self-funded bug-bounty platforms.
[1] https://www.newyorker.com/magazine/2018/08/20/how-bill-browd...
There's a reason why "do what thou wilt shall be the whole of the law" is not the guiding principle for Western society.
So the true spirit of cryptocurrencies is that if there's a flaw in the smart contract, it's okay to exploit it.
In a way, every security measure at a bank is because of a previous attack. Those “undocumented pen testers” did help create the security.
these crypto heists exploit loose rules.
That's the point. It isn't, except in some fantasy world that does not exist.
Let me put it this way: if you don’t think you could tell a judge this without getting laughed at, while you’re wearing an orange jumpsuit and ankle bracelets and chains, it’s probably not real.
I also can't help but wonder whether these sorts of activities would be prohibited conduct under the Computer Fraud and Abuse Act, 18 U.S.C. 1030(a)(4), as the elements seem to be met:
"[Whoever] knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value" - where "authorized access" is liberally construed to mean the intent of the author of the mechanism in question.
Code I Laws just means that if code was executed in the way it was intended to work and you don't like it you don't revert your blockchain. You keep blockchain as is, because it's nature of blockchain. But you're free to go to the law enforcement guys, courts, whatever, to enforce government laws if you think they were broken.
Nature is decentralized. But if you car was burglarized, which is perfectly fine under laws of nature and the glass physics, you still call the centralized police.
That's people who lost the money can say. They call it attack, so I guess they have some grounds. And then the court decides who is right.
At least they've sped up the normal leveraged buyout and corporate looting from months to mere seconds.
The same thing happened after the financial crash of 2008. Banks demanded to be bailed out because of the systemic risk to the American financial system. But when people started to demand that banks claw back the bonuses paid out, the banks said no. They claimed that would be government overreach.
Ah, the irony....
I’m curious why controlling levels of the token were on the market, and I have to assume that’s what the creators didn’t account for: the possibility that the people who were supposed to manage this thing would be buyable at a realistic price. I’d also ask why there wasn’t some kind of time delay on important decisions like that? It’s pretty bizarre.
It doesn’t help that smart contracts are just not super easy to build. They’re just easy enough for you to think you can, but when I’ve dug into the actual complexities, it’s been pretty rough. It’s especially hard when each op costs gas, so you’re having to focus on security and efficiency at the same time. I have to imagine it disincentivizes more complex business logic around managing a DAO, like you’d expect for something like this.
From the article:
> A still-unidentified attacker had borrowed $80m in cryptocurrency and deposited it in the project’s silo, gaining enough voting rights in exchange to be able to pass any proposal instantly.
I’m not sure but my guess is that they basically had an uncapped token that mints in exchange for deposits, and that’s used for voting. So you didn’t need to buy off existing holders, just deposit more than everyone else put together and mint more tokens than have previously existed.
Zero risk for the lender.
Now, the borrower doesn't only have to put the borrow and repay calls into that one transaction. They can put anything in between, for example interacting with Beanstalk.
I can get loans on my assets to participate in defi, arbitrage, & and literally cash out my money into a bank account if i so wished. Pretty useful.
https://www.coindesk.com/learn/2021/02/17/what-is-a-flash-lo...
[0]: https://medium.com/@omniscia.io/beanstalk-farms-post-mortem-...
[1]: https://web3isgoinggreat.com/?id=beanstalk-farms-stablecoin-...
Even a reasonable cost incentive may not be sufficient if enough of the controlling stake is available to borrow, or there's enough liquidity to allow someone to buy, exploit, and resell a controlling stake within a single transaction. That aspect is unclear in this scenario. Did the attacker repay the flash loan with stolen funds (netting ~$100m) or were they able to resell (unwind? return?) the controlling stake within the single transaction? If the former, shouldn't there be $80m floating around (former) holders of 'beans' to at least partially recover? If the latter, how was there enough liquidity to buy + resell a controlling stake's worth of tokens?
The pricing of widely known crypto is pretty dubious as it is. Pricing for off-brand cryptos is more marketing than fact.
> Others were encouraged to deposit cryptocurrencies such as ether into a “silo” to build up the stablecoin’s reserves in exchange for voting rights over the operation of the organisation.
I’m not sure exactly what their reserves consisted of, but it could be mostly ether and similarly liquid currencies, rather than random ones. It sounds like the thing they stole was their non-random-currencies reserves that were supposed to be able to maintain the peg.
People worth their salt have known proof of stake has been broken for many years.
Question 1. Why do people trust the founders of these scams?
Question 2. Why do we refer to them still in mainstream discourse as systems that even qualify as cryptocurrencies?
Because a sizeable part of the population that doesn't care about cryptocurrency but cares about climate change has been sold on the idea of it. They were told that PoS can get by without the energy waste of PoW.
Marketing for PoS was pretty good.
Q2: Agreed - this does not qualify as "cryptocurrency".
Is this more like 182 very wealthy people (i.e. worth $10s to $100s of millions) losing $1M each, or is it more like 1820 people losing their $100K life savings into this?
Well, that rescue package better be at least $500 million this time, or the guy's already written the code to do the same thing again, but $182m richer...
They fell for the Proof of Stake / Ayn Rand fallacy which is the assumption that anyone with a lot of money is a good person.
Btw, that's why proof of stake is so complex. They have to do all these complicated hacks to get stakers to be good.
[0] - https://www.investopedia.com/terms/p/proof-stake-pos.asp
[1] - https://twitter.com/FrankResearcher/status/15156938958872944...
TL;DR: Beanstalk violated several commonly known best-practices and are now suffering the consequences. This kind of economic vulnerability can barely be called an attack - certainly does not clarify as a "hack" and it's several years since the community learned from bzx and similar almost identical incidents what happens when you make irreversible decisions based on on-chain price oracles like Curve (which is jot the fault of Curve - they should just not be used this way!)
Hopefully the FBI recognizes this. If anything, Beanstalk promoters are responsible for irresponsible marketing and shifting blame.
> The lightning hostile takeover raises fresh questions about the unregulated nature of digital currencies and the lack of protections for investors.
No it doesn't. It's quite clear that there weren't any protection mechanisms at all. The kind of investors who put funds into contracts that can have those funds transferred out at the whim of a threshold of governance votes that are tradable on the public market must be aware of these risks - in particular sine it's the umpteenth time that in principle identical scenarios have played out over several years now.
No. How would that even work? Did all the beanholders conspire together to frame this hack? Even if they did, what they'd end up with is transforming a bunch of clean money into a bunch of dirty money. The point of money laundering is usually to do that thing in the other direction.
Yes, exactly, and that is distinctly different from your earlier hypothesis that the whole thing may have been a conspiracy to money launder on behalf of the people who lost money.
> Can these "losses" be used to avert taxes on the part of the "investor"? If the pain of the laundering is less than the potential tax avoidance then you might have a profitable laundry outfit.
Look, if this was a single person who claimed to have lost a bunch of crypto to a hack, then you might plausibly weave this story, but it's not a single person. It's a bunch of random people. This bunch of random people didn't collude together to fake a hack to create tax losses to offset their realized capital gains from somewhere else. And even if they did do that, that wouldn't be called "money laundering", money laundering is something they would have to do later, to hide the origin off their newly-ill-gotten wealth.