Not their fault that they read the contract more carefully than the contract writers did.
Not their fault that they read the contract more carefully than the contract writers did.
> Smart contracts should be considered self-funded bug-bounty platforms.
[1] https://www.newyorker.com/magazine/2018/08/20/how-bill-browd...
There's a reason why "do what thou wilt shall be the whole of the law" is not the guiding principle for Western society.
So the true spirit of cryptocurrencies is that if there's a flaw in the smart contract, it's okay to exploit it.
In a way, every security measure at a bank is because of a previous attack. Those “undocumented pen testers” did help create the security.
these crypto heists exploit loose rules.
That's the point. It isn't, except in some fantasy world that does not exist.
Let me put it this way: if you don’t think you could tell a judge this without getting laughed at, while you’re wearing an orange jumpsuit and ankle bracelets and chains, it’s probably not real.
I also can't help but wonder whether these sorts of activities would be prohibited conduct under the Computer Fraud and Abuse Act, 18 U.S.C. 1030(a)(4), as the elements seem to be met:
"[Whoever] knowingly and with intent to defraud, accesses a protected computer without authorization, or exceeds authorized access, and by means of such conduct furthers the intended fraud and obtains anything of value" - where "authorized access" is liberally construed to mean the intent of the author of the mechanism in question.
* Started with currencies that didn't allow flash loans. * Made a "we feel good about democracy of involvement" rule that supermajority could make any decisions with the funds "because we like people who invest in our work." * They added two currencies that supported flash loans. * Person or persons with currencies used flash loans to gain supermajority to transfer the funds out.
This is why banks are inefficient. There are (in theory) safeguards to transfers make it possible to stop or reverse activities. DeFi is forever going to be dealing with these issues after the fact.
Seems like in this case the outcomes were entirely predicted by the "attacker".
AFAIK but speculating every programming language has primitive recursive arithmetic.
There is no theory that says that there does not exist a program whose behavior can be predicted. We have just criminally underfunded research into formal verification; and somehow decided that even computationally limited, code is law programs handling millions of dollars don't need any type of formal verification
I don't really see how this is different.
The only real question is whether the machines think one bullet to the head is most efficient use of resources, one bullet per organ, or an equivalent mass of non-depleted (they don't care about radiation, the biosphere is not their problem) uranium to the target biomass.
In the same way that a serial killer is a “psychopath is law” problem.
The problem with both descriptions is that both use “law” to mean “something that happens and has consequences” rather than, well, law in any more specific sense.
Code I Laws just means that if code was executed in the way it was intended to work and you don't like it you don't revert your blockchain. You keep blockchain as is, because it's nature of blockchain. But you're free to go to the law enforcement guys, courts, whatever, to enforce government laws if you think they were broken.
Nature is decentralized. But if you car was burglarized, which is perfectly fine under laws of nature and the glass physics, you still call the centralized police.
That's people who lost the money can say. They call it attack, so I guess they have some grounds. And then the court decides who is right.
This was not related to the contract behaving in unexpected ways.
They figured human nature would keep them safe. And that no one who could muster the capital to perform this action would want to, and anyone that would want to wouldn't be able to muster the capital.
Technically, the risk of borrowing that amount of money is high. As is the risk of investing that amount of money into one coin. They figured anyone that would even begin to attempt something like that would operate in good faith. No way they'd tank the coin, because they have so much skin in the game.
Well, that doesn't matter when you can take your skin and go home. Not to mention the skins of everyone else, wearing them Hannibal Lecter style.
Code is not law.
If you're not into the cryptocurrency mess, this reads like regular old hacking. "If code is law and your code allows me to execute arbitrary SQL queries, then this SQL injection is perfectly legal" doesn't hold up in court. The FBI will not let you go because technically you only asked the remote server to execute your request.
It does invalidate the "code is law" concept, but in the real world, code isn't law.
"Manipulating" doesn't seem like the right word here.
This is more like a billionaire buying up a popular social media platform and then once he owns the majority of it, deciding how it should operate.
Looking at the Terms and Conditions as well as the contract, this goes under "A fool and her money". There was no embezzlement at all, this contract literally said people with more money can potentially vote to take all the money. Which is madness, but people agreed to it.
Which is illegal, and will get you sued if you try it.
Code is not law, but this “attack” isn’t abusing the code so much as the basic premise of what the code is designed to do. This is the intended agreement
Here's the challenge, though: it is impossible to definitively say whether the functionality of a program is intended behavior or not. For a classical server that gets "hacked", the code is running on a server that someone owns and access to that server is defined by the owner. Similarly, the maintainer of the code decides whether the behavior of the code was intentional or not.
On a blockchain, there is no single server, the code is being executed on many machines. And you can't trust any individual, the author of the contract got their chance to clearly describe the intention of the code when they wrote it. There is literally no way to determine whether the contract was used as intended, or exploited. You can't go ask the author because they can just lie. The code is all you have.
But that doesn't mean "code is law". Consensus is law. The blockchain can be forked, the transaction reversed, and the contract amended.
> in the real world, code isn't law.
That hardly matters here.
No; the law is the law. What exactly do you intend the content of the statement 'consensus is law' to be? The world 'law' has a meaning, and it's distinct from the meaning of 'consensus'.
The whole idea that you'll replace the existing legal structures with some consensus of transaction miners is some apocalyptic nerdvana with no basis in the real world.
Cryptocurrencies claim to be something else. Something that isn't government by terms of service, laws, etc. How else could you create a worldwide decentralized currency without adopting a rule that code is law.
My main objection is calling it law: if you’re scammed while purchasing illicit substances on a darknet marketplace, you have no legal recourse, but the marketplace’s rules can’t be called “law”, either.
No, it's not.
At best, there is some kind of implied-in-fact legal contract related to to the code in the “smart contract”.
“Code is law” is an aspirational slogan repeated by people who fetishize the former and oppose the latter, usually without understanding it (or either.)
You can have a contract that both parties thinks says one thing, but they each have something different in mind. That's a failure of mutual assent. You can have contracts where the thing which is contracted on becomes impossible. One party can misrepresent the contract, either deliberately or innocently. The contract can be agreed to under duress; or be so uneven in its obligations that is manifestly unconscionable.
To a greater or lesser extent, all these scenarios can give rise to rescission of contracts or their avoidance in courts of law. The idea that code is an unambiguous statement of the contract and therefore definitively legal and perfectly binding is nonsense.
The question isn't, "once we get these people in a room, how do we (as a legislative body) decide who owns what and compel the parties into cooperating?" The question is, "these parties are assumed to retain perfect anonymity, and they operated according to the design of the consensus-based system that we (as miners) agree to; are we ok with the outcome? Should we come to a consensus on an adjustment to the design?"
Smart contracts are unambiguous by definition. What you're describing is PEBKAC at best.
It doesn't matter whether the contract is unambiguously written if you sign it with a gun in your mouth.
There's no way to do this in code. You need a judicial system to make determinations on them based on facts. There is no "adjustment to the design" other than incorporating some kind of arbitrary undoing capability into smart contracts that defers to a legal oracle that consumes decisions of courts and applies them into the chain.
From the little I know of this case it seems likely that this should have been governed under securities law and all participants should have been kyc'd. If that didn't happen then it looks like someone was committing securities fraud.