$34M permanently locked into AkuDreams contract forever due to bad code
twitter.com
twitter.com
With fiat currency, we have many systems for dispute resolution and restitution. They are not all perfect but they work often enough that people still have faith in the system.
Most people do not have the risk tolerance to use a system where one typographical error can irreversibly lose your life savings (for example), the product of decades of work.
The trust built into crypto is rock solid, the problem is that it's scope is so narrow and limited that even after a decade it's still searching for a major trust problem to solve. In this case you cannot reverse crypto payments because there is no oracle that can do it. You would need to find God's own API for reality.
I was however totally wrong about the future (monetary) value of crypto in early 2018. I guess sometimes it pays more to know less.
Edit: Also of course every single crypto org obfuscates and is opaque as possible about the oracle problem. I'd venture that most investing in the space don't know what it is.
You can have decentralized systems but because monetary wealth accumulation is centralized by nature, and any decentralized system that introduces monetary accumulation and inflation reverts to a centralized state.
A good example of this is Bitcoin. Those with the most liquid currency (fiat) can buy more hardware that centralizes wealth. You simply cannot have an MLM scheme without a pyramid.
Your entire post is about inevitable centralization but that is not the oracle problem. The oracle problem is about providing access to real life data on the blockchain, but the issue is that you still need to trust someone to provide that data. Maybe I am misunderstanding you but I don't get how that by design leads to the total financial destruction of most participants?
However the difference is that we can abstract away the oracle from the rest of the value transfer mechanism.
For example if we want to bet on the winner of the Super Bowl, in the old days we’d have to find a trusted third party to hold the money for us. Essentially a bookie. Finding a trusted bookie, especially one who’s licensed in multiple jurisdictions is really hard.
In contrast, we can probably find a trusted “oracle” for the Super Bowl much easier. For example AP is extremely trustworthy (largely because they’re not in the legally dodgy business of sports betting). As long as AP cryptographically signs the outcome of the game (as they do for all HTTPS served content), we now have a highly trusted oracle. We can handle all the other mechanics around betting and payoffs inside a trustless smart contract.
In fact we can take this even a step further and use multiple trusted sources in a multisig setup. The chance that AP, ESPN, NBC sports and Google all collude to lie about the Super Bowl is extremely small.
So while the oracle problem means we can’t completely eliminate the need for trust, it can drastically reduce the surface area of risk by abstracting away the informational layer from the value transference layer.
The bounty in crypto is only in cracking whatever chosen cryptography, and this is the very heart of crypto's provably rock solid trust. This bounty is worth trillions, but we known with a (very) high level of certainty that no one can claim it. You would have to have broken cryptography, or developed a sci-fi level computer chip in total secret.
How much can you trust a handful of news sources when the bounty for gaming them reaches the billions or hundreds of billions in value? What kind of person suddenly wants to become an editor when they get to wear one of the rings of power? (sorry I've been reading LOTR lately)
There is a simple calculus here (and everywhere) that shows that as the value of trust grows, so does the value of breaking that trust. Crypto solves this by making the cost of breaking that trust far outside human's capability. It probably would be be asking too much to introduce an element that suddenly makes that cost practically obtainable compared to cracking crypto.
Anywhere that it is legal, it is significantly easier than dealing with any blockchain. What you've stumbled upon is the reality that the only feature cryptocurrencies provide is opaque law enforcement, and that feature has a timer. Why would it be any easier for a blockchain to be licensed in multiple jurisdictions? The only difference is that the blockchains are almost definitely not licensed. I'm not sure what the statute of limitations is, but I feel like a blockchain holding accounts of illegal gambling is a pretty weird thing to want to create immutable records of, unless you're the FBI.
I looked into this use case before and came to the conclusion that it can't work because TLS is not non-repudiable. Once the initial public-key handshake is finished, the rest of the session uses a symmetric cipher. Because anyone with the symmetric cipher's key can encrypt their own data with it, you could encrypt your own spoofed response from the server in any transcript of the session.
https://crypto.stackexchange.com/questions/29751/are-https-w...
One solution to this is to use the site's public key to sign a Web Bundle instead of using TLS:
https://wicg.github.io/webpackage/draft-yasskin-http-origin-...
Web bundles can be served from any origin (and I'd imagine can be verified by oracles) as the data itself is signed. However, this requires the server to use web bundles in the first place, which likely isn't happening any time soon. Mozilla considers the proposal harmful: they expect Google will serve the majority of web bundles, allowing them to see what sites the user is visiting.
https://github.com/mozilla/standards-positions/issues/264
https://www.ghacks.net/2020/08/30/google-proposed-web-bundle...
While I will concede the example I give above is an extreme edge case, I would also argue that “who won the super bowl” is also an overly simple example.
Video is better explanation than the repos.
https://m.youtube.com/watch?v=HnrFsekayrM
So it could be done. Tho it would require the server to add support.
Repos: https://github.com/tls-n
I find it kind of fascinating to, for (made-up) example, place real-money bets not on the future of the price of gold but on what the contract at $ADDRESS will say it is in the future. Do people understand what they’re actually betting on?
I suspect deep understanding and clever interpretations of those specifics in crypto will be rewarded. Though crypto has the added excitement that, as here, poor understanding and interpretation result not just in loss of value but it’s destruction!
Sometimes banks freeze international wires until the government investigate the source of the funds to make sure they are not funding terrorism, this happen to any sum higher than $5k in my country for example. I just wish to never be in such a position.
If crypto is to be legitimized, the government isn’t simply gonna say, too bad, the stuff we think is absolutely necessary to the point we suspended civil liberties for, that stuff we will ignore for you.
Whether you agree with what the govt is doing or not, they aren’t gonna stop doing it because it’s crypto.
This happened to me when purchasing a house in another country.
Missing the point.
People need to look at this as like chartering a 17th century galleon. It sank. Gold was lost at sea, unreachable by todays tech. Maybe in 200 years someone can crack ECDSA and recover it.
Not everything needs to be sanitized for one’s safety.
Also the current system at least has the potential to be improved, maybe. While irreversibility is baked into the ideology of many (not all) proponents if crypto.
Did you mean reversibility? Because otherwise you're agreeing with me: I'm saying irreversibility is easy, often the default with crypto Yes, that is what I am saying. In traditional banking reversibility is easier, and (mostly) the norm for situations of standard human error.
In the case of this particular contract a limited form of reversibility is even what was intended, but that doesn't matter. It's a system that doesn't allow for honest error.
For some, that's a feature. For the vast majority required to take smart contracts mainstream, that is not a feature. Better error resistant reversibility can be built, and that's when things may become attractive to more people. But, again, many proponents view irreversibility as a feature so it's not primary consideration when building things.
You can't sue a typo.
I don't need to sue as long as I get my money back.
However, it's going to take more than 150 calls and a lawyer to hard fork the ethereum chain to roll back this contract.
Perhaps a class action lawsuit can force the auctioneers to pay back the money despite not having access to it themselves. Either way, there's literally no way for the misdirected cryptocurrency to ever return.
You are replying to somebody who said literally the opposite: "They are not all perfect"
How is the average person expected to feel comfortable doing it?
Without deep knowledge of the crypto space, and excellent operational security pratices, putting a significant amount of money into these projects is a risky prospect.
For many people that's not a sensible trade-off.
FWIW the risk profile is different than interacting with something like WETH contract, which has had an $10+ billion USD open bug bounty for long time frame.[1]
[1] https://etherscan.io/address/0xc02aaa39b223fe8d0a0e5c4f27ead...
If you have basic common sense though you'll probably be ok.
If the typical NFT buyer has their 'Ape' stolen they have to spend tens of thousands of dollars buying it back.
Thought experiment: a bug is exploited tomorrow which locks forever $50 billion worth of ETH, including of prominent VCs/users/exchanges.
You will see suddenly how consensus crystalizes to do a hard fork reversion of the exploit.
Close, but not quite. It's not a democracy, it's a plutocracy. Things are only reversible when those few who hold the majority of the wealth are impacted.
In this case, on a layer 2, the contract code could be updated, but only if those with locked ETH vote for the upgrade to be processed. Better yet, the Layer 2 could allow ETH to be withdrawn from the contract by the owners and the contract itself could be deleted.
I think the general, technically-informed public often miss the distinction between Layer 1 and Layer X and how they differ in the need for decentralization and censorship resistance while still providing users with security.
If you work in the space you realize only a tiny fraction of wealth gets lost to bugs. This $34M is roughly 0.02% of the wealth locked in smart contracts ATM.
But when the alternative is a dictator arbitrarily seizing/taxing your money, devaluing it through poor economic policies, the risk doesn't seem so bad eh?
> But when the alternative is a dictator arbitrarily seizing/taxing your money, devaluing it through poor economic policies, the risk doesn't seem so bad eh?
I'm skeptical that reducing (at the margin) the pressure to transact via (and thus expand use of) free society's institutions is a particularly good side effect.
This might be true without mattering much -- most people don't have decades of savings. If you're not willing to lose the product of decades of work, but you never have more than a year worth of savings, what does your unwillingness mean?
But crypto should become smarter for real world use case than just following "logically right" rules like some rescue protocol that without a receipt signal, it gets rolled back.
<https://bam.kalzumeus.com/archive/no-payments-are-final/>
> Of course wires are reversible. They were not designed by children, but by professionals who live in a society which has systemically important institutions, and in the event of malfeasance or mistakes society does not tolerate a bank failing or a state missing payroll simply because someone said “no takesies-backsies” fast enough.
> Mistakes happen! By, conservatively, the hundreds of thousands daily across all payments systems, millions depending on your definition of mistake. Wire transfers, like almost all payment systems, explicitly contemplate them and have a sociolegal ritual to quickly reverse them.
> The ritual is called “hold harmless” and comes from a soft guarantee about the wire transfer ecosystem, which is that transactions are largely between sophisticated counterparties acting in good faith, intermediated by institutions whose probity is almost sacrosanct. Importantly, wires are in expectation worth having a human in the loop for; that is very not true of most payments.
> It took the combined forces of several agencies of the federal government more than five years to reverse ~$4.5 billion in Bitcoin transaction
Unlike the Bangladesh Bank hack, for example, which they were unable to reverse.
Taking any one scenario where it didn't work out that way is highly selective cherry picking. There is not functional equivalence between "almost always impossible" and "almost always possible".
For the actual topic, I don't have any respect for these ICOs/mints/[newest renaming], they're shameless cash grabs with 98% marketing and 2% upwork-tier code. However, you can burn a million quid; I don't think it's a big deal that you can burn 34 million in digital currency due to extreme negligence.
That's fair, I just see lots of discussions where single examples are used to (often literally) say "that's no different from other finance".
And I agree reversibility can be built for crypto, it's just that right now that is not the norm, and defi probably won't see wide adoption until that changes a bit.
KLF much?
Elaboration: https://news.ycombinator.com/item?id=31139114
And of that hack, I think something like 90% of the transactions for stolen money were reversed, but a significant portion got through because of the timing.
edit- and IIRC the whole thing was caught because of a typo?
A better summary might be "transactions are reversible in more cases than you would expect."
Also, transactions that aren't reversible at a low level are often reversible at a higher level in the stack.
Now try the same scenario when you’re an ordinary Schmoe who wired money to an obvious scammer, and then tell me whether you still believe Patrick’s model of the banking system as a giant kumbaya circle run on gentlemen’s agreements to Do The Right Thing.
The destination of a fraudulent wire will be known, but that money is practically unrecoverable if it takes another hop or gets withdrawn.
I don't want the later for anything I consider a large financial transaction.
Now, imagine this: an error in a transfer contract locks away funds, not only from victims, but also from phishers. What a beautiful world to live in.
> The unforgiving-ness and irreversibility of cryptocurrency are the reasons that it will never gain significant adoption by “normies”.
Exactly. Such that bank / wire transfer, didn't take off or gained significant adoption by normies?
> With fiat currency, we have many systems for dispute resolution and restitution. They are not all perfect but they work often enough that people still have faith in the system.
Chargeback fraud for both the consumer and the merchant is good as well? Is that why when the payment processor encounters tons of friendly fraud in a merchants account they lock up your account and you're unable to accept payments anymore, effectively killing your business.
The bank doesn't even know if the chargeback is fraudlent or not and will take the money from you regardless of you wasting time countering the disputes to prove that it is fraudlent. Thus, it hurts both the merchant and the consumer and that system can be abused.
> Most people do not have the risk tolerance to use a system where one typographical error can irreversibly lose your life savings (for example), the product of decades of work.
Yeah, most businesses and banks are doing just fine with the reversibility of wire transfers aren't they? [0]
ACH has reversal built in. Wire transfers are harder but there are remedies through the legal system. In neither case is the money simply locked up and never usable again.
If such insurance/service guarantees are of interest to the market, they will be provided.
The weird thing is people associate Visa transactions with business that are real legal entities that have contracts with Visa and you could sue, but as soon as you say Bitcoin they assume every transaction is like a Nigerian prince scam. These associations are the result of effective marketing by people who want you to feel that way.
>The bank doesn't even know if the chargeback is fraudlent or not and will take the money from you regardless of you wasting time countering the disputes to prove that it is fraudlent. Thus, it hurts both the merchant and the consumer and that system can be abused.
Merely because the US system of handling chargebacks is dogshit and your companies have taken to making processes so unpractical that chargebacks are common practice. European banks perform 2FA checks for online purchases, and chargebacks are harder to execute, while still doable.
But sure, throw the baby with the bathwater, the bath, the house and the city's water system because you forgot to decrement a counter in a shitty contract.
The kind that can take into account intent via the courthouse mechanism is smarter.
Truly sorry for the digression, just wanted to know what others think, and not blaming you or anything. Spoken languages are weird, even weirder than cryptocurrency contracts with accidental bad logic - the weird logic in spoken languages seems somehow desired.
Like always you can insult and hurt people with "clean" language and use vulgar words in non-offensive ways. But say what you want, I'll keep calling "smart" technology trash ;)
There's lots of names that have acquired negative stereotypes before. In my lifetime the name "Mike" at one point basically meant asshole (not so much anymore) and "Bob" basically meant boring, and "Patel" was a catchall negative for anyone from India.
There's even research on some of the nuances of the phenomenon. [1]
This isn't an aspect of internet mobs, it's an aspect of human nature, or at least society in general.
The Internet may shine a light on our flaws, and provide some new outlets for them, but it doesn't really create new ones, we brought them with us, like settlers from Europe going to the "New World" to escape the plague only to find they brought it with them.
[1] https://www.tandfonline.com/doi/abs/10.1080/00224545.1996.97...
These things tend to happen.
Of course, I don't want a bulletproof contract imposed on me. It's better if "our standard contractual terms" are vague, so that I can sue suppliers. But if it's a private, custom contract, then I really need to know beyond doubt what it means.
My problem with blockchain "contracts" is that they don't seem to be able to affect (or be affected by) the real world - fiat bank accounts, delivery of goods in working order, etc. They only seem to affect digital pictures of monkeys. I suppose that simply means I don't "get it".
The vast majority of business is performed under implicit or explicit contracts without any disputes whatsoever. We’re talking billions of interactions per day.
Courts are there for the rare occasion when a dispute occurs. There are many kinds of disputes, but one occurs when there is a complex agreement that was drafted either vaguely or incorrectly. This happens because human beings are imperfect; unforeseeable events occur; and because the language in which the contract was drafted might be vague or capable of multiple interpretations. Court hearings give the litigants the opportunity to provide evidence and context so that a judge can decide the fairest outcome.
So we don’t need courts to do business, but they exist because we need some peaceful way of resolving disputes. The alternative is violence.
There is a whole industry of arbitrators for hire. They are usually specialised in some field of business, so they don't need bringing up to speed. And they're all experienced lawyers. The work is nearly all paperwork - submissions, affidavits, disclosures. There is rarely a face-to-face hearing. It's more like doing accounts-receivable than sueing someone's ass.
"Just business", as some mobster might have said.
Since software will always have bugs, how do developers of smart contracts intend to fix this kind of problem? Does anyone actually have a solution to this?
Only bad news sells. A $35 million bug makes it to the front page, but how often do you hear about Uniswap processing $1+ billion in trading every day without a single hack in 5 years.
In general, there’s actually been a sustained improving trend of fewer hacks, higher likelihood of recovery, and lower losses as a percent of assets. The headline numbers may be higher, but that’s largely a denominator effect of the meteoric growth in on-chain assets. It’d be like judging New York City based on how many murders are in the paper instead of the murder rate.
This leads to bugs or exploits often ending up in these "contracts". The concept is inherently flawed, as they can't be updated and can't be reevaluated or reinterpreted by e.g. a court. The money's just lost.
This is the way it seems to me too, but I just can't understand how a flaw this obvious could be overlooked by so many people? Surely we are both missing something?
In truth you can write code that is upgradable or ammendable, but always within limits of Ethereum transactions being immutable. However, when a project wants to emphasize that immutability, because that's perceived as the need by the users and the devs, then you end up in this situation.
So, as usual, the problem is solvable with a little diligence. The challenge is for crypto culture to get over itself and mature and actually perform that diligence.
I will say that there are very mature, very well developed projects that you don't hear about getting hacked, because they take advantage of the wealth of experience that's been built on this subject.
If you're going to potentially lose tens or hundreds of millions, you need a lot more than a little diligence. Formally proved code (something along the lines of Ada with Spark Pro) is the bare minimum for something with some much money on the line, and even then I'd still prefer a traditional contract and leave things to the courts.
However, if Ethereum sticks around there will be standardized, off the shelf contracts for people to use that have wide-spread testing/adoption. Once we reach that level of maturity then it could make sense to use it for things like escrow on a contract/purchase.
I can imagine using ETH for escrow; but there has to be a human in the loop for escrow, to direct escrow funds to be released. I guess one could contrive a situation where a "contract" could autonomously determine when it had been completed. But that's not the general case.
Escrow, or an oracle (checking, say, FedEx delivery.)
Most people use them for their projects, but you don't hear about them because they don't make it to hacker news as only crypto pessimism is upvoted here.
Theres no difference between a badly codes contract and a badly written one that doesn't do what one signer intended. Short of you can try to convince a judge to adjust it or handle it differently.
In this case. There is no judgment system to allow for reversal of badly coded or misunderstood contracts. Which means that the standard for the development should be far higher with considerably more insurance and coverage for risk.
They don't. I doubt most are even thinking about it, and of those that are, most probably think it can't happen to them.
Crypto tries to make financial programming more like web development, and less like writing code for a bank, but there's a reason writing code for a bank is such a pain in the ass: it has to work more or less perfectly, every time, at least on the backend.
If you trust your financial framework to someone who took a UDemy course last weekend, you get what you deserve.
When a smart contact developer makes a mistake, your money is just gone, forever, with no recourse.
This is wrong. It's pretty standard for contracts to be able to be upgraded. Usually you want to put a delay before updates are applied. This time delay allows users to see what is happening with the upgrade and gives them a chance to cash out if it's bad.
There might also be a way to do an emergency upgrade, but typically this account is much more locked down compared to just being able to make a normal update.
Because it’s code which means errors are a fact of life, and the goal of crypto pushers was to spread the scam so instead of looking at formal methods in order to make “smart” contract ironclad, they started from ECMAScript so that any idiot could go from a frontend widget to deploying a smart contract with minimal introspection or reflexion.
Maybe one day there will be a sort of unhackable template that everything derives from, or an automatic software-prover.
Companies get hacked every single day too, probably many that you use, it's just more opaque when that happens.
So my guess as to why it keeps happening is a sort of Dunning Kruger effect combine with a selection filter such that the people most eager to get involved are the ones least likely to be able to spot the problems.
As others have mentioned, it was largely chosen because of the ubiquity of 32 byte hashes. But overkill for regular math. One pernicious issue is that it makes translating existing smart contracts into ZK rollups really challenging because 256 but arithmetic blows up the circuit size.
https://www.theblockcrypto.com/post/116413/vitalik-buterin-r...
Wow. I'm pretty ignorant when it comes to Solidity, so it hadn't previously occured to me that it doesn't have floating point. It stretches the limits of the imagination to consider the insanity we'd be seeing if Ethereum did have floating point math.
256 bit integers to avoid floats seems like a good idea too. I’ve wished for it whenever I try to represent integers as double. 2^53 is such an arbitrary restriction.
I.e. can I buy insurance for some percentage of my transaction against a bug swallowing the whole value of my transaction?
Seems like an opportunity to let an economic market drive more rigorous dev and test practices by giving shops with more rigorous practices lower fees.
not sure if I've seen it for NFT collection contracts, but they're pretty robust and actively cater to the DeFi category of services.
here is a list of insurance protocols that also use a token for any number of reasons. its a whole category on the "marketcap" sites.
https://www.coingecko.com/en/categories/insurance
there are likely many well capitalized insurance protocols without a token but I don't know about them for that specific reason, which is a fun irony when wondering "but does this need a token?"
If you lose your money to a smart contract bug in the insured DApp, the insurers will reimburse you.
If you really trust the code of a certain app, you can earn revenue as the insurer on the other side of the trade.
Its more about the project not having the operating capital (99% margin lol) and also loosing some confidence which they can recreate by performing parts of the roadmap and getting the community their NFTs? (the verified person is already saying they will airdrop NFTs and reimburse some participants when banks open so they wire dollars, convert that to ether, and send to some participants)
I want to be clear: the devs aren't incompetent because errors exist; they're incompetent because they're incompetent. I hang out in programming help spaces for devs of varying skills, and 100% of the crypto questions come in on the lowest skill help channels with the most basic questions. It's often opined that programmer skill isn't a real thing. Well, such beliefs have consequences.
I don't think anyone is claiming that the court would always rule your way; that's a strawman. Courts do stupid shit all the time.
The point is that a court could rule in your favor. With something like this, what's the remedy? How is a court going to order some developer to undo a transaction posted to an immutable ledger? What do you do when the source of truth is wrong, and cannot be altered?
With crypto if the cryptography is secure you have absolutely zero recourse to get your money back. Ever. One of the selling points of cryptocurrencies and smart contracts is the non reversibility/mutability of them. However it has been shown many times that that causes harm more often then it has benefit. Loads of assets have been stolen/lost/rendered irrecoverable.
In this case ALL parties would agree that it is definitely not was desired when they went into the contract so it would not even have to go to mediation. They could simply write a new contract rendering the other void in the non crypto world.
If people do it that much, surely you could give us links to 3 or 4 of them? I'm interested, as I've never seen anybody claim that.
https://github.com/Rari-Capital/solmate/blob/main/src/tokens...
Like at this point I'd take my chances in the wild west with a stage coach, a shotgun and a handful of friends over...whatever is going on with crypto.
1. It's extremely hard to come up with the correct rules for expected behavior. It's like making a safe wish versus an evil genie. It's also surprisingly easy to make a rule that doesn't check anything, or what you think it does.
2. In the areas that deal with the most money, DeFi, there may be thirty program involved, most of which were not made by you or under your control. Current formal methods can just handle a single program. The common way to handle networks of contracts is to test each in isolation, making assumptions about what the other contracts can do. But it's really easy to make a wrong assumption here.
At best the most you could do is setup a legal barrier to deploying that code to a block chain. Even then, this is legally iffy, since deploying chain simply involves broadcasting a message to the network. Most likely the court would interpret this as a form of published speech protected by the First Amendment.
But even if not, you can still publish the smart contract code on GitHub and say “I sure hope no one outside my jurisdiction or an anonymous address takes this code and puts it on-chain.
Instead everybody pays the lowest bid? Does everybody get a token as well? Why would anybody bid more than the reserve im this model?
Adoption of this fork would be the critical factor, but if enough money gets locked up, it get more and more lucrative to "unlock it all" will be with your eth-unlocked fork.
The original fork was mostly abandoned, and is known as Ethereum Classic.
lol, once, at the beginning before it had traction...
Since EIP-1559 went live in August 2021, over $6.3 billion worth of Ethereum has been burned since they now burn transaction fees instead of giving them to miners. They burn about $11 million per day!
This $34 million is a drop in the bucket and note that even though all that was ETH burned, the price is still below where it was when they started.
Is this sort of like "I forgot my password"?
If I put 100 $20 bills into a paper shredder, will someone make me whole?
Of course not, yet when the analogous thing happens in crypto, that's somehow an argument crypto is fatally flawed.
Crypto has none, it's a feature to some but a deal breaker for most.
Only the deposit box has a sliding plate at the bottom that may (or may not) be randomly pulled out and when/if this happens your bills will fall into a shredder.
Would you make the deposit knowing how this particular box is made/managed?
Or would you think that this particular kind of deposit box is flawed?
Point is that you were told nothing in advance about the sliding plate and the shredder.
It is pretty normal for money to get damaged and reissued.