Nomad drained of $150m due to a coding mistake
twitter.com
twitter.com
> QSP-19 Proving With An Empty Leaf
> Recommendation: Validate that the input of the function is not empty
> The Nomad team responded that "We consider it to be effectively impossible to find the preimage of the empty leaf".
> We believe the Nomad team has misunderstood the issue. It is not related to finding the pre-image of the empty bytes. Instead, it is about being able to prove that empty bytes are included in the tree (empty bytes are the default nodes of a sparse Merkle tree). Therefore, anyone can call the function with an empty leaf and update the status to be proven.
>It turns out that during a routine upgrade, the Nomad team initialized the trusted root to be 0x00. To be clear, using zero values as initialization values is a common practice. Unfortunately, in this case it had a tiny side effect of auto-proving every message
EDIT:
Reading and noodling I'm 99% sure these are separate issues. The vulnerability talks about passing in an empty leaf to the prove function. But that's not what the exploit is.
The exploit is using an unproven message. So they are passing in an actual leaf to prove. The problem is that unproven messages have 0x00 as root and some jabroni set 0x00 as the trusted root. So every message was treated as proven by default when it should be the opposite.
yes, a routine upgrade. that's what it was..... (→_→)
Very unhappy with how Celo handled the situation, as was much of the technical crypto community at the time.
Not a hard and fast rule, and not something that will catch tons of problems, but now and again it does help me catch an uninitialized value.
then whoever takes over maintenance from you and wants to make improvements says "hey, we can add this new v2 feature through the 0x0 which is available for future enhancements"
enum class Color {
Invalid, // Not a valid value.
Red,
Orange,
Yellow,
Green,
};
I think if someone's crazy enough to reclaim a 0 value in an enum or integer ID, then they're probably going to do a lot of damage to the code no matter what you do.Fun part is as far as I understand this is just a convention and there is nothing intrinsic to 0x0 that makes it different from any other destination address. If someone was to find the private key for which 0x0 is the public half they would have access to a vast amount of stuff that has been transferred there over time. Finding this key is computationally unfeasible however.
The real issue was half-caught in a review on a pull request however. https://github.com/nomad-xyz/monorepo/pull/289/files
If this legacy enum value had been handled later in the code, there would not have been a vulnerability.
(This isn't to say that the developers were bad. The person who wrote the code was extremely knowledgeable. It's just really hard to be perfect every time. )
They are bad because they are not competent to write the decent code required by their profession and job environment.
In normal software writing trade, such engineers are called low performers and routinely managed out of any organization.
Sure, the mistake is not unusual from the perspective of general software engineering. But let's not forget what software they are working on.
I am totally fine with a bartender dropping a glass... I'll put a surgeon on trial if he cannot make his hands steady during a heart surgery...
This "you must be perfect" mentality is detrimental to building a security culture, IMO — no one is perfect, and the most excellent dev will slip up. Seeing the people involved in that commit, I believe that's what happened here.
Hoping we learn more in the post-mortem, and they revise their practices to catch this mistake in the future.
I remember AWS S3 went down in 2017 or so and the key point I took away from their article about it was that they didn't blame the junior dev that caused it, because it shouldn't have been able to happen in the first place.
Ah here we are: https://aws.amazon.com/message/41926/ "We are making several changes as a result of this operational event..." basically boiling down to "the employee in question is not at fault because our tools should not have let him do that".
>Messages popping up in public Discord servers of random people grabbing $3K-$20K from the Nomad bridge - all one had to do was copy the first hacker's transaction and change the address, then hit send through Etherscan. In true crypto fashion - the first decentralized robbery.
'Code is law' is just a reddit meme at this point, that has no basis in reality. 'Smart contracts' are just regular contracts, but with more opportunities for theft.
I'm not a lawyer but I would be very surprised if courts in most countries would buy this argument.
Spelling or grammatical mistakes usually don't invalidate contracts in the real world and robbing a poorly secured vault is still illegal.
The thief was obviously trying to get other people's money without their consent.
I’d love for this type of thing to be tested in court. I’d invest in popcorn futures ahead of that trial.
If they do that and if they get hold of the individual (or their assets) the court can force compliance in the usual ways.
"I can't access it and never will be able to" is not a believable excuse unless you can prove it.
The Law allows people to agree to stupid things, no?
It's so poetic.
Only cryptocurrencies are trying to have it both ways. They boast that big bad governments can't touch their money scheme, until someone finds a loophole in the code-is-law. Then suddenly law is law again.
https://www.bbc.com/worklife/article/20180723-the-commas-tha...
The old mantra of possession is 9/10ths of the law is and always has been false. If i have something i own it. That is the one fundamental truth. Now someone can come and try and take it back from me by force (Person, Court System, Rebels, Corporations) if they can exert more violence on 'me' than i can exert on 'Them'.
The problem with crypto is the 'keys' are what crypto is. No nationstate can come and take that away from me. They can kill/imprison/fine me, but then neither of us will have it. You would have to hack/fork the chain for that to happen (Which has happened) or find some social way around it (If i have it on a centralized exchange, if i have a hackable hard drive, found my keys on AWS, etc etc.) Additionally, with things like Monero, and tornado swap good luck trying to find them.
If you offer a sheep for 100 lb of apples, and someone accepts and gives you the 100 lb of apples, you owe them a sheep, even if you later think that deal was a bad use of that sheep.
If you say "currency is to move and out of my bank/warehouse according to these rules, conducted by this robot", and someone finds a profitable way to transact with that robot according to those rules, you have arguably signed away those profits to that someone, and they are then entitled to keep what the rule-implementing robot gave them.
This doesn't mean "code is law" actually works as a defense in court -- there are are all kinds of reason why that promise might be unenforceable -- but you can't casually asset that this is a robbery without examining the specifics of how the transfer happened.
But again, it ignores my last point completely. Good luck trying to find the person behind the wallet.
thanks for the loud laugh
This is the funniest thing I've read all day
If we have a situation where:
* Its hard to tell, after the fact, 'a mistake' was a bad actor.
* The programmers are, by and large, anonymous.
* The benefit of making 'a mistake' could be hundreds of millions of dollars that are not easily traced.
This situation seems rife for abuse and bad actors. Not saying it happened in this case. . . but how would you know?
Thank you man!
Currently, I believe that most 'web3' and 'crypto applications' exist to drive fear of missing out leading to monetary investments in crypto by people who don't understand the risks leading to the story here (150 million lost or stolen). I think of my grandmother or uncle investing in crypto and losing their retirement savings. I personally know family members who have lost low 5 digits. Why? Because they wanted to invest because it was the future, web 3, fomo.
I actually believe the world is a worst place because of crypto.
Can that change in the future? 100%
Does this mean that you and people who work in the industry are bad? Not at all. I've worked in industries when I was younger that - now - I think were a net negative for the world. I'd be a hypocrite to throw stones at people just trying to live...
Maybe governmental regulations of this will change my view.
i prob didnt say all that super well but i hope you get the spirit of my argument. i totally respect your opinion here though because you are not wrong :)
Liking Crypto because you think hedge funds are scammy is kind of like enjoying swimming because rain makes you wet.
Today's crypto is much more rife with scams and Ponzi schemes than hedge funds currently are (because of actual legislation).
Yes there are scams out there. Lot more than other fields. But just take 2 or 3 solid examples - Uniswap, DyDx, etc -> These are much more open and decentralized and transparent than their TradFi counterparts.
If you think Uniswap is a scam, you haven't looked into it yet. Yes the tokens that get listed on it can be scams but that's up to to the buyer to assume the risk. As a tool, it's so much more transparent than anything that existed before it.
> If you think Uniswap is a scam, you haven't looked into it yet. Yes the tokens that get listed on it can be scams but that's up to to the buyer to assume the risk.
I never said anything about Uniswap personally, but using a company that can list scams as an example about how non-scammy crypto can be is a little strange to me.
I can't recall a brokerage such as Schwab or vanguard ever losing my money, compared to Mt.Gox and other trash crypto exchanges.
PS: this what I actually hate a lot about tokenbros - they say that there is a problem in the economy with unaccountability of the world elites (ok, true at at least somewhat), and then want to supplant it with an even worse system, even more centralized, even more unequal, even more dangerous to common people, even less secure, and even less accountable for the elites in charge. The sheer audacity of their lies is mind boggling and induces literal rage.
Get rid of state extortion and then what? Get extorted by local oligarchs or warlords doing the same thing? If the world changed into their utopia, we would end up with some form of feudalism again and we would have to fight our way back to democracy.
It is easy to argue that X>0 extortion is unjust and hence this pillar of society ought to be demolished, but that is the fallacy of composition. That pillar might not be the best or prettiest but it certainly is important and without it a lot of things would go wrong. What is ignored is that the pillar protects you from Y extortion where Y > X.
For example, I can get a drug that I have a legitimate RX for through the (regulatory) captured corrupt American healthcare system at 100x markup, or I can buy high quality generics on a darknet market for pennies per pill.
Another example: Monero is a privacy coin that is designed to be untraceable, and Mullvad (VPN) "Privacy is a universal right" offers a 10% discount for Monero, Bitcoin and Bitcoin cash. Fantastic utility for people looking to break out of oppressive government firewalls and spying.
I think cryptocurrency is a massive boon for humanity. And treating it like an investment is foolhardy. It's a currency. If you don't have a plan to spend it, why would you mine or buy it?
I saw all this coming when Bitcoin first came out and I remember thinking it was expensive at $6/BTC. If I'd kept half of what I bought back then I'd be a multimillionaire today, but if I'd kept it, it might not have become as valuable as it is today either. The value of a currency comes from using it, not hoarding it.
>Maybe governmental regulations of this will change my view.
Government regulations spurred on by the regulatory capture and oligarchy designed to squash the little guy are the a huge problem.
No. They're magic trading cards.
Saying 'Crypto Is Currency' is saying 'Baseball Cards are Currency - just nobody uses it them as currency, yet!'.
Crypto is neither a very good store of value and it's not a currency.
I possibly could be both (different variations) but likely not better than regular money in most cases.
"I think cryptocurrency is a massive boon for humanity"
Where are these 'boon' things?
Buying 'generics' on the Black market - basically evading the law is a good thing? What about 'hiring hit men'? Maybe it would be better to just have the laws changed. I don't see where Crypto provides the 'boon'.
"Government regulations spurred on by the regulatory capture and oligarchy designed to squash the little guy are the a huge problem. "
Yeah, not with currency though.
Like you say - currency and investment are different things.
If you don't like USDs, then just don't hold onto a lot of them.
It's a great currency, just not a very good store of value.
Crypto hasn't yet demonstrated it's benefits, and a lot of the terrible things about Crypto are still on going.
Net negative, so far. That could change.
I'm a dev interested in learning more.
Crypto Zombies is a very good interactive intro to Solidity, despite being REALLY outdated at this point (last i checked it was using Sol 0.5 or 0.4).
my best advice is find some popular crypto concept you vibe with and just start messing around. Vyper is also growing in popularity so that might be worth checking out too!
> In Solidity, the order of evaluation of sub-expressions is unspecified. This means that in f(g(), h()), g() might get evaluated before h() or h() might get evaluated before g(). Practically, this order is predictable, but Solidity code shouldn’t depend on that behavior between compiler versions. In most circumstances g() is evaluated before h() (left-to-right order), which is also the behavior that most languages specify in their standards. However, in the case of emitting an event with indexed arguments, the arguments are evaluated right-to-left.
I feel that order-of-evaluation dependence is a special case of the general conflict between expression-oriented (functional-style) programming, and impure operations requiring sequential reasoning. Another case of this conflict is temporary values (expressions) with side-effectful destructors (sequential reasoning), for example https://fasterthanli.me/articles/a-rust-match-made-in-hell#w....
At this point, is it good practice to avoid using side-effectful procedure calls as parameters to other expressions (especially those with multiple inputs), but instead first assign to a temporary value to make order of operations explicit?
That said, I personally doubt this happens much if at all, because if you want to scam on web3 you can just do a good old-fashioned pump&dump and nobody seems to be receiving any legal/criminal consequences as of yet.
If they keep it in blockchains only, it's hard to connect to a real identity. But if they cross the line (which is everybody's goal eventually) to the real world, they can get caught as easy or even easier than in traditional financial system.
I don't how anyone would commit anything more than pocket change to a scheme where an insider could deliberately introduce a weakness and then exploit that weakness to walk off with all the funds committed.
Challenge: explain to a normie that their life savings is gone forever because of a zero initialization vector.
Of course there is no justice in either case, but at least normal people can see who is most appropriate to behead in the case of the traditional financial catastrophes, in the purely theoretical revolution.
If you got burned by mortgage backed derivatives and lost your life savings, it's ultimately because you were (knowingly or not) speculating on the value of real estate assets and making an assumption about future values of said assets.
In the case of Nomad, it's that you put yourself at risk by using their service you could've lost everything you put in.
[...]
>it's ultimately because you were (knowingly or not) speculating on the value of crypto assets
Not seeing how these are different
They claimed high-risk mortgages would turn AAA by the magic of financial and statistical shenanigans. That's not far from "zero initialized vector" shenanigans.
Investing in AAA securities is not speculation, by financial standards, by the way.
I would argue that it is now after seeing the bullshit the ratings agencies pulled during that fleecing of the world.
Somebody who directly invested in MBS is by definition not a normie.
However, morons spamming TikTok, Twitter, Facebook and every social network to find a sucker to invest in their super 20% profit moon monkey future currency can be found in a minute, reaching hundreds of thousands. Plenty of normies lose their money in this.
My retort was half-baked because two wrongs don't make a right. But it is ironic to see that many normies here don't see how MBS caused massive wealth loss across all investors worldwide without them directly speculating in that asset class. While, so far, this hack hasn't caused a crash in crypto assets.
Usually just depositing money in a bank doesn't get it stolen so the assumption isn't unreasonable.
Even if it's only 0.25*life saving that's still devastating for most people.
If you want an apple to apples comparison you should be comparing the security of a savings account to that of a cold wallet. Those are much more alike in their function.
I don't think we classify people who engage in cross network token swapping as "normies". That's like classifying algorithmic day traders as an "average joe investor".
This is especially the case for protocols like Nomad that don’t yet have a native token. They’ll get liquidity commitments through over-the-counter SAFT agreements that give the VCs a percent of the future tokens.
You mistook a currency for an investment opportunity, and gambled your life savings on one thing. Currencies have always and will always fluctuate against each other. Diversify your investments.
The issue is treating a currency as an investment is just...foolhardy from the get got. Just don't do that. It's silly. People saw the value of it go up - or start to have any in the first place really - and saw a "get rich quick scheme" where there wasn't one. It was the brith of a digital currency, nothing more.
If a currency crashes, not only does that 'really matter' for most regular people who will have some material savings in that currency, it also creates really terrible problems for everyone using the currency.
The value of a currency is in it's integrity over time.
It doesn't have to maintain perfect pricing parity etc. however, it must not just vanish and fall apart.
We can see this with USD and Seigneurage with the Petrollar.
People hold USDs not because they think 'it'll be worth more' but rather, they'll be valuable in the future, because USA won't crash and fall apart.
This crypto stuff is mostly stupidity with bad economics all the way down.
Maybe some day that will change.
The reason developers make their contracts "upgradable" is simple greed- they want to be able to launch more quickly than other projects without needing to ensure their code will stand the test of time. This may be OK for a social networking app MVP, but it's not OK for a smart contract which a user ideally should be able to audit and understand (or at least rely on the audit of someone else). "Upgradable" smart contracts can always be changed after the fact, as happened here, which means that any audit is meaningless.
Top tier projects still do use simple un-upgradable smart contracts. Uniswap first wrote v1, then improved it and launched v2, then v3. The Uniswap v1 and v2 contracts are still running and usable, and will be for as long as Ethereum is around. Their security properties will always be the same as they were the day they launched.
"Upgradable" contracts mean that you are trusting your money to some anonymous fat fingered (or at worst, criminal) dev, and it could disappear at any minute. They defeat the entire purpose of even using a blockchain.
It’s not really about greed. Deploying a program and having it unchangeable forever comes with risks, and more often when dealing with very complex applications, those aren’t worth it
Yes, writing perfect code is very hard. But smart contracts are an example of code that must be extremely thoroughly tested, formally verified and so on.
But that doesn't go well with being first to market, move fast break things, etc.
* Initialization was done 42 days ago: https://etherscan.io/tx/0x53fd92771d2084a9bf39a6477015ef53b7... -- "Click to see More" and notice "Input Data" parameter [2] which sets _committedRoot to 0x00.
* Click through the To contract to get to the code (click on Contract tab): https://etherscan.io/address/0xb92336759618f55bd0f8313bd8436...
Just adding direct links to what samczsun and 0xfoobar are talking about in https://twitter.com/samczsun/status/1554260106107179010 and https://twitter.com/0xfoobar/status/1554269071214088193/phot...
and so therefore nobody is trying to kill or impair the developers/team
if you were referring to people committing suicide or being suicided by the people they borrowed money from, thats not everyone’s problem and people in those circumstances should re-evaluate to avoid that risk or accept that risk
Depending on how you measure, that value is (in the US and Europe) typically in the order of 1..5 Mio USD.
So it's not outrageous to assume that losing 150m comes with a body count, even if the funds wouldn't have bee used to directly save or improve lives otherwise.
1. Owning ETH with a non-custodial wallet.
2. Owning ETH on a CEX.
3. Depositing ETH into a smart contract to receive a wrapped asset. This includes rollups and L2s.
The majority of major crypto hacks[1] are in the 3rd group, and almost all of these hacks are related to protocol updates and governance. Either: the developers update their code, and accidentally push a bug, or one address or a group of addresses are allow-listed some privileged actions in the contract and that can become a weak point.
Proxying and governance isn't the only way to design contracts. Two examples counter to this that are more robust are WETH ($6B) [2] and ETH2 Deposit ($20B) [3] which cannot be attacked in this way. If users wanted a new feature from the WETH contract, they would have to manually migrate over to the new address. Eventually we might see this kind of design be applied to bridges and rollups.
[1] https://rekt.news/leaderboard/
[2] https://etherscan.io/address/0xc02aaa39b223fe8d0a0e5c4f27ead...
[3] https://etherscan.io/address/0x00000000219ab540356cbb839cbe0...
At my day job, I automate everything because humans can't reliably perform basic tasks.
I'm not a believer in web3 or crypto but believe computers to be more impartial and would rather see them eventually take over certain aspects of legal work.
Which of the two do you think will more likely come back to haunt you? The one where any authorities investigating will need to dig up the backgrounds and connections of hundreds of blockchain addresses exploiting the transaction, or the one where only a single address exploits the transaction? Won't their attention be primarily on those idiots who try to withdraw the money in the US, say, vs that one transaction out of hundreds where someone in Barbados had their proceeds deposited into a bank and withdrawn as cash before closing the bank account (that they opened with a false identity, maybe?).
When there's a single account performing the exploit, all of the investigative resources will be applied immediately to that account, making it far more likely that the account in question will be tracked up to the point of withdrawal, and potentially flagged in time to prevent such a withdrawal. With hundreds of others distracting any authorities, it becomes hundreds of times harder track down the original perp.
Think of those heist movies where someone throws a handful of cash up in the air to help avoid pursuit. Same idea.
This is plausibly a mistake.
I have zero evidence for my "deliberate sabotage" theory. OTOH it seems entirely plausible and in line with the general scamminess of many cryptocurrency systems. OrangeMonkey's comment expounds better on the social and legal aspects that make deliberate fraud such an attractive possibility: https://news.ycombinator.com/item?id=32318939
There was another bug where someone tried to grab the coins without broadcasting the bug into the pool (by using a well designed double transaction), but they made a slight mistake, and other traders immediately took the coins instead by algorithmically detecting the bug (as soon as the example transaction was published on the blockchain) then algorithmically generating transactions.
We can't expect widespread public adoption of a system like that; even lay people are too familiar with how unreliable software is.
Both are functional, which means easier to read, and Pact is non-Turing complete and strictly typed, making it even easier, so much so that formal verification tools can assess what a contract is capable of automatically - a much smaller search space than EVM bytecode.
When code is not permanent and backing millions of dollars or more of value, the trade offs may favor more powerful or flexible languages, but the ability to read and understand code and what it can do it so wildly important for smart contracts that I don’t see a world where Pact isn’t moving the right direction contrary to the EVM.
I don't get your comment: Ethereum itself has worked without any issue since it came out, in 2015 (?) or so. Many smart contracts, not built by the core Ethereum devs, have been exploited, but from Ethereum's point of view everything worked flawlessly.
Why would the Ethereum devs, which have create a blockchain working perfectly fine since seven years (including many upgrades), suddenly screw up the merge to PoS badly?
I mean: I don't doubt we'll see many more hacks (and I don't know why so many people are so keen on putting so much money in smart contracts) but the people in charge of Ethereum itself seems to be quite competent and have a track records of several years without any exploit to prove it.
https://en.wikipedia.org/wiki/The_DAO_(organization) https://en.wikipedia.org/wiki/Ethereum#Launch_and_the_DAO_ev... https://en.wikipedia.org/wiki/Ethereum_Classic
Switching to an entirely new consensus model, that has never been done before, is complicated and a big reason why it has taken as long as it has.
Furthermore, there is a giant target (huge sum of money) on ETH's back now. If you had an exploit for PoS, why would you reveal it early?
As the person below also states... they could just fork and fix things, but this time, it will be a lot harder to do so without entirely destroying the value of ETH.
This is a massively risky venture that takes more than just hope and prayers. As we've seen in many many hacks over the last few years, even the most competent developers can miss something crucial.
As for rollback... that's what created ETC, but this time, it is different... with PoS, the 'stake' is tied up in the network. It isn't external, like it is with PoW and isn't as easy to just fork. You're effectively now forced to convince everyone to follow another canonical chain, but you don't have an external way to do so. Forking becomes a lot harder. It also becomes a lot more complicated and hasn't even been done before... how much 'testing' has that gotten?
This gets messy fast when there is an issue and even worse is that there isn't a published plan for how to deal with things when they do come up. Everyone is betting on it all executing perfectly and given the complexity and value at stake here, chances are that at some point now, or in the future, it won't go well.
[1] https://github.com/stickfigure/blog/wiki/Proof-Of-Stake-Wear...
Nope. The ETH is just in a rather simple write only deposit contract on ETH1. [1] It is also not 'all' ETH, since there is no hard cap on the total amount of ETH in existence.
It is also a bit more complicated than just looking at the beacon chain. That beacon chain has zero value tied to it. So while it has been running just fine, there hasn't been a reason to attack it. It also hasn't been used to actually do anything really... and now there is a use. There is also a lot more communication going on between nodes that didn't exist before. All of these things become attack surfaces.
[1] https://etherscan.io/address/0x00000000219ab540356cbb839cbe0...
- 10% of the current supply of ETH is in the deposit contract, and can't be withdrawn from the deposit contract.
- Every address that deposited ETH into that contract got a corresponding balance of "ETH" on the beacon chain. (I'll call it "ETH" instead of just ETH to avoid arguing over whether it's really ETH.)
- The beacon chain is functioning as designed, and the "ETH" balances of various addresses are getting changed over time. The economic incentives appear to be working. People are keeping their nodes up and running to get rewards, and trying to avoid getting slashed.
- The plan is for stakers to be able to withdraw their balances to the main chain, from the beacon chain. When someone withdraws, an ETH balance will be incremented on the main chain, and the same address will get its "ETH" decremented on the beacon chain.
Right now, the contract is one way and there is no way to withdraw. The code hasn't been developed yet. The ETH or "ETH" or whatever, are secure because there literally cannot be insecurity without some code to break.
Heck, even "The Merge" doesn't enable withdraw... it is scheduled for some time after (still to be decided and coded... more potential security issues) and is of course a slow trickle too (first people who can withdraw win the short market). That 10% is about as secure as you can possibly be in that it is effectively burned at this point and will require yet another hard fork to unburn it.
Let's go back to the premise of my original comment:
PoS is a lot more complicated than PoW and offers a much wider attack surface.
Any large mistake in the code that causes financial loss is going to go down a huge rabbit hole of how to manage consensus around fork choices and will likely have at least a short term devastating effect on the market.
I want to see PoS succeed, but as a 20+ year developer, I'm very skeptical it will go off without a hitch.
Before 2018, Ethereum has a similar downtime to Solana
Ethereum is continuously developed to remove bugs.
For example: Until 2017, it was possible to sent a specifically signed transaction (without the correct private key) that resulted in the msg.sender having null sender address. This was fixed in EIP-86
The reason you cannot just roll back a smart contract exploit like Nomad's is that it is very hard to build consensus across the entire protocol unless it is something that affects many users. The only time this happened was with the DAO which held something like 15% of all Ethers at the time, and so it affected the entire network. Compare this to Nomad which held something like 0.1% of Eth's total circulating supply.
Except with PoS, it is different. People keep applying the PoW mentality of a fork to PoS and it just doesn't work that way. Jeff wrote a good blog post [1] on this a while back that took me a long time to come to terms with. It boils down to this paragraph:
Proof-of-stake is inherently self-referential. It is possible to have two perfectly consistent, equally valid chains - perhaps with different stakers. Since “stake” is defined within a blockchain, it cannot be used to pick between two blockchains. Under the right kind of stress, the real, unwritten meta-consensus protocol that determines "which blockchain do we pay attention to?" will be revealed. Exactly what that is will depend on the nature of the fork.
This is untested on ETH PoS and could result in a significant loss in value for ETH holders. Not only that, but it gets even more complicated with stablecoins that are on ETH. What makes all of this quite interesting is the exchanges who get to decide which USDC on ETH they sell to you. Likely a big reason why exchanges, like Coinbase, are some of the largest ETH stakers.[1] https://github.com/stickfigure/blog/wiki/Proof-Of-Stake-Wear...
The article suggests that two chains can simultaneously exist but that would invalidate the protocol, which will always choose one using LMD GHOST. You can read more about it here[2].
Not really. PoW is orders of magnitude simpler than PoS and is vastly easier to reason about. I can explain the concepts around PoW in 5 minutes to someone who doesn't understand it. PoS is a lot closer to a rube goldberg contraption than PoW is. The proof in all of this is the years it has taken to even get to the point we are at today.
> Articles describing the complexity involved
The whole point of my original comment is that this is A LOT more complex than a bridge contract and therefore will be subject to a larger attack surface. Thanks for validating that point.
Yes, but what will dictate that? ETH today is the hard fork (from what is now ETC).
How much loss will it take to decide what to do?
Where is the failure plan?
The goal of all the shadow forks and merge testnets is to find the different edge cases and failure states to answer those questions of “what is the failure plan?” If mainnet merge somehow does not succeed despite these tests and all clients fail to produce blocks, the merge can just be delayed until the bugs are resolved. If mainnet merge succeeds but later a bug emerges, users can coordinate a change to revert the lost funds.
> the merge can just be delayed until the bugs are resolved
This is one of the losses. Every time the merge is delayed, price drops. Price is currently trending higher right now because the merge looks like it is on track.
Delaying the merge also has a loss... for the miners who are currently securing the network. aka: the bomb. The bomb is an embarrassment because every time it gets pushed out, that is essentially the minimum amount of time before the merge can happen.
> users can coordinate a change to revert the lost funds.
How. I want a detailed plan. So far, I haven't seen it.
You are conflating "people losing tokens" with "people losing the USD value of their tokens." It is very likely that the market becomes unpredictable before and after the merge, value of ETH may plummet or skyrocket, and holders of ETH should be prepared for that.
> The bomb is an embarrassment because every time it gets pushed out, that is essentially the minimum amount of time before the merge can happen.
That is not how the bomb works. It is a soft deadline. If the developers feel the merge is ready, they can initiate it before the bomb occurs, and miners will immediately be forced to transition their hardware to other PoW networks. If the developers do not feel the merge is ready, and the bomb is fast approaching, they can delay the bomb by another month or even a year and it will not have an impact on the timing of when they actually decide to initiate the merge.
If the worst that can happen is "embarrassment" for having to delay the merge again to fix a critical bug, I think you are overblowing this. The developers will happily delay the merge until all the bugs are fixed, and the users are happy to have this happen as they would rather wait for a working merge than rush toward a broken one.
> How. I want a detailed plan. So far, I haven't seen it.
Every time the protocol rules change, developers are activating a fork by coming to consensus on the new rules - all client software must coordinate code updates to match the new rules. Eth core developers and client teams have been doing this regularly over the years, and especially during the approach to the merge. They can coordinate a revert or fork, just as they have coordinated the past several forks[1], to fix these issues.
It is fine to imagine a hypothetical failure case for the merge but this does not mean "it cannot be fixed." It might be messy, the value may drop, coordinating the fix may take some hours or days, and it is even possible the chain stops producing blocks for some short while if it is very catastrophic. Users still holding ETH going into the merge should be prepared for these situations, it is probably the most significant development in crypto currency and DLT since the Bitcoin genesis block.
It is complex to somebody not familiar with consensus and blockchain execution, but you might say that about any modern engineering. PoW is undoubtedly simpler but also exponentially more environmentally destructive.
[1] https://arxiv.org/abs/2003.03052
[2] https://github.com/ethereum/consensus-specs/blob/dev/specs/p...
Often times the market doesn’t like upgradeable contracts for this reason, ironically the misunderstood idea of smart contracts not being upgradeable is paraded as a bug
but its all situational
[1] https://news.ycombinator.com/item?id=32319344
[2] https://github.com/nomad-xyz/monorepo/commit/46d14571f3eada6...
From my vantage point, it seems to be mostly bored twentysomethings.
North Korean cryptocurrency hacks are a bit distinctive. Rather than finding logical bugs in contracts, they tend to use traditional spearphishing / social eng to get targeted people to run malware which they try to pivot to stealing keys / access credentials. Then after a hack, most crypto hackers try to obfuscate and store their stole coins on chain somewhere. North Korea already has a large and practiced money laundering network, so after a hack the money immediately starts going to hundreds of different places in the real world, perhaps to mules or to faked accounts in Southeast Asia.
Google: "North Korea Ransomware"
"The future is already here, just unevenly distributed" and boring
https://blog.mollywhite.net/celsius-letters/ https://blog.mollywhite.net/voyager-letters/
I could see point if we were talking of hundreds, but we are talking of sums of over hundred of thousand. Which to me is very wealthy on global scale at least.
It's not just the wealthy, it's the cab driver giving crypto tips now.
Or at least they where before investing in crypto...
Maybe they are... Perhaps this is the new way the CIA is financing their off the books activities.
Is it really supposed to be open-source? A common cyberpunk trope is that mega corporate conglomerates own verything. Cyberdecks are modified and reverse-engineered, yes. But generally come from a mega corp.
We have all that, although most of it from smaller Chines manufacturers. More than that we do have truly open source hardware, you can download schematics for almost anything, modify and design your own chips and circuits based on open designs, dream up your own hardware, and if know the right people in Shenzhen you can email it all to them and they'll build it for you.
The reason so few people take advantage of any of this is that it didn't turn out to be that useful.
So long as people aren't running around with too much bad money.
If anything these heists prove interest in web3 remains high.
It is probably both. The model of allowing governance updates from a contract owner on a bridge or rollup is not sustainable and will have to change to mitigate these kinds of risks. Whether that means crypto networks as a whole will inevitably be replaced by a central banking system is harder to agree with.
It's being sold as revolutionary, literally, being able to overthrow $x in power or to the more susceptible as a way for everyone to get rich.
So people who believe in it think it's some grand revolution of freedom, and people against it just see it as scammers exploiting the foolish.
What it actually is going to be is boring. Regulated like the rest of finance, centralized like the rest of finance, but with a few new features which will end up not revolutionary but "oh I guess that's nice". It will also come with weaknesses that older centralized institutions don't have that will seem ridiculous at times.
It should be about as exciting as a new programming language for bankers. Like sure if you're a banking programmer you might think it's cool, but not the kind of thing that'll get superbowl ads or the topic of your uncle joe's podcast.
Snarky comparisons to the Hindenburg aside, I really think things like this disaster in the long line of disasters that won't end is just another blow to the excitement of crypto which won't disappear completely or dominate but become a mundane method for the exchange of value which to the end user is only slightly different than the old ways.
I do think it will, over the next 10-20 years, completely revolutionize how we think about digital assets and digital currency. For the average user it might not be any different than paying with Apple Pay. But there will be other novel applications and companies that emerge from this space much like what occurred in the years after the dot com boom.
There hasn't yet been a killer application besides money laundering and speculation bubbles. It's been long enough and there has been nothing but toy applications outside of people specifically trying to evade laws in various jurisdictions.
The actual applications are just going to be boring.
Holding on to crypto personally for actually paying for things is awful, and worse than cash. Not only can someone take it from me with violence, they can also take it from me because of inevitable software bugs. If there's a centralized account with an institution, it isn't at all different than an account with a bank with dollars. And it becomes easier to see my entire spending history for anybody that sells me something unless I actively launder my money.
The killer application is Ethereum and the ideas it has spawned, including new global financial instruments like stablecoins, decentralized exchanges, NFTs.. and cryptography like zk-STARKs and MPC.
With PoS and privacy enabled rollups this technology can certainly disrupt and compete with today’s popular payment processors in the next few years.
But yes, the most successful consumer applications will probably be boring, like PayPal or Apple or Stripe adding blockchain based mechanisms under the hood.
Crypto can also be used to decentralize control of the gates, such as allowing goods services and taxes to be paid in USDC and DAI, so that there is less need to use a CEX. But there are regulatory and technical barriers that prevent this from happening right now. The people who want blockchain adoption ideally would like to see those barriers to be overcome.
- DEX - sure, new thing. We all see how it works out. This is what, 5th DEX exploit just this year? And I'm talking only about big exploits.
- NFT - literally useless junk build on lies and insane lies. I dare you to name even one area which NFT can improve.
- cryptography - maybe, I don't know. Though I suspect that those developments can be simply self serving for token industry and not really transferable to other industries.
- BigCorp adding blockchain - why though? What would they get by introducing a private, inefficient, slow and not user friendly (users = employees of those corps) data storage? Private BC completely defeats all its small promises about decentralisation or privacy etc.
- all these protocols are beta software, less than a few years old. Uniswap as one of the oldest is probably also the most secure.
- NFT: ability to hold custody over a digital record without relying on a single private company's servers to uphold that. But I expect you will move the goalposts...
- Cryptography: take a minute to look at developments in ZKP, MPC, new signature schemes. Many uses outside of pure blockchain[1].
- BigCorp: because they can extract value from it. If 5% of Shopify or PayPal users want to use crypto payments, the company can support that method and charge rent on it. Or they can ignore crypto, and let another company absorb the potential revenue. But because they like profit, this is why we see Shopify, Stripe, and PayPal all integrating crypto currency.
[1] https://blog.cloudflare.com/introducing-zero-knowledge-proof...
I don't see how digital IOUs is anything novel or invented by tokenbros. Paper or digital, it's the same this essentially.
NFTs... How EXACTLY does NFT "holds custody" of anything? Please describe what do you mean by that.
A practical example of an application on top of this is namespace aliases that are held non custodially by the users through an ERC721 contract - see ENS. The user's private key gives them access to a record within a smart contract, allowing them to update some state or transfer ownership of the data object.
I will clarify my question better now, hopefully. How EXACTLY does NFT "hold custody" of anything not living fully on on the blockchain already? So any physical object, or any digital object outside of cryptotokens and DNS records on the blockchain.
I am not suggesting it does. I am suggesting it allows you to hold ownership of an asset on the blockchain. At this point it means ENS, art, collectibles, loans, stablecoin positions, user accounts, and other assets that can be defined digitally and on chain.
At some point in the future, property laws might change to recognize crypto tokens as their own asset class, which would make possible things like having some claim of ownership over a gold bar based on holding a NFT. Many investors today hold gold in their portfolio without it physically being transferred to them. Instead, ownership of the assets is recorded on some ledger, which could be a public ledger.
Mattereum is working in this space, trying to tokenize gold bullion, wine[1], and recently real estate[2] with legal warranty, but I would not put much stock in this idea until there is more clarity from lawmakers.
[1] https://www.businesswire.com/news/home/20220624005079/en/IG-...
[2] https://www.businesswire.com/news/home/20220731005030/en/Mat...
- art - no
- collectibles - no
- loans - as in "loan your NFTs"? Technically yes, but since NFTs are worthless bullshit it is kinda pointless.
- stablecoins positions - please elaborate, never heard this idea before
- use accounts - no
- other on chain assets - yes
- other off chain assets - no
tl;dr - NFTs themselves lack any ability to provide proof of ownership, transfer IP rights, or hold custody simply because it is technically impossible. Any cadaver constructs which allows this are inevitably an additional centralised systems which do all the actual work and actually store digital data. NFTs are fifth leg in a horse - pointless and useless. (DNS records alone of course don't justify NFT existence)
Loans and DeFi - see Uniswap issuing ERC721 Liquidity Pool tokens.
User accounts - exact same mechanism as ENS, but different namespace specific to a protocol. See Lens protocol for example.
https://news.ycombinator.com/newsguidelines.html
Edit: it should be obvious, but this moderation point has zero to do with how any of us feel about web3 or whatever.
Those are both low-value, ad hominem attacks that don't substantively engage with content, and they are both comments that erode the quality of discussion in our community.
The difference is that banks can reverse stuff.
I understand that some of the deposits are from retail 'investors' who are poorly organized more interested in token appreciation or yield than the safety of their funds. But even getting to $150m would take forever if it came from individuals.
Surely there are large investors that provided the bulk of the capital. Shouldn't they intervene in some way? Or do these whales have so much to waste that they throw money into each of these projects knowing that they'll never see a cent back from 50% of them?
From this explainer:
> It’s [Nomad is] built to address security first The Nomad team has been building secure bridges as a team for 4+ years and has studied the pitfalls of multi-sig and validator-based bridges.
https://medium.com/imperator-guide/nomad-a-cross-chain-inter...
Assuming this is true, and assuming the team is not incompetent or composed of the typical grifters, perhaps it's time to draw the inevitable conclusion. No amount of experience is sufficient to safeguard an Ethereum protocol of any interesting complexity.
It's a reasonable question to ask, WTF is Nomad for? After all, isn't Ethereum supposed to be the World Computer, Turing complete and ready for any task? Nope. Never was.
I think a good chunk of the answer can be found on the home page:
> Nomad reduces gas fees by a factor of 10x relative to traditional header relay systems, while remaining decentralized.
That world computer is choked to the gills with accumulated waste. The proliferation of chains is the response. Each one is less secure than its forebear. Gobbledygook like Nomad is the "connective tissue" to get the various organs of this science project talking to each other.
Dive deeply enough down and you find the root of it all: everybody wants to make the next Bitcoin, Ethereum, Cardano, Polkadot, and so on. With each turn of the crank a new crop of Barnums springs up to take the money of an unending supply of digital rubes.
Any chance for the exploiters to be prosecuted, or is it essentially all anonymous?
* The one where the investor lives?
* The alleged thief?
* The creators of the contract?
* Some 4th option?
People should look into those!
The EVM, that it compiles to is a lot of fun though, if you like small understandable virtual machines. I like it a lot.