$570M worth of Binance’s BNB token stolen
cnbc.com
cnbc.com
- Not a problem. It is a write-off for them.
- How is it a write-off?
- All these big companies do it - they just write it off!
- Write what off? You don't even know what a write-off is!
- Maybe I don't but they do. And they are the ones writing it off!
Huge fortunes have been built this way, notably Gould and Kennedy.
So I keep having this thought that if Satoshi really is worth his salt, he would transfer his existing funds (of about 50 billion USD) to an assortment of charities because such an action would be quite the statement in declaring that the crypto experiment has been an abject failure and it's time to stop wasting our time and move on. Better he make this impactful statement, better him the person who started it all be behind the action to finish it, than to have to continue in this painful and agonizing path we are on.
I am really curious why Le Roux has been ruled out even by the author of the book about him "The Mastermind" by Evan Ratliff - quite a good read.
Le Roux seemed like a good candidate to be Satoshi - a Windows C++ programmer with serious crypto knowledge(most other crypto oldschoolers were on Linux/BSD), as the book states he liked adopt other persona on forums, he obviously had a strong anti-government bent,
so far that is not much but more importantly he was dealing with his real life crime empire and had baskets of money laying around the house.
it is hard to imagine Satoshi not spending some money once BTC got over $1 - unless he was really really not worried about money. Of course he could have just lost the keys...
There has to be some crucial detail which book does not mention why Le Roux is ruled out so conclusively.
I'd be curious if any code similarity analysis has been done on old LeRoux codebases and original Bitcoin code.
When the Dorian saga happened, Satoshi posted on p2pfoundation to clear up that Dorian wasn't him with his original account, I think Le Roux was in prison at that time. He's still in prison, he's been cooperating with the US government. US is definitely not letting him go anywhere for the shit he's done, everything from drug cartel work, helping Iranian and North Korean governments acquire weapons, etc.
One more delicious detail: Le Roux in a letter to SDNY judge wrote that he wants to invent ways to mine BTC efficiently. Really it comes down to the fact that Le Roux was involved with a whole bunch of stuff, and when you have this much surface area to scan you'd think you could come upon with just one strong piece of evidence... but there is nil, he's just another criminal warlord, luckily now in the custody of the US government: https://www.govinfo.gov/content/pkg/USCOURTS-ca2-20-03410/pd...
how have you quantified that, and how would you go about doing so? It isn't obvious to me. It also seems like your standard is quite flexible, like even if you quantified that use and didn't find the results you wanted, you would say that the subset of transactions that did fit your results were "enabled" and "made efficient".
- Number of scams/crimes enabled by crypto in the last decade: a ton - Number of constructive, noncriminal use-cases observed in the last decade: zero
By "constructive", I mean a use-case for which it is the best solution, which rules out every single blockchain use that is not a cryptocurrency. And the cryptocurrencies are the ones enabling the crime and scams.
Consider his unease when Wikileaks started soliciting funds in BTC. If he were all about uncontrollable money he would not have sounded unhappiness about his ballgame being used by Wikileaks.
He obviously copied the freedom dollar concept and even said they have a couple years until the government catches up.
He knew what happened to the previous own currency people so he stayed anonymous.
When the international organization can point directly to you as now holding $100M+ worth of crypto tokens and you're in a "jurisdiction like Russia," then the international organization isn't who you should be worried about.
Does anybody have a GitHub commit to the fix Binance is working on rolling on out?
https://coinmarketcap.com/currencies/bnb/
How did it not drop more?...
The actual sending domain for the email is sg.djamo.ci. Most of the links in the email are bit.ly redirects to https://bina-defi.net/markets/. Whois lookup for this domain only results in "Whois record is unavailable at this time." The server IP appears to be hosted in Germany at a hosting provider called Xsserver Gmbh. Links to "Binance.com", Unsubscribe, etc. in the email point to sg.djamo.ci and don't work (either that or my Pi-Hole is blocking them).
Everything on the web site prompts the user to connect their wallet. I can't tell if this is an elaborate phishing attempt to drain people's wallets, or a legitimate site that's set up in a way that look suspicious.
Edit: The footer of the email says the following, in spite of none of the links in the email going to the legitimate Binance.com site
Kindly note: Please be aware of phishing sites and always make sure you are visiting the official Binance.com website when entering sensitive data.
1. make an email look legitimate
2. point to an unrelated scammer-owned domain
3. steal user's financial details (be that a wallet, visa card, bank account, etc).
Was money "Stolen", or "additional tokens generated"?
What I mean by that is: If I have a chair, and you come and take my chair, you've stolen my chair.
If I am carrying $200 in cash, and you take my $200 in cash, you've stolen my cash.
(if I write a nice piece of music, and you copy it, you've performed "copyright infringement" and we can discuss whether that is "theft" or not in legal vs semantic / colloquial terms)
In this particular case, were specific tokens/crypto/something taken out of someone's wallet, OR were additional seemingly-valid tokens generated "out of thin" air? Was it a transfer or generation issue? Was some entity directly negatively affected through a specific loss, or were many entities affected by subsequent inflation due to tokens being generated?
Does my question make sense to anybody but me? :)
Traditionally, scarcity of digital music does not give it value, whereas scarcity of digital tokens does give it value.
Are you asking at what point does inflation start to hurt others?
They're both scarce in the same way.
No, they are not.
Might what possible value your comment might have, then?
> The hack was caused by a bug in the bridge’s smart contract that allowed hackers to forge transactions and send money back to their crypto wallet
The bridge is BSC Token Hub:
https://www.bscscan.com/address/0x00000000000000000000000000...
This smart contract holds coins. A bug allowed someone to forge transactions with the result that they could move coins off of the contract and into to wallets that they control.
Even actual human laws have bugs and exploitable vulnerabilities. We simply call them loopholes instead. There's even a very lucrative market for them, dominated by professionals like lawyers and accountants.
What I do think is that you can’t really call it “forgery” or “stealing”, just like using a loophole in a law isn’t illegal.
If you are, then a contract that does not do what you expect it to do is buggy, by any possible definition of the word.
Otherwise, well done!, you fooled me.
Nobody can cancel those transactions, even if everyone can see them. That's by design (and that's what makes it great for criminal use-cases, among other things).
But seriously, in the current world, if we have a half-billion dollars "worth" of legitimate (or laundered) cryptocurrency, what can you do with it in the real world, especially contrasted to what we can do easily if we have a $$half-billion in legit $, €, £, or ¥ deposits?
I don't think we could even buy a Tesla or a pizza anymore. Maybe some things on Craigslist that take crypto?
At least if I was going to risk a heist like this it's roughly what I would do.
Come to Dubai, buy some mansions with crypto (some real estate developers accept crypto), sell those mansions for USD, and voila.
2. Wait a year
3. Withdraw in batches (not all at once)
4. Move to Dubai
5. Find some sketchy guys who charge ~20-30% to go crypto -> wire transfer and don’t care about source of funds
6. Work with those guys to come up with documentation to placate compliance officers
This may not work forever because Dubai is probably going to have a big crackdown due to getting put on the FATF greylist. This also works in some Eastern European countries.
Exactly you should slowly withdraw from Tornado. But you cannot use companies like Coinbase Gemini et al because they will ask about source of funds after a certain amount which you obviously do not want to reveal and coins that pass through Tornado are tainted now due to Tornado getting put on the OFAC list so they may freeze your accounts. So that’s where the sketchy people come in.
Oh I see how this works now
https://medium.com/algorand/algorand-state-proofs-707d64038e...
https://developer.algorand.org/docs/get-details/stateproofs/
One of the drawbacks of the Algorand approach is that both participating blockchains involved a swap need to be aware of each other's block signers/validators in order to be able to verify each other's proofs. These validator lists need to be kept up to date on both blockchains and this adds performance costs (since block validators can change over time). A blockchain which serves as a hub for many other blockchains (such as the Algorand mainchain) would have to keep track of the state of validators on many different blockchains. Recurring fees need to be paid in order to keep track of validator lists. This is not suitable for low-volume markets with low fees since trading fees need to be sufficient to cover the ongoing blockchain fees. The Algorand approach is only suitable for certain blockchains where the block validator list is relatively stable and predictable, it's not suitable for a broad range of consensus mechanisms including proof of work.
With Algorand, the proof-generation Algorithm should ideally be baked into the blockchain consensus mechanism (this adds complexity and performance costs/fees to the blockchain). Aside from having the proof algorithm baked into the blockchain's code, the alternative approach is to have a separate federation of 'proof validators' on each chain which are distinct from block validators... This setup has essentially the same security characteristics as a standard multi-chain federated bridge (whose validators have visibility over both participating blockchains) except it has more complexity (risk/attack surface).
The benefit of the Algorand approach (assuming that the proof-generation is baked directly into the blockchain logic) is that it offers the maximum degree of decentralization (which matches that of the underlying blockchains). Though this is at the cost of higher fees. Markets based on it would have to have good volume in order to make it viable.
Finally, in practice, most smart contracts are controlled and can be updated by certain multisig wallets (and their members) so they're really just federations behind the scenes.
This thread linked elsewhere here is par for the course -- so many things done right in the code, but one important thing done wrong: https://twitter.com/samczsun/status/1578185275062132736
The main reason we are not afraid to do this today is because we usually get a refund if there is an issue. This is subsidized with the profits the credit card companies make from that 16%+ APY they charge people with revolving debt.
Credit card companies do all sorts of silly advertisements and cards get hacked all the time...
We can go in circles on these comparisons all day long. We have a choice... either keep the status quo, or try to work towards a future where we don't have to give up our privacy and information in order to just buy something on the internet so that we can have ads follow us around.
Whether cryptocurrencies are that solution, is irrelevant... the part where people are working on these sorts of things at all, is what I care about. I personally, would rather be able to provide liquidity and take out a loan without having to ask permission first.
That's your opinion. Integration tests on another planet are just as hard as integration tests across a crypto bridge. One can even argue that an integration test on another planet is more difficult.
So for example you send some $FOO tokens to a contract on the ethereum side then get out $WFOO (wrapped foo) tokens from a contract on another chain.
I've been interested in these protocols for a while as a possibility of making crypto actually scalable and not a pyramid scheme (basically, imagine a network of interoperable chains powered by stable tokens like USDC, and using inter-chain protocols to transfer USDC between them as needed for load balancing).
That said, reality hasn't quite met my expectations, not yet anyways.
How do you manage not having to trust the bridges in such scenarios?
The difference of course, is that if there's a flaw in proof of stake generally it means one person might control transaction flow and collect some transaction fees; if there's a flaw in a bridge then someone prints money and destroys bridge ecosystem
Quick amendment here - most of the bridges operate on these principles. There are hundreds of cryptocurrencies, trading pairs and L2 chains that have zero accountability whatsoever. It's not written anywhere that these bridges have to operate without trust, and many of them straight-up don't.
PoW and PoS are means to achieve distributed consensus. It works for cryptocurrencies because writings to the blockchain are performative (what's written is true because the act of writing it makes it true). This can only work inside a given blockchain and only for its own cryptocurrency.
Which means it cannot be used to ensure anything that happens outside that blockchain. In particular all blockchain usage for certifications, traceability, of NFT-like things are essentially nonsensical. Similarly, I don't see how it could work for writings that happens on other blockchains. Whatever is written on blockchain A cannot be considered true in blockchain B without breaking the security model of blockchain B by making blockchain A a trusted third-party.
Where does a distributed consensus mechanism comes into play here?
Maybe it would be clearer with an example? Let's say someone wants to move X tokens from blockchain A to blockchain B, and that at the time of the move, X A-tokens are equivalent to Y B-tokens (trusting the exchange rate in itself is all another problem, but let's put it aside). How would that go?
To be more specific, when I said "like proof of stake", what I meant is that there's a trusted pool of validators but the individual validators are not assumed to be trustworthy (only the pool in aggregate), and the validators use a adversarial staking model to punish dishonesty.
In the case of bridges, that pool is external to the chain. So yes, there is external trust happening.
I'll try to address your example, but I've researched this a while ago so I'm sure I could be off the mark.
For your example, lets say we're moving A-token in A-chain to wrapped A-tokens in B-chain, so we can easily assume it's a 1:1 exchange rate by construction. User moves 100 A-tokens in A-chain to a bridge smart contract and as data passes the address of their B-chain wallet.
A subset of validators in the trusted pool (chosen via some distributed protocol) together sign a multi-sig transaction that authorizes the bridge contract in B-chain to mint 100 wrapped A-tokens and send 99.9 of them to the destination address that the bridging user, and collect 0.1 of them as fee.
(If transaction were dishonest, a larger subset of validators would together sign a transaction purging those validators' stake in the pool; so the subset of validators chosen are honest out of desire to keep their staking capital and earn the 0.1 fee)
That's at a high level how it works. If you want the full details I recommend finding a technical writeup for a popular trustless bridge.
As I feared, these mechanisms do break the assumptions that would make a blockchain useful in the first place. So it is not actually possible to move tokens from a blockchain to another in the security model that this technology exists for.
> that would make a blockchain useful in the first place
This is generally a matter of opinion :) But you are correct that it has a completely different security / trust posture compared to the underlying chain, so you can't simply say "ethereum works and solana works, therefor this bridge from ethereum to solana works"
It’s not like the people running the BSC daemon are critical about the code. It’s a blockchain run by a central dictatorial authority, if there is a “critical update release” then the nodes will upgrade.
the upgrade disabled the bridge minting method, and also disabled transfers from the hacker's address
now they figure out what was wrong with the bridge and preventative measures
just a slight supply inflation (binance smart chain deflation is greater than this over any month time span), about $80 million was successfully moved to censorship resistant blockchains but as they ran out of liquidity they had to move into censorable stablecoins, which were frozen for their addresses
all validators on binance smart chain disabled all block production and have subsequently updated to freeze the minting function and also disable the hacker's address
Then someone pointed out hilariously the origins of BNB "token" in the first place - because ETH 2.0 PoW edition (not Ethereum Classic (ETC) that's a whole different boondoggle) recently migrated to PoS...
Nevermind this is dumb