> DeFi already exists, and have been existing for almost as long as FTX. Likes of FTX and Binance was created in the first place because decentralized, trustleas on chain transaction is slow and expensive, and people don't like slow and expensive. Just because FTX blew up doesn't mean DeFi is at a better place than it was in the past. "DeFi fixes this" is like saying "moving back to horse drawn carriages solves drunk driving fatalities!" Maybe, but no one wants to deal with horse shit.
So you get speed, low fees, and full transparency and safety. There's a reason both Brian Armstrong and CZ have said they see DeFi replacing their exchanges eventually.
Also, promising my half-assed project will be perfect by the time the finals roll around stopped working in the real world when I graduated from high school. Seems like only in crypto world it's acceptable to judge technology for not what it is but what it dreams to be.
From what I've seen it's basically at a point now where hacking a DeFi bridge essentially guarantees that you can keep 10% as that seems to be the standard for "bug bounties" now. That is, of course, unless you keep 100%...
It's very likely that if DeFi as a whole had the user base of FTX (or major centralized $EXCHANGE) the losses would be similar if not higher. The only thing that has stopped this from happening is the fact that the average centralized exchange user doesn't have a chance of figuring out how to do DeFi (see points above).
[0] - https://hacken.io/discover/top-defi-hacks-of-2022-and-how-to...
I understand what you're saying but the result is the same and it's little consolation to the people who lose their money.
If you get mugged and someone steals your wallet (FTX, crypto wallet, or physical wallet) = money gone.
If you lose your wallet (physical or crypto) = money gone.
If you get handed a counterfeit bill (physical hack) and it's detected and confiscated later = money gone (best analogy I could come up with for a DeFi hack).
In any of these cases if those funds were needed to buy groceries for your kids or pay your rent the end result is the same. Whatever philosophical point you and the last commenter are trying to make means absolutely nothing to the very real people in the very real world who are significantly impacted by these events. People work for their money and the blase attitude and callousness shown towards victims in this space is very disturbing. We wouldn't remotely be having this discussion if someone gets robbed at gunpoint (victim of a crime) vs FTX (victim of a crime), DeFi hack (victim of a crime), wallet hack (victim of a crime), etc.
In the real world outside of crypto these events are exceedingly rare. I've been mugged once and I'm an outlier. I report credit card fraud and it just goes away. I've never had a bank fail. I've never lost access to a bank, trading, etc account. I've never had a negative experience with a wire transfer. I could go on and on while meanwhile all of these things and worse are a daily occurrence for an outsized portion of people involved in crypto.
The FTX failure alone is estimated to have impacted 1 million people. Celsius has 100,000 creditors. Who knows with DeFi, crypto wallets, etc but as I said originally I personally know an order of magnitude more people who have encountered these issues than the equivalents in the traditional financial system (real world).
If someone has deployed a DeFi app that can't be changed and hasn't been hacked in a few months, I'm fairly confident it's safe. With an exchange it doesn't matter if it's been running 10 years, it could start stealing money tomorrow.
When an iOS zero day is discovered (as one example) exploiting it often still takes multiple steps, i.e. some action each individual target needs to take. In most cases (rarer and rarer with the exception of log4j, etc) this limits exposure until it can be discovered and patched. Even in the case of things like log4j you can patch your instance before someone gets around to exploiting your instance.
It's widely known that governments, people like the NSO, hacking groups, etc sit on zero days for as long as possible waiting for an opportune moment with the highest return and biggest impact. Hacking groups, governments, etc have been known to sit in compromised networks for years before striking. Point here is they can be remarkably patient and with smart contracts by the time the issue is discovered there's no point - the smart contract is now at $0 and the attackers have disappeared into the night.
When smart contracts are deployed they sit at an address. If an equivalent "zero day" is discovered it's just there there waiting for someone to exploit it with global/universal impact. No action on the part of any users, no need to deploy target by target. I'm sure I could phrase that better but early-morning HN is what I do between waking up and the caffeine kicking in for real work :).
Point here is, I don't quite understand your "it's been around growing for a few months and $10m (or whatever) is there so it's probably safe". Why strike a buggy contract when it's received some amount of traction and is still early stages? Why grab $10m when you can grab $100m (or more)? As I noted there have been several cases (arguably most) where I'm pretty sure the attackers did just this.
Or, in the case of Axie Infinity, you can steal $620m the "good old fashioned way" by targeting and manipulating one of the people behind it. So, in practice, in many cases, humans are still involved.
This also doesn't get to my other points involving the challenge of securing your own wallet, etc. If you peruse around Discord, Reddit, etc where crypto people of higher than average knowledge, skill, and sophistication are reporting daily wallet hacks you'll see just how hard this is. The equivalent being there's a reason why (for example) the United States keeps gold reserves in places like Fort Knox where there is a literal army of 26,0000 soldiers securing it. Most people don't have that ability and even though this comparison is a little tired I think it applies quite well to the difference between keeping gold in your house vs securing it in a bank vault (for example).
That said, you have a point about centralized exchanges but there's a reason why banks don't run off or gamble (FTX) with customer funds - regulation. I think it's clear from the FTX situation something closer to "bank-ish" regulations are coming to centralized exchanges which only tips the calculus further here towards centralization. So, as is often noted, crypto in general is marching closer and closer towards centralization and consolidation which history has demonstrated is almost always naturally the case.
DeFi has no fiat gateway though, that's the biggest bottleneck. The gateway is the centralized exchanges, and I think people tend to park their money on them once they deposit/convert their dollars.
2. More importantly, an email provider that doesn't make an effort to distinguish between 99% of spam emails and 1% of legit ones is definitely useless and worthless.
Because it's a protocol anyone can build a frontend on top of it to filter out any information they like, just like Email. Zapper, DeFi Saver and Zerion are examples of this. Element Finance runs using Balancer under the hood but you wouldn't know and aren't exposed to any tokens or pools they don't manage.
We have a chance to make finance better with companies that are completely transparent. Where all funds are held by code which can be audited and proven that they can't steal funds.
Decentralized versions of what FTX did already exist:
- Exchanges: Uniswap, Balancer
- Lending Markets: Aave, Compound
- Options: Lyra, Ribbon
- Perps: GMX, Perpetual
We don't have to suffer through scammer after scammer until the end of time, and we don't need overbearing regulation to save us. We just need transparency.
Real finance is already being done in these platforms and I wish more people would take it seriously and realise this can be a much better future for everyone.
Plus because they're open source and composable we can innovate much faster but that's a thread for another time.
What we need is better, more equipped, and less corrupt regulators.
FTX (The entity) going bust and losing all customer funds and you buying a shitcoin and losing your funds.
One is FTX's fault, one is yours. If you are using a DEX, you understand that anyone can add their token to the list if they have enough liquidity.