A software change allowed FTX to use client money
reuters.com
reuters.com
If you want to see what you should never do as a software engineer if you like not being in jail, this is it.
Singh will definitely get prison time as well, though I'm sure all the higher-ups in FTX are trying to point fingers to get deals. In the Madoff scandal, 2 of Madoff's programmers were sentenced to 2 1/2 years each. In this case, Singh has much more culpability as a higher-up (not to mention a pre-collapse billionaire).
"Hey, due to the way our accounting works I need you to subtract X from our dashboard."
"Ok boss."
Are programmers expected to know finance law? If I build a program for a dairy farmer am I supposed to know the laws of the interstate dairy trade? I can't believe that would be the case.
> "Hey, due to the way our accounting works I need you to subtract X from our dashboard."
That is not what happened here. The fact alone that very few people knew about Alameda's special treatment, and, importantly, deliberately conspired to keep that treatment secret is a pretty strong indicator that he knew it was wrong.
(Well, it's not in finance, but it could be in tech-like crypto finance.)
Working on fintech and transaction rails? Probably. I had to know regulations when I worked in fintech. Plus, you don't have to know the law to be found guilty of breaking it.
The engineers working on this are innocent until proven guilty, but you'd better believe all internal comms, meeting notes, and commit messages will be scrutinized.
Someone had to ask for the system to behave this way, and that will have produced certain artifacts.
Engineers with knowledge may be cut deals to testify against the bigger players.
I believe in due process [& friendship, too]. But alas for the engineers concerned, SBF does not:
https://www.businessinsider.com/ftx-collapse-bankman-fried-e...
"When asked to clarify whether they were both gone, Bankman-Fried said that Wang was "scared" and Singh was "ashamed and guilty" because FTX customers' deposits had been lost."
Isn't that a strange thing to say? Singh is the guy who made the change, per Reuters, and this snake knew that.
Precisely, ignorance is never a valid defense.
> Are programmers expected to know finance law?
in our case, we were. it was drilled in, and tested, reviewed, and audited. i’m not saying that something like this couldn’t have happened, but in my case anyone who would have been involved would definitely have known the legality.
When knowledge arrives at my team, is already condensed to the point of: "in X country, you must tell the prices of a call if you show a phone number for assistance"
Why should I explore every loophole of law to be compliant? That's the companies job, not mine.
This is not hard. Nobody needs to be versed in the ins-and-outs of jurisdictional compliance rules to see this was blatant and egregious.
If any of this looks remotely familiar to any software devs out there, you should really re-examine your morals. Or at least hire a lawyer.
It also might depend on seniority so you might not be on the hook.
You're telling me a software engineer could make a change that allowed spending money a company could not legally spend and he had no idea about it? Come on. That is preposterous. At any respectable company alarm bells would be going off everywhere and fingers would all start pointing to that change. Theres virtually 0 chance that there was not intent.
Say you are an engineer working for a gun manufacturer. You need to know how to manufacture the gun. You don't need to know what it is used for or by whom or even how much it is sold for.
If you are aware that a crime is going on you in principle are required to report it, but not doing so is not nearly at the same level of crime as actually doing the crime. So here I think the court will look at two things?
Did the engineer know that a crime was being committed?
Did the engineer personally benefit from the proceeds of the crime more than their ordinary salary?
I am not a lawyer though so don't take my advise.:-)
Developers presumably know how to think and have a vague idea of what the business does to know that a ask to futz with internal financials programmatically is fucking wierd.
Also got reprimanded for disobeying an order at once; my boss — same one as above — would not take "no, we are in a regulated industry, and I cannot do that" for an answer. I ended up going behind his back, getting the approvals he should have gotten himself, and once I'd secured those, granted him the access he wanted. I also tried to escalate to his boss (my grand-boss) … but he didn't respond until it was all moot.
But there is a lot of stress when you're fearing for your job, even though you're just trying to do things by the book. I'm inclined to side with engineers, to a degree: the chain of command's responsibility is to never put eng in that position. (Although here, the eng in question seems far higher up than I am. I'm just a bottom rung eng…)
> Developers presumably know how to think and have a vague idea of what the business does to know that a ask to futz with internal financials programmatically is fucking wierd.
They should but IME they often don't, and even if they do, people are lazy. It's a struggle to get people to do the things they should do some days.
There are no regulations as to who can develop what software as far as I know. Whereas there are for who can design a bridge, act as your lawyer, or prescribe you medicine.
“Software engineer” is just a synonym for “programmer”, in the actually existing practice of the English language.
Call yourself whatever you want, but that doesn't mean you get to define what 'Engineers' are and what ethics they are bound to. Just because you use the term in your title and say it is used properly in English, doesn't mean that you won't get treated any different than someone with a PhD demanding to be called Doctor and pretending there is no difference between them an and M.D.
My impression is that this title comes from the practice of "software engineering", not necessarily that the practitioners are licensed Engineers.
I said I wouldn't do it unless they showed me the legal advise saying that it was ok. The office sycophant piped up and said "I'll do it". From then on I stopped being invited to meetings and my job transitioned into answering the phone and then out the door.
I hope they jail the developers for 500 years, that's the sort of signal that needs to be sent.
This is not dissimilar.
There is test... And there is PROD. Never do the two meet. Ever.
If someone out there does, please make yourself known so we can get the investigators over there ASAP.
You think they're just guessing that the test environment perfectly matches the prod environment?
Just deposit the money before withdrawing it.
This isn't true
I worked for a large bank. I managed data for their mortgages. We bought another bank and processed their mortgages with our systems. There were several thousand accounts that we called "friends of the <former CEO>" because they had really weird terms.
A noteworthy example is: $10m Home Equity loan, with 2% interest for 40 years, and the owner could refinance any anytime without any fees
In English, this means we can't repossess their loan, they pay a super low monthly payment, and the final amount is never really due.
The other customers have no standing there, they have no relationship whatsoever that contract between the bank and another customer, they have no legal expectation to get the same conditions or to know what conditions other customers get. If the bank explicitly and intentionally lied that no other customers get so favorable conditions, that might be false advertising but I'm not sure, I'd expect a reasonable court to interpret that a bank "telling your customers you don't and can't do this" is exaggeration/puffery (i.e. permissible) and doesn't have to literally mean that they're not doing that for anyone, it means that they absolutely refuse to do it for you.
A car salesman telling you they can't sell you the new Buick for $42,000, when they sold one to their neighbor yesterday for $41,000 is not fraud.
Another fact I omitted is that the interest rate is 2%, but the minimum payment is lower. So the borrower is accumulating owed balance because they are paying less than interesting accruing.
And now that the bank has new ownership they might be able to refinance again and continue to kick the can down the road, but they're less likely to get as favorable of terms I'd imagine.
And the technical term for the type of refinance is "recast" (iirc) - so the "new bank" honors the terms because it is a part of the originating documents.
Yeah??
I don’t know what exists in the crypto world operating in the Bahamas, but I’m not going to lose a lot of sleep if the FTX director of engineering winds up going to prison for this.
A senior developer of anything in this area would be expected to fully understand the risk implications of this. I have written the code to closeout positions automatically multiple times in multiple jobs.
It may have been possible someone directed a junior developer to make this change, but then it would be a case of hunting down who told them. If that happened in my team I'd be documenting everything I saw and running, not walking, not walking briskly, out the door.
This said, nothing is black and white. For example, due to immature processes, they might have told the developer that the main account was only one of many accounts they can call on, but the code only allows for one, so we have to make an exception. I'd still be freaking out.
If you are trading or working with customer money, you usually have to take the Series 7 exam.
So I would say for regulated industries, programmers are expected to know some degree of financial law.
Software probably makes things even more hazy but in traditional engineering world there are very clear cut rules around professional ethics, personal liability and disclosure.
https://adage.com/article/marketing-news-strategy/tom-brady-...
I'm surprised that even Football players are being expected to have evaluated the company's legitimacy, which seems unreasonable.
You also need to have faith in the compliance team and senior management. If your company works in legally sticky territory like crypto doubly so.
That’s true, but ignorance of the facts often can be. “I didn’t know I was doing X” rather than “I didn’t know X was illegal”.
But how long? Jerome O'Hara and George Perez were arguably more complicit in Madoff's scheme than anyone, having written the computer software to generate the fake investment return reports and even actively helped dupe the investigating regulators but were only sentenced to two and a half years in prison.
Even the most kind reading of the situation leaves little doubt that they knew exactly what was going on.
Remember Alamada wasn’t a normal customer. It was acting as a market maker/counterparty of last resort to many other FTX customers. In that case there could be situations where ‘normal customer liquidation rules’ shouldn’t apply - it can go in the red temporarily to enable others to trade (and FTX to make commission).
From the facts in the article (which are obviously not complete) if I was Singh my defence would be I assumed/was told the changes were to support Alamadas role as market maker and their actual long term exposure was being monitored elsewhere.
This might be a reasonable argument in a vacuum, except that:
> [SBF] told investors and prospective investors that FTX had top-notch, sophisticated automated risk measures in place to protect customer assets, that those assets were safe and secure, and that Alameda was just another platform customer with no special privileges. [emphasis added]
And also:
> Bankman-Fried also told investors, and directed other FTX and Alameda employees to tell investors, that Alameda received no preferential treatment from FTX. For example, Bankman-Fried told the Wall Street Journal in or around July 2022: “There are no parties that have privileged access.” Likewise, in a Bloomberg article published in or about September 2022, Bankman-Fried claimed that “Alameda is a wholly separate entity” than FTX. In the same article, Ellison is quoted as stating about Alameda: “We’re at arm’s length and don’t get any different treatment from other market makers.” Bankman-Fried made similar statements directly to investors. [emphasis added]
(The above are direct quotes from the SEC complaint [1] against SBF.)
Singh might argue that he wasn't aware of the private statements to investors. But the WSJ and Bloomberg stories show the "arm's length" claim was something they consistently messaged to the public at the highest levels. To argue that Alameda's role as market maker of last resort justified a privileged status would be inconsistent with all their prior public claims to the contrary. "We lied to the public repeatedly about our risk management" isn't a defense; it's a confession.
[1] https://www.sec.gov/litigation/complaints/2022/comp-pr2022-2...
'Hi mate. We just bought this rebar from Alibaba, saved as a ton of money. Could you sign here real quick? We need to finish that bridge!'
No one has had their engineer title taken away for being a crook, as far as I know. Unless the crooked thing they did was fake their diploma.
Titles won't fix this.
This seems an absurd claim, unless you're going to get very pedantic about some distinction between "engineer title" and "legal right to function as an engineer".
> https://montreal.ctvnews.ca/engineer-s-licence-revoked-after...
This is one example found after just a few seconds of searching, but it is absolutely commonplace to have your engineering license revoked for carrying out criminal activity.
> In those jurisdiction where it's a protected title, it just implies that you have some mix of STEM topics in your degree.
This seems a bizarre claim too. In jurisdictions where membership of a professional licensing body is necessary in order to refer to oneself as an engineer and practice as an engineer, it is absolutely not the case that all you need is the right "mix of STEM topics in your degree". It means you have a certain degree, have completed a set amount of work experience, have completed a professional certification exam and then maintain that license, which may require meeting other requirements periodically. And yes, "not being a crook" is certainly one of those requirements, and being involved in major criminal activity, especially criminal activity related to your professional practice, is absolutely grounds for having your license and certification as an engineer revoked.
This seems pretty unambiguous though. Sometimes you're just facilitating breaking the law, or making things dangerously unsafe.
The practical answer is that it's because we do want to discourage criminals from "splitting liability" by having most of a gang doing some illegal goal together stay "clean" and only delegating a single "fall guy" for the final touch; so criminal law is explicitly written to consider everyone who knowingly assists a crime to be partly liable as well.
That is outrageous. The company owners have limited liability protections. The employees should receive at least that unless they are in a position that requires specific legal training like an engineer legislatively appointed to be responsible for some safety function. Where they are appointed and remunerated specifically for their legal responsibility, in other words.
And the court cases after WWII are hardly reliable precedent. They were basically making it up as they went with fairly flimsy justification apart from the fact they had a bunch of troops still in fighting form.
> That is outrageous.
And this is why software engineering is a joke.
Software engineers are not lawyers and they are bad at interpreting laws.
If the product of your engineering directly enables unethical actions, yes, you should bear some of the responsibility for it.
Right, so if something seems sketchy ("please ignore these specific deductions when calculating our holdings") , get a lawyer - or CEO or CFO or whatever - to say in writing that it's fine.
And if something seems actually illegal ("just run the blood test results out-of-spec and report them anyway") just don't do it. Nothing absolves you of some things.
> That is outrageous. The company owners have limited liability protections.
The owners have limited financial liability, not limited legal liability.
https://en.m.wikipedia.org/wiki/Limited_liability
> Limited liability is a legal status in which a person's financial liability is limited to a fixed sum, most commonly the value of a person's investment in a corporation, company or partnership.
Are you serious? Make sure your ass is covered if you're doing illegal shit for your company, because they're never looking out for you over the org.
Yep.
"comprehensive knowledge of their companies media output" is an interesting way to put it. I would really just recommend engineers maintain some sense of self awareness.
There are people who make a living playing poker that are not intellectually gifted. Their secret? Do as you say, play boring, safe strategies that will guarantee you will make money in the long run. They might not run up 1000$ to 10000$ very often but they sure do win. However, remove discipline, add intellectual ability and an abundance of overconfidence and you get FTX and Alameda Research.
And the fact that by far the largest market maker in the US is also a hedge fund (two different companies with the same owner(s), where have we seen that before?).
I am baffled by why fraud was necessary. I guess it's just means to an end for "effective altruism".
These days a naive market making strategy in crypto just incinerates capital very reliably as the tiny bid ask spread is a small fraction of the adverse selection risk (whole spread moving past). They did probably make money on this in the early days and got smoked when the sophisticated tradfi players joined.
Front running large trades by looking at non public info on the order book is possible but this is also fraud, so not a strategy to avoid legal troubles, and it also only works if the large traders are naive and not adversarial (putting fake large orders to front run you etc).
What SBF could have done is close down Alameda when it was clear they were not competitive, and concentrate on growing the exchange by reinvesting the fees, but that would have clipped the growth and donations/acquisitions lifestyle to something much less flamboyant.
That said they are being accused of something much less sophisticated. They were allowed to take money out when they made money but didn’t have to pay money in when they lost.
…do you see the problem?
* Attribution: who's making the order?
* Short labelling... are they selling or shorting?
* Non-display or iceberg orders (not common in crypto?)
* Immediate-or-cancel orders... the executions hit the feed, but not the original order details. Also whiffs (order but no fill) don't get disseminated in any way.
* Certain order types that may rest on the exchanges order book but either don't have a specific price or display doesn't make sense... market orders, midpoint orders, pegged orders, auction order books (less common in crypto)
EDIT: On the attribution side -- they could also know the leverage any customer is taking and use that adversarially (which was the straw that broke their camel).
> Certain order types that may rest on the exchanges order book but either don't have a specific price or display doesn't make sense.
I suppose orders than are designed to only be consumed by a matching engine don't need to be made public unless they are matched.
That's for honestly run APIs, then an exchange can play some games with that feed if they want to...
This is not true at all, in general quoting in these markets is absurdly capital-intensive compared to tradfi.
> These days a naive market making strategy in crypto just incinerates capital very reliably as the tiny bid ask spread is a small fraction of the adverse selection risk (whole spread moving past). They did probably make money on this in the early days and got smoked when the sophisticated tradfi players joined.
Are the sophisticated tradfi players here yet? Seems like no?
Source: I work at a firm that does this.
For example, it's surprising that big tradfi players were not able to prevent take-only basis arb bots written in Python running on a un-tuned VPS from printing five figures on individual new listings in mid 2021, or permitted us to click trade tokenized stock quarterly futures minutes from expiry for nearly guaranteed profit also in mid 2021.
It would be hard (but not impossible) to implement such functionality without dozens of software engineers being very aware of it's existence and the implications.
This kind of software change only touches the edges and can be done with much more plausible deniability. The exclusion to margin calls was a single if statement inserted by a single engineer with the justification Alameda were the primary market maker. The dashboard change might have been just a bug they avoided fixing (If you normally automatically margin call negative balances, why would your dashboard bother reporting negative balances?)
In any case it's not needed: liquidators get the 3% initial margin so are usually in profit. For the cases when the market moves faster than that, they should have done what the better-run exchanges do and close the most leveraged positions from the opposite side: if lots of longs get liquidated in aggregate the shorts get their profit trimmed by the losses of the longs beyond maintenance margin, in order of leverage, which is fair enough when duly documented in the terms.
Reconciliation was still happening every 24h tho.
If the chief engineer for NASDAQ put in a backdoor to allow a market maker unlimited margin, would you assume they just figured it was legit because someone said so?
He knows how markets work too well for a defense like that.
Strange comment.
Are the engineers who made the code change responsible?? Do engineers need to be lawyers and financial gurus too, and evaluate every ticket they are given for possible illegality in every country the software is used??
Or think about people who build bridges. They just follow the orders they get from higher ups. Bridge collapses. The higher-ups should be held accountable not the workers. The question I think is did the engineer here just follow orders? Perhaps he understood very little about finance, only about programming.
I would guess the compensation structure at FTX included a lot of their own crypto tokens, since the company can mint those at no cost. And Alameda was a big holder of those FTT/Serum tokens.
So you're a software engineer who owns theoretically millions of dollars worth of FTT tokens, and then the boss comes to you and asks to make an exception for Alameda... Since you work at FTX, you're probably aware that Alameda holds and trades a lot of FTT. If you do the code change to make Alameda look better and maintain the value of your own crypto portfolio, there's no question that you're a part of the fraud.
A code change excluding a known, named entity from safety checks is more like rigging a bridge to explode when your enemy crosses the bridge.
Zero ambiguity.
That’s not the question — as in, it won’t be an element of any of the crimes he’s eventually charged with. The question is whether he was knowingly or recklessly involved in a scheme to defraud people.
And just generally, legal reasoning does frequently use analogies but they need to be tighter than the ones you’re using. This case isn’t much like building a faulty bridge.
Murder-in-first-degree means you didn't just recklessly cause the death of somebody, it means you did it intentionally, on purpose.
See Mens Rea, "Criminal Intent" https://www.law.cornell.edu/wex/mens_rea
Was this engineer knowingly and intentionally helping to commit the crime? We don't know because we haven't seen many details or testimonies in this case. He must be assumed innocent until proven guilty. And proving him guilty must include proving he had criminal intent, Mens Rea. The court of public opinion as in Hacker News is of course a different matter.
I think what's up to debate is to what extent the developers were lied to regarding the purpose of the code. Maybe they were told it was for testing purposes only, or the higher ups managed to convince them that it's ok despite them questioning it. I suppose those things will come up during investigation and will certainly affect their sentences, but I don't think they will be off the hook that easily.
Your gun analogy is not fair and it does not translate well to the actual situation at hand. A gun engineer is not responsible for all the deaths the weapon causes. But said engineer will be very much accountable if the weapon blows up in the wielder's hands during normal use (even though practically this might not be the case due to liability disclaimers and all that).
We have case studies where deaths were caused by shit software, where the engineer of that wrote the software is clearly the accountable one.
You could make this argument for literally every profession.
The person who commissioned this change, knowing the potential financial ramifications that it opened them and their depositors money up to, is the one who should be charged.
However, "do this bad act and we'll all get rich" seems a bit ... harder to sympathize with.
Yes, you are. Splitting responsibility between those who give orders and those who follow them to avoid penalties is exactly why both are persecuted and put in jail.
That sounds like Julian Assange. Did you mean "prosecuted"?
I work in another regulated industry today, and throughout the year sign off on understanding various regulations and trainings of 3 letter agencies, that are essentially in place to indemnify the company in case of a violation. I’d expect financial services follows similar steps.
This is very odd special pleading by programmers. Every industry needs to do this: journalists learn media law in their university degrees, architects have to learn the building regulations. Why is programming any different?
That's absolutely ridiculous, and no court would expect it.
I expect other engineers to know laws when creating things (not like having a JD). Accredited business schools in the US teach business law to their undegrads. It's absolutely not ridiculous or a stretch to have a similar expectation.
> When it's something seemingly egregious like this
You don't even know what "this" is. So the BI engineer that stitches together data for a report should have known that combining these two values was illegal? What silliness.
Have you ever looked at media law or libel law? It does not have clear boundaries, but journalists are still expected to follow the law. Journalists are not absolved of the responsibility because it’s complicated.
You just need to not break the law. It’s how it works. If you don’t want exposure to liability, you need to acquaint yourself with relevant law.
They absolutely have boundaries that a lawyer or prosecutor can use to make a case in a court of law. How do you think the law works? Interpretation of laws is a big part of how the common law system works.
You can't prosecute someone for murder just for insulting you. You can't prosecute someone for robbery if all they did was jaywalking. Media laws have clear boundaries sufficient for legal professionals to do their job. Building codes have clear boundaries sufficient for legal professionals to do their job.
In this Chancery case from 2021, the judge mulls over what it means that a defendant is “unaware”. He considers the distinction between someone who knows about the relevant law and misunderstands it vs someone who doesn’t know at all. And the judge briefly wonders whether someone working in regulated activity (like finance) and completely unaware poses the most risk to the public.
The judge left the issue unsettled, but it raises the possibility that ignorance might count against a defendant. The Chancery Division handles business disputes, though, and I imagine the criminal courts have their own rules.
Paragraphs 22-25 are most relevant: https://www.bailii.org/ew/cases/EWHC/Ch/2021/995.html
Complete nonsense. This is criminal law. Google "Mens rea".
This is not an argument against programmers, like other professionals, learning the aspects of the law which are relevant to their job. Why should programming be the one profession where this is not required?
You can still get sued in civil court of course, but that's not the state trying to put you in a cage and so the standard goes from beyond reasonable doubt to most likely.
If you're a coder coding shady shit for your shady employer, you most likely know you're doing so and there's typically some trace or record left. But coders are not investment bankers and in fact may not even know anything about investment laws and regulations. And it's completely unreasonable to expect them to know. I worked on many projects, including medical and education... if I had to question and investigate every executive decision impacting my work then I wouldn't get anything done.
E.g. if I take your wallet off of a table because I thought it was mine, I’m probably not guilty of theft. If I took it because I didn’t know theft was illegal, I probably still am.
Furthermore, even in cases where mens rea is required, it gets satisfied if you intended to achieve the prohibited result even if you thought that the result was permitted. "Intent" is not about intent to break the law, it's about the intent to do the thing that happens to be illegal. In this case, it matters if you knew what the thing you're making was going to be used for (e.g. hide some stuff from auditors) but your knowledge or ignorance of the relevant laws and regulations doesn't matter at all - as another poster noted, https://en.wikipedia.org/wiki/Ignorantia_juris_non_excusat .
Exactly. And if you suspect you _are_ doing stuff like this right now, speak to a lawyer, today.
Not quite the same level, but in my early days working on a payment system, a request from the product team was to create a summary screen where customer service reps could see payment histories AND THE CC INFORMATION USED FOR THE PAYMENTS. In my mind, there was no way that would end well, so I strenuously objected and had to endure some very heated conversations over the course of a month or two. Eventually product team agreed to last 4 digits + expiration.
Nowadays it wouldn't even be a conversation, but in the early 2000's, it was a different world.
I remember one site that saved all the CC and order details to a plain text file in the web root. This was opened using an FTP programme every evening and someone would run the numbers through the machine in their store and post out the orders...
They aren't coming from a baseline assumption that their job is to protect and interests and the money of their clients.
Traditional banks, for the most part, have DNA built around protecting customer interests and customer money. Crypto companies have none of that attitude - behind every one of them is a sleazy tale of self interest and corruption.
My first introduction to this way of thinking was many years ago when I worked on a software development project and the project manager was extremely concerned about a single cent being wrong in the calculations - he taught me that with customer money you cannot get even a single cent wrong.
These crypto idiots are just young cowboys who see a giant pile of loot and don't have any concept of how to manage it in an ethical manner. They just wanted to work out how to gamble it all in the hope of more crypto gold. If there are crypto companies that have not yet had their rotten hearts exposed and gone bust, it's simply a matter of time.
Every single one of these companies will - and should - go bust - good riddance. It's a pity Robinhood won't go with them - the filthiest scumbags of all.
Edge cases matter a lot more to Wall Street than to Silicon Valley. Wall Street is a world where the new hire on the desk gets a talking-to by the managing director for making an error that could have led to a big loss, and where people are regularly reminded not to put anything in writing that they wouldn't want to see on the cover of the New York Times. Silicon Valley is a world where "move fast and break things" is a central mantra, and sometimes those things that get broken are the rules.
It's sad that the entire crypto industry happened too fast for the regulations to keep up, with the unsurprising result that vast amounts of customer money have been lost and stolen - the precise reason for regulation.
I would not be surprised if many people have taken their own lives as a result of crypto losses arising directly from lack of integrity of the companies managing the customer money.
Licenses/certifications do exist. SBF had the FINRA Series 7 and 55.
https://brokercheck.finra.org/individual/summary/6204362
The loophole is that employees at hedge funds and investment advisers don't face the same licensing requirements as employees at banks and brokerages who deal directly with customers. There are people who trade billions of dollars of customer funds a week without any required regulatory exam or license.
So he knew what he was supposed to be doing.
I have a Series 7 and have never handled client money, but I wrote software and had had access to these systems.
Not all fintechs are evil.
If exchanges and stuff had to play by any rules, they’d go out of business because there is no other reason for crypto’s existence but to run scams.
(Okay maybe it won’t entirely collapse but crypto certainly wouldn’t be valued anywhere near what it is now)
At the same time I read stories about other countries where people think it's completely normal that some third party app has replaced the bank's role as a payment processor, even going so far as to include these services within the banking environment itself.
The way I see a large amount of fintech is that business savy people see their banks struggle to get up to standards that were common elsewhere ten years ago and try to make a quick buck throwing together an implementation before the banks can get themselves together. These companies solves the needs of the end customer, but only patch over the underlying problems that keep building up because there is no reason to address them anymore.
How much can you really trust a company built on profiting off the failings of a basic institution underlying almost all commerce?
Meh. Being a middleman, or doing something better than companies do themselves, is the foundation of most economic value creation.
As Schumpeter observed, value creation is accompanied by creative destruction, and right now it looks like we're in the "creative destruction" phase when it comes to fintech.
It was one thing when in the early 2000s creative destruction was involving entities like pets.com, no-one was really hurt by those companies going down, but it's another thing when the company going down might hold your "savings" or owe you money as a SME, like Revolut or Klarna.
The "move fast and break things" slogan was by Zuckerberg at Facebook, though they've since abandoned it.
And, Wall St is where this isn't the case?
An interesting observation. My take is that even though Wall Street has unfathomable levels of hubris and poor ethics, it understands CYA.
Fintech on the other hand...
You don't need integrity while "the line goes up". Integrity is only for when it goes down. Until recently, the line has been consistently going up. SBF was banking on it going up forever. If it had gone up forever, he would not have been caught!
While the line goes up, integrity just eats into potential profits. It's an extra cost. No business willingly spends extra money they don't have to. That's why regulation and oversight is mandatory.
> ...he taught me that with customer money you cannot get even a single cent wrong.
SBF gave an accounting on FTX holdings with an error margin of "plus-minus 10 billion dollars".
Can you imagine having error bars 20 billion dollars in size!?
For reference, companies with market caps in that range include: Tata Motors, Best Buy, Komatsu, Zoom, East Japan Railway, Mitsubishi Electric, Delta Airlines, or Panasonic!
Sit down and picture telling someone with a straight face that you may or may not have misplaced "value" on the same order of magnitude as an entire airline, or an electronics manufacturer with a worldwide presence built up over seven decades of growth.
Integrity is how you behave when no-one is watching.
“Integrity is doing the right thing even when no-one is watching.”
It's outrageous that there is no honour amongst scammers.
Yes, I can imagine having error bars in 20 billion dollars in size, its what the financial audit space does every single year. It's what keeps companies like you've listed in line, because you audit against a materiality.
Let’s not forget that these regulations they’re getting rid of came about after 2008, when banks had to be bailed out by taxpayers around the world.
As they say, what causes more damage, the founding of a bank or the robbing of a bank?
The teams managing the money-handling-software care very much about protecting your cents.
The product managers inventing new fees do not.
> One of things that tends to boggle programmer brains is while most software dealing with money uses multiple-precision numbers to make sure the pennies are accurate, financial modelling uses floats instead. This is because clients generally do not ring up about pennies.
Would you feel comfortable wiring your money off to a bank account in the Bahamas? I wouldn't. I think safety is more about jurisdiction (and therefore regulations) than it is about what type of currency a business deals in.
Bank DNA has always coded for taking foolhardy risks with customer money. It wasn't until heavy regulation came into play that banks stopped going bust left and right, at least in the USA. Even under heavy regulation, you still see their true colors from time to time such as when they discovered risk loopholes in 2008 that led to the financial panic.
Until regulation hits crypto custodians, they will largely be fly-by-night yokels that go bust left and right, just like the first American banks did. After regulation hits, they will be just as safe as modern banks (and likely, many crypto custodians WILL be modern banks - see e.g. Fidelity entering the custody business recently.)
> The real problem behind all these crypto companies is the people who make the money have no concept of what "integrity" is.
The entirety of Wall street has no concept of what "integrity" is. The solution was heavy regulation. It happened to banks, and it will happen to crypto. Crypto custodians are speed-running banking regulation.
> Traditional banks, for the most part, have DNA built around protecting ...
Traditional banks lack of "integrity" has wrecked considerable more havoc than crypto companies. Actually, the impact of these exchange crashes are completely negligible compared to the financial crisis ~2007.
I don't think we're living in the same world :) Traditional financial institutions are just as bad, if not worse, than most crypto companies. You just have look at all the financial system crashes and exchange frauds. A key difference is that the government is there to bail them out because they are tightly linked, and that traditional institutions know they'll be punished because of strict regulations. It's not about the actors, or some kind of fuzzy DNA/culture, but about government and regulation.
I think it's also important to note the discrepancy in transparency. Yes, FTX was just a centralized exchange that had little to do with the blockchain, but you were still be able to see some of FTXs balance movements on-chain, simply because they are forced to use ETH/BTC/FTT/etc. If we hadn't, FTX may have gotten away with what they're doing a lot longer. Nobody may have found out.
With traditional financial institutions you have almost no transparency. You have absolutely no idea what they're doing behind your back. All you can do is trust the government to eventually bail them out if they mess up. Or trust that they're scared enough of going to prison that they don't try shady things.
I think people might have noticed that customers could not withdraw funds, and the exchange declaring bankruptcy in any case.
Banking meanwhile can fail even with honesty because of the nature of borrowing short and lending long.
Yes these crypto bros are young grifters out for the big score with zero integrity or morals and hopefully they will look forward to spending their best years in a jail cell. But they are enabled and encouraged by a good old boys network of VCs, journalists, and other influential figures in the tech community. Madoff at least picked rich people as his marks; the media have blown up the likes of SBF as geniuses and encouraged ordinary people to invest money they can't afford to lose in crypto.
On one of of my previous contracting gigs (about 20 years ago), for a very large, USA-based financial services company, the VP hired me for a full month (at consultants pay rate, 40 hrs a week) to investigate and track down a 1-cent discrepancy in $4,000,000,000 under assets for a particular division that differed between two reports by exactly 1 penny(one generated on the mainframe/cobol system, and one generated on a custom pc based system).
Turned out it was a rounding error in like the 8th decimal place on the mainframe side. I thought it was crazy at the time - but guess his thinking was there is no difference between being a penny off, or a million dollars off - you need to be able to account for every cent.
And thus do we have another piece of evidence for why morals and ethics matter, even for software developers. I doubt they'll end up with liability, but I do hope they at least recognize and think about how their actions enabled this whole mess.
They're each going to run up five, maybe six, figure legal bills.
These guys are going to spend a good bit more than that.
When you should know it's criminal, "just following orders" isn't a great defense.
> but I do hope they at least recognize and think about how their actions enabled this whole mess.
They should get lawyers. And be prepared to sing like canaries.
That's even true in the military if you're given illegal orders. It's called the "duty to disobey".
It's not enough that employees "should" know what's illegal and what's not in an exchange -- companies need to be held criminally negligent for employing people who don't know.
But that's why software "engineers" have quotes around "engineer"
If my boss came to me and said, “continue showing customer funds sent to our “sister” investment company in the staff dashboards” I wouldn’t find that suspicious. I would probably push back and say that might be confusing unless we separate out that amount and rename the total to something that denotes part of this value is with our sister company. But I would assume design incompetence and not fraud.
But then again if I was just one of a handful of devs that worked with the company I would probably find it suspicious, as I would confidently know that nowhere else in the codebase do we support a close integration with our sister investment company and should therefore know we shouldn’t treat them any differently.
Also the modification to exempt the investment company from risk rules does seem suspicious, unless again you believed there was an integration somewhere and believed investment risk mitigation rules were handled on the other platform or something.
I doubt that. If they haven’t been sued already, they will tomorrow.
Singh is going to jail. He was an executive, not just a low-level employee, and was a pre-collapse billionaire. I have no doubt the evidence like this will show that he knew what he was doing was willingly fraudulent. Madoff's programmers each got 2 1/2 years.
It sounds like there's plenty of other evidence, but allowing a 'negative balance' hardly sounds like a smoking gun.
A negative balance is often how credit is displayed.
>Since Alameda didn't have the funds to meet these requests, Bankman-Fried directed Alameda to tap its "line of credit" with FTX to obtain billions of dollars in financing, the complaint said
The article actually says as much. Now as Chief Engineer it's possible he was aware it was a scam, but it's also possible he was just told they have an arrangement with Alameda that allows them to maintain a credit line.
Unfortunately what happened here is a fraudster latched on to a movement that decried centralized trust and said that he is trustworthy and, when asked, pointed to some code that no one could inspect or understand. Simpletons believed him because they believed in the 'trust the code' hype, and believed his money was real. They were wrong.
But at the end of the day, expecting code to replace the core human emotion of trust, the source of money, is ridiculous.
No, the point is for code to replace the institutions/people that people trust (ie. trusting the bitcoin network's consensus code, rather than a central bank), not "replace the core human emotion of trust".
Knowing how computing hardware and software works, I wouldn't put more trust in code either - in fact it would be less.
If you don't understand currency basics, I advise to stay away from crypto
By the same token, money is debt from the past.
The origins of debt are ultimately material. Alice has a bushel of apples today, but Bob won't have a bushel of oranges until next month. The function of money is to decouple the general function of debt from its material details. In other words, you can have debt without money, but you cannot have money without an underlying debt.
This type of synchronization requires a negative price signal on money though.
This is really sad. Especially the guy who 'advised' to stay away from crypto. I don't need advice to know it's for idiots
You are never borrowing from the future. In a 100% reserve system you borrow from other people in the present. If you fail to repay you don't disappoint your future self, you disappoint another person in the present.
In a fractional reserve system loans create both debt and new money and the debt is always an obligation to pay back present money on a fixed schedule.
I don't think the movement cares about centralized trust? Instead it's a movement of get rich quick schemes
There's some separate movement that cares about decentralization, but they're only tangentially affected because they didn't use FTX, and they don't value their crypto in terms of stuff it can buy, but how it makes them feel
Even expert programmers aren't able to check smart contracts for all possible issues.
It's actually sane when your contract is written in a non-turing-complete language with strong typing and the smart contract system has deterministic execution (i.e. you know the result when you submit the Tx and if the result would be different, the tx fails, preferably without charging you).
I'm convinced that one of the main issues with most smart contracts is that they have such weak guarantees and the guarantees they do have are brittle and hidden behind complex, opaque proofs & constraint systems.
What was the language and why did running it in a stack based VM lead to this? I'm curious about the intersection of the language and the type of VM it ran in.
They didn't. They made a hard fork and the community followed. The "hacked" chain still exists, go use it if you want.
It's hard to name any crypto organization that was seen as more reputable than FTX before this happened.
If we can't even trust someone with SBF's track record, what's left?
The guy showed up out of nowhere... suddenly being promoted by throwaway reddit accounts, claiming to have made more than ten billion on trades where claiming a million dollar payoff would have been surprising and dubious.
Their exchange specialized in offering almost anonymous retail traders access to leveraged trading on the most dubious of cryptocurrencies stuff popular exchanges won't carry and they carry a lot of bullshit. They even had varrious weirdo products 'index funds' including one called 'shitcoin index'.
When FTX acquired a derivatives clearing house I used, I pulled 95% of my account value out right away. I also warned my friends to stay away from FTX or anything related when I had the chance-- which wasn't often because it wasn't something most bitcoiners I encountered were particularly aware of (as mentioned, their service was more of a casino than an exchange-- big leverage for the most volitile crap).
So while I get how people that might have been in the right media bubbles might have thought it was reputable... but generally? Not a chance, at least not from my perspective.
Was the media critical? No-- there are reports that negative stories about SBF and FTX were actively suppressed in some newsrooms and it's already the case that scamcoiners are actively suing people who criticize them, so that's a big incentive to say nothing when you see a fraud.
Countless charlatans have run confidence scams (cons) in the crypto space, accuring money and attention around a centralized platform, in a tech area predicated on decentralized technology.
Living through the MtGox era, watching the corners of the Internet refer to the incident for a decade and then the Shocked Pikachu faces now? I just can't.
I don't care about crypto and "the masses". I invest in things I understand, and it hasn't _burnt_ me yet. I understand crypto and it's unique value prop and it sure as hell doesn't involve investing in or putting my money into a centralized platform. And certainly not one run by the blessed-ilk of Wall Street.
Once again, ever so slight skepticism for the win. It's truly unbelievable the irrationality people engage in when they think they're in on something even when they don't actually understand it!
"The line goes up" is a cautionary tale, and yet I think some folks really missed the whole middle section talking about the psychology that the vultures (NFT, centralized exchanges, etc) are preying upon when chasing explosive growth (or riches, on the other side of the equation).
> and smart contracts don't replace the need for social trust.
idk, a (still relatively) fat stack of crypto sitting on my Ledger would disagree.
A bad actor can steal the voting tokens, and decide the vote. Even without that, I can't assume that the voters are aligned to my interests
Right, but all those attacks are harder to pull off and more visible than what the parent implied (ie. someone can unilaterally make changes without anyone finding out). Like I said in my previous comment, there are many issues with smart contracts, but the objection raised by OP is just really badly conceived.
>Even without that, I can't assume that the voters are aligned to my interests
This seems like an impossible demand to me. What type of system (democratic/non-democratic, crypto/non-crypto) ensures that the decision made will always align with everyone's interests?
The reporting has a high content to fluff ratio - refreshing.
He may ask the judge for a rebase.
Is there a line item for "this code feels like there's something wrong, but I can't tell what" ?
I don’t know how prevalent it is but I’ve done it enough times that I don’t bat an eye when it comes up.
In congressional testimony on May 12, he called FTX’s software “safe, tested and conservative.” By quickly unwinding the riskiest, most undercollateralized positions, the risk engine prevents build-up of credit risk that could otherwise cascade beyond the platform, resulting in contagion,” Bankman-Fried testified. He did not tell lawmakers about the software change to exempt Alameda. Indeed, he told investors that Alameda received no preferential treatment from FTX, the SEC complaint said
This isn't like coding a bomb to kill people, where the programmer clearly has an ethical choice.
Singh was an employee, whose bosses had the job of ensuring what they asked him to do was legal, and he was not obliged to consider the ethics or legality with full view of the "big picture" nor even know or take the "big picture" into account.
That's the bosses job, that's why they're paid more, that's why they take more risk, that's why they may end up in prison.
Even where Singh knew something was up, it wasn't his place to be a financial expert. That's what the company's senior staff are supposed to be. Even where Singh had a partial knowledge or view of the entire company/companies or the legal framework they operated in, in his role as a programmer he was not obliged to have a full view (nor could he have).
This partial view of what's going on means his decisions can not be in full consideration. It's the bosses job to make the consideration. They failed.
To judge Singh in hindsight as if he knew everything we know now, or that the courts will come to know, is bizarre.
Would not be surprised if this move was advised by their legal counsel.
Not that we didn’t see that coming or anything
I don't see you being jailed for your random GitHub project being sloppy. However, if your closed source software that you advertise as 100% safe and secure gets used by a chemotherapy clinic, and then it comes out to be downright sloppy after killing 20 patients you may be accused of fraud. Anyway, not a lawyer so take it with a grain of salt.
The perfect crime would be to add a natural looking bug in the code that can be exploited by someone else, and then we split the money!
> Every year, we will propose a challenge to coders to solve a simple data processing problem, but with covert malicious behavior. Examples include miscounting votes, shaving money from financial transactions, or leaking information to an eavesdropper. The main goal, however, is to write source code that easily passes visual inspection by other programmers.
I think this revelation points to the further guilt of SBF and his excuse that "he was incompetent" will fall face down under scrutiny.
const evil = false // do not change to true[0]https://www.statista.com/statistics/576473/united-states-qua...