Quite a few of their clients have gone on to do that with relatively simple vulnerabilities. To the point where “certik audit” is a meme about not providing any actual assurances (and thus implying they are incompetent).
There also was the story a month or two ago where they actually took funds from a bug bounty target and eventually did give it back: https://blockworks.co/news/krakens-cso-confirms-certik-retur...
There's just absolutely no point to crypto if you end up having to trust institutions that are fundamentally less trustworthy than mainstream financial institutions and regulators, even if they have plenty of issues too.
There's also a non-zero sum of crypto proponents that think a large swathe of things that are illegal "IRL", should be non-criminal because ... "online".
Sure, but there is a reason that real banks have tons of laws and regulations. It's more or less not a crime to steal crypto because it's not a thing that's protected by law. And crypto bros are doing everything they can to keep it from being protected by law while whining that the law isn't able to help them.
Unequivocally false in the United States. Despite what computer professionals may sometimes think, judicial opinions and most of our legal system are based on what a "reasonable person" would believe. Judges don't agree with the "Neener neener neener! The terms are exactly X!" methodology, typically.
A reasonable, everyday person (and therefore a judge) would consider a party being deprived their valuable assets as theft, absent some form of agreement. Invariably, the reply incoming is "codeislaw," but that's absolutely not the case in every circumstance.
In this meme, why isn’t the permissionless aspect seen as not gatekeeping who is involved?
Any "service" that goes against this is basically normal money except way worse. That doesn't mean crypto is broken or useless. It just means scammers gonna scam.
Nice example: Bitcoin ETFs completely miss this point. Is a Bitcoin ETF actually backed by real Bitcoin? Nobody really knows, but judging by Wallstreet's track record and who's behind it (Blackrock and Coinbase) the answer is almost certainly: no, your ETF order is not hitting a lit exchange and no it's not backed by anything and no, the SEC doesn't care.
Literally every US financial crisis can be summarized as "it turned out not to be backed by anything". More info: https://www.amazon.com/Decade-Armageddon-New-Geography-Essay...
VW squeeze: short positions that cannot be closed, because more stocks where sold than where supposed to exist. Same thing for Gamestop (except worse, 220% shorted at some point).
2008 crash: packages of high quality mortgages / credit that turned out to be backed by 0 high quality mortgages.
FTX scandal: sold tons of "Bitcoin" that turned out to never have existed + traded "tokenized stocks, backed 1-by-1 with real stock by some shady broker in Germany" that turned out to be a complete lie.
In the real world trust is something thats tied to people, then to organizations, etc. Online, to trust is more than just security
Without a real-world identity and a reasonable guarantee of enforcement, it's a lot harder to establish any kind of serious trust, possibly fundamentally impossible.
...and all the miners, the backing infrastructure, internet and so on.
At least for BITW ETF addresses are disclosed and you can verify it yourself.
For others there is actually on-chain intellegence that let's approximate how they moving BTC itself. I mean there is always a lag between fund adjustments, but you can pretty much verify that BlackRock actually hold a lot of BTC.
https://platform.arkhamintelligence.com/explorer/entity/blac...
They were pointing out that crypto users rely on these worse-than-worthless audits and as an example how it wasn't until threatened with traditional law enforcement certik gave tokens back.
> What's holding the safety level back ironically is the overbearing regulations making individual financial sovereignty a pain.
There is absolutely no evidence of this.
The reality is, that because of KYC/AML laws it's difficult for ordinary people to replace cash with crypto, which - if it were easy - would be a superior form of money and transacting as any amount from tenths of a cent to billions, moves frictionlessly.
But still, would you bet a billion dollars that whatever crypto system you are using has no bugs, vulnerabilities or backdoors? Are you going to audit the whole codebase yourself and trust your technical assessment? Do you even have access to the code that is deployed?
In terms of the blockchains themselves, they all have a kind of built-in bounty, in that if on-chain funds have inherent risk of being lost or taken due to faults in the system, this will have happened - as the biggest / most popular systems are valued in the multi-billions. Ie, a huge bounty if an exploit exists.
To my knowledge, this has not occurred to date with any of the major systems themselves.
It's important not to mistake the above with a different issue of trusting applications development built on blockchain projects.
Almost all blockchains have kind of two layers of functionality.
The base layer allows self-custody and transfer.
Above that, people can build other things using smart contract languages, or hardware solutions, or software that interacts with the chain. Those can have huge bugs or be outright scams.
It's a bit like HTTPS could be provably secure, but that doesn't mean if you visit https://dodgy-website.com-dodgy.tk you're protected against it doing something dodgy.
The different is while HTTPS is limited in its user-facing application, the base layer of say Bitcoin or Ethereum isn't so much.
People can securely store and transact any amount with anyone worldwide, sometimes in seconds, with complete finality and determinism, without needing to trust anyone in between.
In almost all cases, you also have access to the code, and can build it yourself. But as mentioned, the built-in bounty acts as your best security.
Eg, if there was a hole in the base layer of Bitcoin right now, there's hundreds of billions up for grabs.
We already have that in many countries. Yes, it's subject to AML/KYC regulations, and? Why is that a problem? It's only a problem if you want to remain anonymous (which you don't, really, with crypto), which is a very niche use of money. A lot of it related to crime too, which makes it hard to justify.
If governments are acting fairly, some of crypto's use-cases will simply not be adopted en masse. If they're not acting fairly, it will all have huge take up. In that sense it's like a check and balance on democratic values.
This has demonstrably been the case in many countries.
Governments that come down extremely heavy-handed against it, are almost certainly themselves either corrupt in the worst case, or against common democratic principles of freedom and personal sovereignty in the best case.
The common BS trotted out is that crypto os used for financing terrorism. The reality is, cash is used for financing terrorism, banks are used for financing terrorism, and governments are used for financing terrorism.
Why target only crypto for this? Because it's a ruse. It's being targeted for other reasons.
A government truly "for the people, and by the people", would welcome the people being more easily able to transfer value between each other and hold it closer to them without a middle-man they need to trust.
What are those reasons? I'm not doubting you, I actually don't understand.
A government structure concerned more with self-preservation, will - accurately - perceive crypto as a threat to its antithetic hegemony, through a diminished ability to, for example:
- conduct itself without transparency. In a functionally-crypto world, government transactions would be immediately and openly public and auditable by anyone, and likely so automated. Currently, months long latency and bureaucratic obfuscation work against accountability.
- unfairly freeze assets for the purposes of self-preservation or power. In many cases there could well be no ability to freeze assets at all. (Private keys can be stored in minds, and this can be plausibly denied.)
- control the economy, and so ultimately, manipulate every aspect of a populations direction. A sufficiently smart-contract operated world could decentralise and democratise economic "policy" so much it may no longer fit inside that definition, as it may potentially become less of an affectation and more of an effect.
A proposed downside of all this is it simply may not work. I don't buy that. I think the main problems we have as a species are in how we allow ourselves to be exploitable. Building in greater sovereignty is the solution, not a problem.
> Why target only crypto for this?
But this just isn't true. All financial institutions are subject to KYC and AML laws are large penalties have been applied, eg https://www.austrac.gov.au/news-and-media/media-release/aust...
It's not the crypto exchanges pushing for that - they actively work against it as it's a major expense as well as costing them customers.
Aside from exchanges, consider: cash itself is not targeted by these laws, which is crypto's closest existing analog. Do you need to submit KYC and AML documents to pull cash from your physical wallet and pay someone? Yet the push is for that level of involvement in your crypto wallets.
Finally, the SEC's actions for example are very clear: an obvious scammer like FTX gets a tick of approval and ends up reaming customers for billions. Whereas long-stable contributors such as LBRY or Ripple, get bogged down with heavy-handed enforcement. There are more examples.
HSBC was legally found to be actively engaged in facilitating criminal gangs, money-laundering etc. They paid a fine. You think a crypto exchange found to be doing those things would pay a fine? No, the executives would be jailed.
There's a big difference in application, across the board.
I notice substantially lower documentation requirements for a crypto exchange vs a bank. For example for both Binance and Gate (and I think Coinbase - not entirely sure there) I only had to supply a single identification document. For my bank accounts I've never been able to open one with less than 3 documents.
Not sure what your point about HSBC is. If you think SBF or CZ shouldn't be in jail then I don't know what to say. In the case of HSBC I'm not aware of individual witness accounts of deliberate criminal behaviour of individuals like both CZ and SBF did. But I absolutely agree people should have gone to jail.
In general crypto people seem to disagree with the idea of laws - specifically ones that apply to them. When challenged they resort to whataboutism or conspiracy theories. It's a set of weak arguments and really lays bare the weak intellectual foundation the whole crypto industry is based on.
I notice the reverse though it does vary by jurisdiction.
I described FTX as an "obvious scam", citing it as an example of the SEC greenlighting a bad actor - so your speechlessness is the result of comprehension issues on your part.
It's not a "conspiracy theory" to hold a different opinion to you regarding financial policy direction.
What I regard as "weak" is the use of such derogatory labels, rather than proper discussion.
Good day!
We already know crypto is being used for real, actual terrorist funding[1]. How do propose to balance access to crypto against that real harm? KYC rules seems a reasonable compromise here.
[1] https://home.treasury.gov/news/press-releases/jy1925 (note funding of ISIS amongst others)
It's slower than the growth of storage/$$$
In general, it turns out that it's very hard to build a crypto wallet that both is easy to use for regular people and doesn't take the control of your keys away from you.
Also let's not ignore that the crypto system itself is not magical and can have plenty of security issues too. At this point we can be fairly confident that BTC and ETH are safe, they have been battle-tested, but this is still about trust. When you get into smart contracts and other complex usages of blockchains, who knows what bugs they might have, there is zero enforced oversight. Crypto only ensures that it will work how it is programmed to work, but the programming could be wrong.
I actually have the skills to evaluate such a device if I had a few weeks of spare time. Expecting the average joe to have that ability is folly.
We have a system of laws and contracts and enforcement that allows someone to trust their bank account without a great deal of sophistication.
To be fair, it's a little hard not to when crypto is so bad.
A) the smart contract audit is a choice, certik is one player providing them, there are many players and its a choice that consumer and investors misuse the point of those audits to even make the make. certik provides disclosure of vulnerabilities, consumers chose to see that as a greenlight instead of an objective decision to participate or not
B) your ensuing conversation about exchanges has nothing to do with what certik does or has made a meme for. so thats the conversation you actually wanted to have the whole time, a copy pasted “look! Crypto mentioned, my time to generically complain about it” discussion, but not one really relevant here.
certik and others are just providing cybersecurity, its a sector that needs it, there is demand for it and thats as deep as it goes. if your crusade is to reduce demand for it, its an ineffective and redundant use of energy at this point.
There are zero trust protocols within some crypto ecosystems and some of the world's top crypto PhDs work on these projects. There are just so a lot of amateur devs and uneducated users trying to make a buck, of which get exploited by a much more sophisticated party who also wants to make a buck, sounds like pretty much any other capital market just much more blatant.
Or, I can buy USDT and move it to my cold wallet and call it a day.
Yeah, but if you get wronged on normal capital markets you can complain at the authorities and get your money back. Your bank goes bust? FDIC covers up to 250k per account. Your credit card company doesn't side with you in a dispute or your bank's customer "service" department acts up? Call the CFPB, and you'll get a call from somewhere very high up the bank's chain who actually has the power to make things happen to make sure you withdraw your complaint. A public traded company does bullshit to mislead investors? The SEC will tear them a new hole. And so on.
In the crypto world, you're left to deal with all of that on your own. Maybe the police will file a fraud complaint that won't lead anywhere.
They are two completely different things, once you dig a bit deeper. One is going to improve the world immeasurably - in fact one of mankind's most important (maybe greatest) inventions, and the other is a snake pit.
If what I say sounds crazy, it won't after you've studied the topic for 5000 hours.
The running joke is that protocols with no security audits are safer than protocols with security audits done by CertiK.
They're ostensibly an audit/security firm, but miss many vulns
Most egregiously recently they tried to blackmail Kraken, a big exchange, for $2m