[HN Gopher] Wormhole confirms all $320M in funds have been restored
___________________________________________________________________
Wormhole confirms all $320M in funds have been restored
Author : ushakov
Score : 144 points
Date : 2022-02-03 18:19 UTC (4 hours ago)
(HTM) web link (finbold.com)
(TXT) w3m dump (finbold.com)
| [deleted]
| agd wrote:
| Another question to ask - who lost most of the ETH in the first
| place? Could some of this be VCs paying themselves back and
| shoring up their investment in Solana at the same time?
| danielvf wrote:
| Wormhole is now owned by the crypto arm of a large traditional
| financial trading company, Jump Trading. Here's a tweet from the
| CEO of Jump Crypto saying that they put up the funds:
|
| "Jump put up 120k of it's own ETH because we believe in Wormhole
| and want to support it in this stage of its development."
|
| https://twitter.com/KariyaKanav/status/1489312871456649228
|
| I think Jump Crypto also also heavily trading across the bridge,
| which means that some portion of the lost funds were their own
| funds.
| benreesman wrote:
| I know relatively little about Jump Crypto BU per se.
|
| But I know people who work at Jump and they are serious as a
| heart attack.
|
| I think we can all sleep easy that the terrifyingly smart rich
| people made the right call on how to handle their own exposure.
|
| If retail people got jacked that's another matter, but that's
| not how I'm reading this? Did I miss something?
| Tenoke wrote:
| Yes you did. They could've not deposited the funds in which
| case it would've been retail that covers the cost. Instead
| they do and the loss is purely on them.
| gaogao wrote:
| I got a pretty extensive walkthrough of Jump's risk
| management stack and wasn't particularly impressed as a
| counterpoint.
|
| Side note: it's interesting that Jane Street is pretty anti-
| crypto and sort of indirectly results FTX from Sam and co.
| jumping ship.
| Zababa wrote:
| Interesting that Jane Street is anti-crypto too considering
| they somewhat collaborate with Tezos through OCaml.
| exdsq wrote:
| I don't think they are from my somewhat limited exposure
| to them through events
| zvzztz wrote:
| That doesn't appear to be true.
|
| https://www.bloomberg.com/news/articles/2022-01-24/jane-
| stre...
| gaogao wrote:
| Hmm, fair. I guess really only historically. My data
| point was from about 6 months ago when they had stated
| far less exposure, but money I guess.
| tylersmith wrote:
| Wormhole has always been owned by Jump.
| cldellow wrote:
| I don't think that's true. Disclaimer: I know nothing about
| this space.
|
| But:
|
| - Oct 2020: Certus One is proud to announce the Wormhole
| project [1]
|
| - August 2021: Jump Trading acquires Certus One [2]
|
| [1]: https://medium.com/certus-one/introducing-the-wormhole-
| bridg...
|
| [2]:
| https://www.bloomberg.com/news/articles/2021-08-03/quant-
| sho...
| almalkemqq wrote:
| guys, if you have crypto assets, move them qredonetowrk they are
| decentralized custody. they will save you fees from ETH.
| remember, if you don't own your keys, it's not your assets
|
| this is why I advise you to use qredonetwork :)
| T3RMINATED wrote:
| bigdaddyrabbit2 wrote:
| This is interesting. The hacker did not return the ETH, so the
| $320M has come from the deep-pocketed investors and VCs behind
| Solana/Wormhole.
|
| Interesting to note that the VCs are bailing out the retail users
| here, instead of the usual flow where taxpayers are on the hook
| for bailing out too-big-to-fail WallStreet banks.
| duxup wrote:
| If they didn't have the money / decided it was too much for
| them, they would just walk too.
| somenewaccount1 wrote:
| How is it interesting for them to fulfill their fiduciary
| responsibility to individual retail user? Banks do this all the
| time.
| slg wrote:
| They aren't doing this because it is the morally right thing to
| do. They are doing it because they feel that the $320m is
| important to secure the value of their business, the Solana
| ecosystem (thanks for the correction arberx), and crypto in
| general.
|
| My personal interpretation of that, there are a lot of awfully
| rich people who are scared of the bubble popping.
| X6S1x6Okd1st wrote:
| Were the 2008 bank bailouts done because it was the morally
| right thing to do or because they felt like it was important
| to secure the value of the economy.
|
| It seemed like there was a lot of awfully well resourced
| individuals that were scared of slipping into a depression
| slg wrote:
| >Were the 2008 bank bailouts done because it was the
| morally right thing to do or because they felt like it was
| important to secure the value of the economy
|
| Both. It was done to preserve the value of the overall
| economy. That impacts everyone at every level of society
| and therefore it was the morally right thing to do. You can
| argue that the specific action taken wasn't the most
| effective approach, but the goals were noble in 2008. The
| goal here is that these rich people don't want to lose
| their investments.
| throw_nbvc1234 wrote:
| Not meant as an attack on the parent comment but I've been
| interested in the concept of judging things by inputs versus
| outputs. I see aspects of this in many controversial
| subjects; particularly homelessness. Different groups of
| people seem to focus on one side and ignore the other side of
| the equation when making arguments. These groups just end up
| talking past each other then and don't make progress towards
| a consensus.
|
| I'm curious what kind of research (or keywords to search for)
| there is around this topic. Is it just a morality thing or
| does it go beyond that?
| arberx wrote:
| Solana ecosystem*
|
| Exploit happened on Solana. Jump Trading has a vested
| interest in the Solana ecosystem and is effectively the sole
| market maker on it.
| lima wrote:
| There's a number of market markers besides Jump, like
| Alameda Research.
| benreesman wrote:
| I think Wintermute and Efficient frontier also at least
| dabble.
| bigdaddyrabbit2 wrote:
| Nothing happens in finance because it is "the morally right
| thing". It's all a game of incentives. Wall Street Banks take
| disproportionate risks because they are incentivized to do
| so.
|
| The interesting thing here is how the un-bailout-able nature
| of ETH affects the players in Crypto. Because ETH can't be
| magically printed, the VCs have to decide if they will walk
| away or bail out the retail end users. It looks like they
| decided to do the latter.
|
| This has happened more than once in Crypto - I can think of
| the Binance hack, where Binance bailed out the users. OpenSea
| has also been covering ETH lost by its users who had their
| Bored Apes stolen because of user mistakes.
|
| I wonder what it is about Crypto that causes large players to
| cover user loses. I need to learn more.
| latexr wrote:
| > I wonder what it is about Crypto that causes large
| players to cover user loses.
|
| The answer is in the comment you replied to:
|
| > there are a lot of awfully rich people who are scared of
| the bubble popping.
|
| The value or cryptocurrencies depends on hype and on
| convincing the next chump that they should buy in. The
| large players have a lot of money invested which they will
| lose if the cryptocurrency value tanks because people lost
| trust. Covering user loses is itself an investment; it
| contains the damage by making the issue die down.
| slg wrote:
| Exactly, this move tells us that the people behind
| Wormhole think that $325m is the lower bound for the risk
| to their previous investment if they didn't act. That
| means they likely have billions at stake in which they
| fear losing or like I originally said they are worried it
| is a bubble that might pop.
| naraga wrote:
| they are scared of bubble popping yet give away $320m. okay.
| quartz wrote:
| There's precedence for this in the crypto space as well. In
| 2017 Coinbase famously reimbursed everyone [1] impacted by an
| ETH flash crash that pushed the price from $320 to $0.10.
|
| [1] https://techcrunch.com/2017/06/24/coinbase-is-reimbursing-
| lo...
| rlt wrote:
| If that's the case "restored" is an interesting way to put it.
| kwertyoowiyop wrote:
| And the passive voice is telling.
| verdverm wrote:
| I was thinking "replaced" is more accurate
| kordlessagain wrote:
| I was thinking an "investigation" is in order.
| shrimpx wrote:
| Something similar happened in the WSB/GameStop fiasco where
| Citadel and Point72 bailed out Melvin Capital and its
| investors.
| keewee7 wrote:
| >instead of the usual flow where taxpayers are on the hook for
| bailing out too-big-to-fail WallStreet banks
|
| Why is there so much misinformation on the 2009 bank bailouts?
|
| The bailouts were loans and investments that became profitable
| for tax payers.
|
| >In total, the government has realized a $109B profit
|
| https://projects.propublica.org/bailout/
| defaultprimate wrote:
| This is a commonly repeated trope that is completely false
| and based on very questionable accounting. Namely the
| omission of opportunity cost and the comparison of static
| parameters to temporal parameters.
|
| https://mitsloan.mit.edu/ideas-made-to-matter/heres-how-
| much...
| NovemberWhiskey wrote:
| What do you think that paper actually says? I keep seeing
| it cited as "no, this is how much the bailouts _really_
| cost! ", but that's not what it's about at all and anyone
| who has actually read it cannot credibly come to that
| conclusion.
|
| It's about assessing the fair value of the bailout
| programs, at the time they were executed - i.e. the
| estimated net present value of the future cashflows under
| the bailout programs. The author argues that it unhelpful
| from a policy perspective to do an _ex post_ analysis
| because it only describes what happened in this case,
| rather than what _could 've_ happened. i.e. when
| considering whether a bailout is good value, we should
| consider what happens if its unsuccessful.
|
| There is absolutely no doubt that the bailouts have been
| profitable for the government in terms of actual
| repayments.
| defaultprimate wrote:
| From the abstract:
|
| "Drawing selectively on existing cost estimates and
| augmenting them with new calculations, I conclude that
| the total direct cost of crisis-related bailouts in the
| U.S. was on order of $500 billion, or 3.5 percent of GDP
| in 2009. [...] Those conclusions stand in sharp contrast
| to popular accounts that claim there was no cost because
| the money was repaid, and with claims of costs in the
| multiple trillions of dollars."
|
| From 3.1.3. See Wall's analysis of Fannie Mae and Freddie
| Mac for more detailed discussion of their bailout costs:
|
| "Treasury collected $147 billion from Fannie and $98
| billion from Freddie. As explained earlier, interpreting
| this tally as a cost measure is conceptually flawed for
| several reasons. Wall (2014) also discusses the
| shortcomings of this approach, which has been used to
| argue that the government has been more than fully repaid
| and that value should be returned to the shareholders."
|
| From the conclusion:
|
| "Nevertheless, the total is large enough to conclude that
| the bailouts were not a free lunch for policymakers as
| some have claimed."
|
| What the paper is saying seems pretty clear to me:
| bailout costs have been inaccurately measured and
| reported popularly at both ends. It was neither
| unfathomably expensive, nor profitable to the tax payer.
|
| If you lend me $100 and I pay you back $107 you can
| declare you profited from the loan if you literally only
| look at the principal and repayment amount, but finance
| is not so simple, especially at a national level.
| Opportunity cost, inflation, depreciation, and numerous
| other factors exist. The total cost of you lending me
| $100 could have been significantly more than $107.
| NovemberWhiskey wrote:
| I invite you actually to read the whole paper. Please pay
| attention specifically to section 2.1 where the author
| contrasts "fair value", "ex ante" and "ex post"
| approaches to direct cost _estimation_.
|
| The paper says that you cannot look at a successful
| bailout and conclude that it must have been good policy,
| because success was not guaranteed; you instead need to
| look at the range of outcomes that are reasonably
| possible to estimate the likely costs.
|
| The author doesn't at all say that the "ex post" account
| of actual cashflows is an inaccurate _measurement_ of
| what happened; only that it doesn 't represent a useful
| policy tool for estimating whether other bailouts
| represent good value.
| srcreigh wrote:
| $109B profit from a $635B investment over 13 years is less
| than 2% yearly return.
|
| It's a huge waste considering other higher return
| investments.
|
| EDIT: see replies for much needed nuance
| ClumsyPilot wrote:
| This is thoroughly wrong.
|
| Government does not invest a limited pot of money like
| 'savings', it conjures up money out of nowhere and can
| deploy ulimited amount of capital. The only limit on this
| activity is literally breaking the economy, causing
| inflation, etc,
|
| If you propose we dump that money in education, well, we
| should, but it does not mean we should not bail out the
| banks - these two problems do not compete for same
| resources.
| srcreigh wrote:
| Sure. The GGP tried to say the bailout was an investment
| with profits though. It's not as simple as "They got low
| returns so it was a bad investment", but it's also not as
| simple as "They got returns so it was a good because it
| was an investment."
| NovemberWhiskey wrote:
| Even if you accept the amazing, faulty premise inherent in
| this comment (see the other response for more on why one
| shouldn't), the timeline is misleading.
|
| For example, TARP (about $475bn) was more than 93%
| recovered by the end of 2012. The bank-related programs had
| already over-recovered $23bn versus the $245bn disbursement
| by that point with approximately a 4% internal rate of
| return.
| arcticbull wrote:
| Not to mention the inflation rate between 2008 and 2010
| was -4% and then 0% for a hot minute thereafter.
| Factoring that, plus the 4% nominal return, meant that
| the programs yielded something like 8-10% annualized real
| returns.
| cguess wrote:
| Not if you consider that the return was a nice side effect
| of also not crashing the world economy. Not every
| "investment" is just about making money, this one just had
| the nice side effect of not costing it as well.
| andrepd wrote:
| Opportunity cost [?] 0$.
| ClumsyPilot wrote:
| > The bailouts were loans and investments that became
| profitable for tax payers
|
| I dunno man, I was always told that government being active
| in the market is socialism, and socialism always fails. /s
|
| Surely we could extend this success by having the government
| invest trillions in zero carbo energy, an investment that has
| to succeed.
| steelstraw wrote:
| An underappreciated improvement.
| arcticbull wrote:
| > Interesting to note that the VCs are bailing out the retail
| users here, instead of the usual flow where taxpayers are on
| the hook for bailing out too-big-to-fail WallStreet banks.
|
| If you're referring to the 2008 bail-outs, those weren't
| grants, they were loans and investments. To date, beneficiaries
| have repaid more than the initial amount netting the government
| (and hence the people) a significant profit. $109B to date. And
| the expectation of significantly more to come. Talk about a
| good investment. [1]
|
| Fannie and Freddie alone received $191B and have paid $301B in
| dividends so far - and all the principal remains outstanding.
|
| [1] https://projects.propublica.org/bailout/
| panarky wrote:
| _> those weren 't grants, they were loans and investments_
|
| Those loans and investments weren't guaranteed to be paid
| back, the government took a risk.
|
| Assuming risk of loss is a valuable thing that gets traded
| all the time through futures, options, swaps and other
| derivatives. Those futures, options and swaps have a cost.
|
| The fact that the government gave away that value for free
| means it was a massive gift to Wall Street banks.
| NovemberWhiskey wrote:
| I suppose it depends on exactly which program you're
| looking at, but since you mention Wall Street banks, I
| assume you're talking about the Capital Purchase Program.
|
| I don't think it's reasonable to say that this was given
| away "for free". If it was "free" then there wouldn't have
| been any over-recovery at all, would there?
|
| In the CPP, the government bought preferred stock in a
| number of banks (mostly not Wall Street ones, but
| whatever). That stock could've been worthless if the banks
| failed, but otherwise the banks were required to pay an
| annual dividend of 5% through 2013 and 9% thereafter; plus
| there was a whole host of supervision of their activities,
| including limitations on their ability to pay ordinary
| dividends.
| joe_the_user wrote:
| Aside from the other considerations, "it was a good
| investment" stuff is just ridiculous. The general bank isn't
| in operations to make money - it's in operation to protect
| the market, the currency and the economy as a whole so
| whether it makes money is irrelevant to whether these loans
| were a good idea.
|
| But even more, if the Fed basically designates a bank "too
| big to fail" (as the Fed did) and loans the bank the money it
| currently needs, the markets can this. And this allows the
| bank to "print money" itself by issuing bonds - since now the
| market knows those bonds are effective guaranteed by the Fed
| and so equal to money. Thus the bank can easily issue enough
| bonds to repay or over-pay the Fed. But that's not a "see,
| problem solved!" situation.
|
| The theoretical problem of this sort of action is naturally
| these large entities potentially issue loans and borrow
| without being disciplined by risk. That might be compensated
| for by other actions - say preventing them from issuing risky
| loans. But things still wind-up a bit "distorted". I'd
| recommend Doug Noland's Credit Bubble Bulletin on the
| subject.
| arcticbull wrote:
| > Aside from the other considerations, "it was a good
| investment" stuff is just ridiculous. The general bank
| isn't in operations to make money - it's in operation to
| protect the market, the currency and the economy as a whole
| so whether it makes money is irrelevant to whether these
| loans were a good idea.
|
| The central bank did not make these investments, Congress
| did, and so the yields did not accrue to the central bank
| but to the Treasury. If you've ever met the IRS you know
| that the job of the Treasury is in fact to accrue revenue.
|
| The central bank's charter is to maintain a low,
| predictable rate of inflation over a medium term and to
| maintain maximum employment.
|
| > The theoretical problem of this sort of action is
| naturally these large entities potentially issue loans and
| borrow without being disciplined by risk.
|
| I agree, which is why Congress needs to better regulate the
| sector. However that's Congress' job not the Fed's.
| joe_the_user wrote:
| I don't think any of your actually change my point that
| the project making money is irrelevant to and a
| distraction from the basic impact of the loans.
|
| While one can debate whether just regulation can prevent
| private investors from engaging in risk, there are other
| impacts as well. Putting a whole lot of money into bank
| which invest in "safe assets" like real estate, causes
| the relative price of those assets to increase. This
| distorts the economy - that disproportionate rent and
| real estate price increases over the last ten and twenty
| years are arguably a product of Fed largess. And these
| have been a disaster for anyone not being buoyed by the
| risings - the majority of those in lower income
| categories.
| arcticbull wrote:
| Housing is a very different matter, one primarily defined
| by zoning. Zoning rules in major metros prevented supply
| from meeting demand by preventing new construction.
| Zoning rules outside major metros made the average new
| home 2X bigger. [1] Combined these make houses
| dramatically more expensive even though the cost per
| square foot on average, adjusted for inflation, is
| exactly the same as it has been since the 1970s.
|
| Japan for instance has seen their M2 money supply 3X from
| 1990 to 2022, while the affordability of a house there
| hasn't decreased since 1995. [2]
|
| This is due to their federal zoning rules which permit
| housing construction practically everywhere. [3]
|
| The increase in price of housing is what's _driving_
| inflation, not vv imo.
|
| And for what it's worth, I think Glass-Steagall (brought
| in as part of the post-Great Depression reforms) did a
| very good job of preventing retail banks from investing
| in toxic garbage and its repeal in 1999 was IMO a major
| contributing factor to the crisis in the first place. [4]
|
| [1] https://fee.org/articles/new-homes-today-have-twice-
| the-squa...
|
| [2] https://fred.stlouisfed.org/series/JPNCPIHOUAINMEI
|
| [3] https://marketurbanism.com/2019/03/19/why-is-
| japanese-zoning...
|
| [4] https://www.federalreservehistory.org/essays/glass-
| steagall-...
| papito wrote:
| I hope this is not an argument for more bailouts. A _lot_ of
| people walked away with riches while ruining the US economy.
| "I lost $100 but lookit I just got back $15" is not a win,
| it's just... less of a loss.
| [deleted]
| andrepd wrote:
| That's very nice and good. So if I struggle to pay my
| mortgage, why am I evicted instead of bailed out? It's highly
| unlikely that I be unemployed for the rest of my life, so I
| would surely be able to pay back any bailout, with interest
| to spare. Why do banks struggle and get bailed out, but
| people struggle and don't?
|
| Or looking at it from another point of view: the money spent
| on bailouts wouldn't be stored under a mattress if it were
| not spent that way, therefore you cannot compare $109B with
| $0. You have to compare it, for example, with the money lost
| from the moral hazard of rewarding the irresponsible
| behaviour which led to the most destructive recession in 75
| years, or to the effect the money would have had it been
| spent helping the millions of people that lost their jobs or
| had their homes foreclosed on, etc.
| somenewaccount1 wrote:
| beeboop wrote:
| Why do people go to jail and lose all ability to make
| income, but corporations don't? Corporations should get
| virtual jail time where they're not allowed to operate for
| a set period of time and have all their rights stripped
| away.
| andrepd wrote:
| Honestly, I'd settle for jail time for the _actual
| persons making the illegal decisions_ , rather than
| virtual jail time for corporations. You know... personal
| accountability.
|
| Say a factory is poisoning the riverwater, what is more
| likely to disssuade such actions: penalties to the
| company (taken in stride as the cost of doing business),
| or actual jail time and forfeit of assets to the person
| making the decision and reaping the profits from it?
| beeboop wrote:
| The problem is that a company can be a revolving door of
| people taking the fall for crimes. The better dissuading
| action is to force the company to shutter operations for
| a set period of time. It's only fair that such a
| catastrophic punishment can happen to individuals that it
| can also happen to businesses that are generally much,
| much more harmful.
| yupper32 wrote:
| You don't go to jail if you can't repay your mortgage.
| beeboop wrote:
| I meant more in the context of corps only getting fines
| for illegal activities that actual people would go to
| jail for
| MattGaiser wrote:
| > It's highly unlikely that I be unemployed for the rest of
| my life
|
| Unemployed? No. Earn what you did before? Anecdotal, but my
| parents know a lot of people in their 50s that when laid
| off, never went anywhere close to their prior salaries.
|
| This was especially true for people who couldn't get their
| current job with their credentials. Plenty of senior people
| in places like factories and warehouses don't have degrees
| for example. Would they find work again if laid off?
| Dylan16807 wrote:
| The government could have done both, so I don't think we
| should frame it as competing loans.
| arcticbull wrote:
| These are all separate responsibilities of different
| groups.
|
| The Fed's charter is to maintain a low, predictable rate of
| inflation over the medium term and to maximize employment.
| You (in aggregate) won't have a job if all the employers go
| bankrupt due to direct investments and contagion. This will
| directly impact (in aggregate) your ability to make your
| mortgage payments.
|
| Secondarily, regulation of the financial sector to ensure
| this doesn't happen again isn't JPow's job, it's the job of
| Congress.
|
| Bailing out the institutions does not preclude further
| regulation to prevent the situation from happening again.
| And it certainly doesn't preclude creating a meaningful
| social safety net.
| kcatskcolbdi wrote:
| The Federal Reserve is absolutely tasked with regulating
| the banks[1].
|
| Congress should not be in the business of preventing
| banks from imploding in on themselves via regulation.
| Congressional regulations should insulate consumers from
| predatory financial institution practices. FDIC insurance
| exists to protect consumers in the event their banks
| behave irrationally. There should be no backstop for the
| banks themselves. Even if they wanted to Congressional
| regulations couldn't keep pace with the speed at which
| financial instruments of institutional suicide are
| forged.
|
| 1 https://www.federalreserve.gov/supervisionreg/reglistin
| g.htm
| Barrin92 wrote:
| >why am I evicted instead of bailed out?
|
| probably because you, collectively speaking, kept electing
| people who didn't pass anti-eviction laws or strengthened
| tenant rights. Which most countries by the way did put in
| place during covid at the very least.
| not2b wrote:
| Because you didn't owe enough money to tank the world
| economy if you went broke, mainly. Small debtors have no
| power, but huge debtors do.
| throwawayboise wrote:
| Yep. If you owe the bank $1,000 that's your problem. If
| you owe the bank $100M that's the bank's problem.
| arcticbull wrote:
| I mean small debtors just get to declare bankruptcy and
| not pay, which is a pretty good power to have. Large
| debtors have broader obligations to the community.
| wizzwizz4 wrote:
| So why don't debtors unionise?
| beebmam wrote:
| Were you evicted in the 2008 crisis?
| pirate787 wrote:
| There were multiple stages of bailouts, including Federal
| Reserve asset purchases which directly transferred resources
| from dollar holders to for-profit shareholders and
| bondholders. The Fed's intervention dwarfed the TARP bailout
| and is the largely the reason TARP was successful...they
| moved the economic loss from Treasury to the Fed.
|
| https://mitsloan.mit.edu/ideas-made-to-matter/heres-how-
| much...
| arcticbull wrote:
| That's not how the Fed works. [edit] (As I replied in a
| peer comment, increasing the money supply is not debasement
| or a loss - that is measured from its impact. In the years
| subsequent to the bailouts inflation hit at some point an
| annualized -4% before returning to a range of 0-2% going
| into COVID.
|
| Modern economics isn't as simple as "supply up bad.")
| NovemberWhiskey wrote:
| Your comment doesn't appear to have much to do with the
| link you have provided; could you add some more context?
| MadSudaca wrote:
| Didn't they have to debase the currency to make those
| payments?
| arcticbull wrote:
| An increase in supply is not a debasement. That is measured
| post-facto based on its impact. Inflation was strongly
| negative between 2008 and 2010, hitting an annualized -4%
| in 2009. [1] The Fed was also making good progress
| unwinding its balance sheet going into 2020, before COVID
| hit.
|
| [1] https://tradingeconomics.com/united-states/inflation-
| cpi
| mr_spothawk wrote:
| > Inflation was strongly negative
|
| It's not clear to me if you're talking about monetary or
| price inflation.
|
| https://mises.org/library/money-inflation-and-price-
| inflatio...
|
| > some economists have interpreted price inflation as a
| desperate method by which the public, suffering from
| monetary inflation, tries to recoup its command of
| economic resources by raising prices at least as fast, if
| not faster, than the government prints new money.
| arcticbull wrote:
| Only the long-debunked Austrian school defines inflation
| as a function of supply alone. The rest of the world
| moved on to defining inflation in terms of the measured,
| real-world change in the purchasing power of money -
| which comes under pressure from a number of different
| factors that aren't captured by supply.
|
| For instance, supply chain disruptions making basic goods
| more expensive and increasing competition for them. Or,
| zoning policy prohibiting construction of new housing
| sufficient to meet demand in high-growth metro areas
| raising the cost of housing. Or zoning policies in
| suburban areas making housing 2x bigger on average now
| than in the 1970s. [1]
|
| Defining inflation as a function of supply distracts us
| from the real-world problems causing broad-based
| increases in price.
|
| [1] https://fee.org/articles/new-homes-today-have-twice-
| the-squa...
| mr_spothawk wrote:
| > long-debunked
|
| lol.
|
| > Defining inflation as a function of supply distracts us
| from the real-world problems causing broad-based
| increases in price.
|
| price is a function of supply and demand already. you
| don't need to redefine inflation unless you're trying to
| dupe feeble-minded rubes.
| arcticbull wrote:
| Purchasing power is a function of a whole ton of things,
| including supply chains. If goods require more inputs or
| are less efficient to produce that will increase their
| price. This in turn decreases the relative purchasing
| power of a dollar. This can happen due to all sorts of
| externalities, for instance a tax. Or it can go down due
| to efficiencies in manufacturing technology or biotech.
| Or, a massive global pandemic leading to supply chain
| disruptions can cause prices to go up. Or housing can
| become more expensive because of zoning rules.
|
| The "supply of currency units" is a fundamentally
| inadequate measure to capture this. It is too simplistic.
| Nobody takes it seriously except for a small group of
| very vocal online crackpots because it is so obviously
| unfit for purpose. [1]
|
| We re-defined it as our understanding grew. The way we
| update practically any model in the face of new evidence.
|
| Japan single-handedly demolishes the Austrian model.
| Their M2 supply grew 3X from 1990 to present but
| inflation remained 0% measured over thirty two years.
| Prices did not change from 1990 to 2022. [2, 3]
|
| [1] https://www.pragcap.com/understanding-why-austrian-
| economics...
|
| [2] https://fred.stlouisfed.org/series/JPNCPIALLMINMEI
|
| [3] https://tradingeconomics.com/japan/money-supply-m2
| mr_spothawk wrote:
| > This in turn decreases the relative purchasing power of
| a dollar.
|
| you're again conflating price and monetary inflation. and
| again mixing in somebody else's prejoratives to flavor
| your discussion of their topics.
|
| here's a link [1]
|
| [1] https://mises.org/library/inflation
| RC_ITR wrote:
| I love all the Austrian Economics (thanks Satoshi!)
| comments we get in a supposedly data-driven environment.
|
| How does this chart [0] show a debasement of any sort? We
| were in a 'secular demand stagnation crisis' back then!
| Is everyone here just too young (oh God) to remember
| 2012?
|
| https://fred.stlouisfed.org/graph/fredgraph.png?g=LBU7
| thaumasiotes wrote:
| > How does this chart [0] show a debasement of any sort?
|
| It's the gigantic jump in the blue line almost halfway
| between 2008 and 2010. A spike in the value of "all
| assets" is the definition of currency devaluation.
| RC_ITR wrote:
| Hey, sorry for not providing more context, the blue line
| is the Fed's balance sheet and the red line is inflation.
|
| Yes, the Fed's balance sheet skyrocketed, but inflation
| (the value of money vs. goods & services) remained lower
| than before that line spiked.
| MadSudaca wrote:
| So why did they stop growing their balance sheets then?
| RC_ITR wrote:
| Because QE is an active tool to support credit liquidity
| and they determined that markets were liquid enough to
| remove that support.
|
| EDIT: And just to be very clear to the 2 people who read
| this comment, maintaining a balance sheet is still market
| support b/c you still buy treasuries on the open market
| to offset the principle of your existing treasuries that
| reach maturity. So stopping the growth of the balance
| sheet just means you're not accelerating support.
| Tapering is the thing that you do if you're worried that
| your balance sheet is 'debasing' the currency.
| thaumasiotes wrote:
| > An increase in supply is not a debasement. That is
| measured post-facto based on its impact.
|
| An increase in supply is always a debasement.
|
| It's true that you might see the following chronology:
|
| 1/1/2020: value of the currency measured
|
| 6/6/2020: supply of the currency increased
|
| 1/1/2021: value of the currency measured; it's higher
| than it was last year!
|
| But that doesn't mean the issue on 6/6/2020 wasn't a
| debasement. It definitely was, and the reason it doesn't
| look that way is your very low-resolution measurement of
| value. If the supply increase hadn't happened, the value
| on 1/1/2021 would have been _even higher_.
| arcticbull wrote:
| An increase in supply alone isn't debasement. A higher
| supply doesn't imply a lower value, because what you do
| with that new supply matters. If you mint a $10T coin and
| throw it under your mattress, then you haven't decreased
| the value of anything even though the supply has
| increased dramatically.
|
| This is why we measure, and why Austrian economics fell
| out of favor decades ago.
|
| See Japan for a concrete example. [1, 2] Their M2 money
| supply is almost 2.5X higher since 1990 but their CPI is
| dead flat over the same time period. It's actually
| seriously problematic for them.
|
| [1] https://fred.stlouisfed.org/series/JPNCPIALLMINMEI
|
| [2] https://tradingeconomics.com/japan/money-supply-m2
| thaumasiotes wrote:
| > If you mint a $10T coin and throw it under your
| mattress, then you haven't decreased the value of
| anything even though the supply has increased
| dramatically.
|
| How has the supply increased in this scenario? What if,
| instead of minting the coin, you just tell people that
| you've done so?
|
| The supply of money has only increased if you're able to
| _spend_ the putative addition to the money supply.
| arcticbull wrote:
| You can tell them all you want, but as Japan shows us, it
| doesn't actually matter. What matters is what you _do_
| with the supply which is why we measure.
| thaumasiotes wrote:
| Let's focus on the opening question, "how has the supply
| increased in this scenario?".
| arcticbull wrote:
| I'm sorry I don't understand the question.
|
| Are you asking how supply works in my hypothetical,
| simplified example where the point I'm trying to make is
| that new supply in isolation doesn't matter - what you do
| with it does?
|
| Or as you asking how it happens in the real-world example
| of Japan, where their supply increased from 400000B JPY
| to 1200000B JPY between 1990 and present, while
| everything remained the same price? And how this is
| seriously problematic in their economy?
| lottin wrote:
| I guess you didn't get the memo. The US abandoned the gold
| standard in the 1930s and with that the US dollar became a
| fiat currency, i.e. a currency that isn't backed by
| anything. A fiat currency cannot be debased because it has
| no "base".
| MadSudaca wrote:
| Maybe not to you, but every time the FED prints money, my
| dollars are worth less. From my POV they're currently
| debasing the currency.
| OscarCunningham wrote:
| In 2009 they printed money and dollars were worth more.
| MadSudaca wrote:
| So if printing makes dollars worth more, why stop? Or
| that effect only applied to 2009?
| arcticbull wrote:
| Because supply _alone_ is not what defines the value of
| money. This is the concrete example of why Austrian
| economics is a wholly insufficient model.
| MadSudaca wrote:
| I think the Austrian school explains quite well the
| phenomenon, like Newton's Laws for dynamics.
| arcticbull wrote:
| If you can buy the same amount with them, then they are
| demonstrably not worth less.
| tgv wrote:
| > deep-pocketed investors
|
| Or people with a lot of ETH, that want to hold on to the value
| of the rest they still own.
| cbenneh wrote:
| Not really bailing out retail. There was enough liquidity for
| retail users to exit the tokens at risk without a penalty.
|
| On the other hand the VCs themselves that are large owners of
| the tokens in Solana ecosystem would incur large losses, and
| that's excluding additional losses from reputation in future.
| It just shows how successful Jump VCs are when they put up
| $320M in a few hours. Maybe a month of their PnL?
| im_down_w_otp wrote:
| I don't see how this is an indicator of that. They didn't put
| in USD. They put in ETH. Which is a thing that has no
| requirements to be backed by fungible legal tender reserves.
| So, they're not actually putting up cash as a replacement.
| It's more like they're putting up assets as a replacement,
| but it's not even that concrete really. They're not the same
| thing.
|
| They're trading in chits, not money, when things like this
| happen. At least that's the case for as long as you can't
| regularly and commonly transact in ETH. The spot price/value
| of ETH multiplied across all the ETH that exists doesn't seem
| to be a description of total USD (or EUR or whatever)
| reserves available to convert ETH to USD, et al. as far as I
| can tell.
| ludamad wrote:
| You overcomplicate things. There is plenty of liquidity to
| sell 120k eth; the opportunity cost of doing this is near
| $300 million
| antocv wrote:
| 2 days ago Jump had 93 000 ETH, today they do not have 93
| 000 ETH.
|
| By casting a spell, today they also have 93 000 extra
| ETH. They are saving some of their potions for later time
| to cast wider spells.
| ludamad wrote:
| Your spell metaphor doesn't serve you being this
| handwavey. What are you even saying happened on the
| ethereum blockchain during this?
| im_down_w_otp wrote:
| The point I'm making is that this says absolutely nothing
| about their ability to eat a $320M loss because they
| didn't eat a $320M loss if what they put up was ETH
| because they can't transact in ETH, they don't fund their
| operations in ETH, they don't pay their LPs returns in
| ETH, etc. etc. etc.
|
| It might well be that they can eat a $320M loss on the
| regular, but if so, this situation isn't any kind of
| indicator of it.
| paulpauper wrote:
| sounds suspicious how the hack occurred an hour after update, and
| all the funds restored as if nothing happened. Inside job or
| someone was tipped off? Tell your friend that there will be an
| update, the time, and have him exploit it on your behalf. I
| wonder how many of these hacks, exploits are inside jobs.
| Probably a lot.
| cwkoss wrote:
| One of the more interesting aspects of this incident is that it's
| possible that they attacker discovered the attack via reading the
| bugfix:
|
| https://twitter.com/kelvinfichter/status/1489050921938132996...
|
| I love FOSS, but attackers being able to exploit bugs they read
| in fixes before they are deployed is certainly a downside -
| especially when the project manages billions of dollars.
|
| What process can/should be implemented to address this attack
| vector?
| Firmwarrior wrote:
| Holey moley, that is insane. It's pretty wild that a good test
| engineer can either eat dirt at a big company or help himself
| to millions of internet dollars by robbing poorly-secured
| startups
|
| Your argument about security is as old as FOSS itself, and it
| usually comes down to whether security through obscurity is
| valuable or not. I wouldn't say I'm qualified to weigh in on it
| either way myself
| cwkoss wrote:
| My question is less about security by obscurity, and more
| "how does solana/wormhole move forward"?
|
| Would node administrators accept a non-OSS (or post-adoption
| open sourcing) patch, and run it on their nodes trusting the
| devs until adoption is wide enough to prevent exploitation?
|
| It seems like blockchains could be in a pickle where bugfixes
| will inherently get exploited if they aren't released
| obscurely, but their users wont tolerate obscurity.
| wmf wrote:
| Nobody except attackers looks at the code so you can
| release whatever, claim it's open source whether it is or
| not, and people will run it. As long as number go up. Also,
| this hack was on a smart contract not the node software so
| there's really no convincing needed; Wormhole probably
| could have updated the contract on chain then released the
| source seconds later and it wouldn't have been vulnerable.
| Their mistake was releasing source of the patch over 10
| days before applying the patch on chain.
| _3u10 wrote:
| More importantly, how much does it cost to find these clauses
| in the smart contracts before the contract is modified?
|
| With $320M pay days it's one of the best bounty programs I've
| ever heard of.
| hypertele-Xii wrote:
| Looks like your money got sucked into a crypto wormhole.
|
| Teleported, elsewhere, through mathematimal impossibilities no-
| one with a computer can prove; and if they do, all the value put
| in disappears into the void.
| abalaji wrote:
| For those interested, here's a great thread explaining how the
| hack happened:
| https://twitter.com/kelvinfichter/status/1489041221947375616
| nhoughto wrote:
| Restored is an interesting choice of word, Jump replaced the ETH
| at their cost is my read? It's not like they wound back the
| transaction or got the ETH back.
|
| They would want to be confident there are no more bugs, only a
| few days ago this happened, did they do a full audit of things
| before tipping it in? Imagine if they lost another 320m !
| syspec wrote:
| > How was Wormhole exploited?
|
| > Notably, the hacker carried out an unlawful mint of 120,000
| wETH, which was valued at around $322 million at the time. They
| carried out the assault by taking advantage of a Solana VAA
| weakness, a bridge function that verifies asset transfers.
|
| Could anyone provide specific details as to what occurred, and
| how the weakness was actually exploited?
| ypeterholmes wrote:
| Detailed breakdown here:
| https://twitter.com/kelvinfichter/status/1489041221947375616
| syspec wrote:
| That's an excellent write up! Thanks a bunch
| ww520 wrote:
| I was replying to another comment and came to a realization. It
| deserves its own comment.
|
| Jump Trading fixed the problem by depositing $320M ETH tokens
| into the Wormhole's ETH account to ensure the falsely issued wETH
| tokens are backed. The fake Solana tokens released from the fake
| wETH were deposited back into Wormhole's Solana account. They are
| still in Wormhole's Solana account after the re-capitalization.
| It's basically they're using the $320M ETH tokens to buy a bunch
| of Solana tokens, created by the hackers.
|
| So at the end, they're not really out of $320M money; they still
| have the $320M Solana tokens, fake or not. It's just the general
| public got screwed by having $320M of Solana tokens inflated up
| on them.
| ddalex wrote:
| Yea, if the public trades in Solana. But they are out of $320M
| in ETH which is way more used then Solana.
| ww520 wrote:
| Yeah, so they accidentally expanded the supply of Solana
| tokens by $320M. Whether it's a good thing or bad thing, no
| one is sure.
| pcmonk wrote:
| This isn't correct. There's no Solana tokens in the equation at
| all, so I assume you mean wrapped ETH on Solana, and that all
| got sent through the bridge to Ethereum, so it doesn't exist
| anymore.
| ww520 wrote:
| Which wallet does the Solana tokens go when they are released
| from the wETH tokens?
| ffggvv wrote:
| so can you use this as a loophole to print inordinate amounts
| of solana? confused how they inflated the supply
| ww520 wrote:
| Sure. Ever wonder how Tether work? Ha.
| SilasX wrote:
| Or central banks, for that matter? They print new money,
| and use it to buy and hold financial assets (usually
| government bonds). New money was added to the system, other
| assets were taken out.
| lxgr wrote:
| They apparently just supplied the backing assets without
| receiving anything in exchange, presumably to preserve trust
| in the larger ecosystem/chain. Pretty interesting precedent!
| uncomputation wrote:
| Yes and no. I see your point on one hand. Hackers mint 120k
| wETH. Bridge guarantees 1 wETH = 1 ETH. Therefore, hacker
| transfers 120k ETH to their Ethereum account. They can then
| sell this for approximately $320 M not to Wormhole or Jump
| Trading, but to the market who will collectively pay $320 M
| hypothetically (of course, slippage is a thing).
|
| But, on the other hand, since Jump restored 120k wETH (valued
| at $320 M), they kind of are "out" that money in the sense that
| they would not have spent that without the hack. They are now
| forced into an "investment" of 120k wETH. They may profit from
| their investment if the price of the asset rises, but they may
| also lose some of their investment if the price decreases.
| Likely, it won't fall to 0 so they are not "out" $320 M in the
| sense that the hackers directly stole that, but they
| essentially forced to trade $320 M for 120k wETH.
|
| I don't see how the public is screwed here. There is no
| "inflation." They essentially increased the backing assets of
| the bridge by 120k wETH at current ETH market price.
| ww520 wrote:
| The public invested in SOL directly or indirectly got their
| SOL value diluted by $320M. The public here includes Jump.
| throwhauser wrote:
| Isn't it Jump Trading that is out $320M? Didn't they put up the
| money to make sure the maliciously created Solana tokens were
| backed by [whatever they're supposed to be backed by]? Jump
| doesn't own the tokens now, do they?
| ww520 wrote:
| Jump Trading still has the maliciously created Solana tokens
| at the end, valued at $320M. They might lose some by Solana
| inflation but it's not like they're really out of $320M.
| firloop wrote:
| > It's just the general public got screwed by having $320M of
| Solana tokens inflated up on them.
|
| The general public didn't get screwed here. Solana ETH is an
| IOU for ETH. Now it's backed by ETH. It's not like anyone got
| diluted or anything.
| ww520 wrote:
| "The SOL token distribution is as follows: 16.23% went
| towards an initial seed sale, 12.92% of tokens were dedicated
| to a founding sale, 12.79% of SOL coins were distributed
| among team members and 10.46% of tokens were given to the
| Solana Foundation. The remaining tokens were already released
| for public and private sales or are still to be released to
| the market."
|
| So how were the seed Solana tokens backed by ETH based on the
| distribution? Weren't they created out of the thin air?
| mutant_self wrote:
| I think you've gotten confused. Jump did have to fork over
| $320m worth of tokens to fill the hole from the hack. There's
| no weird accounting trick here
| ww520 wrote:
| Who is holding the SOL from the created wETH by the hackers
| at the end?
| vilhelm_s wrote:
| I don't think this is right at all. The attack first created
| 100,000 wETH ($320 million) on the Solana side, and then
| bridged 93,750 wETH ($250 million) to ETH on the Ethereum side
| [1]. So some of the added ETH backs the remaining 6250 "extra"
| wETH tokens on the Solana side, but almost all of it would have
| gone to replace the stolen 93,750 ETH, and that's a pure loss.
| Either way I don't think this would cause any inflation, since
| the wETH still corresponds 1:1 with locked ETH.
|
| [1] https://twitter.com/samczsun/status/1489044939732406275
| ww520 wrote:
| Who is holding the SOL from the created wETH by the hackers
| at the end?
| vilhelm_s wrote:
| creating wETH doesn't create any SOL, they are separate
| things.
| ww520 wrote:
| In a normal setting when a user deposits his SOL to
| create the wETH, where does the SOL go at the end when
| the wETH is settled? Where does the SOL go when it's
| released from the wETH?
|
| The wETH pairs X amount of SOL with an ETH. When it's
| settled, it releases both the SOL and the ETH to the
| corresponding parties. When the wETH is falsely created,
| it creates the SOL it wraps.
| somebodythere wrote:
| wETH wraps ETH, not SOL.
| steelstraw wrote:
| Vitalik warned about cross-chain bridge risk just a few weeks
| ago:
|
| My argument for why the future will be _multi-chain_ , but it
| will not be _cross-chain_ : there are fundamental limits to the
| security of bridges that hop across multiple "zones of
| sovereignty".
|
| Note that cross-rollup apps within one zone of sovereignty are
| still fine. Not also that this also is a limit to the "modular
| blockchains" vision: you can't just pick and choose a separate
| data layer and security layer. Your data layer must be your
| security layer.
|
| https://twitter.com/vitalikbuterin/status/147950136619213209...
| X6S1x6Okd1st wrote:
| To be fair the situation he was talking about was that bridges
| are vulnerable to reorgs/51% attacks on either side and if that
| happens the bridged asset might lose it's peg, while the
| local/native asset won't.
| okwubodu wrote:
| This isn't the quite the scenario he was talking about. The
| Wormhole exploit is just a bug that could've occurred even if
| the bridge didn't cross chains.
|
| Despite being large, it was still an isolated incedent compared
| to the multi-chain heist one could pull off with a 51% attack
| on a single chain.
| ricardobeat wrote:
| > the whole network is down for maintenance
|
| "decentralized finance"
|
| Bitcoin's network cannot be stopped by anyone. How does Solana
| achieve that? What does "decentralized" even mean when everything
| depends on individual operators?
| mr_spothawk wrote:
| tfw "maintenance" is actually just "still in development"
| Tenoke wrote:
| If you had quoted the whole sentence you would've seen it's
| Wormhole that's down for maintenance and not Solana. Bridges
| aren't fully on-chain by definition and even if they were just
| a smart contract you can definitely have a pause clause in your
| code.
| wonderwonder wrote:
| Could this hack have allowed for the printing of eth on solana
| that did not actually exist on the eth blockchain or was it
| limited to real eth that had been bridged to solana?
| wmf wrote:
| You probably could have printed infinite fake ETH on Solana,
| but soon enough someone would have noticed that the amount in
| circulation exceeded what was stored in the bridge which should
| be impossible.
| okwubodu wrote:
| They did use some of the fake weETH to trade for 430k SOL,
| valued at a little under $40 million.
|
| https://explorer.solana.com/address/CxegPrfn2ge5dNiQberUrQJk.
| ..
| Youden wrote:
| IIUC, the hackers minted new coins, they didn't transfer
| ownership of anything from its legitimate owner to themselves.
|
| So I'm curious to hear: do people consider this "stealing"?
|
| The article uses the word often and even goes as far as
| "unlawful" but would this have broken any laws? Even CFAA seems
| out since no computer was accessed without authorisation.
| danielvf wrote:
| As a part of the hack the attacker did transfer 320M million
| worth of previously existing coins to themselves. That was the
| payoff for the hack, and the entire point of doing the hack.
| The minting part was just a stepping stone to that.
|
| Also, the attacker definitely exceeded authorization - it was
| literally the authorization component of the code that the
| attacker bypassed by substituting part of it with their own
| ringer code.
| Youden wrote:
| Ah, I wasn't aware of the previously existing coins. This
| being DeFi though, was it clear who owned those particular
| coins or were they "owned" by the program?
|
| I'd actually be interested to know if crypto can, from a
| legal perspective, be owned. Has crypto theft been
| successfully prosecuted before?
|
| As for exceeding authorisation, yes, true, but IIUC, CFAA
| only makes illegal the unauthorised access to a _computer_.
| Since this is a crypto program, is there an identifiable
| computer that was accessed without consent?
|
| To be clear, I'm not making any moral judgements here, I'm
| just curious how our current laws and moral positions apply
| to crypto.
| danielvf wrote:
| Yes, people have gone to jail for stealing Bitcoins - In
| fact a US DEA agent and a US Secret Service agent did a few
| years ago.
|
| See https://www.justice.gov/sites/default/files/opa/press-
| releas... for the initial criminal complaint, which is well
| worth reading.
| cwkoss wrote:
| How is this different from a bitcoin miner minting coins,
| trading them for another coin, and withdrawing?
|
| If code is law, attacker was playing by the rules. I don't
| think this is clear-cut illegal. It looks illegal-ish, but I
| think a good lawyer could argue it isnt.
|
| Does Solana/Wormhole have ToS that (in the courts eyes)
| overrides the state of the blockchain? If they did, doesn't
| that kind of defeat the purpose of a decentralized
| blockchain?
| TameAntelope wrote:
| Code isn't law, is the point. No matter how many times
| people try to claim that, the legal system does not, to my
| understanding, actually work that way.
|
| It would depend entirely on what a judge and a jury think
| about how the law ends up getting applied, were this tried
| in US courts.
| cwkoss wrote:
| If code isn't law, could a crypto holder sue a crypto
| miner for inflating the market supply and reducing the
| value of their holdings?
|
| What is the legal distinction between mining (which is
| intent of the protocol) and this attack (presumably not
| the intent of wormhole)? Do blockchain services need to
| create ToS's which can legally supercede in the case of
| bugs in order for courts to punish attackers? Would
| blockchain users accept a service with such a delegation
| of state?
| TameAntelope wrote:
| You can sue anyone for anything in my country (USA), but
| I don't know if you'd win, for so, so many reasons.
| PretzelPirate wrote:
| Interestingly enough, the only people I see saying "code
| is law" nowadays are people who are accusing the
| blockchain community of being the ones pushing that idea.
| shinryuu wrote:
| An exploit is technically always following the rules of a
| system. Take for example a sql injection. The system
| allowed a sql injection, you told the system to execute the
| sql code of your choice and bam you got what you wanted at
| the expense of the counterparty. This would still be
| considered illegal.
|
| code is code, code isn't law. Even if you try to call it
| 'smart contracts'.
| aaroninsf wrote:
| "Restored" is not really the word.
|
| They got robbed. Their parent and VC stepped in to bandaid over
| the terrible terrible press by throwing money at the problem in a
| bid to rebuy trust.
|
| I've started asking people explicitly: how can anyone who has
| ever programmed professionally, entrust themselves to someone's
| program?
|
| The interesting lemma is, don't we do that all day?
|
| To which the obvious rejoinder is, yes, but when we do so, it is
| almost always in contexts in which litigation and consumer action
| and introduced a massive obligation of transparency, best
| practices, liability, insurance, and other regulatory oversight
| and burdens. Which _still_ fails, e.g. when Boeing bug kill
| planeloads.
|
| The wild west of this "smart contract" world has almost none of
| that.
|
| Sadly the answer to the rhetorical "what are people thinking!?"
| is no mystery. Those that are, are mostly on the side of the
| grift.
| blunte wrote:
| "restored"... that's an interesting word here, and it suggests
| that money was manufactured to replace that which was drained
| (which itself was a kind of manufacturing).
|
| The previous HN tweet thread story about this described so many
| dependent moving parts that I imagine great difficulty in
| properly testing and proving that the entire system worked
| correctly in all cases. If it is built as described in that
| story, auditing would be an enormous task... and further, putting
| your name on that audit would be very risky to your reputation
| (since almost inevitably you will miss something and it will be
| exploited).
|
| In summary, the system was too complex and offered too many ways
| for something to go wrong or be exploited.
| not2b wrote:
| The stolen cryptocurrency was not recovered. The company put in
| its own real (fiat if you prefer) money to cover the losses.
| They did this because if they don't, the operation will
| collapse; no one will invest if bad security means all the
| money disappears.
| Grustaf wrote:
| Reminds me of the good old days when exchanges got hacked (or
| "hacked") every other day, with hundreds of millions stolen.
| mdoms wrote:
| Good old days?
|
| https://web3isgoinggreat.com/
| dang wrote:
| Previous related thread:
|
| _In second largest DeFi hack, Blockchain Bridge loses $320M
| Ether_ - https://news.ycombinator.com/item?id=30186894 - Feb 2022
| (561 comments)
| NelsonMinar wrote:
| Bloomberg's story on this includes the paragraph "Wormhole
| developers offered the hacker a $10 million bug bounty for
| exploit details and the return of the funds." It does not
| explicitly say the hacker _took_ that bounty or refunded the
| stolen money. Any guesses?
|
| https://www.bloomberg.com/news/articles/2022-02-02/blockchai...
| cheeze wrote:
| How does that work? If the money was moved to ETH, how did they
| restore the funds?
| ww520 wrote:
| Guessing from the available information, Wormhole works by
| having a pile of ETH in its account, a piles of wETH tokens
| backed 1-to-1 by the ETH in the account, and piles of other
| types of tokens, like Solana.
|
| When the wETH coins are initially set up, there's a way to
| deposit the initial ETH tokens into the Wormhole's ETH account
| to jump start the whole process.
|
| When a user wants to convert Solana to ETH, he deposits the
| Solana tokens to the Wormhole smart contract and it issues the
| wETH tokens at some exchange rate, taking a 1-1 ETH from
| Wormhole's ETH account, tying the Solana and the ETH in the
| wETH tokens. After the dust is settled, the user can convert
| the wETH tokens to ETH. The Solana tokens held in the wETH
| tokens are deposited in Wormhole's Solana account, the ETH
| tokens held in the wETH tokens are released to the user.
| Everything is good.
|
| The hack was to create a bunch of Solana based wETH tokens out
| of the thin air, exploiting a bug in teh Wormhole smart
| contract. The hackers forced a settling of the fake wETH tokens
| against Wormhole's ETH account, taking the ETH away. In the
| process, leaving whole bunch garbage Solana tokens in
| Wormhole's Solana account. Now Wormhole's ETH account is down
| by $320M. Whatever wETH tokens floating out there have no 1-1
| backing from the ETH account. The whole thing can collapse with
| a bank run.
|
| They fixed it by depositing $320M ETH tokens into the
| Wormhole's ETH account to ensure the fake wETH tokens are
| backed as well. The fake Solana tokens are still in their
| account. It's basically they're using $320M ETH tokens to buy a
| bunch of Solana tokens, which the hackers created.
|
| So at the end, they're not really out of $320M money; they
| still have the $320M Solana tokens, fake or not. It's just the
| general public got screwed by having $320M of Solana tokens
| inflated on them.
| Kranar wrote:
| My speculation on this is that such a failure is catastrophic
| enough to destroy an entire blockchain. Solana has made
| billionaires out of a small group of people and they'd much
| rather fork over the 300 million dollars to plug this hole so
| as to preserve the remainder of their wealth, instead of having
| Solana crash to become worthless.
|
| While in principle a bug like this could have happened on
| Ethereum, or any programmable blockchain platform, ultimately
| this attack happened on the Solana blockchain and is an attack
| on Solana. The people who have a vested interest in seeing
| Solana survive will have coughed up the funds.
|
| Finally, it's worth keeping in mind that while failures like
| these become very public and it seems like cryptocurrencies are
| always doing nothing but crashing, failing, and losing money,
| there are also plenty of people making millions and even
| billions of dollars a year offering crypto related services. To
| those folks 300 million dollars, while not trivial by any means
| is also not the end of the world if it will allow them to
| continue operating.
| vmception wrote:
| Also noteworthy is that bridge technology is what allows
| these chains to have immediate utility to the market faster.
|
| Centralized Exchanges are extremely slow in listing new
| blockchains, especially meta assets on those blockchains. For
| example, want USDC on Solana? Sorry even if your exchange
| listed Solana and allow for withdrawal of native SOL, they
| aren't allowing withdrawals of tokens to the Solana network.
| They dont know, don't care, don't have the development
| resources to prioritize that, aren't even familiar with a
| erc-20 standard of tokens yet, and legal hasn't gotten the
| rubber stamp from the New York Department of Financial
| Services anyway so why bother catering to the rest of the
| world..
|
| Whereas the permissionless bridges plug in immediately and
| billions of dollars of assets can move in without bothering
| with a centralized exchange. Building starts immediately,
| forget about the permits.
|
| So, private participants fixing a crucial bridge is the
| rational move.
| wmf wrote:
| I was wondering how a bridge could hope to earn back $300M
| in fees in any reasonable horizon, but if we view Wormhole
| as a loss leader to pump the overall Solana ecosystem
| (which I guess Jump is invested in) it makes sense.
| dboreham wrote:
| Also noteworthy: this kind of "trusted" bridge architecture
| is probably now doomed.
| vmception wrote:
| I don't get that impression. It's patched and more
| resilient now, the exploit occurred with someone watching
| the github about the patch, or even more likely it was
| someone on the dev team/discussion about why the patch
| was needed. The "guardians" are still there and
| distributed. I don't see more distributed bridge styles
| being real competitors at least to Wormhole on the Solana
| network. Individual users didn't lose funds and their
| exposure is always limited to a few minutes.
| oblio wrote:
| Didn't they do the unthinkable a few years back, for Ethereum
| itself? They forked the immutable database because of a bug
| or exploit, I forget what it was exactly.
|
| Similar story, rich people protecting their assets.
| rvz wrote:
| The failure of the first DAO for Ethereum in 2016 is what
| you are talking about. [0]
|
| Its a similar story, but this time no individual at the top
| reversing the whole blockchain of that transaction and hard
| forking it to cause a revoult against the main blockchain
| or a new group creating something like Solana Classic, etc.
| whilst talking about 'code is law'.
|
| At least this is indeed 'Code is law'.
|
| [0] https://en.wikipedia.org/wiki/The_DAO_(organization)
| roland35 wrote:
| Yup, it was called "the dao" and a hacker ran away with a
| third of their Ethereum.
|
| https://en.m.wikipedia.org/wiki/The_DAO_(organization)
| WJW wrote:
| It's not the original funds that were restored; one of the
| hedge funds behind Wormhole put in an extra $320 million to
| balance the books again. The hackers still have the original
| $320 million.
| newbie789 wrote:
| bhaak wrote:
| Somebody has deep pockets to fix such a blunder.
|
| Where is this money coming from?
|
| Who had enough ETH lying around to refill the bridge? They
| certainly didn't just buy it on the open market, that would have
| moved the SOLETH ratio.
| PaywallBuster wrote:
| The parent company is Jump Crypto - crypto HFT
|
| It's parent company is huge HFT trading company too - Jump
| Trading
|
| https://www.coindesk.com/business/2022/02/03/jump-trading-ba...
|
| https://en.wikipedia.org/wiki/Jump_Trading
| tylersmith wrote:
| Wormhole is owned by a trading firm, Jump, who is providing the
| eth to restore the bridge liquidity.
| beaned wrote:
| Jump itself just had $320M laying around?
| nexuist wrote:
| Jump Trading Group isn't some rando crypto org, it's a
| legit hedge fund established in 1999. Supposedly it has at
| minimum $150M AUM[1] but because it's a private company
| nobody actually knows the real amount. We can predict that
| they probably have a few billion in cash lying around if
| they've been successfully trading for over 20 years. Jump
| Crypto, the group that bailed out Wormhole, is their crypto
| trading division.
|
| [1] https://wallmine.com/fund/3mg/jump-trading-llc
| joezydeco wrote:
| Jump is a black hole. I had a friend go there 20 years
| ago and haven't heard from him since. But he's got a
| lovely mansion on the North Shore.
| x86_64Ubuntu wrote:
| And $300M available for use within 24 hours. I'm sure
| Google, Netflix and Walmart all have $300M+ they wouldn't
| care if it went missing. But all the paper and
| presentations needed to touch a tenth of that sum would
| take months. But this guys had it on hand as if they were
| quarters at an arcade.
| kccqzy wrote:
| That's quite possible, judging by the huge bonuses a few
| friends working there got as a SWE.
| e4e78a06 wrote:
| Jane Street made $8bn in 2020 [1]. $320M is probably
| peanuts in exchange for maintaining the stability of a
| market they dominate in capturing arbitrage money on.
|
| [1]:
| https://www.bloomberg.com/news/articles/2021-06-18/jane-
| stre...
| idohft wrote:
| Jump is very profitable.
| Yizahi wrote:
| Easy - print 300 millions of any one of the half a hundred
| existing stabletokens, then exchange them for ethereum tokens.
| Or if they were of the founders of some token, they can spend
| part of their premine for Eth. Possibilities are endless if the
| market is "free" :)
| poontang1 wrote:
| Tell me you don't understand stablecoins without telling me
| you don't understand stablecoins.
| mdoms wrote:
| This isn't Tiktok.
| Hjfrf wrote:
| Bitfinex already did it once that we know of.
|
| It's not too absurd.
| Karunamon wrote:
| Bitfinex isn't the party in question here. Unless Jump
| has their own coin they can mint out of thin air and
| convince people to buy for Ether, or are able to convince
| any of the other main tokens to mint for them, this
| scenario isn't even plausible.
| ricardobeat wrote:
| Apparently they do, it's called Solana, and the hacker
| did the minting for them :)
|
| See the top comment.
| Tenoke wrote:
| None of this is remotely accurate and nobody minted
| Solana. They minted tokens that no longer exist ON
| Solana. $320 was spent in ETH - a plenty liquid asset
| that they have that much less of and that lowers the
| total value of their holdings by that much.
| NelsonMinar wrote:
| The folks behind Tether, the pre-eminent stablecoin, are
| accused of doing exactly this manufacturing of supposedly
| stable coins out of thin air.
| dboreham wrote:
| That's not actually a thing though. There are people/entities
| with large ETH holdings who could well be motivated to foot
| this loss, but they can't just magic (real) money out of thin
| air.
| grey-area wrote:
| That is actually a thing.
|
| https://www.coindesk.com/markets/2021/07/16/tether-hasnt-
| pri...
|
| They're not playing with real money here.
| GrumpyNl wrote:
| Its not real money, nobody did put 320M dollars at the
| table.
| nikanj wrote:
| Bitfinex does not agree
| oneoff786 wrote:
| Sell them to dumbasses for real dollars
| 300bps wrote:
| I can't imagine the target they have on their back right now.
| They'll have quite a decision on their hands if someone takes
| this second round of $320 million.
___________________________________________________________________
(page generated 2022-02-03 23:01 UTC)