[HN Gopher] The math prodigy whose hack upended DeFi won't retur...
       ___________________________________________________________________
        
       The math prodigy whose hack upended DeFi won't return funds
        
       Author : atlacatl_sv
       Score  : 214 points
       Date   : 2022-05-23 13:31 UTC (9 hours ago)
        
 (HTM) web link (www.bloomberg.com)
 (TXT) w3m dump (www.bloomberg.com)
        
       | [deleted]
        
       | tzs wrote:
       | > It would take weeks to figure out precisely what had happened,
       | but it appeared that the platform had been fooled into severely
       | undervaluing tokens that belonged to its users and selling them
       | to the attacker at an extreme discount.
       | 
       | Q: is the programming language these things are written in
       | powerful enough and have sufficient data access for the
       | developers to include sanity checks that would halt trading
       | automatically if something is happening too far out of the norm
       | such as an unusually high volume of attempted night discount
       | sales? Or maybe that would just block extreme discount sales if
       | there have been too many of those recently?
        
         | meetups323 wrote:
         | The language could represent that, but you pay per operation so
         | checks tend to get thrown out the window.
        
           | isolli wrote:
           | This part seems relevant:
           | 
           | > It also saved on costs by limiting the number of
           | interactions between the platform and outside entities. For
           | example, when Indexed needed to calculate the total value
           | held within a pool, instead of checking token prices on an
           | exchange such as Uniswap, it sometimes extrapolated from the
           | value and weight of the largest token within the pool, called
           | the "benchmark" token.
           | 
           | > This way, it reduced the fees it paid for transactions on
           | the Ethereum blockchain.
           | 
           | This cost-saving mechanism ultimately allowed the hack to
           | take place.
        
         | hiq wrote:
         | See this very good comment about Solidity, the main language
         | used to write software on Ethereum:
         | https://news.ycombinator.com/item?id=14691212
         | 
         | More to your point, you can always have more logging, slow
         | things down to make them safer and allow communities to react
         | in a timely manner, but it's far from trivial. The real problem
         | is that any mistake can be fatal from the defender's point of
         | view.
        
       | tediousdemise wrote:
       | We all know that most cryptocurrencies are big ponzi schemes, in
       | which founders stand to gain the most.
       | 
       | Well played for the hacker. What he did is probably less illegal
       | than what coin founders and crypto bros do on the daily...
       | swindle thousands of innocent people with misleading statements
       | on Twitter and steal their hard earned cash.
        
       | Imnimo wrote:
       | I think of this like if you empty the 'take a penny, leave a
       | penny' tray into your pocket. It's clearly allowed by the terms
       | to take the pennies, but it's also clearly immoral.
        
         | sib wrote:
         | Is it? Or is taking _a_ penny allowed, but not taking _all_ the
         | pennies (which feels more code-is-lawish...)
        
       | neonate wrote:
       | https://archive.ph/ZG3rP
        
       | henning wrote:
       | Web 3 is going great!
        
       | knorker wrote:
       | > Once cyberattackers have been identified, they often return
       | funds in exchange for a face-saving bounty and credit for being a
       | "white hat" hacker.
       | 
       | Jesus, this whole cryptocurrency racket is a joke.
        
       | smk_ wrote:
       | @dang can you please permaban anyone using the phrase "code is
       | law". It's always used to scapegoat. Any crypto discussion on HN
       | is absolute garbage. This was such an interesting article I am
       | immensely disappointed in the quality of discussion.
        
       | vfclists wrote:
       | This sounds like
       | https://www.theguardian.com/business/2020/jan/28/navinder-sa...,
       | Navinder Sarao, the British Indian trader who was blamed for the
       | "flash crash" of 2010.
       | 
       | It looks like if you fall foul of big merchant banks and stock
       | traders you can have the full force of the DOJ land on you, but
       | crypto is not important enough.
        
       | Jon_Lowtek wrote:
       | -- EDIT --
       | 
       | i found the address and i take everything back and declare the
       | opposite, that address is not random at all.
       | 
       | -- original post --
       | 
       | > _The Ethereum address used for the attack included the number
       | ... shorthand for ..._
       | 
       | So Bloomberg thinks people choose the numbers in their wallet
       | addresses and are responsible for any perceived numerological
       | meaning. Are they for real?
       | 
       | Sure the guy could have sat there recreating addresses until one
       | includes this number, but i consider it more likely this is the
       | result of searching randomness for patterns they want to find.
       | 
       | Someone noticed the pattern in the randomness and Bloomberg
       | includes it, as it makes the antagonist more evil and the story
       | more interesting.
        
         | buzzy_hacker wrote:
         | I'll give the full quote:
         | 
         | > The Ethereum address Medjedovic used for the attack included
         | the number "1488"--shorthand for a neo-Nazi slogan--and he'd
         | written the N-word into the code itself, 16 times. A Twitter
         | user called him the "Dylan [sic] Roof of Balancer Pools," a
         | reference to the mass shooter who killed nine Black people at a
         | church in Charleston, S.C., in 2015. Medjedovic liked the
         | tweet.
         | 
         | Here's another:
         | 
         | > Medjedovic apparently flirted with extremist ideas: The
         | classmate says he heard him speak favorably about White
         | supremacy and eugenics.
         | 
         | He is clearly a white supremacist, how is this "searching
         | randomness for patterns they want to find"? This is
         | speculation, but it wouldn't surprise me if this guy generated
         | lots of addresses until he got one that did have 1488 in it.
        
           | JKCalhoun wrote:
           | Parents, don't rush your kids.
        
           | [deleted]
        
       | jrm4 wrote:
       | I'll keep saying it -- a "smart contract" is nothing nothing
       | nothing at all like a real contract, it's a stupid little piece
       | of vending machine code that just operates. If we're going to
       | argue the ridiculously dumb idea that smart contracts are, in
       | fact, legal contracts -- congrats to the kid because he is 100%
       | entitled to that money.
        
       | eftychis wrote:
       | Good luck to the judge. Commodities laws still apply so this will
       | be interesting to follow.
       | 
       | They had to sue or they would be sued themselves (which they
       | might regardless), but there is no law restricting you actually
       | from inflating the market value of an item (or a security). Their
       | advantage is that he doesn't have a lawyer (or claims to) --
       | which is a stupid move; and that they froze his gains (another
       | stupid move). If a hack is actually involved under Canadian law
       | we shall see but a civil lawsuit is not unlikely to dictate that.
       | 
       | He misled their market maker, not the holders. Of course without
       | reading the case one can not say anything and has an incomplete
       | view, but they are trying to shift blame here.
       | 
       | There is precedent of course, when Oil futures went negative and
       | in the end brokers paid the difference -- as their software
       | wouldn't allow people to trade non-negative ranges.
       | 
       | tl;dr: I think they are still on the hook for the lost funds back
       | in the E.U./U.K.
        
       | __turbobrew__ wrote:
       | For all of those involved: play stupid games, win stupid prizes.
        
       | JackFr wrote:
       | As I understand it, Indexed behaved as a sort of ETF for crypto,
       | that had automated their creation/redemption mechanism.
       | 
       | Importantly they had automated the creation/redemption mechanism
       | poorly. Here's the operative passage:
       | 
       |  _By eliminating human managers, Indexed could forgo management
       | fees like the 0.95% its bigger rival, Index Coop, charged for
       | simply holding its most popular index token. (Indexed would
       | charge a fee for burning tokens and swapping assets within a
       | pool, but those only applied to a small fraction of users.)
       | 
       | It also saved on costs by limiting the number of interactions
       | between the platform and outside entities. For example, when
       | Indexed needed to calculate the total value held within a pool,
       | instead of checking token prices on an exchange such as Uniswap,
       | it sometimes extrapolated from the value and weight of the
       | largest token within the pool, called the "benchmark" token.
       | 
       | This way, it reduced the fees it paid for transactions on the
       | Ethereum blockchain. Kellar saw full passivity as a "natural
       | extension of the way index funds already operate." _
       | 
       | Kellar was wrong.
       | 
       | In bringing down the costs, they eliminated the very thing that
       | might have prevented the transactions that cost them all the
       | money. The trades were legitimate, just unfortunate for the
       | holders and to ask the courts to reward the incompetence of the
       | management of indexed is to ask the courts too much.
        
       | yobananaboy wrote:
       | They were holding $17m in funds and only paid 2 unnamed security
       | auditors?
       | 
       | Yes, getting a proper audit for a Defi Protocol is expensive
       | (probably 8 person weeks at $20-30k/week or ~$200k), and every
       | good audit firm has a 3-6 month waiting period. But when you've
       | got 100x that to lose, it's a drop in the bucket.
        
       | bobsmooth wrote:
       | "They discovered that the Ethereum wallet used to transfer tokens
       | during the attack was connected to another wallet used to collect
       | winnings in a recent hacking contest by a participant who
       | sometimes identified himself as UmbralUpsilon. Pulling up the
       | participant's registration, they saw that it linked to a profile
       | on the collaborative coding platform GitHub."
       | 
       | Opsec really isn't that difficult, you just have to give it some
       | thought.
        
       | npollock wrote:
       | source:
       | https://www.bloomberg.com/news/features/2022-05-19/crypto-pl...
        
       | Overtonwindow wrote:
       | This was fascinating to read, but I think the guy is ultimately
       | innocent. He executed a series of speculative trades using the
       | platform's rules and mechanisms. It reminds me of the 2013 case
       | of some guys who took advantage of a software bug in a video
       | poker game. "All these guys did is simply push a sequence of
       | buttons that they were legally entitled to push."
       | 
       | This sounds very much like the same thing, and since digital
       | currency is not heavily regulated, some might say at all, I think
       | the outcome, while unfortunate, is not illegal.
       | 
       | Sadly Day & Keller and others will likely haunt this poor kid
       | with lawsuits and frivolous attacks, but in my book he did not
       | break the law.
       | 
       | https://www.wired.com/2013/11/video-poker-case/
        
       | jakear wrote:
       | > His profile on one social network included a quote from Kurt
       | Vonnegut's Cat's Cradle about the futility of humanity's quest
       | for knowledge: "Tiger got to hunt, bird got to fly; Man got to
       | sit and wonder 'why, why, why?' Tiger got to sleep, bird got to
       | land; Man got to tell himself he understand."
       | 
       | Hey! He's just like me.
       | 
       | > But did Medjedovic do this, or did the algorithm? Barry
       | Sookman, a lawyer in Toronto specializing in information
       | technology, says it's a distinction without a difference:
       | "Individuals are responsible for the activities of technologies
       | they control."
       | 
       | This of course goes both ways -- aren't the index fund creators
       | responsible for their technologies too?
        
         | DangitBobby wrote:
         | If I write code that can be exploited with a buffer overflow
         | and you exploit it, who is the law going to punish more
         | harshly?
        
           | shadowgovt wrote:
           | But the entire raison d'etre of most of crypto is to get out
           | from under the thumb of existing national and legal
           | entanglements.
           | 
           | So the question becomes "Who's law?"
        
           | TremendousJudge wrote:
           | If code is law, you.
        
       | bix6 wrote:
       | Can someone explain how you can take out a ~$150m flash loan?
       | (Did he post $300m collateral?) Did he only need 3 ETH for that
       | or were the ETH only used for the transaction fees?
        
         | colinmhayes wrote:
         | So flash loans must be repaid before the next block is mined,
         | so you don't need to post any collateral, just the interest. If
         | the loan isn't repaid in time it automatically unwinds and you
         | lose the interest payment.
        
           | bix6 wrote:
           | Thank you
        
         | yobananaboy wrote:
         | The 3 ETH was the gas fees for the transactions. (Some went to
         | deploying the attacking contract, some went to contract
         | interactions afterwards.)
         | 
         | With a flash loan, the funds must be returned by the end of the
         | transaction, or the transaction fails. This makes the
         | completion of the transaction the collateral, as if it fails at
         | any point, all transactions (including the loan) get reverted.
        
           | bix6 wrote:
           | Thank you
        
       | omarhaneef wrote:
       | What is interesting to me is how it shines a light on the
       | regulatory framework of the non-crypto economy. If you read up on
       | edge cases, there is a lot of people deciding if something is
       | "fair", and my notions of fair and a particular judges notions of
       | fair are often at odds.
       | 
       | To steal from Frank Zappa: Legal isn't the same as allowed,
       | allowed isn't the same as fair, fair isn't the same as just, and
       | just isn't music.
        
         | tablespoon wrote:
         | > What is interesting to me is how it shines a light on the
         | regulatory framework of the non-crypto economy. If you read up
         | on edge cases, there is a lot of people deciding if something
         | is "fair", and my notions of fair and a particular judges
         | notions of fair are often at odds.
         | 
         | Yeah, that's by design. If your "notions of fair are often at
         | odds" with someone else's notions of fair, and a judge needs to
         | intervene to resolve the dispute, then things may not break
         | your way.
        
         | lbriner wrote:
         | A judge is not deciding whether something is "fair" they are
         | deciding whether it is illegal to the letter and/or spirit of
         | the law. The reason this is at odds with us is that many things
         | are legal that are not "fair".
         | 
         | The specific danger here legally is trying to apply general
         | laws into an unregulated market. It's a bit like borrowing
         | money from your mate and then trying to take him to court
         | because he's asking for too much interest.
        
           | Brian_K_White wrote:
           | "many things are legal that are not "fair"."
           | 
           | They are, or at least purport to be, fair at some level or
           | through some mechanism most people may not immediately
           | percieve.
           | 
           | When something really isn't fair, even by some indirect means
           | or when accounting for some other imperative like geneneral
           | societal necessity, then they are at least understood to be
           | failures not successes.
           | 
           | This story though... it actually provides a good example of
           | indirect fairness. Well yes and no, there's a point and also
           | a counter to that point, net result throw up my hands glad
           | I'm not in crypto:
           | 
           | Point, it's fair: You got robbed and think it's unfair that
           | there's no recourse. That downside is just the fair price of
           | being in that game at all, which you pay in trade for not
           | having to deal with the traditional system and "the man". You
           | have to absorb the occasional loss from a mistake as just a
           | feature of the environment like the risk of your shipping
           | boat sinking because the ocean is not a safe place. The only
           | protection possible is pay an insurer or maintain your own
           | emergency escrow or something, not any kind of police or
           | rule-daddy.
           | 
           | Point, it's not fair: They are not in fact free of the man,
           | and so they are not really getting the true freedom they are
           | paying for by assuming all responsibility for their own risk.
        
           | omarhaneef wrote:
           | Well, this is going to send us down a rabbit hole but the
           | reverse is also true: there are multiple interpretations of a
           | given law and the judge tries to use their judgement to
           | square the law with the facts.
           | 
           | (Rabbit hole because I sense this is a debate lawyers have
           | all through law school, and there are various schools of
           | thoughts about the nature of the law etc)
        
             | Brian_K_White wrote:
             | Right? There probably is not agreement on fundamentals like
             | the root purpose of law.
        
         | criddell wrote:
         | There are lots of stories lately about stolen NFTs. The podcast
         | ReplyAll did an episode where they tracked down the current
         | owner of a stolen NFT. He had sympathy for the original owner
         | but he had no intention of turning it over.
         | 
         | I don't get why purchasing a stolen NFT is different than
         | purchasing a stolen guitar from a pawn shop. Shouldn't the
         | previous owner be able to use the courts to demand the return
         | of the item that was stolen from them?
         | 
         | Or is this just something that hasn't been tested yet?
        
           | bombcar wrote:
           | The whole _point_ of an NFT is that the ownership is on the
           | blockchain and guaranteed by said blockchain - if the courts
           | can  "force" return of the NFT than the NFT isn't actually
           | synonymous with the ownership, and so then is kinda
           | pointless.
        
             | colinmhayes wrote:
             | There are 2 different issues here. Do courts physically
             | have the ability to change the blockchain so that an NFT
             | goes to a different wallet? No. Do courts have the ability
             | to arrest someone when they ignore a court order to
             | transfer an NFT? Yes. I don't think the courts really care
             | about some pure intentioned "code is law" argument, because
             | they tend to think law is law.
        
               | tablespoon wrote:
               | > I don't think the courts really care about some pure
               | intentioned "code is law" argument, because they tend to
               | think law is law.
               | 
               | "Code is law" is a mantra chanted by people in no
               | position to make it so.
        
               | criddell wrote:
               | Kind of like sovereign citizens?
        
               | oldgradstudent wrote:
               | With the ledger being public, it could be very simple for
               | courts and police to deal with it given the appropriate
               | legislation.
               | 
               | Mark the result of theft or other illegal transactions,
               | and any subsequent transaction as dirty.
               | 
               | Make any exchange, any vendor, any trader, and any user
               | check with a government database before or immediately
               | after receiving a payment, with penalties prescribed by
               | law.
               | 
               | You immediately limit stolen crypto to the black market.
        
               | colinmhayes wrote:
               | Except crypto is decentralized, and you can use mixers,
               | which are not owned by anyone, to anonymously move coins
               | from a blacklisted wallet. There is no mechanism in
               | decentralized crypto to freeze an address, and I don't
               | think the crypto community would adopt such a blockchain.
        
               | pornel wrote:
               | Blacklisting doesn't have to be a feature of a
               | blockchain. It's enough if most countries decide to make
               | it illegal for anyone to spend coins received from a
               | blacklisted address. It's not easy to enforce of course,
               | but people would be afraid they get in trouble if they're
               | ever deanonimized, and businesses could be required to
               | report their trades, just like taxes.
               | 
               | This will force creation and use of wallet reputation
               | checkers for most users of cryptocurrencies. Mixers will
               | not want to be left holding all the blacklisted coins,
               | since that causes them financial loss. Therefore mixers
               | will launder coins at a very high premium (lemon market)
               | and compete on developing their own systems for
               | reputation checks and escrows to reduce their risk of
               | being left with coins nobody wants.
        
               | colinmhayes wrote:
               | Everyone already knows mixers are holding illicit coins.
               | It doesn't matter because mixers don't actually "want"
               | anything. They're just code in the ether. You send your
               | coins to an address along with a receiver address and the
               | smart contract sends coins to the other address. How do
               | courts stop that without shutting down exactly what makes
               | blockchains valuable?
        
             | blitzar wrote:
             | Nothing in crypto belongs to _you_. It belongs to the
             | private key or whomever holds that.
        
             | tomhallett wrote:
             | This is why I struggle understanding the mainstream
             | usecases for crypto. Will it forever be bound to the "only
             | put in what you can afford to lose?" mindset?
             | 
             | Or are people banking on another layered solution which has
             | arbitration, disputes, clawbacks, etc - all built _within_
             | the blockchain. (I remember EOS discussing something like
             | this)
             | 
             | Note: I understand that risk is present in _any_ financial
             | endeavor, but knowing that the courts _can_ help you does
             | de-risk the amount people will feel comfortable investing.
        
             | criddell wrote:
             | Is there really any question about whether or not courts
             | can force the transfer of an NFT or impose penalties?
             | 
             | Say you hold most of your wealth in some cryptocurrency and
             | are going to file for bankruptcy. Do you think the courts
             | will tell your creditors that the Bitcoin is beyond reach?
             | I suspect they wouldn't treat it differently from any other
             | asset.
             | 
             | That the blockchain is interpreted as a record of ownership
             | is irrelevant. It merely records what has happened and says
             | nothing about the nature of those transfers.
        
             | albertgoeswoof wrote:
             | But the NFT was actually stolen, she was phished for her
             | seed phrase, and the criminal moved ownership of the nft to
             | their wallet, and then sold that to the person who was
             | interviewed on the podcast.
             | 
             | It's no different to a thief stealing your bike then
             | selling it to someone else on a street corner. Just because
             | that person is the current owner and thinks they
             | legitimately purchased it doesn't make it rightfully
             | theirs. In fact it's even worse because it's trivial to
             | identify who the rightful owner is in this case, and if you
             | buy an NFT you can look back at exactly who has owned it
             | previously.
             | 
             | Now imagine if this was the deeds to your house on the
             | blockchain.
        
               | Dylan16807 wrote:
               | An NFT exists purely in the realm of thought, and the
               | owner is whoever knows the password.
               | 
               | Therefore phishing the seed phrase is not "actually
               | stealing" it within the rules of NFT.
               | 
               | And outside the rules of NFT it's just a receipt; it's
               | worthless. It's taking a picture of a picture of a bike,
               | not stealing it.
        
           | omarhaneef wrote:
           | One of the points of digital assets is that the code is the
           | contract, so whatever the code says is what was agreed to.
           | There can be no cheating (in theory) hence no need to resort
           | to courts etc.
        
             | antifa wrote:
             | And there is a chance that the courts will recognize law as
             | law instead of code as law.
        
               | uoaei wrote:
               | And that will expose the fundamental contradictions and
               | hypocrisy of the crypto community writ large, if they
               | accept that help from the legal system.
        
             | shkkmo wrote:
             | Which is why the big players the smart contract that was
             | exploited in this article just accepted the loss and moved
             | on? Oh wait, the two largest losers here BOTH went to court
             | independently.
             | 
             | The cryotocurrency community supports the "code is law"
             | talking point only until serious money is lost. Then they
             | go the courts for redress under actual law, or they fork
             | the blockchain.
        
             | plandis wrote:
             | When two or more parties sign a contract, it doesn't
             | necessarily mean that all the terms in that contract are
             | enforceable.
        
               | uoaei wrote:
               | That's true if you are litigating the enforcement of the
               | contract through traditional legal systems. Crypto
               | enthusiasts want to be completely divorced from those.
        
           | SamBam wrote:
           | The courts haven't even determined whether anyone even "owns"
           | an NFT, so no.
           | 
           | --
           | 
           | For the downvotes, I'll add some further explanation: you
           | have _access_ to the keys in order to perform a sale of
           | "your" NFT, but no US court (I am unsure of other countries)
           | has yet ruled in a case that clarifies whether a person
           | actually _owns_ an NFT. For example, they have not ever ruled
           | against someone who has  "stolen" an NFT. Therefore, there is
           | no case law that says whether a person legally "owns" an NFT.
           | 
           | Don't just take my word for it:
           | 
           | > Ultimately, an NFT owner has _access_ to the underlying
           | asset, but they may lack exclusive access to or control of
           | the asset, let alone ownership of the asset or any
           | intellectual property (IP).
           | 
           | https://www.lawyer-monthly.com/2021/05/nfts-and-ip-law-
           | who-o...
        
       | thawaya3113 wrote:
       | Code is law.
        
         | curiousgal wrote:
         | A common misconception about law/contracts is that they are
         | static. You can technically "not break" any laws and still be
         | held accountable by a court of law.
        
         | BitwiseFool wrote:
         | >"Code is law."
         | 
         | I agree, but with the caveat that code is _the letter of the
         | law_ only. As it currently stands, there is no way to resolve a
         | dispute, ambiguity, or unintended consequence with smart
         | contracts in the same way that a court of law would handle such
         | issues with a conventional contract. There is no room for
         | interpretation and all smart contracts must be understood as
         | such.
        
       | SamBam wrote:
       | > But in our email exchanges, he argued that he'd executed a
       | perfectly legal series of trades.
       | 
       | In real finance, there is an understanding that technical
       | loopholes can exist, since not every outcome can be foreseen when
       | writing laws, but the legal system can frequently prosecute
       | against a series of actions which are, individually, legal, but
       | which together are taken in order to achieve something illegal.
       | 
       | That is, modern finance and the law also attempt to deal with
       | intent.
       | 
       | But in the Ethereum smart contracts world isn't the whole
       | _premise_ that the code is the law? That we don 't need any of
       | these pesky courts or banks or auditors or anything: the code is
       | the law, and the decentralized blockchain will enforce it.
       | 
       | With this worldview, if the attacker simply exploited poorly-
       | written code to find a loophole, how do the owners of Index have
       | a leg to stand on?
        
         | roastedpeacock wrote:
         | Am I missing something or did Medjedovic simply use unforeseen
         | actions in the implementation of the contract as arbitrage and
         | did not have an agreement to not attempt such actions?
         | 
         | Do not see any 'unauthorised access' in that case i.e not the
         | classic definition of 'computer hacking'. However if the case
         | does end up progressing I do wonder what form a defense will
         | take.
        
         | silverlake wrote:
         | Citibank mistakenly sent $900M to a bunch of hedge funds. Many
         | refused to return it. Citi lost the court case.
         | 
         | https://www.cnn.com/2021/02/16/business/citibank-revlon-laws...
        
           | rat9988 wrote:
           | They sent their lender the exact sum of the loan. It's kind
           | of a different case.
        
           | colinmhayes wrote:
           | They accidentally repaid their loan early, which was
           | explicitly allowed in the contract. The hedge funds were
           | under no obligation to pay them back, since the money was now
           | rightfully theirs.
        
             | Dylan16807 wrote:
             | They repaid _someone else 's_ loan early.
        
             | sjtindell wrote:
             | And everything done in this case was in a smart contract.
             | That's the idea.
        
               | colinmhayes wrote:
               | I don't think the smart contract explicitly said "there's
               | this arbitrage opportunity available", but it's
               | definitely a fine line.
        
               | Dylan16807 wrote:
               | This kind of automated index fund seems pretty suggestive
               | of arbitrage to me.
               | 
               | And flash loan contracts are a bright neon sign saying
               | "arbitrage opportunity!"
        
             | not2b wrote:
             | Yes, exactly. They sent the money to their creditors. Had
             | they accidentally sent it to someone who they didn't owe
             | money to, the courts would order the money to be returned.
        
           | daniel-cussen wrote:
           | Yeah like the other guy replied, they intended internally to
           | send it to a wash fund but mistakenly (due to a UI glitch)
           | paid the debt back to the lenders. Now that UI glitch was
           | their fault too, so...the courts said, cry all you want.
           | 
           | And they're a gigantic bank, it's the original digital
           | business, every banker knows a single arithmetic error is
           | dangerous.
           | 
           | Just bankers being inept.
        
         | miltondts wrote:
         | > That is, modern finance and the law also attempt to deal with
         | intent.
         | 
         | It does? Maybe for the poor, but certainly not for the
         | rich/corporations.[1]
         | 
         | [1] -
         | https://www.imf.org/external/pubs/ft/fandd/2019/09/tackling-...
        
           | kmlx wrote:
           | so called "tax havens" actually have a role to play in the
           | world economy.
           | 
           | but on your main point regarding "modern finance and law":
           | 
           | 2021: https://member.fintech.global/2022/01/05/the-top-five-
           | compli...
           | 
           | https://www.kyckr.com/aml-fines-2021/
           | 
           | tldr fines amount to billions in total and sometimes criminal
           | proceedings are brought forward.
        
             | throw_m239339 wrote:
             | > so called "tax havens" actually have a role to play in
             | the world economy.
             | 
             | So does the mafia and the child slaves corporations like
             | Nestle profit from, they all have "a role to play in the
             | world economy". But it's about the morals and ethics and
             | the hypocrisy of western institutions that allow these
             | loopholes for the super rich in order for them to protect
             | their wealth from taxation.
        
         | mikkergp wrote:
         | This is a twitter thread apparently from the lawyers hired by
         | Indexed "I want to explain to you why what you did was illegal
         | and wrong":
         | 
         | https://twitter.com/ohaiom/status/1451142195369725957
        
           | Spivak wrote:
           | Until this pans out in an actual court this is basically a
           | strongly worded vaguely threatening letter from a lawyer. If
           | they actually had him dead to rights they wouldn't be posting
           | their legal theory publicly and asking pretty please give it
           | back or else _these other people we're not at all affiliated
           | with and have no control over_ (but don't pay attention to
           | that fact) might put you in jail.
        
         | fnordpiglet wrote:
         | The courts have found that a written description of the
         | contract is legally binding even if the smart contract has a
         | bug that allows things that were intended to be disallowed.
         | Further the courts held the right to decide whether something
         | was allowed or not allowed on their own judgement regardless of
         | the smart contract, asserting the primacy of the law and
         | jurisprudence over cryptonerd utopian fantasy.
        
           | victor9000 wrote:
           | Which cases and jurisdiction are you referring to?
        
             | fnordpiglet wrote:
             | I've long lost my references to the cases, I tried to
             | Google around for a bit but didn't turn it up. However I
             | did find this analysis from Harvard law that says more or
             | less the same thing, start with the section:
             | 
             | What is the "Final" Agreement Between the Parties?
             | 
             | https://corpgov.law.harvard.edu/2018/05/26/an-
             | introduction-t...
        
         | SkyMarshal wrote:
         | _> With this worldview, if the attacker simply exploited
         | poorly-written code to find a loophole, how do the owners of
         | Index have a leg to stand on?_
         | 
         | They don't. They simply have to accept it as a bug bounty
         | successfully collected and paid out, and treat it as a learning
         | experience and evolutionary process. Do better next time, if
         | there is a next time.
        
           | toomuchtodo wrote:
           | Good luck making that argument in court. Intent is key, and
           | if this is not the intent of the "smart" (lol) contract,
           | "finder's keeper's" is not a legal defense. The legal system
           | doesn't care about your blockchain arguments.
        
             | glerk wrote:
             | A smart contract deployed on a public permissionless
             | blockchain is not owned by anyone. Only the contract's
             | logic determines how one can interact with it. This is a
             | fact.
             | 
             | It doesn't matter who can make the best argument in court.
             | A good enough lawyer can convince a stupid enough jury of
             | pretty much anything.
        
               | er4hn wrote:
               | Let's say that I place a vending machine in a public
               | space, such as a street or a park. The public is able to
               | interact with it by inserting FIAT coins to purchase
               | DRNK. Someone clever figures out a way to interact with
               | the vending machine to extract DRNK at less than it's
               | intended FIAT price. Two questions at this point:
               | 
               | (a) Is this a theft from the person who placed the
               | vending machine? Why or why not?
               | 
               | (b) How is this different from a smart contract on a
               | blockchain?
        
               | stickfigure wrote:
               | I'll try to steelman the code-is-law argument (not really
               | sure how I feel about it myself):
               | 
               | In the case of the smart contract, you don't own the
               | vending machine. It doesn't have an owner, it just "is".
               | If it _did_ have an owner, that person is probably
               | violating all sorts of securities laws in countless
               | jurisdictions. That 's at least part of the point of all
               | this smart contract stuff.
               | 
               | To make the analogy a little more apt, let's say the
               | smart autonomous vending machine 1) lets people buy DRNKs
               | by inserting money, 2) incentivizes people to refill it
               | with DRNK by spitting out money, 3) once a month spits
               | out money to the amused landlord, and 4) was deposited by
               | aliens who disappeared without trace.
               | 
               | Presumably the smart vending machine would continue on
               | its merry way like this until it either broke down or
               | someone figured out a way to jimmy the lock. Looks like
               | the later happened. Though everyone is upset, it's not
               | clear who has the right to prosecute.
        
               | glerk wrote:
               | > If did have an owner, that person is probably violating
               | all sorts of securities laws in countless jurisdictions.
               | 
               | That's probably what upsets me most about this story.
               | These developers want to have it both ways: it is
               | decentralized finance and nobody owns the contract as
               | long as we are making money, but we want all the laws and
               | regulations of traditional finance to protect us if
               | things don't go our way.
               | 
               | I am saying this as someone who is pro-crypto. There are
               | trade-offs to this technology. We need to pick a lane be
               | prepared to deal with the consequences.
        
               | nicoburns wrote:
               | Frankly, I don't think it's up to you to pick a lane.
               | It's the wild-west at the moment because the technology
               | is new. But it won't be long before the law catches up
               | and crypto will be subject to it the same as everything
               | else.
        
               | s1artibartfast wrote:
               | Imagine in your example the vending machine has a
               | variable pricing and lowers its price if nobody purchases
               | soda. Is it theft to wait longer than the designers
               | thought people would wait and purchase the DRNK at price
               | lower than the machine owner thought they would.
               | 
               | I think a better example is a claw gambling machine. You
               | pay Fiat for a chance to grab fiat out of a pool.
               | 
               | If you come up with a strategy whereby you can grab more
               | or all of the Fiat in a way that the game/machine
               | designer and other players did not anticipate, is that
               | theft?
               | 
               | Alternatively, people are playing a modified version of
               | Poker with rules they don't understand, and someone
               | understands the rules better and gets their money, is
               | that a crime?
        
               | jdmichal wrote:
               | Broken slot machines do happen, and it's been made very
               | clear that the player does not benefit.
               | 
               | https://www.aol.com/2016-11-02-broken-slot-machine-dupes-
               | wom...
               | 
               | https://www.foxnews.com/us/not-a-winner-oregon-woman-
               | denied-...
               | 
               | However, this works both ways. If the mistake is in the
               | favor of the player, they are obligated to pay out:
               | 
               | https://www.msn.com/en-us/news/us/a-slot-machine-in-las-
               | vega...
        
               | s1artibartfast wrote:
               | I would argue that the fund wasn't broken-it was working
               | exactly as designed. It was just a bad design
        
               | cogman10 wrote:
               | That sort of depends on what the exploit is, right?
               | 
               | For example, if DRNK costs $1 per unit, but I find out
               | that by putting in $1.25 I get 2 units, have I actually
               | exploited the machine? Is it not reasonable to assume
               | that discount was intended?
               | 
               | Now, of course, if I'm prying open the machine with a
               | prybar then we could argue that's just theft. But,
               | putting money in the machine and getting units out is the
               | intended interaction.
               | 
               | Similar to how if a gas station accidentally puts the
               | price of gas at $0.20 per gallon, even though everyone
               | knows that's probably a mistake, it isn't on them for
               | taking advantage of the artificially low price.
               | 
               | So, that's what I'd say the difference is. A smart
               | contract defines all the interactions that are valid.
               | Thus, it is impossible to interact with a smart contract
               | in a way that is "invalid" or "stealing". That'd be
               | different if the user could modify the contract (apply a
               | prybar) however, that's sort of the point, that you can't
               | modify the contract to fix it.
               | 
               | If the contract said "all your deposited crypto goes to
               | cogman10" would we call that a theft when someone put
               | their crypto into that contract? Perhaps if I
               | misrepresented the contract, but then the whole point of
               | these contracts is they are visible to anyone that wants
               | to read/use them.
        
               | IanCal wrote:
               | > For example, if DRNK costs $1 per unit, but I find out
               | that by putting in $1.25 I get 2 units, have I actually
               | exploited the machine? Is it not reasonable to assume
               | that discount was intended?
               | 
               | What if you remove the last part? What if you know,
               | clearly, that your interaction what not what the designer
               | wanted?
               | 
               | > So, that's what I'd say the difference is. A smart
               | contract defines all the interactions that are valid.
               | 
               | Implementations are not specifications. What do you mean
               | by "valid"?
        
               | jdmichal wrote:
               | And what if the vending machine measures coins by weight,
               | and you so happen to have a "coin" that is just a
               | properly-weighted blank. You're still interacting with
               | the vending machine _as technically intended_. But by not
               | inserting the correct amount of money, you are not
               | interacting with it as intended by the creators.
               | 
               | The smart contract implements a technical intent, just
               | like the vending machine. But that technical intent will
               | always have limitations. Some exploits are non-
               | destructive, such as properly-weighted blanks. Some are
               | destructive, such as crowbars. But let's not pretend that
               | they aren't, in fact, exploits.
        
             | bawolff wrote:
             | I mean, all these smart contract people basically advertise
             | this scenario as a feature not a bug.
             | 
             | Ianal and don't know how a court would see it, but the way
             | smart contracts are advertised would probably give you a
             | fighting chance to make this argument where in normal
             | finance you would have no chance.
        
             | SkyMarshal wrote:
             | Can they make a strong case about what their intent was? Do
             | they have some legal agreement with the hacker that the
             | judge can use to divine their intent and the hacker's
             | violation of it beyond reasonable doubt?
             | 
             | Or might the hacker and his clever lawyers have an equally
             | strong case that whatever the code allowed was the "true"
             | intent, that the code is the ultimate arbiter of intent,
             | regardless what Index might have said otherwise?
             | 
             | I kind of hope it does go to court, will be interesting to
             | see what the opposing legal teams come up with.
        
         | c3534l wrote:
         | Yes, but the I believe similar cases have appeared where the
         | courts have found against the objectivity of smart contracts. I
         | think, ultimately, the point of regulating the financial
         | markets is not to protect investors, but to protect the
         | economy. And if a smart contract undermines the security of our
         | financial system, then that smart contract may simply be
         | illegal.
        
         | twox2 wrote:
         | "Code is law" is a dream that is not actualized. It's not
         | actually law, it's just code. I'm pretty sure law enforcement
         | will gladly prosecute for a lot of these "hacks".
        
           | gizmo686 wrote:
           | What specific law was broken? In the US, generic "hacks"
           | generally fall under the computer fraud and abuse act, which
           | is notoriously vague about what qualifues as "authorized".
           | Perhaps some other lawvis applicable. But I cannot think of
           | any that are obviously on point. Nor can I think of a clear
           | precedent that clarifies the issue.
        
             | buzzdenver wrote:
             | > What specific law was broken?
             | 
             | Market manipulation, fraud.
        
               | Dylan16807 wrote:
               | Market manipulation might work, but since it was all
               | inside of a flash loan that's harder to argue.
               | 
               | I'm skeptical that any fraud happened here.
        
           | knorker wrote:
           | Indeed it cannot be actualized, as it connects to the real
           | world.
           | 
           | This is why things like "land registry on the blockchain"
           | will never happen. When a court decides that a sale of a
           | house was unlawful, then the blockchain is wrong and
           | irrelevant.
           | 
           | Code isn't law. Law is system that ultimately sends people to
           | your house and puts you in a locked house that you're not
           | allowed to leave, and lets other people live in "your" house
           | now.
           | 
           | Math can't enforce who lives in your house.
        
             | antisthenes wrote:
             | Exactly.
             | 
             | Law isn't law unless it's been enforced through courts,
             | precedent and ultimately someone with authority to use
             | force to force compliance.
        
               | twox2 wrote:
               | In other words, "code is law" only if it complies within
               | the existing framework of our laws. IMO, this still
               | leaves a lot of room for creative applications of smart
               | contracts.
        
               | knorker wrote:
               | Could be. But then any smart contract system needs to
               | acknowledge this overarching law, and give it "super user
               | access", if you will.
               | 
               | And these systems could exist. But they are not the
               | systems that are being designed. They are in fact
               | antithetical to the stated goals of all of these
               | cryptocurrencies and smart contract systems.
        
           | marcosdumay wrote:
           | If you widely publicize that "code is law", and get customers
           | due to that promise, things are not that black on white.
        
         | godelski wrote:
         | This is a thing that confused me about smart contracts. I don't
         | see how they can exist without a judicial system. They do seem
         | to have some uses under that framework. Like the system is
         | auditable so you can prove if someone cheated and changed a
         | contract out from under you (and you lost your copy), but
         | that's only a minor improvement on the current system. The US
         | has a lot of legal policy that is based on spirit of the law
         | because it is well recognized that humans are imperfect and
         | never will be. It then seems silly that people who are fully
         | aware of failure analysis/engineering would design a system
         | where the mode of failure is easily exploitable.
        
           | dcolkitt wrote:
           | > I don't see how they can exist without a judicial system.
           | 
           | Smart contracts don't have to exist outside the judicial
           | system. Smart contracts are simply a way to automate
           | transactions in a way that's efficient, transparent, and
           | credibly neutral. Yes, we may still have to invoke courts for
           | the 0.01% of transactions that are clear exploits. But the
           | other 99.99% of the time, it's a much more efficient system
           | than using written contracts to handle normal, everyday
           | outcomes.
           | 
           | Even without blockchains or smart contracts, we already have
           | automated systems that execute transactions based on
           | algorithmic rules. If you blatantly exploit a vulnerability
           | in those systems, then courts will generally punish you. That
           | doesn't mean that automated systems are pointless, because
           | 99.9% of the transactions aren't exploits. That's still a
           | huge win, because it means we don't have to have our lawyers
           | email redlines back and forth every time we want to trade an
           | S&P index futures contract. (Near) fully automated
           | transactions are 1) orders of magnitude more efficient, 2)
           | expose general purpose composability where one automated
           | system can be predictably inter-connected with another.
           | 
           | When you put an automated transaction system on-chain, you
           | drastically increase the advantages of both, because you're
           | embedded in an open application network with credible
           | neutrality. A smart contract exchange like Uniswap can
           | process about the same amount of volume as a centralized
           | exchange like Coinbase, but the difference is that Uniswap
           | only needs about 50 employees, whereas Coinbase needs 5000.
           | That's primarily because Coinbase runs inside a silo'd
           | network. That entails replicating many functions like user
           | account management, that aren't necessary for an application
           | like Uniswap that piggybacks off the credible neutrality of a
           | decentralized consensus layer like Ethereum.
        
           | young_unixer wrote:
           | > The US has a lot of legal policy that is based on spirit of
           | the law
           | 
           | Yes, but that's a wrong and unfair way to define and apply
           | laws.
           | 
           | > humans are imperfect
           | 
           | Smart contracts and "code is the law" mantra don't contradict
           | this. You're imperfect and you commit a mistake, you lose.
           | You find a mistake in someone else's code, you win.
           | 
           | This is much better than the current legal system where we
           | are all collectively forced to adapt to, or even pay for,
           | someone else's mistakes.
        
             | lostcolony wrote:
             | >> The US has a lot of legal policy that is based on spirit
             | of the law
             | 
             | >Yes, but that's a wrong and unfair way to define and apply
             | laws.
             | 
             | Sounds like you're interpreting how to define and apply the
             | law there based on what you feel is the right and fair way
             | to do so. Seems a bit paradoxical.
        
           | webmaven wrote:
           | The legal system has failure modes that are just as easily
           | exploitable, but humans can intervene and reverse the
           | failure, make people whole, etc.
           | 
           | The problem with smart contracts isn't that there are bugs,
           | but that buggy results are final with little to no recourse,
           | by design, unless you get everyone to agree to hard fork the
           | chain (rolling the "bad" transactions back and eplacing the
           | buggy contract) and/or the implementation (if the bug was in
           | the platform rather than the contract).
           | 
           | The legal system has a similar principle of not being liable
           | for conduct that predates a ruling or law that forbids it,
           | but it also has the principle of agreements being interpreted
           | according to common sense understanding by a person with
           | ordinary skill, and where skill differences exist between
           | them the non-expert's interpretation is the one given
           | precedence.
           | 
           | These meta rules don't have equivalents in smart contract
           | systems, which makes them brittle. The only way smart
           | contracts end up being used for non-trivial purposes is if
           | they are made explicitly subordinate to the existing legal
           | infrastructure in ways that will gum up the works, or if
           | smart contracts are subject to mandatory formal verification
           | possibly including game theoretic 2nd order effects.
        
             | LeifCarrotson wrote:
             | I think a lot of the appeal of crypto/smart contracts is
             | that they are final with little to no recourse, humans
             | can't intervene and exploit failure modes which individuals
             | using the so-called contracts can't defend against.
             | 
             | Corporations and wealthy individuals with influence in the
             | writing of this legal system, with massive amounts of
             | financial resources, with negligible moral agency, and with
             | limited criminal liability find very different utility in
             | the ability to use the legal system to roll back contracts,
             | to enforce them, or to ignore them.
             | 
             | Those who find themselves on the other side of this power
             | disparity would often prefer to risk a potentially buggy
             | but inviolate contract than one which they expect to be
             | abused against them.
        
               | mbreese wrote:
               | I want to know what kind of contracts people entered into
               | before this where they thought they were being abused by
               | a big corporation?
               | 
               | This seems like a noble endeavor, but not an entirely
               | practical one. Both sides of a transaction have to agree
               | to these smart contracts, so where is this an advantage
               | (outside of internal crypto trading)?
        
               | majormajor wrote:
               | A bunch of those many-to-one individual:corporation
               | contracts (like phone service) are in such imbalanced
               | markets that you'd have to overcome the power balance
               | problem in order to get the other party to adopt the
               | "smart" contract.
               | 
               | But if you can overcome the power balance problem, you
               | can just fix the contracts directly anyway without them
               | being smart?
        
               | jeffbee wrote:
               | I don't know what jurisprudence you live under, but under
               | English common law (also America, Canada, etc) - which, I
               | must say, I also always denounce and rarely defend -
               | inequitable negotiating power between parties to a
               | contract is considered by courts when adjudicating
               | whether parties have broken it or can be awarded damages.
               | We _don 't_ have a system where big powerful
               | organizations can just dictate contracts to powerless
               | individuals and then later enforce them.
        
             | chx wrote:
             | There was a wonderful summary of what smart contracts are.
             | 
             | https://twitter.com/qrs/status/1395784294451265536
             | 
             | > Smart contracts should be considered self-funded bug-
             | bounty platforms.
        
               | cinntaile wrote:
               | Mark the "should". It's just an opinion, not a fact.
        
               | arcticbull wrote:
               | More like a pinata full of money sitting next to a whole
               | pile of sticks.
        
               | lostcolony wrote:
               | "Should" is modifying "consider". Considering something
               | is obviously subjective and not fact.
        
             | fvdessen wrote:
             | AFAIK the legal system still applies to crypto; the
             | recourse when somebody hacks your smart contract is the
             | same as when somebody defrauds you; you sue. Except with
             | smart contracts you have more traceability as to what
             | happened.
             | 
             | And you don't need to make the smart contract explicitly
             | subordinate to the law, they are as a matter of fact,
             | because everything de facto is. This idea that code is law
             | and crypto exists in a vacuum is complete delirium
             | (although a popular one and sign that the scene has a lot
             | of room to mature)
        
         | bolasanibk wrote:
         | The Worlds littlest skyscraper
         | https://en.wikipedia.org/wiki/World%27s_littlest_skyscraper
        
         | sushid wrote:
         | I never hear "code is law" from defi protocols, their ToS, or
         | really from anyone. It's only the detractors of Web3 who tout
         | this false logic of "code is law" so I guess you're screwed.
         | 
         | Examples of code NOT being the law: Some defi protocols have
         | made those affected by a hack/loophole whole again with their
         | own funds. Some defi protocols explicitly exclude certain
         | jurisdictions like the US from accessing their protocol. Surely
         | if they all belived "code is law" they wouldn't give a fuck,
         | right?
        
         | glerk wrote:
         | They really don't have any leg to stand on.
         | 
         | A smart contract is a piece of code running on a public
         | permissionless blockchain. The developers who deployed that
         | code do not _own_ it. Medjedovic had as much the right to take
         | money out of the smart contract using the contract 's logic as
         | Kellar and Day.
         | 
         | Being blockchain developers, Kellar and Day know these facts
         | very well, but they persist in their hypocrisy because it is in
         | their financial interest to do so. They are betting on a non-
         | technical jury being convinced by a good lawyer that Medjedovic
         | "hacked them" or "stole their funds" (which is not at all what
         | happened here).
        
           | woojoo666 wrote:
           | By that token, wouldn't rugpulls be legal too?
        
             | glerk wrote:
             | Probably? A priori there is nothing wrong with someone who
             | owns a large amount of a certain asset transferring it into
             | a liquidity pool in exchange for a different asset.
             | 
             | It gets more murky if a founder explicitly lies to
             | investors in order to get them to buy their token.
             | Fraudulent misrepresentation is problematic in most
             | jurisdictions, but this has nothing to do with the
             | mechanics of the "rugpull" itself.
        
               | s1artibartfast wrote:
               | rugpulls are different because crypto developers lie and
               | deceive investors in their disclosure.
               | 
               | A better example would be 3rd parties pumping and dumping
               | a crypto asset. Should this be illegal?
        
               | ac29 wrote:
               | Here's a recent case where the SEC litigated
               | misappropriation of funds among other things:
               | 
               | "According to the SEC's complaint, the defendants
               | misappropriated nearly $4 million of investor funds. The
               | SEC also alleges that Chiang and Tippetts misused
               | additional Sharenode investor funds by spending at least
               | 133 bitcoin to list NSG tokens on an unregistered trading
               | platform and to fund a team of captive traders to trade
               | NSG tokens amongst themselves to create the false
               | appearance of a robust market with increasing prices.
               | These traders allegedly created the false impression that
               | more than $2.5 million worth of NSGs were traded daily on
               | BitForex during the first 60 days and that the price of
               | NSGs was steadily increasing due to investor demand.
               | According to the complaint, however, the manipulation
               | scheme collapsed when investors tried to sell their NSG
               | tokens, because there were no actual buyers, causing the
               | token's trading price and volume to fall precipitously."
               | 
               | This isnt exactly a classic "rugpull", but it does make
               | it fairly clear that you cant just take customer funds
               | and use them however you'd like just because its a
               | cryptotoken and you have access to the smart contracts
               | controlling it. You _really_ shouldnt use customer funds
               | in furtherance of additional frauds, like these people
               | did here.
               | 
               | https://www.sec.gov/litigation/litreleases/2022/lr25377.h
               | tm
        
               | paulmd wrote:
               | That doesn't really turn on any crypto-related concepts
               | at all, but rather false/deceptive disclosures about the
               | security itself. That actually would be equally illegal
               | to do with regular securities too - you _don 't_ fuck
               | around with disclosure documents, that's an absurdly easy
               | way to go straight to jail.
               | 
               | > These traders allegedly created the false impression
               | that more than $2.5 million worth of NSGs were traded
               | daily on BitForex during the first 60 days and that the
               | price of NSGs was steadily increasing due to investor
               | demand. According to the complaint, however, the
               | manipulation scheme collapsed when investors tried to
               | sell their NSG tokens, because there were no actual
               | buyers, causing the token's trading price and volume to
               | fall precipitously."
               | 
               | This is also _the fund owners_ doing something nefarious
               | - that doesn 't mean that somebody else executing a
               | transaction according to the contract and the market
               | could be held accountable because the fund's customers
               | lost money. Someone has to be on the other end of every
               | transaction, that is how a market works.
        
             | t_mann wrote:
             | Rugpulls, as in projects attracting funds and then
             | absconding with them, are different from exploits in that
             | they involve outright lies / deception. There's a (moral,
             | at least) difference between bad intent and honest
             | incompetence. The attacker didn't ask anyone to contribute
             | the funds that he appropriated.
        
         | Ajedi32 wrote:
         | I've seen this argument regarding smart contracts several times
         | now, and I don't think it makes any sense. It's like robbing
         | someone in real life, then claiming you did nothing wrong
         | because you didn't violate the "laws" of physics. Those are two
         | entirely separate things.
         | 
         | In the world of smart contracts code is indeed law, but that
         | doesn't change the fact that in the real world law is law, and
         | the fact that you used a smart contract to commit a crime
         | doesn't make it any less a crime.
        
           | meowface wrote:
           | In the real world law is law, but I think it's still not
           | entirely clear whether smart contracts can be considered
           | legal contracts and how to judge if any particular smart
           | contract is one.
           | 
           | If this smart contract is considered a legally binding
           | contract, then, yes, this would likely be illegal despite the
           | proverbial "letter" of the smart contract not being broken.
           | If it isn't, then it may not necessarily be illegal (but
           | possibly still could be).
        
           | thrwy_918 wrote:
           | >In the world of smart contracts code is indeed law, but that
           | doesn't change the fact that in the real world law is law
           | 
           | I think some confusion arises because that "smart contracts"
           | only make sense if code really is law, in the sense that any
           | transaction executed by the contract -- even unexpected,
           | surprising transactions -- is considered to be fully
           | consented to by all parties interacting with the contract.
           | 
           | I agree that that's a terrible idea - bugs can always exist,
           | and having no recourse when millions of dollars are lost due
           | to a coding error is a huge and unreasonable risk.
           | 
           | But otherwise -- if, ultimately, courts can force "smart
           | contract" transactions to be unwound if they are found to be
           | exploitative, unintended or otherwise invalid -- then what's
           | the point of having smart contracts in the first place?
           | What's the value proposition? Why not just use regular
           | contracts?
        
             | IanCal wrote:
             | > Why not just use regular contracts?
             | 
             | It's just code, so the same reason we use APIs rather than
             | doing everything by lawyers.
        
             | verdverm wrote:
             | Most people will be coerced into returning funds if the
             | alternative is hard jail time
             | 
             | Smart contract is really the misnomer. In reality, they are
             | automations of contractual obligations and cannot automate
             | complete contract clauses.
        
           | daveed wrote:
           | Respectfully disagree. I think I've seen several times the
           | belief(from crypto supporters) that the code is the code is
           | the code, and these are the rules that we play with.
           | 
           | The "laws of physics" analogy doesn't match up. I feel like
           | it would be more appropriate in an anarchist society (physics
           | are the only laws, thus everything that obeys physics is
           | game).
           | 
           | This feels more like discovering an exploit in a video game.
           | It's up to the devs to patch it, or tournaments to outlaw,
           | but if you find something out, you can use it. We agree to
           | play by the rules, but if someone comes up with something
           | last minute, they can win.
        
             | Ajedi32 wrote:
             | That's not how the law works though, at least not in any
             | country I know of. If you exploit flaws in computer code to
             | steal something of real-world value, that's a crime.
             | 
             | We're all bound to the laws of physics, just as in the
             | world of smart contracts all are bound to the laws of code.
             | But none of that changes the existence of the laws of men.
        
               | ddingus wrote:
               | Actually, we are only bound to the laws of physics within
               | the limits of our understanding. As our understanding
               | grows, those laws become less and less restrictive. I
               | think it's an interesting analogy or parallel for the
               | case we are discussing.
        
               | Dylan16807 wrote:
               | I would argue that this wasn't really a code flaw. They
               | made a synthetic asset that calculated its price in a
               | dumb way. That happens plenty often without code, and
               | gets exploited by savvy buyers without code.
        
               | daveed wrote:
               | (Replying to this one, but the sibling comment feels
               | similar in vein).
               | 
               | - I'm not really saying the crypto-side argument is
               | right, really just trying to clarify my perception of
               | what they're saying re: the comment above me.
               | 
               | - The physics thing is really just a comment re: when
               | it's hypocrisy and when it's not.
               | 
               | - FWIW, theft in crypto isn't super well-defined to me
               | re: the laws of men either. Maybe someone who knows
               | current law better than me can explain, but calling a
               | function in a contract that sends updates from one
               | pseudonymous address to another... I don't actually know
               | if current written definitions of theft covers that, or
               | needs some court to interpret it as theft. We kind of
               | understand it as people, but I honestly don't know if
               | "laws of men" as written, do.
        
               | majormajor wrote:
               | If you do a promotion for giving away free food, and your
               | smart contract accidentally allows someone to get a free
               | sandwich every minute instead of once a day, is it so
               | obvious that someone using your promotion more than once
               | a day is "stealing"?
               | 
               | Ever use a different email address to sign up for a
               | different free trial, say? Let alone people sharing
               | Netflix accounts... where do you draw the line around
               | "stealing" here?
        
               | mikkergp wrote:
               | > is it so obvious that someone using your promotion more
               | than once a day is "stealing"?
               | 
               | Yes. This is very obviously stealing, particularly if the
               | promotion said it was for use once a day.
               | 
               | Edit: Also, sharing your netflix password may also very
               | well be illegal: https://www.lawjournalnewsletters.com/si
               | tes/lawjournalnewsle...
        
             | bombcar wrote:
             | Many people in crypto want to not have to comply with "real
             | world" laws right up until the point where it would be to
             | their benefit to do so.
             | 
             | And if "smart contracts" depend on real law, then they're
             | not really needed in many of the supposed use cases.
        
               | sushid wrote:
               | Just because there are crypto anarchists doesn't mean
               | that all crypto proponents are anarchists. And smart
               | contracts (not sure why they're in quotes in your
               | comment) can depend on real law and still operate fine
               | (e.g. I'm sure NBA Topshot would file a legal case again
               | Dapper Labs if they did something significantly damaging
               | to their brand/NFTs, etc.).
        
           | DannyBee wrote:
           | This claim makes no sense. In the real world, crimes have
           | very specific definitions. Most are physical, in fact.
           | 
           | For example, robbery is when, with intent to commit theft,
           | you take property by force.
           | 
           | Anything else is not robbery.
           | 
           | Theft by taking is: when a person unlawfully takes or, being
           | in lawful possession thereof, unlawfully appropriates any
           | property of another with the intention of depriving him of
           | the property, regardless of the manner in which property is
           | taken or appropriated.
           | 
           | (The above is georgia, robbery/theft/etc are state crimes so
           | defintions vary a bit)
           | 
           | Again, it requires doing so unlawfully (or converting
           | unlawfully).
           | 
           | If doing what this person did isn't unlawful _in the real
           | world_ , it's not theft, it's not robbery, it's not
           | _anything_.
           | 
           | So you have to find a crime that actually matches what
           | happened.
           | 
           | It's not wire fraud - that would require " false statement,
           | promise, or misrepresentation in order obtain money or
           | something of value from someone else."
           | 
           | etc
           | 
           | So what crime do you believe this actually is?
           | 
           | (So far i've only seen a civil lawsuit, and while there is a
           | warrant for his arrest, that's for refusing to move the
           | tokens to a neutral third party, or show up to court :P )
        
             | notahacker wrote:
             | In addition to sounding like textbook _embezzlement_ , I
             | don't think there's any reason to believe that "theft" as
             | define by that very broad Georgia definition couldn't apply
             | here (the "unlawfully" is to exclude certain property
             | appropriations explicitly permitted by law like bailiff
             | seizures or deposit retentions from the definition, not to
             | mean it's not theft if you keep someone's property against
             | their will without breaking any other laws. I don't think
             | it ceases to be "appropriation" of funds simply because you
             | provide something worthless as an exchange either,
             | particularly not with that last clause)
        
           | yongjik wrote:
           | I think the problem is, if you put a sign saying "Feel free
           | to break in, I dare you, if you manage to get in the house
           | then you're free to take anything you want!" then you can't
           | later complain when someone does exactly that.
           | 
           | (Well, maybe you can still complain, IANAL, but it gets a lot
           | murkier.)
        
             | rootusrootus wrote:
             | That might be useful in a civil case, but I don't see how
             | it would apply to a criminal case. "If you do X, it is not
             | considered fraud" isn't going to legally bind the criminal
             | justice system in any way.
        
             | IanCal wrote:
             | This comes down to the intent, doesn't it? It would be
             | different if you had no sign but on the door that opened if
             | someone pushed it because it was _badly designed_.
             | 
             | People on HN argue this with openly accessible APIs fairly
             | regularly "ah but the machine let me do it, they must be OK
             | with it" and I think that goes down badly in court.
        
           | SamBam wrote:
           | But that _is_ the premise of smart contracts. Sure, it doesn
           | 't excuse you from the law if your contract is to pay someone
           | to shoot someone, but it's supposed to be the final word on
           | the actual financial transactions that happen _within_ the
           | contract.
           | 
           | Plenty of crypto hypers say the same. E.g. from a quick
           | search of "Smart Contract advantages," the very first
           | article, by a law firm:
           | 
           | > Guaranteed Outcomes: Potentially the most attractive
           | feature, smart contracts could offer a way to substantially
           | reduce or completely eliminate the need for litigation and
           | courts. This is because when parties commit to using self-
           | executing contracts, they bind themselves to the rules and
           | determinations of the underlying code, rather than exposing
           | themselves to interpretations med by parties outside of the
           | contractual relationship.
           | 
           | https://www.newburnlaw.com/benefits-of-smart-contracts
        
             | sushid wrote:
             | Smart contracts allow for guaranteed outcomes. Some
             | commentary added by a random law firm does not mean that
             | guaranteed outcomes == no need for litigation and courts.
             | 
             | Just think of non-smart contract parallels. If a bank had
             | an ATM, the premise is that this ATM will execute a series
             | of commands and allow you to withdraw/deposit/transfer
             | funds. If a nefarious back actor found a series of user
             | input that allowed them to withdraw millions of extra
             | dollars, do you believe that the ATM provider will have no
             | legal recourse? What about electronic slot machines?
        
               | cellis wrote:
               | A true non-smart parallel is this. You and I agree on a
               | sporting event between humans. Because I want to
               | construct a fantasy, let's just say it's a three-point
               | basketball contest between adolescents (under 13).
               | 
               | The observer will pay $100 dollars per blocked shot, and
               | earn $1 per 3 point play made. All the games are played
               | 1v1. To the untrained basketball player participants,
               | this may seem to be a fair game. After all, it's quite
               | rare in a real basketball game to see a 3 point shot
               | blocked. So they sign the contract, fully agreeing to pay
               | $100 per blocked shot and earn $1 per made 3 pointer.
               | 
               | To game this as a participant, I go to the ends of the
               | earth ( I hear Sudan and the Netherlands are both nice
               | this time of year ), and find a 6'8 ,215 lb boy and
               | recruit him to play for me. He proceeds to block every
               | single shot in every contest, winning hundreds of
               | thousands of dollars and bankrupting the organizers. Just
               | to further weight this, I also hire an opposing player
               | who is only 4'3 to shoot as many 3 points as possible as
               | quickly as possible.
               | 
               | Now, they signed the contract and agreed to it. They
               | didn't have a clause for height, or any sort of caps, and
               | now they have unlimited downside. How would the legal
               | system handle this? Do you think they would release the
               | participants liability? Perhaps, but not likely if they
               | didn't sign the contract under duress. They fully agreed
               | and had consideration ( the $1 per 3 point made ).
               | 
               | It's a contrived example, but it's useful to show that
               | technicalities can be exploited in real world contracts
               | just the same as smart contracts.
        
               | majormajor wrote:
               | In a world where you're falling back to the legal system,
               | why do I care if your buggy ATM is powered by a "smart
               | contract" or by "regular" code? Why even do _you_ care?
               | 
               | (There _have_ been exploits in both ATMs and smart
               | contracts, after all.)
        
               | fao_ wrote:
               | > Some commentary added by a random law firm does not
               | mean that guaranteed outcomes == no need for litigation
               | and courts.
               | 
               | But it would appear that you expect us to believe that
               | some commentary added by a random _hacker news poster_
               | means the opposite?
        
               | sushid wrote:
               | I'm not extrapolating on the premise adding my own
               | commentary. The parent commenter asserts an axiom (that
               | we all purported agree with) and then links an
               | observation to said axiom. I'm merely stating that the
               | observation is not part of said axiom.
        
               | Veserv wrote:
               | The difference is that the ATM provider did not
               | explicitly promise that the "code is law" which directly
               | implies that they want to and aggressively argue that
               | they are waiving their legal recourse as long as they
               | were valid user inputs.
               | 
               | In contrast, basically nobody outside of the blockchain
               | space would waive their legal recourse in such a manner
               | and thus would have legal recourse if the intent of their
               | system was bypassed.
               | 
               | To go on to then argue that a legal system should not
               | allow one to waive those rights as it would be idiotic to
               | do so is a perfectly valid legal/moral/justice position,
               | but also directly contradicts basically the entire
               | purported value proposition of everything in the
               | blockchain space whose primary "positive" differentiating
               | factor is that "code is law" and they have waived those
               | rights. To not allow them to do so basically invalidates
               | their entire purpose.
               | 
               | Essentially, either let people bind themselves to "code
               | is law" and suffer the consequence of their choice, or
               | ban it at which point you lose decentralized trust and
               | censorship-resistance making them no different than
               | traditional implementations except that they are slower
               | with higher operational costs.
        
             | jallen_dot_dev wrote:
             | > it's supposed to be the final word on the actual
             | financial transactions that happen within the contract.
             | 
             | The court doesn't care how crypto idealists think the world
             | should work.
        
             | Ataraxic wrote:
             | That may be the premise, but has that actually be held up
             | and recognized as such in courts in major countries? Like
             | are there precedents regarding this?
             | 
             | At that point it's no longer a premise (for those
             | particular countries), but until then it's just a
             | supposition.
             | 
             | I think courts are wary to wade deeply into a new financial
             | system like this but at the same time I find it hard to
             | believe that the judiciary and the legislature would rule
             | (in the long run) that they have no ability to "make things
             | right".
             | 
             | If crypto grows as as many people suggest and you have some
             | significant percentage of the country that has savings or
             | investments tied to these smart contracts, if there is a
             | loophole like in this case, you'd have lots of people
             | writing their local or national representative about this.
             | I find it hard to believe that politicians would tell the
             | people they represent "tough luck code is law".
        
               | nomel wrote:
               | > be held up and recognized as such in courts in major
               | countries?
               | 
               | Only having a slight understanding of crypto, if local
               | courts are required, what's the point of crypto? Why not
               | use the existing financial systems, where all of this is
               | built in?
        
               | knorker wrote:
               | The article even hints at this:
               | 
               | > [a crypto bro] criticized the team for turning to a
               | centralized institution like the courts for help
               | 
               | But that's exactly the flaw of smart contracts, and why
               | its promises will never work.
               | 
               | The hard part of contracts was never execution. The hard
               | part was always conflict resolution and abidance by fair
               | rules (i.e. "laws"). The hard part is what creates the
               | overhead.
               | 
               | Smart contracts never solved the hard part. They remove
               | the solution to the hard part, claiming the hard part is
               | not needed at all. But the problems these solutions solve
               | are the hard part. Pretending they don't exist is not
               | "solving" anything.
               | 
               | There are so many examples of this. A minor can't enter
               | into a contract. Severely mentally disabled can't either.
               | Someone with a gun to their head can't either. It doesn't
               | matter if they enter into a million dollar contract. That
               | contract is invalid.
               | 
               | This is not "waste". This is the hard parts.
        
               | sushid wrote:
               | Crytocurrencies != smart contracts. The original premise
               | of bitcoin was essentially to create a decentralized fiat
               | currency. As its value grew the thesis then changed to
               | equate more of a decentralized digital gold/inflation
               | hedge that's easier to store and authenticate than actual
               | gold.
               | 
               | So that's one use of crypto.
               | 
               | In the non Web3 world, we typically have to rely solely
               | on the financial institution providing the service to
               | make transactions. That is, we have to have a Paypal
               | account to withdraw from Paypal. We can only buy/sell
               | Robux on Roblox, etc. Smart contracts allow us to
               | essentially utilize any provider we want without the
               | provider having custody of the funds at any given time.
               | 
               | I can go to any dex I want and transact without
               | depositing funds. The dex also cannot agree to perform a
               | transaction and hold my funds hostage, like how Paypal
               | screws over some of their merchants with their "internal
               | investigations." I can also buy/sell coins that the dex
               | mints (e.g. ORCA coin) anywhere I want. It's not tied to
               | a single account nor is it tied to single exchange.
               | 
               | And that's without getting into NFTs, flash loans, LPs,
               | and other features of Web3.
        
         | renewiltord wrote:
         | Contracts are contracts and law is law. Law can overrule
         | contracts. Smart contracts just let you have executable terms
         | which allows greater composition and commoditization.
        
       | motohagiography wrote:
       | This isn't a hack, it was straight arbitrage. I distinguish them
       | because there was at no time a transfer of administrative power
       | or control over the contract or targets infrastructure to
       | Medjedovic.
       | 
       | In a smart contract, I'd make a legal distinction between
       | syntactic parsing and calculation, which has to do with the
       | purity of functions and data. An arbitrage would be fair game if
       | it levered an unanticipated calculation, whereas a recent example
       | where the contract was only checking the last several bytes of a
       | destination address key would be a parsing exploit. Medjedovic's
       | arbitrage as described appears to be a pure calculation
       | advantage, and not exploiting a parsing error, and so this is
       | very reasonably fair game.
       | 
       | He used logic endogenous to the contracts, with no exogenous
       | control of the systems running the contracts. When you exploit a
       | buffer overflow, you are breaking through (sabotaging) a parser
       | as a means to manipulate the raw memory and machine - whereas
       | this arbitrage is closer to something that lies somewhere between
       | clicking on a link someone provided but had some unspoken
       | intention about you not using it, and a SQL injection or other
       | evaluation error that yields an index. (edit: Actually, it's more
       | like saying something really funny and unexpected on a platform
       | that hasn't banned that kind of humor yet, and they're just mad
       | about the consequences. we could even see a future where the
       | distinction between a hack and arbitrage will be the complexity
       | class of the algorithm and whether it represented a scheme that
       | was Turing complete)
       | 
       | Unfortunately, in Canada they'll go after him just as a fugitive
       | now, and there is no shortage of political actors who will want
       | to make him the perfect example villain for their hysterical
       | policy objectives. This is one of those increasingly classic
       | situations where a really smart kid gets system-involved and
       | can't comprehend how insane it is because the legal system and
       | politics are not subject to mere reason. If he has the money,
       | fleeing before charges were laid was probably even rational, as
       | there is no reason to expect the legal system is equipped to
       | deliver justice in something so new.
        
         | mathgenius wrote:
         | > This isn't a hack, it was straight arbitrage.
         | 
         | Yeah, but tradfi has this problem too: sometimes it's hard to
         | tell the difference between straight up trading, and
         | spoofing/otherwise manipulating the market. Maybe the moral of
         | the story is this, that free markets are a myth, and crypto is
         | just making this even more clear.
        
           | motohagiography wrote:
           | Arguably, the myth is that markets are efficient. That is to
           | say that the clearing price is the expression of all the
           | information available to participants is a fiction.
           | 
           | This idea of the Turing completeness, or maybe complexity
           | class of your transaction logic determining whether it is an
           | endogenous logical arbitrage trade, or an exogenous
           | manipulation scheme may have some really appealing features.
           | 
           | Hypothetically, if the steps of your transaction logic
           | operate on or recurse over feedback into and from the market,
           | you are in fact, "manipulating," it. I'd wonder how
           | describing manipulation in terms of recursion limits and
           | feedback would impact the definiton. Whereas, if you are
           | precalculating or front running some periodic market
           | function, you are arbitraging it with endogenous market
           | information and that makes it "legit."
           | 
           | Where this guy might be vulnerable in that model is the
           | question of how far upstream of his actual transaction did he
           | get before the feedback loop he was operating over is not
           | considered a part of that market - and whether his arbitrage
           | was legit because it was _between_ markets.
        
         | meetups323 wrote:
         | > If he has the money, fleeing before charges were laid was
         | probably even rational, as there is no reason to expect the
         | legal system is equipped to deliver justice in something so
         | new.
         | 
         | Except what's next? Live in hiding in a foreign country? Craft
         | a new identity and find new chains to exploit? I suppose 18
         | years old is a good time to learn that you can have all the
         | money in the world, but it won't do shit for you if you can't
         | spend time with the people you want to.
         | 
         | I'd wager this individual could get much more satisfaction out
         | of developing novel, interesting mathematics that do actual
         | good for humanity, surrounded by a group of like minded high
         | performing individuals. But he seems to have thrown hopes of
         | that out the window. It's sad, really.
         | 
         | But I'm perhaps projecting.
        
           | motohagiography wrote:
           | Regarding these like minded high performing individuals
           | surviving in institutions - after a couple of sigmas and
           | making some money, it can become difficult to value their
           | esteem. Canada is full of people who have fled their home
           | countries with their money, foreign capital flight drives our
           | entire real estate and supercar markets, wealthy fugitives as
           | a lifestyle choice are probably more common than we expect.
        
         | charcircuit wrote:
         | >He used logic endogenous to the contracts, with no exogenous
         | control of the systems running the contracts
         | 
         | The same description can be said for using XSS to steal
         | someone's cookies. XSS doesn't escape the JavaScript virtual
         | machine similar to how you aren't escaping Ethereum's virtual
         | machine. Technically the code allows you to inject arbitrary
         | JavaScript, but that behaviour wasn't intend to be possible by
         | the designers of the site.
        
         | aidenn0 wrote:
         | > If he has the money, fleeing before charges were laid was
         | probably even rational, as there is no reason to expect the
         | legal system is equipped to deliver justice in something so
         | new.
         | 
         | TFA claims he was originally offered to keep 10% (over a
         | million dollars) from this hack, free and clear. Not agreeing
         | to that deal meant willingly putting himself at the mercy of
         | said legal system. Talking about a single decision as rational
         | in isolation is disingenuous.
        
       | RcouF1uZ4gsC wrote:
       | I have a compromise. Allow hacks of cryptocurrency to be
       | prosecuted, but when they are, the also prosecute the creators of
       | the cryptocurrency for making unregistered securities and for any
       | fraudulent marketing of the cryptocurrency, or any failure to
       | disclose risks, or for not following financial regulations.
       | 
       | This is another example of make risks public and reward private.
       | They are arbitraging the financial system and trying to have the
       | freedom of cryptocurrency, but when things go bad, want law
       | enforcement to come fix it.
        
       | viksit wrote:
       | Smart contracts are badly named lambda functions. They need the
       | same regulation as any other code, the difference being, the
       | regulation can come in the form of more lambda functions.
       | 
       | The judiciary could write the latter any time they got the right
       | technical input. The question really is - what's worth putting in
       | the effort right now?
       | 
       | And those answers are coming soon.
       | 
       | But we shouldn't conflate smart contracts with legal contracts in
       | discussions.
        
       | paulpauper wrote:
       | Yeah, the attacker resides in Canada, so even if found guilty
       | he's looking at easy jail time at the worst. All he has to do is
       | wait a few years and the $ is his. not like in the US in which
       | feds hand out decade+ sentences like candy on Halloween.
        
         | moneywoes wrote:
         | Can't he be extradited
        
           | retrac wrote:
           | Maybe. That actually raises some interesting questions, come
           | to think.
           | 
           | A key factor in an offence is the location of the offence,
           | which usually determines jurisdiction and the relevant laws.
           | 
           | In the classic example of hacking an American bank from
           | Canada, the offence occurs on the American bank's servers in
           | the United States. That's relatively clean and simple,
           | legally.
           | 
           | With an Ethereum smart contract ... I'm not even sure where
           | to begin. Where does the offence even occur, legally
           | speaking? What aspect of fraud by a non-American, against an
           | American resident by executing an adverse smart contract,
           | occurs under the jurisdiction of the United States, if any?
        
       | anonu wrote:
       | Are there any good resources someone can point to on getting into
       | the code and mechanics of this? The article was a nice read, but
       | probably distills the real stuff behind some journalistic
       | simplification.
        
         | Graziano_M wrote:
         | ethernauts is particularly good intro that has you work through
         | a lot of the common security issues.
        
       | giantg2 wrote:
       | "In their complaint, lawyers for Kellar and Day argued that two
       | particular steps of the attack violated statutes against market
       | manipulation and computer hacking."
       | 
       | So now they want crypto to be treated as regulated securities,
       | but let me guess, only when it benefits them...
        
       | turtledove wrote:
       | The people who genuinely believe "code is law" are stunned to
       | learn that: a) humans won't act "rationally", b) regulations
       | exist for a reason, and c) no, the law is law, code is brittle.
        
         | [deleted]
        
         | vmception wrote:
         | d) I genuinely believe that Medjedovic should show up in court
         | to test that theory.
         | 
         | The only thing interesting about this case is how incompetent
         | he was, while having his entire brand and identity be based on
         | intellectual superiority. He should have used a virgin address
         | and Tornado cash. He should have not needed to risk any funds
         | for failure, as he should have tested the transaction in a
         | localhost staging environment for free. Him getting doxxed is
         | the only thing that allows this theory to be tested, whether
         | he, or we, believe it was legal, it is now unnecessary
         | liability. Instead, everyone knows who he is, that he's
         | spiraling mentally, a judge in his hometown jurisdiction froze
         | his addresses and the funds within it (which is a legal
         | abstraction that does not freeze the funds but makes it illegal
         | to move them until the order is lifted, in his favor or not).
         | Just piling on the liability.
         | 
         | I think "code is law" is a decent crux of a more fleshed out
         | defense, I think the Canadian attorney for the project founders
         | is grasping but I'm not as familiar with the direction courts
         | go there, I would prefer to see something similar play out in
         | US federal appeals court (which is sadly _after_ the drama of
         | trials court and how opinions calcify throughout). It would be
         | great and beneficial to see a transcript of how the "Sushi
         | flooding" is argued the context of a broad computer access
         | abuse law.
        
           | richbell wrote:
           | > The only thing interesting about this case is how
           | incompetent he was
           | 
           | I'm astonished at how poor his OPSEC was. He could have taken
           | any number of precautions to shield his identity -- did he
           | really think that deleting the messages on Discord would be
           | sufficient?
        
             | vmception wrote:
             | yeah its strange. one of his addresses was funded
             | previously by a Tornado Cash balance as well
             | 
             | oh well, he slipped up and is now probably a fugitive since
             | he keeps using his court "frozen" funds.
        
         | shadowgovt wrote:
         | "Code is law" really seems to me to be a philosophical position
         | that can only be held by people who haven't fully internalized
         | Godel's incompleteness theorems.
        
       | trasz wrote:
       | I find it disturbing that Medjedovic was prosecuted in the first
       | place. If anyone is guilty of this situation, it's Kellar and
       | Day.
        
         | glerk wrote:
         | Absolutely, they are guilty, but they won't take any
         | responsibility.
         | 
         | When you deploy a smart contract on a permissionless
         | blockchain, you don't _own_ the smart contract or the funds
         | that it controls.
         | 
         | These developers are hypocrites who don't believe in the basic
         | premises of this technology. It is easy to preach the virtues
         | of decentralization when it makes you money and run back in the
         | arms of daddy government when things don't play out in your
         | favor.
        
         | DangitBobby wrote:
         | Absolutely. They are guilty of writing vulnerable code, being
         | hacked, and stolen from.
        
           | trasz wrote:
           | They are guilty of implementing a mechanism that was broken
           | by design, and wasting customers' money. They hadn't been
           | hacked or stolen from - the "attacker" didn't need to hack
           | any particular security mechanism, he was just smarter at how
           | their market worked than the owners.
        
           | [deleted]
        
       | turtledove wrote:
       | You love to see it. Love to see crypto taking Ls.
        
         | meroes wrote:
         | If only so it lessens some of the bad behavior I've witnessed.
         | My cousin has been investing most of his paycheck in Bitcoin
         | for several years.
         | 
         | He also thinks Tesla Wall Batteries will mine crypto soon and
         | "broke into" a private event Elon was at and made a TikTok of
         | it.
         | 
         | I want him to have a successful future is all.
        
           | Brian_K_White wrote:
           | I feel this, but you know in a case like that, Elon and
           | Bitcoin don't actually matter.
           | 
           | If it weren't those, it would be whatever else existed to
           | fixate on.
           | 
           | I have a friend or two like that and I know that if I could
           | fix Bitcoin it would not clear up their life or make them
           | safe.
        
         | randomhodler84 wrote:
         | "Love to see your retirement 401k investments lose, eating away
         | at your life's labor and rendering it worthless."
         | 
         | This is a nasty position to take. You should never take joy at
         | others losses.
        
           | turtledove wrote:
           | Nope. Sorry. Those are not the same.
           | 
           | I'm cheering to see the grift coming apart. Yes, some people
           | are losing. But the early the grift falls apart, the fewer
           | future people get destroyed by it.
           | 
           | I'd rather cheer seeing crypto fail, then stand by and watch
           | it suck in vulnerable person after vulnerable person in
           | perpetuity.
           | 
           | Also, I absolutely do cheer the losses of bad people. If a
           | scammer or ethnonationalist loses their hard earned
           | winnings.... Good.
        
             | randomhodler84 wrote:
             | Its the same. You have an irrational fear/hatred of
             | decentralized peer-to-peer money. Grifts unwinding is a
             | thing, but don't throw out the baby with the bath water
             | here. I fully intend on using Bitcoin for the next few
             | decades, both as a saving and international remittance
             | system.
             | 
             | It's from a place of spite. Don't be spiteful, it makes you
             | a bad person.
        
         | onepointsixC wrote:
         | No I don't think I'll love to see a person who "written the
         | N-word into the code itself, 16 times." to steal 16 Million.
        
           | gaze wrote:
           | yeah the ideal thing to happen here is for that money to be
           | sent to a nonexistent address and for everyone involved to be
           | arrested.
        
           | turtledove wrote:
           | The white supremacist who did this is not a hero. I'm not
           | cheering for that asshole.
        
       | kristjansson wrote:
       | There's something delicious in a critical part of the arb relying
       | on a mechanism the contract authors included to reduce gas fees.
       | Not only are we enshrining code as law, we're playing code golf
       | with it first!
        
       | rvz wrote:
       | Good for the hacker then and well played.
       | 
       | If you _really_ hate crypto projects so much, rather than
       | complain all day long about the crypto-bros getting rich off of
       | their tokens, just hack the smart contracts themselves and the
       | project should offer a bounty if not beg for a negotiation for
       | that and once the project creators fix the bug, you keep the
       | rest.
       | 
       | Job done, until the regulators come.
        
         | paulpauper wrote:
         | easier said than done. you can be sure that when news breaks of
         | a contract being hacked it was only after maybe dozens, if not
         | hundreds, of contracts had been tried and failed, by many
         | hackers all over the world. Also, likely illegal: Code may be
         | law but the judge may not see it that way.
        
       | TameAntelope wrote:
       | For all the people shouting "Way to go!" and "The money is his!"
       | I think you should remember he's currently a fugitive, and would
       | need to spend the rest of his life living this way.
       | 
       | If that's what it takes to live the "code is law" dream, count me
       | out.
        
         | silentsea90 wrote:
         | I like the very web3 middle ground where the attacker
         | negotiates with the company and returns a part of the money,
         | the rest being the lawful reward for reporting the
         | vulnerability.
        
           | knorker wrote:
           | Do you mean "like" as in you're amused by it's absolute
           | absurdity, or that you think this is a good standard
           | practice?
        
             | silentsea90 wrote:
             | Sorry, I should make it clear - it is very very absurd.
             | Can't edit comments after some time sadly.
        
           | silentsea90 wrote:
           | To make my stance very clear - this is an absurd and
           | hilarious practice and feels similar to ransom, with the
           | hacked entity putting "white hat hackery" on the table as an
           | option to get some of their money back.
        
         | wang_li wrote:
         | Plus his family aren't choosing to live their lives in hiding.
         | What part of the smart contract is going to prevent acts of
         | violence against them? Seems like he was relying on maintaining
         | anonymity and now that that's out the window his family is on
         | real danger. $16-17 million is a lot of dough and it would cost
         | a lot less than that to hire some kidnapping & ransom
         | specialists to visit his family.
        
       | kristjansson wrote:
       | This is an outright copy of
       | https://www.bloomberg.com/news/features/2022-05-19/crypto-pl....
       | 
       | e: missed at the end of the article:
       | 
       | > (Except for the headline, this story has not been edited by
       | NDTV staff and is published from a syndicated feed.)
       | 
       | So perhaps this is reproduced under a legit syndication deal?
        
         | Brian_K_White wrote:
         | It says "(c) 2022 Bloomberg Christopher Beam, Bloomberg
         | Businessweek" right in it.
        
           | [deleted]
        
         | dang wrote:
         | Ok, we've changed to that from
         | https://www.ndtv.com/business/the-math-prodigy-whose-hack-up...
         | above. Thanks!
        
       | dimator wrote:
       | I'm getting strong Neuromancer vibes from this. It's so
       | interesting that we're now officially cyberpunk in some corners
       | of our world.
        
       | [deleted]
        
       | vmception wrote:
       | > Medjedovic added that he'd taken on "substantial risk" in
       | pursuing this strategy. If he'd failed he would have lost "a
       | pretty large chunk of my portfolio." (The 3 ETH he stood to lose
       | in fees was worth about $11,000 at the time.)
       | 
       | This is misleading, either intentionally or due to Medjedovic's
       | incompetence.
       | 
       | You can fork the current head of the mainnet blockchain to
       | localhost and try infinite permutations for free to see what the
       | next state of the blockchain will be. And then if you like that
       | state, you can then pay to send the working transaction to the
       | mainnet to make that same state occur, in a sure bet. ( _nearly_
       | sure fire bet as in some cases, someone could replace the mainnet
       | transaction in route, but they wouldn 't necessarily know what to
       | look for or change if its a distinct kind of transaction)
       | 
       | Medjedovic either didn't know this, because his skills didn't
       | translate as well as he thinks, or Medjedovic knows this and
       | hasn't come up with a stronger argument to support his actions
       | yet (of which there are plenty) and actually is relying on public
       | sympathy to support his actions.
       | 
       | Either way, there is an opportunity for broader education on how
       | these exploits can be cooked in something akin to a "hyperbolic
       | time chamber" or quantum reality without anyone's knowledge,
       | ready to hop back into our dimension fine tuned and ready to
       | cause maximum effect, all within the ~15 seconds between blocks
       | if necessary, as the state changes per block.
        
         | drcode wrote:
         | > And then if you like that state, you can then pay to send the
         | working transaction to the mainnet to make that same state
         | occur, in a sure bet.
         | 
         | That often isn't true anymore, see
         | https://ethereum.org/en/developers/docs/mev/
        
           | vmception wrote:
           | > but they wouldn't necessarily know what to look for or
           | change if its a distinct kind of transaction
           | 
           | which means non-trading transactions would look so different
           | that someone playing with higher gas wouldn't know what to
           | replace in the bytecode within the 15 seconds between blocks
           | 
           | and the user also has the choice of sending directly to a
           | miner just like the MEV people do, to skip the mempool
           | 
           | which is looks like he did (but not sure, just noticed his
           | contract mentions MEV)
           | 
           | https://etherscan.io/tx/0x1710f8c91f03d43a51b94fb5db00305cdd.
           | ..
        
           | kristjansson wrote:
           | MEV is something different though? GPs (excellent) point is
           | that anyone can play out the effects of their transaction
           | locally ad infinitum, and chose to transact once they're
           | convinced of its behavior. Of course, this can't account for
           | the response of other actors, but the point stands that
           | Medjedovic (should have) been taking far less risk than
           | implied by that quote.
        
             | xur17 wrote:
             | Medjedovic stood to lose all of the ETH he was paying in
             | transaction fees (which could have easily been 3 ETH) if
             | someone decided to frontrun his transaction. If that was
             | most of his ETH, that does sound "significant" to me.
        
               | vmception wrote:
               | He used some kind of MEV shielding thing. But I'm not
               | sure if it went directly to miners or did something else.
        
               | xur17 wrote:
               | Yeah, typically MEV shielding == sending directly to a
               | mining pool that promises that not frontrun it. It's not
               | a guarantee though, the miner could decide to still
               | frontrun, or a small reorg could occur, and another actor
               | could replace the transaction.
        
             | vmception wrote:
             | Another thing to note is that all the quotes from
             | Medjedovic are directly to a journalist (at Bloomberg, the
             | article was there a few days ago), which leads me to think
             | there are intentional omissions towards the journalist. It
             | is new that this level of detail is reported about
             | happenings in the crypto space, from traditionally and
             | previously non-crypto publications. It had usually been
             | confined to "broad market selloff, here's a bunch of hot
             | takes from our gloomy college friends on how it goes to
             | zero!" instead of "specific incident within a crypto
             | community, here's what happened". Medjedovic on the other
             | hand is only seen as taking advantage of situations, such
             | as a journalist that is perhaps merely enthused by the
             | crypto asset economy at a publication that needs someone
             | looking at it, but maybe not well versed in it or having
             | editors that would notice either.
        
         | qeternity wrote:
         | * MEV has entered the chat *
         | 
         | This is of course entirely untrue, and anyone who has done even
         | the smallest amount of onchain trading would know this.
        
           | vmception wrote:
           | He used MEV shielding and the rest of this thread has already
           | had that conversation to its completion
           | 
           | Its improbable that the transactions he formed would have
           | been able to be frontrun
        
         | MockObject wrote:
         | > You can fork the current head of the mainnet blockchain to
         | localhost and try infinite permutations for free to see what
         | the next state of the blockchain will be. And then if you like
         | that state, you can then pay to send the working transaction to
         | the mainnet to make that same state occur, in a sure bet.
         | 
         | You have described mining.
        
           | vmception wrote:
           | Yeah good observation. But instead of arbitrarily hashing a
           | algorithm used in consensus to find a block, this would be
           | hammering specifically constructed bytecode at a smart
           | contract's ABI endpoints to see how many other things get
           | effected.
        
         | buggeryorkshire wrote:
         | Jesus, and we wonder why grandma is entirely unsuited to
         | putting her savings in this crap.
        
           | vmception wrote:
           | This is only slightly different than what goes on in the
           | stock market
           | 
           | But yield farmers and high value targets should open
           | insurance policies
           | 
           | And the insurance pool participants should also be wary ha
        
           | Dylan16807 wrote:
           | That's just a complicated way of saying "you can locally test
           | a smart contract that you're coding".
           | 
           | Nobody is suggesting grandmas code their own smart contracts.
           | 
           |  _This_ is not the reason to keep grandma 's savings away.
        
         | uncomputation wrote:
         | Not quite a sure bet. It depends on your magic TX getting
         | picked up from the mempool by the winning node.
        
         | SamBam wrote:
         | If anyone could perfectly predict what was going to happen in
         | the next state then those with this ability would only ever
         | make money and never lose it. Yet this can't happen. In the
         | real world there are sniper bots and all sorts of other things
         | that another agent could do in parallel with your own script,
         | which would lead the outcome to be uncertain.
        
           | vmception wrote:
           | The main issue is constructing a valid transaction.
           | 
           | An exploiter conducting a big heist and disappearing never
           | has to prove that they can't do it again, because they're
           | rich immediately.
        
           | tromp wrote:
           | > would only ever make money and never lose it.
           | 
           | They'd at least risk losing the transaction fees...
        
         | [deleted]
        
         | jallen_dot_dev wrote:
         | I took "fail" to mean someone seeing his transaction in the
         | mempool and frontrunning him, exploiting the flaw for
         | themselves before he could. AKA Ethereum's "Dark Forest." Not
         | that the transaction would fail as in a bug or something. I'm
         | sure he knows how to simulate transactions locally if he could
         | figure all this out.
        
       | shockeychap wrote:
       | "But passivity also created risk. If there was a problem with the
       | code, someone could exploit it directly, without needing to
       | bypass any human safeguards. And limiting blockchain interactions
       | to cut costs entailed a trade-off: When a smart contract--a
       | script that executes automatically when certain criteria are met
       | --has fewer steps, it can leave more room for security
       | vulnerabilities."
       | 
       | So much of this reminds me of Chesterton's Fence, where
       | "innovative" solutions are deployed by people who never put forth
       | the time and effort to fully understand how the existing system
       | came to be the way that it was - and the problems that it had to
       | deal with and solve along the way.
       | 
       | I'm not trying to sing the praises of finance and banking;
       | there's much there that is broken. (I'm also not a fan of crypto
       | or NFTs.) But I am saying that many of the "old" ways came about
       | in response to a litany of problems that are neither obvious nor
       | intuitive, and you need to understand why it works the way it
       | does before putting out a new solution.
        
       | blakesterz wrote:
       | This was an interesting read. The case is now in limbo until
       | authorities can locate Medjedovic or he decides to appear.
       | 
       | "I did not steal anyone's private keys. I interacted with the
       | smart contract according to its very own publicly available
       | rules. The people who lost internet tokens in this trade were
       | other people seeking to use the smart contract to their own
       | advantage and taking on risky trading positions that they,
       | apparently, did not fully understand."
        
         | dehrmann wrote:
         | Reminds me of the standard advice of "don't roll your own
         | cryptography." There are a lot of subtle nuances that make it
         | hard to get right. When you have well-funded teams of absolute
         | novices writing rules for complex games with money on the line,
         | this is what happens. Rather than _just_ having user accounts
         | taken over and having to do a mea culpa, the reward isn 't lolz
         | or dark web money, it's actual money, and a lot of it.
        
           | Gordonjcp wrote:
           | I read a thing where someone called cryptocoins "Dunning-
           | Krugerrand" and that has stuck with me for years.
        
         | hartator wrote:
         | > I did not steal anyone's private keys. I interacted with the
         | smart contract according to its very own publicly available
         | rules.
         | 
         | Yes, it's a little disingenuous to claim "code is law" until it
         | doesn't suit you anymore.
        
       | liminal wrote:
       | The fact that Ethereum code is public seems to weigh in favor of
       | allowing him to get away with his "hack". For any other financial
       | instrument, we rely on verbal descriptions of how it will be
       | conducted and behave. With Ethereum, the code speaks for itself
       | -- for better or worse. This leads to a rather absolutist dog-
       | eat-dog rationality that I don't much like, but also don't see
       | how to avoid.
        
         | cbm-vic-20 wrote:
         | > For any other financial instrument, we rely on verbal
         | descriptions of how it will be conducted and behave.
         | 
         | My brokerage sends me plenty of prospectuses and other
         | documentation that I don't read that describes exactly that. I
         | depend on the regulators and the lawyers of other clients that
         | have a lot more to lose than I do to make sure they stick to
         | the rules.
        
       | vfclists wrote:
       | Why did this link land me on the Indian site ntdv.com?
        
       | qgin wrote:
       | Hey, code is law right? He is the rightful owner now.
        
         | postalrat wrote:
         | Until someone finds a way to calculate another key to move his
         | eth.
        
       | snickerbockers wrote:
       | "code is law" until you suddenly realize you suck at coding and
       | come crying to the actual law.
        
       | antishatter wrote:
       | What'd he do that was illegal? Seems like he didn't cheat and
       | insider trading laws don't seem to apply. Oops crypto is a
       | unregulated market.
        
         | postalrat wrote:
         | Isn't making people angry illegal yet?
        
         | onepointsixC wrote:
         | It's an exploit no matter how you look at it.
        
           | postalrat wrote:
           | Would it be an exploit if I discover the math to move all
           | bitcoin in existence to whatever address I want then do so?
        
             | grumple wrote:
             | Uh... yes? Are you seriously trying to imply that would be
             | legal?
             | 
             | If someone ever cracks modern encryption, that doesn't mean
             | they can do whatever they want with everyone's accounts
             | everywhere. If you find an exploit and exploit it, that's
             | illegal.
        
               | postalrat wrote:
               | What doesn't owning bitcoin really mean? If I had the
               | math to generate keys why wouldn't I also be considered
               | an owner?
        
               | grumple wrote:
               | If you copy my signature does that mean you can sign my
               | checks?
        
             | billpg wrote:
             | If you discovered a significant shortcut to hashing and
             | then went back to block 1 and re-mined every block until
             | your branch was the one with the most proof-of-work, I'd
             | have a hard time trying to claim that your branch wasn't
             | the legitimate one, according to Bitcoin's own rules.
             | 
             | I suspect in this hypothetical scenario, however, the
             | bitcoin developers would write a new rule.
        
               | postalrat wrote:
               | Perhaps a way to generate working private keys for any
               | address. So I could move coins as I wish.
        
             | [deleted]
        
         | iak8god wrote:
         | FTA:
         | 
         | > In their complaint, lawyers for Kellar and Day argued that
         | two particular steps of the attack violated statutes against
         | market manipulation and computer hacking. One was swapping
         | almost all the UNI tokens out of the DEFI5 pool, the otherwise
         | irrational trade that distorted the pricing such that
         | Medjedovic could buy tokens out from under Indexed users, who
         | were forced by the algorithm to sell. "The only purpose of that
         | trade was to mislead token holders to part with tokens on terms
         | they never would have agreed to," says Stephen Aylward, a
         | lawyer representing Kellar and Day. "We say that's a form of
         | market manipulation." The same argument applied to Medjedovic's
         | interaction with the CC10 pool.
         | 
         | > The second illegal transaction, they argued, was when
         | Medjedovic overwhelmed the pool with free Sushi, thereby
         | tricking the algorithm into letting him bypass the size limit
         | on certain trades. Aylward calls this "an intentional act by
         | Andean to disable a security measure, like disabling the
         | security system at a bank." He argues that this falls under
         | Canada's "extremely broad" legal definition of a hack, which
         | can be interpreted as "subverting the intended purpose of a
         | computer system."
        
           | motohagiography wrote:
           | Their complaint hinges on an interpretation of what the
           | correct level of abstraction for describing the transactions
           | is. Their argument, "to mislead token holders to part with
           | tokens on terms they never would have agreed to," is
           | literally a counterfactual that presumes both fictional
           | market conditions as well as intentions of anonymous owners.
           | 
           | The second argument is an analogy, "disable a security
           | measure, like disabling the security system at a bank," and
           | the limit expressed in the code was definitely an expressed
           | preference by the contract author, but if they wanted it to
           | be a legal contract subject to human interpretation, they
           | would have specified this in English. Instead, they created a
           | software tool, and they did not take into account how that
           | tool might be used by the public.
           | 
           | The argument about this is whether code written for the
           | express purpose of partipating in risky transactions can be
           | imbued with any other coherent intention. The closest analogy
           | would be that Medjedovic was at their gambling table and was
           | counting cards, except there was no policy keeping him out of
           | there, or against card counting.
        
           | colinmhayes wrote:
           | > to part with tokens on terms they never would have agreed
           | to
           | 
           | Didn't they agree when they bought the token though?
        
           | paulmd wrote:
           | So for the first claim, they are arguing that forcing a
           | leveraged short squeeze is market manipulation? There seems
           | to be lots of straightforward counterexamples that it's not -
           | that's an extremely common tactic the big guys use to squash
           | little guys in the regulated markets. The little guys "would
           | never have agreed to part with those securities on those
           | terms" and the squeeze is often deliberate, transient, and
           | leveraged.
        
           | faeriechangling wrote:
           | If the law is held to have supremacy over "smart contracts"
           | and implicit intent is held to be more important than
           | explicit terms, than this undermines not just a major
           | argument for smart contracts but a major argument as to why
           | crypto as a whole is valuable.
           | 
           | Enforcing a contract through a written contract & traditional
           | finance vs a smart contract becomes a mere implementation
           | detail since in either case somebody can come crying to the
           | courts when they lose money. Smart contracts are only
           | interesting if they're a form of binding arbitration. If
           | smart contracts are not binding, they just become poorly
           | written contracts.
           | 
           | Smart contracts being binding honestly might need to be
           | legislated.
        
             | antiterra wrote:
             | Even then, a binding contract is still subject to what is
             | contractually enforceable, which could break the
             | functionality and purported benefit of a smart contract.
        
             | TameAntelope wrote:
             | Yes, that's exactly the problem with smart contracts and
             | why people are interested in resolving the case.
        
             | xur17 wrote:
             | > If the law is held to have supremacy over "smart
             | contracts" and implicit intent is held to be more important
             | than explicit terms, than this undermines not just a major
             | argument for smart contracts but a major argument as to why
             | crypto as a whole is valuable.
             | 
             | No, it really doesn't. There are 2 questions that you are
             | conflating here:
             | 
             | 1. Can the courts force a user to return funds made via a
             | valid smart contract transaction?
             | 
             | 2. Can the courts force a blockchain to reverse a
             | transaction that was made.
             | 
             | > Enforcing a contract through a written contract &
             | traditional finance vs a smart contract becomes a mere
             | implementation detail since in either case somebody can
             | come crying to the courts when they lose money. Smart
             | contracts are only interesting if they're a form of binding
             | arbitration. If smart contracts are not binding, they just
             | become poorly written contracts.
             | 
             | Can you elaborate on why this would be the case? To me
             | there is a large difference between a system (like credit
             | card settlement) that can have transactions revoked easily
             | after settlement, and one that can only be revoked by
             | another separate transaction that the sender makes. To me
             | it comes down to a mix of probability of reversal, and who
             | can actually do the reversal (only the sender in the case
             | of a blockchain system).
        
               | faeriechangling wrote:
               | >2. Can the courts force a blockchain to reverse a
               | transaction that was made.
               | 
               | The courts already can't necessarily force a transaction
               | to be reversed as it is. The money can be gone long
               | before they get involved.
               | 
               | >To me there is a large difference between a system (like
               | credit card settlement) that can have transactions
               | revoked easily after settlement, and one that can only be
               | revoked by another separate transaction that the sender
               | makes.
               | 
               | There's a good deal of irreversible transactions, such as
               | inter-bank transfers in traditional finance. It's also my
               | understanding that most "Reversals" are just new
               | transactions or cancellations of pending transactions. I
               | don't see a HUGE difference in how an inter-bank wire
               | transfer works and how sending somebody crypto works
               | except that in the case of crypto it's the wallet/account
               | holder in full control.
               | 
               | I'll acknowledge there are differences, which impacts the
               | probability of reversal and who can do the reversal, but
               | I still feel it borders on the edge of "implementation
               | detail". It only feels like a truly profound difference
               | if you want to make a transaction a bank would normally
               | interfere with, like a ransom payment, payment for
               | fraudulent goods/services, drug deal, money laundering,
               | funds being sent to political dissidents, or similar.
               | Whereas the idea of smart contracts bypassing the expense
               | of the courts entirely seemed like a much more broadly
               | useful notion.
        
           | hedora wrote:
           | Isn't the intended purpose of this particular computer to
           | part fools and their money in a non-regulated "code is law"
           | ecosystem?
           | 
           | It seems like it's working as designed, even if it's not the
           | outcome its operators wanted.
        
             | betwixthewires wrote:
             | The funny thing is, based on the architecture of these
             | types of systems, they aren't the operators. Arguably the
             | miners are the operators, otherwise only the users are the
             | operators.
        
         | davidweatherall wrote:
         | Stop regulating crypto! (Unless I've been hacked, then we need
         | to regulate it)
        
           | rnk wrote:
           | Or unless you've lost money! Lots of people saying "the fed
           | could make crypto losers whole without putting up a sweat"
           | the last few days.
        
             | antifa wrote:
             | And they already do for all crypto that's FDIC insured.
        
         | lupire wrote:
         | He was in communication with the IF team, and contributed
         | something to their system, so it's _possible_ that he defrauded
         | them and inserted malicious code into the protocol, not just
         | interacted with the protocol.
        
         | rnk wrote:
         | I'd tend to agree with you. People with money and power will
         | push for laws that protect them though. But this situation is
         | why I'm skeptical of these kinds of contracts - too much
         | potential for problems.
        
       | WhitneyLand wrote:
       | Some insight as to what this guy is made of:
       | 
       |  _The Ethereum address Medjedovic used for the attack included
       | the number "1488"--shorthand for a neo-Nazi slogan--and he 'd
       | written the N-word into the code itself, 16 times. A Twitter user
       | called him the "Dylan [sic] Roof of Balancer Pools," a reference
       | to the mass shooter who killed nine Black people at a church in
       | Charleston, S.C., in 2015. Medjedovic liked the tweet._
       | 
       | Completely counter to every experience I've had working with
       | Waterloo people. My sample group always seemed smart,
       | interesting, kind.
        
       | zecken wrote:
       | I feel like the fact this person, per the article, is a white
       | supremacist who used the n-word in his code repeatedly is under-
       | discussed here. Folks here jumping through hoops to rationalize
       | why what he did is actually demonstrative of either flaws in
       | crypto or the purity of arbitrage come off seeming very tone
       | deaf.
        
         | antiterra wrote:
         | What exactly are you proposing here? That we have a different
         | set of financial and legal rules for despicable people? Or that
         | the financial and legal rules everyone is subject to should be
         | based on how they impact a specific despicable person?
         | 
         | If a despicable bigot is facing the death penalty for stealing
         | a bag of chips, would it be 'tone deaf' to say that's an unfair
         | punishment?
        
       | caymanjim wrote:
       | Forget about the exploit itself. Why are people trusting two
       | young nobodies (Day and Kellar of Indexed Finance) with so much
       | money in the first place? Ok, so Day has some decent academic
       | credentials, but he's just one person. Who was doing risk
       | analysis? Which independent experts analyzed their algorithms?
       | Which accounting firm audited them? Where's the oversight? These
       | two guys whipped something up, threw it out in the wild, and the
       | masses fed tens or hundreds of millions of dollars into it
       | without a care in the world.
       | 
       | This is how crypto operates. Buyer beware.
        
         | pohl wrote:
         | Haven't people who are attracted to crypto, for the most part,
         | already decided that oversight is bad because something
         | something decentralization?
        
           | Red_Leaves_Flyy wrote:
           | It's the Libertarian fantasy. Crypto bros, many VCs, angels,
           | and other mini napoleons think they can solve the world's
           | problems without addressing any of their personal problems,
           | studying history, taking responsibility for their actions,
           | engaging in community building, or hiring people with spines.
           | Which is why crypto and ilk keep reinventing every scam and
           | repeating the mistakes of the past that directly led to
           | regulation.
        
             | fron wrote:
             | "Libertarians are like house cats: absolutely convinced of
             | their fierce independence while utterly dependent on a
             | system they don't appreciate or understand."
             | 
             | No idea who said this originally but it continues to be
             | true. Abandon the system, and they find it was there for a
             | reason.
        
         | xur17 wrote:
         | Because people want to and decided the risk was worth it to
         | them? If a consenting adult wants to deposit their money into a
         | system that they have full visibility into, why should we stop
         | them?
         | 
         | > This is how crypto operates. Buyer beware.
         | 
         | This statement rings very true for me, and perhaps is the bit
         | we agree on. With crypto there is no "oversight" that blocks
         | you from depositing your funds into unsafe contracts, etc. It's
         | up to you as the user to do your own research before depositing
         | funds.
         | 
         | There are many projects within crypto that ARE well built, and
         | have been carefully tested, analyzed, slowly released to the
         | public, etc. I like having the ability to make this choice
         | myself instead of relying on some gatekeeper to decide what I
         | can do with my money ( _cough_ "accredited investor rules").
        
           | rootusrootus wrote:
           | > If a consenting adult wants to deposit their money into a
           | system that they have full visibility into, why should we
           | stop them?
           | 
           | We already do exactly that, e.g. Accredited Investor.
        
             | why_only_15 wrote:
             | Yes but _should_ we do it? Those rules prevent most people
             | from e.g. investing into startups.
        
       ___________________________________________________________________
       (page generated 2022-05-23 23:01 UTC)