[HN Gopher] The math prodigy whose hack upended DeFi won't retur...
___________________________________________________________________
The math prodigy whose hack upended DeFi won't return funds
Author : atlacatl_sv
Score : 214 points
Date : 2022-05-23 13:31 UTC (9 hours ago)
(HTM) web link (www.bloomberg.com)
(TXT) w3m dump (www.bloomberg.com)
| [deleted]
| tzs wrote:
| > It would take weeks to figure out precisely what had happened,
| but it appeared that the platform had been fooled into severely
| undervaluing tokens that belonged to its users and selling them
| to the attacker at an extreme discount.
|
| Q: is the programming language these things are written in
| powerful enough and have sufficient data access for the
| developers to include sanity checks that would halt trading
| automatically if something is happening too far out of the norm
| such as an unusually high volume of attempted night discount
| sales? Or maybe that would just block extreme discount sales if
| there have been too many of those recently?
| meetups323 wrote:
| The language could represent that, but you pay per operation so
| checks tend to get thrown out the window.
| isolli wrote:
| This part seems relevant:
|
| > It also saved on costs by limiting the number of
| interactions between the platform and outside entities. For
| example, when Indexed needed to calculate the total value
| held within a pool, instead of checking token prices on an
| exchange such as Uniswap, it sometimes extrapolated from the
| value and weight of the largest token within the pool, called
| the "benchmark" token.
|
| > This way, it reduced the fees it paid for transactions on
| the Ethereum blockchain.
|
| This cost-saving mechanism ultimately allowed the hack to
| take place.
| hiq wrote:
| See this very good comment about Solidity, the main language
| used to write software on Ethereum:
| https://news.ycombinator.com/item?id=14691212
|
| More to your point, you can always have more logging, slow
| things down to make them safer and allow communities to react
| in a timely manner, but it's far from trivial. The real problem
| is that any mistake can be fatal from the defender's point of
| view.
| tediousdemise wrote:
| We all know that most cryptocurrencies are big ponzi schemes, in
| which founders stand to gain the most.
|
| Well played for the hacker. What he did is probably less illegal
| than what coin founders and crypto bros do on the daily...
| swindle thousands of innocent people with misleading statements
| on Twitter and steal their hard earned cash.
| Imnimo wrote:
| I think of this like if you empty the 'take a penny, leave a
| penny' tray into your pocket. It's clearly allowed by the terms
| to take the pennies, but it's also clearly immoral.
| sib wrote:
| Is it? Or is taking _a_ penny allowed, but not taking _all_ the
| pennies (which feels more code-is-lawish...)
| neonate wrote:
| https://archive.ph/ZG3rP
| henning wrote:
| Web 3 is going great!
| knorker wrote:
| > Once cyberattackers have been identified, they often return
| funds in exchange for a face-saving bounty and credit for being a
| "white hat" hacker.
|
| Jesus, this whole cryptocurrency racket is a joke.
| smk_ wrote:
| @dang can you please permaban anyone using the phrase "code is
| law". It's always used to scapegoat. Any crypto discussion on HN
| is absolute garbage. This was such an interesting article I am
| immensely disappointed in the quality of discussion.
| vfclists wrote:
| This sounds like
| https://www.theguardian.com/business/2020/jan/28/navinder-sa...,
| Navinder Sarao, the British Indian trader who was blamed for the
| "flash crash" of 2010.
|
| It looks like if you fall foul of big merchant banks and stock
| traders you can have the full force of the DOJ land on you, but
| crypto is not important enough.
| Jon_Lowtek wrote:
| -- EDIT --
|
| i found the address and i take everything back and declare the
| opposite, that address is not random at all.
|
| -- original post --
|
| > _The Ethereum address used for the attack included the number
| ... shorthand for ..._
|
| So Bloomberg thinks people choose the numbers in their wallet
| addresses and are responsible for any perceived numerological
| meaning. Are they for real?
|
| Sure the guy could have sat there recreating addresses until one
| includes this number, but i consider it more likely this is the
| result of searching randomness for patterns they want to find.
|
| Someone noticed the pattern in the randomness and Bloomberg
| includes it, as it makes the antagonist more evil and the story
| more interesting.
| buzzy_hacker wrote:
| I'll give the full quote:
|
| > The Ethereum address Medjedovic used for the attack included
| the number "1488"--shorthand for a neo-Nazi slogan--and he'd
| written the N-word into the code itself, 16 times. A Twitter
| user called him the "Dylan [sic] Roof of Balancer Pools," a
| reference to the mass shooter who killed nine Black people at a
| church in Charleston, S.C., in 2015. Medjedovic liked the
| tweet.
|
| Here's another:
|
| > Medjedovic apparently flirted with extremist ideas: The
| classmate says he heard him speak favorably about White
| supremacy and eugenics.
|
| He is clearly a white supremacist, how is this "searching
| randomness for patterns they want to find"? This is
| speculation, but it wouldn't surprise me if this guy generated
| lots of addresses until he got one that did have 1488 in it.
| JKCalhoun wrote:
| Parents, don't rush your kids.
| [deleted]
| jrm4 wrote:
| I'll keep saying it -- a "smart contract" is nothing nothing
| nothing at all like a real contract, it's a stupid little piece
| of vending machine code that just operates. If we're going to
| argue the ridiculously dumb idea that smart contracts are, in
| fact, legal contracts -- congrats to the kid because he is 100%
| entitled to that money.
| eftychis wrote:
| Good luck to the judge. Commodities laws still apply so this will
| be interesting to follow.
|
| They had to sue or they would be sued themselves (which they
| might regardless), but there is no law restricting you actually
| from inflating the market value of an item (or a security). Their
| advantage is that he doesn't have a lawyer (or claims to) --
| which is a stupid move; and that they froze his gains (another
| stupid move). If a hack is actually involved under Canadian law
| we shall see but a civil lawsuit is not unlikely to dictate that.
|
| He misled their market maker, not the holders. Of course without
| reading the case one can not say anything and has an incomplete
| view, but they are trying to shift blame here.
|
| There is precedent of course, when Oil futures went negative and
| in the end brokers paid the difference -- as their software
| wouldn't allow people to trade non-negative ranges.
|
| tl;dr: I think they are still on the hook for the lost funds back
| in the E.U./U.K.
| __turbobrew__ wrote:
| For all of those involved: play stupid games, win stupid prizes.
| JackFr wrote:
| As I understand it, Indexed behaved as a sort of ETF for crypto,
| that had automated their creation/redemption mechanism.
|
| Importantly they had automated the creation/redemption mechanism
| poorly. Here's the operative passage:
|
| _By eliminating human managers, Indexed could forgo management
| fees like the 0.95% its bigger rival, Index Coop, charged for
| simply holding its most popular index token. (Indexed would
| charge a fee for burning tokens and swapping assets within a
| pool, but those only applied to a small fraction of users.)
|
| It also saved on costs by limiting the number of interactions
| between the platform and outside entities. For example, when
| Indexed needed to calculate the total value held within a pool,
| instead of checking token prices on an exchange such as Uniswap,
| it sometimes extrapolated from the value and weight of the
| largest token within the pool, called the "benchmark" token.
|
| This way, it reduced the fees it paid for transactions on the
| Ethereum blockchain. Kellar saw full passivity as a "natural
| extension of the way index funds already operate." _
|
| Kellar was wrong.
|
| In bringing down the costs, they eliminated the very thing that
| might have prevented the transactions that cost them all the
| money. The trades were legitimate, just unfortunate for the
| holders and to ask the courts to reward the incompetence of the
| management of indexed is to ask the courts too much.
| yobananaboy wrote:
| They were holding $17m in funds and only paid 2 unnamed security
| auditors?
|
| Yes, getting a proper audit for a Defi Protocol is expensive
| (probably 8 person weeks at $20-30k/week or ~$200k), and every
| good audit firm has a 3-6 month waiting period. But when you've
| got 100x that to lose, it's a drop in the bucket.
| bobsmooth wrote:
| "They discovered that the Ethereum wallet used to transfer tokens
| during the attack was connected to another wallet used to collect
| winnings in a recent hacking contest by a participant who
| sometimes identified himself as UmbralUpsilon. Pulling up the
| participant's registration, they saw that it linked to a profile
| on the collaborative coding platform GitHub."
|
| Opsec really isn't that difficult, you just have to give it some
| thought.
| npollock wrote:
| source:
| https://www.bloomberg.com/news/features/2022-05-19/crypto-pl...
| Overtonwindow wrote:
| This was fascinating to read, but I think the guy is ultimately
| innocent. He executed a series of speculative trades using the
| platform's rules and mechanisms. It reminds me of the 2013 case
| of some guys who took advantage of a software bug in a video
| poker game. "All these guys did is simply push a sequence of
| buttons that they were legally entitled to push."
|
| This sounds very much like the same thing, and since digital
| currency is not heavily regulated, some might say at all, I think
| the outcome, while unfortunate, is not illegal.
|
| Sadly Day & Keller and others will likely haunt this poor kid
| with lawsuits and frivolous attacks, but in my book he did not
| break the law.
|
| https://www.wired.com/2013/11/video-poker-case/
| jakear wrote:
| > His profile on one social network included a quote from Kurt
| Vonnegut's Cat's Cradle about the futility of humanity's quest
| for knowledge: "Tiger got to hunt, bird got to fly; Man got to
| sit and wonder 'why, why, why?' Tiger got to sleep, bird got to
| land; Man got to tell himself he understand."
|
| Hey! He's just like me.
|
| > But did Medjedovic do this, or did the algorithm? Barry
| Sookman, a lawyer in Toronto specializing in information
| technology, says it's a distinction without a difference:
| "Individuals are responsible for the activities of technologies
| they control."
|
| This of course goes both ways -- aren't the index fund creators
| responsible for their technologies too?
| DangitBobby wrote:
| If I write code that can be exploited with a buffer overflow
| and you exploit it, who is the law going to punish more
| harshly?
| shadowgovt wrote:
| But the entire raison d'etre of most of crypto is to get out
| from under the thumb of existing national and legal
| entanglements.
|
| So the question becomes "Who's law?"
| TremendousJudge wrote:
| If code is law, you.
| bix6 wrote:
| Can someone explain how you can take out a ~$150m flash loan?
| (Did he post $300m collateral?) Did he only need 3 ETH for that
| or were the ETH only used for the transaction fees?
| colinmhayes wrote:
| So flash loans must be repaid before the next block is mined,
| so you don't need to post any collateral, just the interest. If
| the loan isn't repaid in time it automatically unwinds and you
| lose the interest payment.
| bix6 wrote:
| Thank you
| yobananaboy wrote:
| The 3 ETH was the gas fees for the transactions. (Some went to
| deploying the attacking contract, some went to contract
| interactions afterwards.)
|
| With a flash loan, the funds must be returned by the end of the
| transaction, or the transaction fails. This makes the
| completion of the transaction the collateral, as if it fails at
| any point, all transactions (including the loan) get reverted.
| bix6 wrote:
| Thank you
| omarhaneef wrote:
| What is interesting to me is how it shines a light on the
| regulatory framework of the non-crypto economy. If you read up on
| edge cases, there is a lot of people deciding if something is
| "fair", and my notions of fair and a particular judges notions of
| fair are often at odds.
|
| To steal from Frank Zappa: Legal isn't the same as allowed,
| allowed isn't the same as fair, fair isn't the same as just, and
| just isn't music.
| tablespoon wrote:
| > What is interesting to me is how it shines a light on the
| regulatory framework of the non-crypto economy. If you read up
| on edge cases, there is a lot of people deciding if something
| is "fair", and my notions of fair and a particular judges
| notions of fair are often at odds.
|
| Yeah, that's by design. If your "notions of fair are often at
| odds" with someone else's notions of fair, and a judge needs to
| intervene to resolve the dispute, then things may not break
| your way.
| lbriner wrote:
| A judge is not deciding whether something is "fair" they are
| deciding whether it is illegal to the letter and/or spirit of
| the law. The reason this is at odds with us is that many things
| are legal that are not "fair".
|
| The specific danger here legally is trying to apply general
| laws into an unregulated market. It's a bit like borrowing
| money from your mate and then trying to take him to court
| because he's asking for too much interest.
| Brian_K_White wrote:
| "many things are legal that are not "fair"."
|
| They are, or at least purport to be, fair at some level or
| through some mechanism most people may not immediately
| percieve.
|
| When something really isn't fair, even by some indirect means
| or when accounting for some other imperative like geneneral
| societal necessity, then they are at least understood to be
| failures not successes.
|
| This story though... it actually provides a good example of
| indirect fairness. Well yes and no, there's a point and also
| a counter to that point, net result throw up my hands glad
| I'm not in crypto:
|
| Point, it's fair: You got robbed and think it's unfair that
| there's no recourse. That downside is just the fair price of
| being in that game at all, which you pay in trade for not
| having to deal with the traditional system and "the man". You
| have to absorb the occasional loss from a mistake as just a
| feature of the environment like the risk of your shipping
| boat sinking because the ocean is not a safe place. The only
| protection possible is pay an insurer or maintain your own
| emergency escrow or something, not any kind of police or
| rule-daddy.
|
| Point, it's not fair: They are not in fact free of the man,
| and so they are not really getting the true freedom they are
| paying for by assuming all responsibility for their own risk.
| omarhaneef wrote:
| Well, this is going to send us down a rabbit hole but the
| reverse is also true: there are multiple interpretations of a
| given law and the judge tries to use their judgement to
| square the law with the facts.
|
| (Rabbit hole because I sense this is a debate lawyers have
| all through law school, and there are various schools of
| thoughts about the nature of the law etc)
| Brian_K_White wrote:
| Right? There probably is not agreement on fundamentals like
| the root purpose of law.
| criddell wrote:
| There are lots of stories lately about stolen NFTs. The podcast
| ReplyAll did an episode where they tracked down the current
| owner of a stolen NFT. He had sympathy for the original owner
| but he had no intention of turning it over.
|
| I don't get why purchasing a stolen NFT is different than
| purchasing a stolen guitar from a pawn shop. Shouldn't the
| previous owner be able to use the courts to demand the return
| of the item that was stolen from them?
|
| Or is this just something that hasn't been tested yet?
| bombcar wrote:
| The whole _point_ of an NFT is that the ownership is on the
| blockchain and guaranteed by said blockchain - if the courts
| can "force" return of the NFT than the NFT isn't actually
| synonymous with the ownership, and so then is kinda
| pointless.
| colinmhayes wrote:
| There are 2 different issues here. Do courts physically
| have the ability to change the blockchain so that an NFT
| goes to a different wallet? No. Do courts have the ability
| to arrest someone when they ignore a court order to
| transfer an NFT? Yes. I don't think the courts really care
| about some pure intentioned "code is law" argument, because
| they tend to think law is law.
| tablespoon wrote:
| > I don't think the courts really care about some pure
| intentioned "code is law" argument, because they tend to
| think law is law.
|
| "Code is law" is a mantra chanted by people in no
| position to make it so.
| criddell wrote:
| Kind of like sovereign citizens?
| oldgradstudent wrote:
| With the ledger being public, it could be very simple for
| courts and police to deal with it given the appropriate
| legislation.
|
| Mark the result of theft or other illegal transactions,
| and any subsequent transaction as dirty.
|
| Make any exchange, any vendor, any trader, and any user
| check with a government database before or immediately
| after receiving a payment, with penalties prescribed by
| law.
|
| You immediately limit stolen crypto to the black market.
| colinmhayes wrote:
| Except crypto is decentralized, and you can use mixers,
| which are not owned by anyone, to anonymously move coins
| from a blacklisted wallet. There is no mechanism in
| decentralized crypto to freeze an address, and I don't
| think the crypto community would adopt such a blockchain.
| pornel wrote:
| Blacklisting doesn't have to be a feature of a
| blockchain. It's enough if most countries decide to make
| it illegal for anyone to spend coins received from a
| blacklisted address. It's not easy to enforce of course,
| but people would be afraid they get in trouble if they're
| ever deanonimized, and businesses could be required to
| report their trades, just like taxes.
|
| This will force creation and use of wallet reputation
| checkers for most users of cryptocurrencies. Mixers will
| not want to be left holding all the blacklisted coins,
| since that causes them financial loss. Therefore mixers
| will launder coins at a very high premium (lemon market)
| and compete on developing their own systems for
| reputation checks and escrows to reduce their risk of
| being left with coins nobody wants.
| colinmhayes wrote:
| Everyone already knows mixers are holding illicit coins.
| It doesn't matter because mixers don't actually "want"
| anything. They're just code in the ether. You send your
| coins to an address along with a receiver address and the
| smart contract sends coins to the other address. How do
| courts stop that without shutting down exactly what makes
| blockchains valuable?
| blitzar wrote:
| Nothing in crypto belongs to _you_. It belongs to the
| private key or whomever holds that.
| tomhallett wrote:
| This is why I struggle understanding the mainstream
| usecases for crypto. Will it forever be bound to the "only
| put in what you can afford to lose?" mindset?
|
| Or are people banking on another layered solution which has
| arbitration, disputes, clawbacks, etc - all built _within_
| the blockchain. (I remember EOS discussing something like
| this)
|
| Note: I understand that risk is present in _any_ financial
| endeavor, but knowing that the courts _can_ help you does
| de-risk the amount people will feel comfortable investing.
| criddell wrote:
| Is there really any question about whether or not courts
| can force the transfer of an NFT or impose penalties?
|
| Say you hold most of your wealth in some cryptocurrency and
| are going to file for bankruptcy. Do you think the courts
| will tell your creditors that the Bitcoin is beyond reach?
| I suspect they wouldn't treat it differently from any other
| asset.
|
| That the blockchain is interpreted as a record of ownership
| is irrelevant. It merely records what has happened and says
| nothing about the nature of those transfers.
| albertgoeswoof wrote:
| But the NFT was actually stolen, she was phished for her
| seed phrase, and the criminal moved ownership of the nft to
| their wallet, and then sold that to the person who was
| interviewed on the podcast.
|
| It's no different to a thief stealing your bike then
| selling it to someone else on a street corner. Just because
| that person is the current owner and thinks they
| legitimately purchased it doesn't make it rightfully
| theirs. In fact it's even worse because it's trivial to
| identify who the rightful owner is in this case, and if you
| buy an NFT you can look back at exactly who has owned it
| previously.
|
| Now imagine if this was the deeds to your house on the
| blockchain.
| Dylan16807 wrote:
| An NFT exists purely in the realm of thought, and the
| owner is whoever knows the password.
|
| Therefore phishing the seed phrase is not "actually
| stealing" it within the rules of NFT.
|
| And outside the rules of NFT it's just a receipt; it's
| worthless. It's taking a picture of a picture of a bike,
| not stealing it.
| omarhaneef wrote:
| One of the points of digital assets is that the code is the
| contract, so whatever the code says is what was agreed to.
| There can be no cheating (in theory) hence no need to resort
| to courts etc.
| antifa wrote:
| And there is a chance that the courts will recognize law as
| law instead of code as law.
| uoaei wrote:
| And that will expose the fundamental contradictions and
| hypocrisy of the crypto community writ large, if they
| accept that help from the legal system.
| shkkmo wrote:
| Which is why the big players the smart contract that was
| exploited in this article just accepted the loss and moved
| on? Oh wait, the two largest losers here BOTH went to court
| independently.
|
| The cryotocurrency community supports the "code is law"
| talking point only until serious money is lost. Then they
| go the courts for redress under actual law, or they fork
| the blockchain.
| plandis wrote:
| When two or more parties sign a contract, it doesn't
| necessarily mean that all the terms in that contract are
| enforceable.
| uoaei wrote:
| That's true if you are litigating the enforcement of the
| contract through traditional legal systems. Crypto
| enthusiasts want to be completely divorced from those.
| SamBam wrote:
| The courts haven't even determined whether anyone even "owns"
| an NFT, so no.
|
| --
|
| For the downvotes, I'll add some further explanation: you
| have _access_ to the keys in order to perform a sale of
| "your" NFT, but no US court (I am unsure of other countries)
| has yet ruled in a case that clarifies whether a person
| actually _owns_ an NFT. For example, they have not ever ruled
| against someone who has "stolen" an NFT. Therefore, there is
| no case law that says whether a person legally "owns" an NFT.
|
| Don't just take my word for it:
|
| > Ultimately, an NFT owner has _access_ to the underlying
| asset, but they may lack exclusive access to or control of
| the asset, let alone ownership of the asset or any
| intellectual property (IP).
|
| https://www.lawyer-monthly.com/2021/05/nfts-and-ip-law-
| who-o...
| thawaya3113 wrote:
| Code is law.
| curiousgal wrote:
| A common misconception about law/contracts is that they are
| static. You can technically "not break" any laws and still be
| held accountable by a court of law.
| BitwiseFool wrote:
| >"Code is law."
|
| I agree, but with the caveat that code is _the letter of the
| law_ only. As it currently stands, there is no way to resolve a
| dispute, ambiguity, or unintended consequence with smart
| contracts in the same way that a court of law would handle such
| issues with a conventional contract. There is no room for
| interpretation and all smart contracts must be understood as
| such.
| SamBam wrote:
| > But in our email exchanges, he argued that he'd executed a
| perfectly legal series of trades.
|
| In real finance, there is an understanding that technical
| loopholes can exist, since not every outcome can be foreseen when
| writing laws, but the legal system can frequently prosecute
| against a series of actions which are, individually, legal, but
| which together are taken in order to achieve something illegal.
|
| That is, modern finance and the law also attempt to deal with
| intent.
|
| But in the Ethereum smart contracts world isn't the whole
| _premise_ that the code is the law? That we don 't need any of
| these pesky courts or banks or auditors or anything: the code is
| the law, and the decentralized blockchain will enforce it.
|
| With this worldview, if the attacker simply exploited poorly-
| written code to find a loophole, how do the owners of Index have
| a leg to stand on?
| roastedpeacock wrote:
| Am I missing something or did Medjedovic simply use unforeseen
| actions in the implementation of the contract as arbitrage and
| did not have an agreement to not attempt such actions?
|
| Do not see any 'unauthorised access' in that case i.e not the
| classic definition of 'computer hacking'. However if the case
| does end up progressing I do wonder what form a defense will
| take.
| silverlake wrote:
| Citibank mistakenly sent $900M to a bunch of hedge funds. Many
| refused to return it. Citi lost the court case.
|
| https://www.cnn.com/2021/02/16/business/citibank-revlon-laws...
| rat9988 wrote:
| They sent their lender the exact sum of the loan. It's kind
| of a different case.
| colinmhayes wrote:
| They accidentally repaid their loan early, which was
| explicitly allowed in the contract. The hedge funds were
| under no obligation to pay them back, since the money was now
| rightfully theirs.
| Dylan16807 wrote:
| They repaid _someone else 's_ loan early.
| sjtindell wrote:
| And everything done in this case was in a smart contract.
| That's the idea.
| colinmhayes wrote:
| I don't think the smart contract explicitly said "there's
| this arbitrage opportunity available", but it's
| definitely a fine line.
| Dylan16807 wrote:
| This kind of automated index fund seems pretty suggestive
| of arbitrage to me.
|
| And flash loan contracts are a bright neon sign saying
| "arbitrage opportunity!"
| not2b wrote:
| Yes, exactly. They sent the money to their creditors. Had
| they accidentally sent it to someone who they didn't owe
| money to, the courts would order the money to be returned.
| daniel-cussen wrote:
| Yeah like the other guy replied, they intended internally to
| send it to a wash fund but mistakenly (due to a UI glitch)
| paid the debt back to the lenders. Now that UI glitch was
| their fault too, so...the courts said, cry all you want.
|
| And they're a gigantic bank, it's the original digital
| business, every banker knows a single arithmetic error is
| dangerous.
|
| Just bankers being inept.
| miltondts wrote:
| > That is, modern finance and the law also attempt to deal with
| intent.
|
| It does? Maybe for the poor, but certainly not for the
| rich/corporations.[1]
|
| [1] -
| https://www.imf.org/external/pubs/ft/fandd/2019/09/tackling-...
| kmlx wrote:
| so called "tax havens" actually have a role to play in the
| world economy.
|
| but on your main point regarding "modern finance and law":
|
| 2021: https://member.fintech.global/2022/01/05/the-top-five-
| compli...
|
| https://www.kyckr.com/aml-fines-2021/
|
| tldr fines amount to billions in total and sometimes criminal
| proceedings are brought forward.
| throw_m239339 wrote:
| > so called "tax havens" actually have a role to play in
| the world economy.
|
| So does the mafia and the child slaves corporations like
| Nestle profit from, they all have "a role to play in the
| world economy". But it's about the morals and ethics and
| the hypocrisy of western institutions that allow these
| loopholes for the super rich in order for them to protect
| their wealth from taxation.
| mikkergp wrote:
| This is a twitter thread apparently from the lawyers hired by
| Indexed "I want to explain to you why what you did was illegal
| and wrong":
|
| https://twitter.com/ohaiom/status/1451142195369725957
| Spivak wrote:
| Until this pans out in an actual court this is basically a
| strongly worded vaguely threatening letter from a lawyer. If
| they actually had him dead to rights they wouldn't be posting
| their legal theory publicly and asking pretty please give it
| back or else _these other people we're not at all affiliated
| with and have no control over_ (but don't pay attention to
| that fact) might put you in jail.
| fnordpiglet wrote:
| The courts have found that a written description of the
| contract is legally binding even if the smart contract has a
| bug that allows things that were intended to be disallowed.
| Further the courts held the right to decide whether something
| was allowed or not allowed on their own judgement regardless of
| the smart contract, asserting the primacy of the law and
| jurisprudence over cryptonerd utopian fantasy.
| victor9000 wrote:
| Which cases and jurisdiction are you referring to?
| fnordpiglet wrote:
| I've long lost my references to the cases, I tried to
| Google around for a bit but didn't turn it up. However I
| did find this analysis from Harvard law that says more or
| less the same thing, start with the section:
|
| What is the "Final" Agreement Between the Parties?
|
| https://corpgov.law.harvard.edu/2018/05/26/an-
| introduction-t...
| SkyMarshal wrote:
| _> With this worldview, if the attacker simply exploited
| poorly-written code to find a loophole, how do the owners of
| Index have a leg to stand on?_
|
| They don't. They simply have to accept it as a bug bounty
| successfully collected and paid out, and treat it as a learning
| experience and evolutionary process. Do better next time, if
| there is a next time.
| toomuchtodo wrote:
| Good luck making that argument in court. Intent is key, and
| if this is not the intent of the "smart" (lol) contract,
| "finder's keeper's" is not a legal defense. The legal system
| doesn't care about your blockchain arguments.
| glerk wrote:
| A smart contract deployed on a public permissionless
| blockchain is not owned by anyone. Only the contract's
| logic determines how one can interact with it. This is a
| fact.
|
| It doesn't matter who can make the best argument in court.
| A good enough lawyer can convince a stupid enough jury of
| pretty much anything.
| er4hn wrote:
| Let's say that I place a vending machine in a public
| space, such as a street or a park. The public is able to
| interact with it by inserting FIAT coins to purchase
| DRNK. Someone clever figures out a way to interact with
| the vending machine to extract DRNK at less than it's
| intended FIAT price. Two questions at this point:
|
| (a) Is this a theft from the person who placed the
| vending machine? Why or why not?
|
| (b) How is this different from a smart contract on a
| blockchain?
| stickfigure wrote:
| I'll try to steelman the code-is-law argument (not really
| sure how I feel about it myself):
|
| In the case of the smart contract, you don't own the
| vending machine. It doesn't have an owner, it just "is".
| If it _did_ have an owner, that person is probably
| violating all sorts of securities laws in countless
| jurisdictions. That 's at least part of the point of all
| this smart contract stuff.
|
| To make the analogy a little more apt, let's say the
| smart autonomous vending machine 1) lets people buy DRNKs
| by inserting money, 2) incentivizes people to refill it
| with DRNK by spitting out money, 3) once a month spits
| out money to the amused landlord, and 4) was deposited by
| aliens who disappeared without trace.
|
| Presumably the smart vending machine would continue on
| its merry way like this until it either broke down or
| someone figured out a way to jimmy the lock. Looks like
| the later happened. Though everyone is upset, it's not
| clear who has the right to prosecute.
| glerk wrote:
| > If did have an owner, that person is probably violating
| all sorts of securities laws in countless jurisdictions.
|
| That's probably what upsets me most about this story.
| These developers want to have it both ways: it is
| decentralized finance and nobody owns the contract as
| long as we are making money, but we want all the laws and
| regulations of traditional finance to protect us if
| things don't go our way.
|
| I am saying this as someone who is pro-crypto. There are
| trade-offs to this technology. We need to pick a lane be
| prepared to deal with the consequences.
| nicoburns wrote:
| Frankly, I don't think it's up to you to pick a lane.
| It's the wild-west at the moment because the technology
| is new. But it won't be long before the law catches up
| and crypto will be subject to it the same as everything
| else.
| s1artibartfast wrote:
| Imagine in your example the vending machine has a
| variable pricing and lowers its price if nobody purchases
| soda. Is it theft to wait longer than the designers
| thought people would wait and purchase the DRNK at price
| lower than the machine owner thought they would.
|
| I think a better example is a claw gambling machine. You
| pay Fiat for a chance to grab fiat out of a pool.
|
| If you come up with a strategy whereby you can grab more
| or all of the Fiat in a way that the game/machine
| designer and other players did not anticipate, is that
| theft?
|
| Alternatively, people are playing a modified version of
| Poker with rules they don't understand, and someone
| understands the rules better and gets their money, is
| that a crime?
| jdmichal wrote:
| Broken slot machines do happen, and it's been made very
| clear that the player does not benefit.
|
| https://www.aol.com/2016-11-02-broken-slot-machine-dupes-
| wom...
|
| https://www.foxnews.com/us/not-a-winner-oregon-woman-
| denied-...
|
| However, this works both ways. If the mistake is in the
| favor of the player, they are obligated to pay out:
|
| https://www.msn.com/en-us/news/us/a-slot-machine-in-las-
| vega...
| s1artibartfast wrote:
| I would argue that the fund wasn't broken-it was working
| exactly as designed. It was just a bad design
| cogman10 wrote:
| That sort of depends on what the exploit is, right?
|
| For example, if DRNK costs $1 per unit, but I find out
| that by putting in $1.25 I get 2 units, have I actually
| exploited the machine? Is it not reasonable to assume
| that discount was intended?
|
| Now, of course, if I'm prying open the machine with a
| prybar then we could argue that's just theft. But,
| putting money in the machine and getting units out is the
| intended interaction.
|
| Similar to how if a gas station accidentally puts the
| price of gas at $0.20 per gallon, even though everyone
| knows that's probably a mistake, it isn't on them for
| taking advantage of the artificially low price.
|
| So, that's what I'd say the difference is. A smart
| contract defines all the interactions that are valid.
| Thus, it is impossible to interact with a smart contract
| in a way that is "invalid" or "stealing". That'd be
| different if the user could modify the contract (apply a
| prybar) however, that's sort of the point, that you can't
| modify the contract to fix it.
|
| If the contract said "all your deposited crypto goes to
| cogman10" would we call that a theft when someone put
| their crypto into that contract? Perhaps if I
| misrepresented the contract, but then the whole point of
| these contracts is they are visible to anyone that wants
| to read/use them.
| IanCal wrote:
| > For example, if DRNK costs $1 per unit, but I find out
| that by putting in $1.25 I get 2 units, have I actually
| exploited the machine? Is it not reasonable to assume
| that discount was intended?
|
| What if you remove the last part? What if you know,
| clearly, that your interaction what not what the designer
| wanted?
|
| > So, that's what I'd say the difference is. A smart
| contract defines all the interactions that are valid.
|
| Implementations are not specifications. What do you mean
| by "valid"?
| jdmichal wrote:
| And what if the vending machine measures coins by weight,
| and you so happen to have a "coin" that is just a
| properly-weighted blank. You're still interacting with
| the vending machine _as technically intended_. But by not
| inserting the correct amount of money, you are not
| interacting with it as intended by the creators.
|
| The smart contract implements a technical intent, just
| like the vending machine. But that technical intent will
| always have limitations. Some exploits are non-
| destructive, such as properly-weighted blanks. Some are
| destructive, such as crowbars. But let's not pretend that
| they aren't, in fact, exploits.
| bawolff wrote:
| I mean, all these smart contract people basically advertise
| this scenario as a feature not a bug.
|
| Ianal and don't know how a court would see it, but the way
| smart contracts are advertised would probably give you a
| fighting chance to make this argument where in normal
| finance you would have no chance.
| SkyMarshal wrote:
| Can they make a strong case about what their intent was? Do
| they have some legal agreement with the hacker that the
| judge can use to divine their intent and the hacker's
| violation of it beyond reasonable doubt?
|
| Or might the hacker and his clever lawyers have an equally
| strong case that whatever the code allowed was the "true"
| intent, that the code is the ultimate arbiter of intent,
| regardless what Index might have said otherwise?
|
| I kind of hope it does go to court, will be interesting to
| see what the opposing legal teams come up with.
| c3534l wrote:
| Yes, but the I believe similar cases have appeared where the
| courts have found against the objectivity of smart contracts. I
| think, ultimately, the point of regulating the financial
| markets is not to protect investors, but to protect the
| economy. And if a smart contract undermines the security of our
| financial system, then that smart contract may simply be
| illegal.
| twox2 wrote:
| "Code is law" is a dream that is not actualized. It's not
| actually law, it's just code. I'm pretty sure law enforcement
| will gladly prosecute for a lot of these "hacks".
| gizmo686 wrote:
| What specific law was broken? In the US, generic "hacks"
| generally fall under the computer fraud and abuse act, which
| is notoriously vague about what qualifues as "authorized".
| Perhaps some other lawvis applicable. But I cannot think of
| any that are obviously on point. Nor can I think of a clear
| precedent that clarifies the issue.
| buzzdenver wrote:
| > What specific law was broken?
|
| Market manipulation, fraud.
| Dylan16807 wrote:
| Market manipulation might work, but since it was all
| inside of a flash loan that's harder to argue.
|
| I'm skeptical that any fraud happened here.
| knorker wrote:
| Indeed it cannot be actualized, as it connects to the real
| world.
|
| This is why things like "land registry on the blockchain"
| will never happen. When a court decides that a sale of a
| house was unlawful, then the blockchain is wrong and
| irrelevant.
|
| Code isn't law. Law is system that ultimately sends people to
| your house and puts you in a locked house that you're not
| allowed to leave, and lets other people live in "your" house
| now.
|
| Math can't enforce who lives in your house.
| antisthenes wrote:
| Exactly.
|
| Law isn't law unless it's been enforced through courts,
| precedent and ultimately someone with authority to use
| force to force compliance.
| twox2 wrote:
| In other words, "code is law" only if it complies within
| the existing framework of our laws. IMO, this still
| leaves a lot of room for creative applications of smart
| contracts.
| knorker wrote:
| Could be. But then any smart contract system needs to
| acknowledge this overarching law, and give it "super user
| access", if you will.
|
| And these systems could exist. But they are not the
| systems that are being designed. They are in fact
| antithetical to the stated goals of all of these
| cryptocurrencies and smart contract systems.
| marcosdumay wrote:
| If you widely publicize that "code is law", and get customers
| due to that promise, things are not that black on white.
| godelski wrote:
| This is a thing that confused me about smart contracts. I don't
| see how they can exist without a judicial system. They do seem
| to have some uses under that framework. Like the system is
| auditable so you can prove if someone cheated and changed a
| contract out from under you (and you lost your copy), but
| that's only a minor improvement on the current system. The US
| has a lot of legal policy that is based on spirit of the law
| because it is well recognized that humans are imperfect and
| never will be. It then seems silly that people who are fully
| aware of failure analysis/engineering would design a system
| where the mode of failure is easily exploitable.
| dcolkitt wrote:
| > I don't see how they can exist without a judicial system.
|
| Smart contracts don't have to exist outside the judicial
| system. Smart contracts are simply a way to automate
| transactions in a way that's efficient, transparent, and
| credibly neutral. Yes, we may still have to invoke courts for
| the 0.01% of transactions that are clear exploits. But the
| other 99.99% of the time, it's a much more efficient system
| than using written contracts to handle normal, everyday
| outcomes.
|
| Even without blockchains or smart contracts, we already have
| automated systems that execute transactions based on
| algorithmic rules. If you blatantly exploit a vulnerability
| in those systems, then courts will generally punish you. That
| doesn't mean that automated systems are pointless, because
| 99.9% of the transactions aren't exploits. That's still a
| huge win, because it means we don't have to have our lawyers
| email redlines back and forth every time we want to trade an
| S&P index futures contract. (Near) fully automated
| transactions are 1) orders of magnitude more efficient, 2)
| expose general purpose composability where one automated
| system can be predictably inter-connected with another.
|
| When you put an automated transaction system on-chain, you
| drastically increase the advantages of both, because you're
| embedded in an open application network with credible
| neutrality. A smart contract exchange like Uniswap can
| process about the same amount of volume as a centralized
| exchange like Coinbase, but the difference is that Uniswap
| only needs about 50 employees, whereas Coinbase needs 5000.
| That's primarily because Coinbase runs inside a silo'd
| network. That entails replicating many functions like user
| account management, that aren't necessary for an application
| like Uniswap that piggybacks off the credible neutrality of a
| decentralized consensus layer like Ethereum.
| young_unixer wrote:
| > The US has a lot of legal policy that is based on spirit of
| the law
|
| Yes, but that's a wrong and unfair way to define and apply
| laws.
|
| > humans are imperfect
|
| Smart contracts and "code is the law" mantra don't contradict
| this. You're imperfect and you commit a mistake, you lose.
| You find a mistake in someone else's code, you win.
|
| This is much better than the current legal system where we
| are all collectively forced to adapt to, or even pay for,
| someone else's mistakes.
| lostcolony wrote:
| >> The US has a lot of legal policy that is based on spirit
| of the law
|
| >Yes, but that's a wrong and unfair way to define and apply
| laws.
|
| Sounds like you're interpreting how to define and apply the
| law there based on what you feel is the right and fair way
| to do so. Seems a bit paradoxical.
| webmaven wrote:
| The legal system has failure modes that are just as easily
| exploitable, but humans can intervene and reverse the
| failure, make people whole, etc.
|
| The problem with smart contracts isn't that there are bugs,
| but that buggy results are final with little to no recourse,
| by design, unless you get everyone to agree to hard fork the
| chain (rolling the "bad" transactions back and eplacing the
| buggy contract) and/or the implementation (if the bug was in
| the platform rather than the contract).
|
| The legal system has a similar principle of not being liable
| for conduct that predates a ruling or law that forbids it,
| but it also has the principle of agreements being interpreted
| according to common sense understanding by a person with
| ordinary skill, and where skill differences exist between
| them the non-expert's interpretation is the one given
| precedence.
|
| These meta rules don't have equivalents in smart contract
| systems, which makes them brittle. The only way smart
| contracts end up being used for non-trivial purposes is if
| they are made explicitly subordinate to the existing legal
| infrastructure in ways that will gum up the works, or if
| smart contracts are subject to mandatory formal verification
| possibly including game theoretic 2nd order effects.
| LeifCarrotson wrote:
| I think a lot of the appeal of crypto/smart contracts is
| that they are final with little to no recourse, humans
| can't intervene and exploit failure modes which individuals
| using the so-called contracts can't defend against.
|
| Corporations and wealthy individuals with influence in the
| writing of this legal system, with massive amounts of
| financial resources, with negligible moral agency, and with
| limited criminal liability find very different utility in
| the ability to use the legal system to roll back contracts,
| to enforce them, or to ignore them.
|
| Those who find themselves on the other side of this power
| disparity would often prefer to risk a potentially buggy
| but inviolate contract than one which they expect to be
| abused against them.
| mbreese wrote:
| I want to know what kind of contracts people entered into
| before this where they thought they were being abused by
| a big corporation?
|
| This seems like a noble endeavor, but not an entirely
| practical one. Both sides of a transaction have to agree
| to these smart contracts, so where is this an advantage
| (outside of internal crypto trading)?
| majormajor wrote:
| A bunch of those many-to-one individual:corporation
| contracts (like phone service) are in such imbalanced
| markets that you'd have to overcome the power balance
| problem in order to get the other party to adopt the
| "smart" contract.
|
| But if you can overcome the power balance problem, you
| can just fix the contracts directly anyway without them
| being smart?
| jeffbee wrote:
| I don't know what jurisprudence you live under, but under
| English common law (also America, Canada, etc) - which, I
| must say, I also always denounce and rarely defend -
| inequitable negotiating power between parties to a
| contract is considered by courts when adjudicating
| whether parties have broken it or can be awarded damages.
| We _don 't_ have a system where big powerful
| organizations can just dictate contracts to powerless
| individuals and then later enforce them.
| chx wrote:
| There was a wonderful summary of what smart contracts are.
|
| https://twitter.com/qrs/status/1395784294451265536
|
| > Smart contracts should be considered self-funded bug-
| bounty platforms.
| cinntaile wrote:
| Mark the "should". It's just an opinion, not a fact.
| arcticbull wrote:
| More like a pinata full of money sitting next to a whole
| pile of sticks.
| lostcolony wrote:
| "Should" is modifying "consider". Considering something
| is obviously subjective and not fact.
| fvdessen wrote:
| AFAIK the legal system still applies to crypto; the
| recourse when somebody hacks your smart contract is the
| same as when somebody defrauds you; you sue. Except with
| smart contracts you have more traceability as to what
| happened.
|
| And you don't need to make the smart contract explicitly
| subordinate to the law, they are as a matter of fact,
| because everything de facto is. This idea that code is law
| and crypto exists in a vacuum is complete delirium
| (although a popular one and sign that the scene has a lot
| of room to mature)
| bolasanibk wrote:
| The Worlds littlest skyscraper
| https://en.wikipedia.org/wiki/World%27s_littlest_skyscraper
| sushid wrote:
| I never hear "code is law" from defi protocols, their ToS, or
| really from anyone. It's only the detractors of Web3 who tout
| this false logic of "code is law" so I guess you're screwed.
|
| Examples of code NOT being the law: Some defi protocols have
| made those affected by a hack/loophole whole again with their
| own funds. Some defi protocols explicitly exclude certain
| jurisdictions like the US from accessing their protocol. Surely
| if they all belived "code is law" they wouldn't give a fuck,
| right?
| glerk wrote:
| They really don't have any leg to stand on.
|
| A smart contract is a piece of code running on a public
| permissionless blockchain. The developers who deployed that
| code do not _own_ it. Medjedovic had as much the right to take
| money out of the smart contract using the contract 's logic as
| Kellar and Day.
|
| Being blockchain developers, Kellar and Day know these facts
| very well, but they persist in their hypocrisy because it is in
| their financial interest to do so. They are betting on a non-
| technical jury being convinced by a good lawyer that Medjedovic
| "hacked them" or "stole their funds" (which is not at all what
| happened here).
| woojoo666 wrote:
| By that token, wouldn't rugpulls be legal too?
| glerk wrote:
| Probably? A priori there is nothing wrong with someone who
| owns a large amount of a certain asset transferring it into
| a liquidity pool in exchange for a different asset.
|
| It gets more murky if a founder explicitly lies to
| investors in order to get them to buy their token.
| Fraudulent misrepresentation is problematic in most
| jurisdictions, but this has nothing to do with the
| mechanics of the "rugpull" itself.
| s1artibartfast wrote:
| rugpulls are different because crypto developers lie and
| deceive investors in their disclosure.
|
| A better example would be 3rd parties pumping and dumping
| a crypto asset. Should this be illegal?
| ac29 wrote:
| Here's a recent case where the SEC litigated
| misappropriation of funds among other things:
|
| "According to the SEC's complaint, the defendants
| misappropriated nearly $4 million of investor funds. The
| SEC also alleges that Chiang and Tippetts misused
| additional Sharenode investor funds by spending at least
| 133 bitcoin to list NSG tokens on an unregistered trading
| platform and to fund a team of captive traders to trade
| NSG tokens amongst themselves to create the false
| appearance of a robust market with increasing prices.
| These traders allegedly created the false impression that
| more than $2.5 million worth of NSGs were traded daily on
| BitForex during the first 60 days and that the price of
| NSGs was steadily increasing due to investor demand.
| According to the complaint, however, the manipulation
| scheme collapsed when investors tried to sell their NSG
| tokens, because there were no actual buyers, causing the
| token's trading price and volume to fall precipitously."
|
| This isnt exactly a classic "rugpull", but it does make
| it fairly clear that you cant just take customer funds
| and use them however you'd like just because its a
| cryptotoken and you have access to the smart contracts
| controlling it. You _really_ shouldnt use customer funds
| in furtherance of additional frauds, like these people
| did here.
|
| https://www.sec.gov/litigation/litreleases/2022/lr25377.h
| tm
| paulmd wrote:
| That doesn't really turn on any crypto-related concepts
| at all, but rather false/deceptive disclosures about the
| security itself. That actually would be equally illegal
| to do with regular securities too - you _don 't_ fuck
| around with disclosure documents, that's an absurdly easy
| way to go straight to jail.
|
| > These traders allegedly created the false impression
| that more than $2.5 million worth of NSGs were traded
| daily on BitForex during the first 60 days and that the
| price of NSGs was steadily increasing due to investor
| demand. According to the complaint, however, the
| manipulation scheme collapsed when investors tried to
| sell their NSG tokens, because there were no actual
| buyers, causing the token's trading price and volume to
| fall precipitously."
|
| This is also _the fund owners_ doing something nefarious
| - that doesn 't mean that somebody else executing a
| transaction according to the contract and the market
| could be held accountable because the fund's customers
| lost money. Someone has to be on the other end of every
| transaction, that is how a market works.
| t_mann wrote:
| Rugpulls, as in projects attracting funds and then
| absconding with them, are different from exploits in that
| they involve outright lies / deception. There's a (moral,
| at least) difference between bad intent and honest
| incompetence. The attacker didn't ask anyone to contribute
| the funds that he appropriated.
| Ajedi32 wrote:
| I've seen this argument regarding smart contracts several times
| now, and I don't think it makes any sense. It's like robbing
| someone in real life, then claiming you did nothing wrong
| because you didn't violate the "laws" of physics. Those are two
| entirely separate things.
|
| In the world of smart contracts code is indeed law, but that
| doesn't change the fact that in the real world law is law, and
| the fact that you used a smart contract to commit a crime
| doesn't make it any less a crime.
| meowface wrote:
| In the real world law is law, but I think it's still not
| entirely clear whether smart contracts can be considered
| legal contracts and how to judge if any particular smart
| contract is one.
|
| If this smart contract is considered a legally binding
| contract, then, yes, this would likely be illegal despite the
| proverbial "letter" of the smart contract not being broken.
| If it isn't, then it may not necessarily be illegal (but
| possibly still could be).
| thrwy_918 wrote:
| >In the world of smart contracts code is indeed law, but that
| doesn't change the fact that in the real world law is law
|
| I think some confusion arises because that "smart contracts"
| only make sense if code really is law, in the sense that any
| transaction executed by the contract -- even unexpected,
| surprising transactions -- is considered to be fully
| consented to by all parties interacting with the contract.
|
| I agree that that's a terrible idea - bugs can always exist,
| and having no recourse when millions of dollars are lost due
| to a coding error is a huge and unreasonable risk.
|
| But otherwise -- if, ultimately, courts can force "smart
| contract" transactions to be unwound if they are found to be
| exploitative, unintended or otherwise invalid -- then what's
| the point of having smart contracts in the first place?
| What's the value proposition? Why not just use regular
| contracts?
| IanCal wrote:
| > Why not just use regular contracts?
|
| It's just code, so the same reason we use APIs rather than
| doing everything by lawyers.
| verdverm wrote:
| Most people will be coerced into returning funds if the
| alternative is hard jail time
|
| Smart contract is really the misnomer. In reality, they are
| automations of contractual obligations and cannot automate
| complete contract clauses.
| daveed wrote:
| Respectfully disagree. I think I've seen several times the
| belief(from crypto supporters) that the code is the code is
| the code, and these are the rules that we play with.
|
| The "laws of physics" analogy doesn't match up. I feel like
| it would be more appropriate in an anarchist society (physics
| are the only laws, thus everything that obeys physics is
| game).
|
| This feels more like discovering an exploit in a video game.
| It's up to the devs to patch it, or tournaments to outlaw,
| but if you find something out, you can use it. We agree to
| play by the rules, but if someone comes up with something
| last minute, they can win.
| Ajedi32 wrote:
| That's not how the law works though, at least not in any
| country I know of. If you exploit flaws in computer code to
| steal something of real-world value, that's a crime.
|
| We're all bound to the laws of physics, just as in the
| world of smart contracts all are bound to the laws of code.
| But none of that changes the existence of the laws of men.
| ddingus wrote:
| Actually, we are only bound to the laws of physics within
| the limits of our understanding. As our understanding
| grows, those laws become less and less restrictive. I
| think it's an interesting analogy or parallel for the
| case we are discussing.
| Dylan16807 wrote:
| I would argue that this wasn't really a code flaw. They
| made a synthetic asset that calculated its price in a
| dumb way. That happens plenty often without code, and
| gets exploited by savvy buyers without code.
| daveed wrote:
| (Replying to this one, but the sibling comment feels
| similar in vein).
|
| - I'm not really saying the crypto-side argument is
| right, really just trying to clarify my perception of
| what they're saying re: the comment above me.
|
| - The physics thing is really just a comment re: when
| it's hypocrisy and when it's not.
|
| - FWIW, theft in crypto isn't super well-defined to me
| re: the laws of men either. Maybe someone who knows
| current law better than me can explain, but calling a
| function in a contract that sends updates from one
| pseudonymous address to another... I don't actually know
| if current written definitions of theft covers that, or
| needs some court to interpret it as theft. We kind of
| understand it as people, but I honestly don't know if
| "laws of men" as written, do.
| majormajor wrote:
| If you do a promotion for giving away free food, and your
| smart contract accidentally allows someone to get a free
| sandwich every minute instead of once a day, is it so
| obvious that someone using your promotion more than once
| a day is "stealing"?
|
| Ever use a different email address to sign up for a
| different free trial, say? Let alone people sharing
| Netflix accounts... where do you draw the line around
| "stealing" here?
| mikkergp wrote:
| > is it so obvious that someone using your promotion more
| than once a day is "stealing"?
|
| Yes. This is very obviously stealing, particularly if the
| promotion said it was for use once a day.
|
| Edit: Also, sharing your netflix password may also very
| well be illegal: https://www.lawjournalnewsletters.com/si
| tes/lawjournalnewsle...
| bombcar wrote:
| Many people in crypto want to not have to comply with "real
| world" laws right up until the point where it would be to
| their benefit to do so.
|
| And if "smart contracts" depend on real law, then they're
| not really needed in many of the supposed use cases.
| sushid wrote:
| Just because there are crypto anarchists doesn't mean
| that all crypto proponents are anarchists. And smart
| contracts (not sure why they're in quotes in your
| comment) can depend on real law and still operate fine
| (e.g. I'm sure NBA Topshot would file a legal case again
| Dapper Labs if they did something significantly damaging
| to their brand/NFTs, etc.).
| DannyBee wrote:
| This claim makes no sense. In the real world, crimes have
| very specific definitions. Most are physical, in fact.
|
| For example, robbery is when, with intent to commit theft,
| you take property by force.
|
| Anything else is not robbery.
|
| Theft by taking is: when a person unlawfully takes or, being
| in lawful possession thereof, unlawfully appropriates any
| property of another with the intention of depriving him of
| the property, regardless of the manner in which property is
| taken or appropriated.
|
| (The above is georgia, robbery/theft/etc are state crimes so
| defintions vary a bit)
|
| Again, it requires doing so unlawfully (or converting
| unlawfully).
|
| If doing what this person did isn't unlawful _in the real
| world_ , it's not theft, it's not robbery, it's not
| _anything_.
|
| So you have to find a crime that actually matches what
| happened.
|
| It's not wire fraud - that would require " false statement,
| promise, or misrepresentation in order obtain money or
| something of value from someone else."
|
| etc
|
| So what crime do you believe this actually is?
|
| (So far i've only seen a civil lawsuit, and while there is a
| warrant for his arrest, that's for refusing to move the
| tokens to a neutral third party, or show up to court :P )
| notahacker wrote:
| In addition to sounding like textbook _embezzlement_ , I
| don't think there's any reason to believe that "theft" as
| define by that very broad Georgia definition couldn't apply
| here (the "unlawfully" is to exclude certain property
| appropriations explicitly permitted by law like bailiff
| seizures or deposit retentions from the definition, not to
| mean it's not theft if you keep someone's property against
| their will without breaking any other laws. I don't think
| it ceases to be "appropriation" of funds simply because you
| provide something worthless as an exchange either,
| particularly not with that last clause)
| yongjik wrote:
| I think the problem is, if you put a sign saying "Feel free
| to break in, I dare you, if you manage to get in the house
| then you're free to take anything you want!" then you can't
| later complain when someone does exactly that.
|
| (Well, maybe you can still complain, IANAL, but it gets a lot
| murkier.)
| rootusrootus wrote:
| That might be useful in a civil case, but I don't see how
| it would apply to a criminal case. "If you do X, it is not
| considered fraud" isn't going to legally bind the criminal
| justice system in any way.
| IanCal wrote:
| This comes down to the intent, doesn't it? It would be
| different if you had no sign but on the door that opened if
| someone pushed it because it was _badly designed_.
|
| People on HN argue this with openly accessible APIs fairly
| regularly "ah but the machine let me do it, they must be OK
| with it" and I think that goes down badly in court.
| SamBam wrote:
| But that _is_ the premise of smart contracts. Sure, it doesn
| 't excuse you from the law if your contract is to pay someone
| to shoot someone, but it's supposed to be the final word on
| the actual financial transactions that happen _within_ the
| contract.
|
| Plenty of crypto hypers say the same. E.g. from a quick
| search of "Smart Contract advantages," the very first
| article, by a law firm:
|
| > Guaranteed Outcomes: Potentially the most attractive
| feature, smart contracts could offer a way to substantially
| reduce or completely eliminate the need for litigation and
| courts. This is because when parties commit to using self-
| executing contracts, they bind themselves to the rules and
| determinations of the underlying code, rather than exposing
| themselves to interpretations med by parties outside of the
| contractual relationship.
|
| https://www.newburnlaw.com/benefits-of-smart-contracts
| sushid wrote:
| Smart contracts allow for guaranteed outcomes. Some
| commentary added by a random law firm does not mean that
| guaranteed outcomes == no need for litigation and courts.
|
| Just think of non-smart contract parallels. If a bank had
| an ATM, the premise is that this ATM will execute a series
| of commands and allow you to withdraw/deposit/transfer
| funds. If a nefarious back actor found a series of user
| input that allowed them to withdraw millions of extra
| dollars, do you believe that the ATM provider will have no
| legal recourse? What about electronic slot machines?
| cellis wrote:
| A true non-smart parallel is this. You and I agree on a
| sporting event between humans. Because I want to
| construct a fantasy, let's just say it's a three-point
| basketball contest between adolescents (under 13).
|
| The observer will pay $100 dollars per blocked shot, and
| earn $1 per 3 point play made. All the games are played
| 1v1. To the untrained basketball player participants,
| this may seem to be a fair game. After all, it's quite
| rare in a real basketball game to see a 3 point shot
| blocked. So they sign the contract, fully agreeing to pay
| $100 per blocked shot and earn $1 per made 3 pointer.
|
| To game this as a participant, I go to the ends of the
| earth ( I hear Sudan and the Netherlands are both nice
| this time of year ), and find a 6'8 ,215 lb boy and
| recruit him to play for me. He proceeds to block every
| single shot in every contest, winning hundreds of
| thousands of dollars and bankrupting the organizers. Just
| to further weight this, I also hire an opposing player
| who is only 4'3 to shoot as many 3 points as possible as
| quickly as possible.
|
| Now, they signed the contract and agreed to it. They
| didn't have a clause for height, or any sort of caps, and
| now they have unlimited downside. How would the legal
| system handle this? Do you think they would release the
| participants liability? Perhaps, but not likely if they
| didn't sign the contract under duress. They fully agreed
| and had consideration ( the $1 per 3 point made ).
|
| It's a contrived example, but it's useful to show that
| technicalities can be exploited in real world contracts
| just the same as smart contracts.
| majormajor wrote:
| In a world where you're falling back to the legal system,
| why do I care if your buggy ATM is powered by a "smart
| contract" or by "regular" code? Why even do _you_ care?
|
| (There _have_ been exploits in both ATMs and smart
| contracts, after all.)
| fao_ wrote:
| > Some commentary added by a random law firm does not
| mean that guaranteed outcomes == no need for litigation
| and courts.
|
| But it would appear that you expect us to believe that
| some commentary added by a random _hacker news poster_
| means the opposite?
| sushid wrote:
| I'm not extrapolating on the premise adding my own
| commentary. The parent commenter asserts an axiom (that
| we all purported agree with) and then links an
| observation to said axiom. I'm merely stating that the
| observation is not part of said axiom.
| Veserv wrote:
| The difference is that the ATM provider did not
| explicitly promise that the "code is law" which directly
| implies that they want to and aggressively argue that
| they are waiving their legal recourse as long as they
| were valid user inputs.
|
| In contrast, basically nobody outside of the blockchain
| space would waive their legal recourse in such a manner
| and thus would have legal recourse if the intent of their
| system was bypassed.
|
| To go on to then argue that a legal system should not
| allow one to waive those rights as it would be idiotic to
| do so is a perfectly valid legal/moral/justice position,
| but also directly contradicts basically the entire
| purported value proposition of everything in the
| blockchain space whose primary "positive" differentiating
| factor is that "code is law" and they have waived those
| rights. To not allow them to do so basically invalidates
| their entire purpose.
|
| Essentially, either let people bind themselves to "code
| is law" and suffer the consequence of their choice, or
| ban it at which point you lose decentralized trust and
| censorship-resistance making them no different than
| traditional implementations except that they are slower
| with higher operational costs.
| jallen_dot_dev wrote:
| > it's supposed to be the final word on the actual
| financial transactions that happen within the contract.
|
| The court doesn't care how crypto idealists think the world
| should work.
| Ataraxic wrote:
| That may be the premise, but has that actually be held up
| and recognized as such in courts in major countries? Like
| are there precedents regarding this?
|
| At that point it's no longer a premise (for those
| particular countries), but until then it's just a
| supposition.
|
| I think courts are wary to wade deeply into a new financial
| system like this but at the same time I find it hard to
| believe that the judiciary and the legislature would rule
| (in the long run) that they have no ability to "make things
| right".
|
| If crypto grows as as many people suggest and you have some
| significant percentage of the country that has savings or
| investments tied to these smart contracts, if there is a
| loophole like in this case, you'd have lots of people
| writing their local or national representative about this.
| I find it hard to believe that politicians would tell the
| people they represent "tough luck code is law".
| nomel wrote:
| > be held up and recognized as such in courts in major
| countries?
|
| Only having a slight understanding of crypto, if local
| courts are required, what's the point of crypto? Why not
| use the existing financial systems, where all of this is
| built in?
| knorker wrote:
| The article even hints at this:
|
| > [a crypto bro] criticized the team for turning to a
| centralized institution like the courts for help
|
| But that's exactly the flaw of smart contracts, and why
| its promises will never work.
|
| The hard part of contracts was never execution. The hard
| part was always conflict resolution and abidance by fair
| rules (i.e. "laws"). The hard part is what creates the
| overhead.
|
| Smart contracts never solved the hard part. They remove
| the solution to the hard part, claiming the hard part is
| not needed at all. But the problems these solutions solve
| are the hard part. Pretending they don't exist is not
| "solving" anything.
|
| There are so many examples of this. A minor can't enter
| into a contract. Severely mentally disabled can't either.
| Someone with a gun to their head can't either. It doesn't
| matter if they enter into a million dollar contract. That
| contract is invalid.
|
| This is not "waste". This is the hard parts.
| sushid wrote:
| Crytocurrencies != smart contracts. The original premise
| of bitcoin was essentially to create a decentralized fiat
| currency. As its value grew the thesis then changed to
| equate more of a decentralized digital gold/inflation
| hedge that's easier to store and authenticate than actual
| gold.
|
| So that's one use of crypto.
|
| In the non Web3 world, we typically have to rely solely
| on the financial institution providing the service to
| make transactions. That is, we have to have a Paypal
| account to withdraw from Paypal. We can only buy/sell
| Robux on Roblox, etc. Smart contracts allow us to
| essentially utilize any provider we want without the
| provider having custody of the funds at any given time.
|
| I can go to any dex I want and transact without
| depositing funds. The dex also cannot agree to perform a
| transaction and hold my funds hostage, like how Paypal
| screws over some of their merchants with their "internal
| investigations." I can also buy/sell coins that the dex
| mints (e.g. ORCA coin) anywhere I want. It's not tied to
| a single account nor is it tied to single exchange.
|
| And that's without getting into NFTs, flash loans, LPs,
| and other features of Web3.
| renewiltord wrote:
| Contracts are contracts and law is law. Law can overrule
| contracts. Smart contracts just let you have executable terms
| which allows greater composition and commoditization.
| motohagiography wrote:
| This isn't a hack, it was straight arbitrage. I distinguish them
| because there was at no time a transfer of administrative power
| or control over the contract or targets infrastructure to
| Medjedovic.
|
| In a smart contract, I'd make a legal distinction between
| syntactic parsing and calculation, which has to do with the
| purity of functions and data. An arbitrage would be fair game if
| it levered an unanticipated calculation, whereas a recent example
| where the contract was only checking the last several bytes of a
| destination address key would be a parsing exploit. Medjedovic's
| arbitrage as described appears to be a pure calculation
| advantage, and not exploiting a parsing error, and so this is
| very reasonably fair game.
|
| He used logic endogenous to the contracts, with no exogenous
| control of the systems running the contracts. When you exploit a
| buffer overflow, you are breaking through (sabotaging) a parser
| as a means to manipulate the raw memory and machine - whereas
| this arbitrage is closer to something that lies somewhere between
| clicking on a link someone provided but had some unspoken
| intention about you not using it, and a SQL injection or other
| evaluation error that yields an index. (edit: Actually, it's more
| like saying something really funny and unexpected on a platform
| that hasn't banned that kind of humor yet, and they're just mad
| about the consequences. we could even see a future where the
| distinction between a hack and arbitrage will be the complexity
| class of the algorithm and whether it represented a scheme that
| was Turing complete)
|
| Unfortunately, in Canada they'll go after him just as a fugitive
| now, and there is no shortage of political actors who will want
| to make him the perfect example villain for their hysterical
| policy objectives. This is one of those increasingly classic
| situations where a really smart kid gets system-involved and
| can't comprehend how insane it is because the legal system and
| politics are not subject to mere reason. If he has the money,
| fleeing before charges were laid was probably even rational, as
| there is no reason to expect the legal system is equipped to
| deliver justice in something so new.
| mathgenius wrote:
| > This isn't a hack, it was straight arbitrage.
|
| Yeah, but tradfi has this problem too: sometimes it's hard to
| tell the difference between straight up trading, and
| spoofing/otherwise manipulating the market. Maybe the moral of
| the story is this, that free markets are a myth, and crypto is
| just making this even more clear.
| motohagiography wrote:
| Arguably, the myth is that markets are efficient. That is to
| say that the clearing price is the expression of all the
| information available to participants is a fiction.
|
| This idea of the Turing completeness, or maybe complexity
| class of your transaction logic determining whether it is an
| endogenous logical arbitrage trade, or an exogenous
| manipulation scheme may have some really appealing features.
|
| Hypothetically, if the steps of your transaction logic
| operate on or recurse over feedback into and from the market,
| you are in fact, "manipulating," it. I'd wonder how
| describing manipulation in terms of recursion limits and
| feedback would impact the definiton. Whereas, if you are
| precalculating or front running some periodic market
| function, you are arbitraging it with endogenous market
| information and that makes it "legit."
|
| Where this guy might be vulnerable in that model is the
| question of how far upstream of his actual transaction did he
| get before the feedback loop he was operating over is not
| considered a part of that market - and whether his arbitrage
| was legit because it was _between_ markets.
| meetups323 wrote:
| > If he has the money, fleeing before charges were laid was
| probably even rational, as there is no reason to expect the
| legal system is equipped to deliver justice in something so
| new.
|
| Except what's next? Live in hiding in a foreign country? Craft
| a new identity and find new chains to exploit? I suppose 18
| years old is a good time to learn that you can have all the
| money in the world, but it won't do shit for you if you can't
| spend time with the people you want to.
|
| I'd wager this individual could get much more satisfaction out
| of developing novel, interesting mathematics that do actual
| good for humanity, surrounded by a group of like minded high
| performing individuals. But he seems to have thrown hopes of
| that out the window. It's sad, really.
|
| But I'm perhaps projecting.
| motohagiography wrote:
| Regarding these like minded high performing individuals
| surviving in institutions - after a couple of sigmas and
| making some money, it can become difficult to value their
| esteem. Canada is full of people who have fled their home
| countries with their money, foreign capital flight drives our
| entire real estate and supercar markets, wealthy fugitives as
| a lifestyle choice are probably more common than we expect.
| charcircuit wrote:
| >He used logic endogenous to the contracts, with no exogenous
| control of the systems running the contracts
|
| The same description can be said for using XSS to steal
| someone's cookies. XSS doesn't escape the JavaScript virtual
| machine similar to how you aren't escaping Ethereum's virtual
| machine. Technically the code allows you to inject arbitrary
| JavaScript, but that behaviour wasn't intend to be possible by
| the designers of the site.
| aidenn0 wrote:
| > If he has the money, fleeing before charges were laid was
| probably even rational, as there is no reason to expect the
| legal system is equipped to deliver justice in something so
| new.
|
| TFA claims he was originally offered to keep 10% (over a
| million dollars) from this hack, free and clear. Not agreeing
| to that deal meant willingly putting himself at the mercy of
| said legal system. Talking about a single decision as rational
| in isolation is disingenuous.
| RcouF1uZ4gsC wrote:
| I have a compromise. Allow hacks of cryptocurrency to be
| prosecuted, but when they are, the also prosecute the creators of
| the cryptocurrency for making unregistered securities and for any
| fraudulent marketing of the cryptocurrency, or any failure to
| disclose risks, or for not following financial regulations.
|
| This is another example of make risks public and reward private.
| They are arbitraging the financial system and trying to have the
| freedom of cryptocurrency, but when things go bad, want law
| enforcement to come fix it.
| viksit wrote:
| Smart contracts are badly named lambda functions. They need the
| same regulation as any other code, the difference being, the
| regulation can come in the form of more lambda functions.
|
| The judiciary could write the latter any time they got the right
| technical input. The question really is - what's worth putting in
| the effort right now?
|
| And those answers are coming soon.
|
| But we shouldn't conflate smart contracts with legal contracts in
| discussions.
| paulpauper wrote:
| Yeah, the attacker resides in Canada, so even if found guilty
| he's looking at easy jail time at the worst. All he has to do is
| wait a few years and the $ is his. not like in the US in which
| feds hand out decade+ sentences like candy on Halloween.
| moneywoes wrote:
| Can't he be extradited
| retrac wrote:
| Maybe. That actually raises some interesting questions, come
| to think.
|
| A key factor in an offence is the location of the offence,
| which usually determines jurisdiction and the relevant laws.
|
| In the classic example of hacking an American bank from
| Canada, the offence occurs on the American bank's servers in
| the United States. That's relatively clean and simple,
| legally.
|
| With an Ethereum smart contract ... I'm not even sure where
| to begin. Where does the offence even occur, legally
| speaking? What aspect of fraud by a non-American, against an
| American resident by executing an adverse smart contract,
| occurs under the jurisdiction of the United States, if any?
| anonu wrote:
| Are there any good resources someone can point to on getting into
| the code and mechanics of this? The article was a nice read, but
| probably distills the real stuff behind some journalistic
| simplification.
| Graziano_M wrote:
| ethernauts is particularly good intro that has you work through
| a lot of the common security issues.
| giantg2 wrote:
| "In their complaint, lawyers for Kellar and Day argued that two
| particular steps of the attack violated statutes against market
| manipulation and computer hacking."
|
| So now they want crypto to be treated as regulated securities,
| but let me guess, only when it benefits them...
| turtledove wrote:
| The people who genuinely believe "code is law" are stunned to
| learn that: a) humans won't act "rationally", b) regulations
| exist for a reason, and c) no, the law is law, code is brittle.
| [deleted]
| vmception wrote:
| d) I genuinely believe that Medjedovic should show up in court
| to test that theory.
|
| The only thing interesting about this case is how incompetent
| he was, while having his entire brand and identity be based on
| intellectual superiority. He should have used a virgin address
| and Tornado cash. He should have not needed to risk any funds
| for failure, as he should have tested the transaction in a
| localhost staging environment for free. Him getting doxxed is
| the only thing that allows this theory to be tested, whether
| he, or we, believe it was legal, it is now unnecessary
| liability. Instead, everyone knows who he is, that he's
| spiraling mentally, a judge in his hometown jurisdiction froze
| his addresses and the funds within it (which is a legal
| abstraction that does not freeze the funds but makes it illegal
| to move them until the order is lifted, in his favor or not).
| Just piling on the liability.
|
| I think "code is law" is a decent crux of a more fleshed out
| defense, I think the Canadian attorney for the project founders
| is grasping but I'm not as familiar with the direction courts
| go there, I would prefer to see something similar play out in
| US federal appeals court (which is sadly _after_ the drama of
| trials court and how opinions calcify throughout). It would be
| great and beneficial to see a transcript of how the "Sushi
| flooding" is argued the context of a broad computer access
| abuse law.
| richbell wrote:
| > The only thing interesting about this case is how
| incompetent he was
|
| I'm astonished at how poor his OPSEC was. He could have taken
| any number of precautions to shield his identity -- did he
| really think that deleting the messages on Discord would be
| sufficient?
| vmception wrote:
| yeah its strange. one of his addresses was funded
| previously by a Tornado Cash balance as well
|
| oh well, he slipped up and is now probably a fugitive since
| he keeps using his court "frozen" funds.
| shadowgovt wrote:
| "Code is law" really seems to me to be a philosophical position
| that can only be held by people who haven't fully internalized
| Godel's incompleteness theorems.
| trasz wrote:
| I find it disturbing that Medjedovic was prosecuted in the first
| place. If anyone is guilty of this situation, it's Kellar and
| Day.
| glerk wrote:
| Absolutely, they are guilty, but they won't take any
| responsibility.
|
| When you deploy a smart contract on a permissionless
| blockchain, you don't _own_ the smart contract or the funds
| that it controls.
|
| These developers are hypocrites who don't believe in the basic
| premises of this technology. It is easy to preach the virtues
| of decentralization when it makes you money and run back in the
| arms of daddy government when things don't play out in your
| favor.
| DangitBobby wrote:
| Absolutely. They are guilty of writing vulnerable code, being
| hacked, and stolen from.
| trasz wrote:
| They are guilty of implementing a mechanism that was broken
| by design, and wasting customers' money. They hadn't been
| hacked or stolen from - the "attacker" didn't need to hack
| any particular security mechanism, he was just smarter at how
| their market worked than the owners.
| [deleted]
| turtledove wrote:
| You love to see it. Love to see crypto taking Ls.
| meroes wrote:
| If only so it lessens some of the bad behavior I've witnessed.
| My cousin has been investing most of his paycheck in Bitcoin
| for several years.
|
| He also thinks Tesla Wall Batteries will mine crypto soon and
| "broke into" a private event Elon was at and made a TikTok of
| it.
|
| I want him to have a successful future is all.
| Brian_K_White wrote:
| I feel this, but you know in a case like that, Elon and
| Bitcoin don't actually matter.
|
| If it weren't those, it would be whatever else existed to
| fixate on.
|
| I have a friend or two like that and I know that if I could
| fix Bitcoin it would not clear up their life or make them
| safe.
| randomhodler84 wrote:
| "Love to see your retirement 401k investments lose, eating away
| at your life's labor and rendering it worthless."
|
| This is a nasty position to take. You should never take joy at
| others losses.
| turtledove wrote:
| Nope. Sorry. Those are not the same.
|
| I'm cheering to see the grift coming apart. Yes, some people
| are losing. But the early the grift falls apart, the fewer
| future people get destroyed by it.
|
| I'd rather cheer seeing crypto fail, then stand by and watch
| it suck in vulnerable person after vulnerable person in
| perpetuity.
|
| Also, I absolutely do cheer the losses of bad people. If a
| scammer or ethnonationalist loses their hard earned
| winnings.... Good.
| randomhodler84 wrote:
| Its the same. You have an irrational fear/hatred of
| decentralized peer-to-peer money. Grifts unwinding is a
| thing, but don't throw out the baby with the bath water
| here. I fully intend on using Bitcoin for the next few
| decades, both as a saving and international remittance
| system.
|
| It's from a place of spite. Don't be spiteful, it makes you
| a bad person.
| onepointsixC wrote:
| No I don't think I'll love to see a person who "written the
| N-word into the code itself, 16 times." to steal 16 Million.
| gaze wrote:
| yeah the ideal thing to happen here is for that money to be
| sent to a nonexistent address and for everyone involved to be
| arrested.
| turtledove wrote:
| The white supremacist who did this is not a hero. I'm not
| cheering for that asshole.
| kristjansson wrote:
| There's something delicious in a critical part of the arb relying
| on a mechanism the contract authors included to reduce gas fees.
| Not only are we enshrining code as law, we're playing code golf
| with it first!
| rvz wrote:
| Good for the hacker then and well played.
|
| If you _really_ hate crypto projects so much, rather than
| complain all day long about the crypto-bros getting rich off of
| their tokens, just hack the smart contracts themselves and the
| project should offer a bounty if not beg for a negotiation for
| that and once the project creators fix the bug, you keep the
| rest.
|
| Job done, until the regulators come.
| paulpauper wrote:
| easier said than done. you can be sure that when news breaks of
| a contract being hacked it was only after maybe dozens, if not
| hundreds, of contracts had been tried and failed, by many
| hackers all over the world. Also, likely illegal: Code may be
| law but the judge may not see it that way.
| TameAntelope wrote:
| For all the people shouting "Way to go!" and "The money is his!"
| I think you should remember he's currently a fugitive, and would
| need to spend the rest of his life living this way.
|
| If that's what it takes to live the "code is law" dream, count me
| out.
| silentsea90 wrote:
| I like the very web3 middle ground where the attacker
| negotiates with the company and returns a part of the money,
| the rest being the lawful reward for reporting the
| vulnerability.
| knorker wrote:
| Do you mean "like" as in you're amused by it's absolute
| absurdity, or that you think this is a good standard
| practice?
| silentsea90 wrote:
| Sorry, I should make it clear - it is very very absurd.
| Can't edit comments after some time sadly.
| silentsea90 wrote:
| To make my stance very clear - this is an absurd and
| hilarious practice and feels similar to ransom, with the
| hacked entity putting "white hat hackery" on the table as an
| option to get some of their money back.
| wang_li wrote:
| Plus his family aren't choosing to live their lives in hiding.
| What part of the smart contract is going to prevent acts of
| violence against them? Seems like he was relying on maintaining
| anonymity and now that that's out the window his family is on
| real danger. $16-17 million is a lot of dough and it would cost
| a lot less than that to hire some kidnapping & ransom
| specialists to visit his family.
| kristjansson wrote:
| This is an outright copy of
| https://www.bloomberg.com/news/features/2022-05-19/crypto-pl....
|
| e: missed at the end of the article:
|
| > (Except for the headline, this story has not been edited by
| NDTV staff and is published from a syndicated feed.)
|
| So perhaps this is reproduced under a legit syndication deal?
| Brian_K_White wrote:
| It says "(c) 2022 Bloomberg Christopher Beam, Bloomberg
| Businessweek" right in it.
| [deleted]
| dang wrote:
| Ok, we've changed to that from
| https://www.ndtv.com/business/the-math-prodigy-whose-hack-up...
| above. Thanks!
| dimator wrote:
| I'm getting strong Neuromancer vibes from this. It's so
| interesting that we're now officially cyberpunk in some corners
| of our world.
| [deleted]
| vmception wrote:
| > Medjedovic added that he'd taken on "substantial risk" in
| pursuing this strategy. If he'd failed he would have lost "a
| pretty large chunk of my portfolio." (The 3 ETH he stood to lose
| in fees was worth about $11,000 at the time.)
|
| This is misleading, either intentionally or due to Medjedovic's
| incompetence.
|
| You can fork the current head of the mainnet blockchain to
| localhost and try infinite permutations for free to see what the
| next state of the blockchain will be. And then if you like that
| state, you can then pay to send the working transaction to the
| mainnet to make that same state occur, in a sure bet. ( _nearly_
| sure fire bet as in some cases, someone could replace the mainnet
| transaction in route, but they wouldn 't necessarily know what to
| look for or change if its a distinct kind of transaction)
|
| Medjedovic either didn't know this, because his skills didn't
| translate as well as he thinks, or Medjedovic knows this and
| hasn't come up with a stronger argument to support his actions
| yet (of which there are plenty) and actually is relying on public
| sympathy to support his actions.
|
| Either way, there is an opportunity for broader education on how
| these exploits can be cooked in something akin to a "hyperbolic
| time chamber" or quantum reality without anyone's knowledge,
| ready to hop back into our dimension fine tuned and ready to
| cause maximum effect, all within the ~15 seconds between blocks
| if necessary, as the state changes per block.
| drcode wrote:
| > And then if you like that state, you can then pay to send the
| working transaction to the mainnet to make that same state
| occur, in a sure bet.
|
| That often isn't true anymore, see
| https://ethereum.org/en/developers/docs/mev/
| vmception wrote:
| > but they wouldn't necessarily know what to look for or
| change if its a distinct kind of transaction
|
| which means non-trading transactions would look so different
| that someone playing with higher gas wouldn't know what to
| replace in the bytecode within the 15 seconds between blocks
|
| and the user also has the choice of sending directly to a
| miner just like the MEV people do, to skip the mempool
|
| which is looks like he did (but not sure, just noticed his
| contract mentions MEV)
|
| https://etherscan.io/tx/0x1710f8c91f03d43a51b94fb5db00305cdd.
| ..
| kristjansson wrote:
| MEV is something different though? GPs (excellent) point is
| that anyone can play out the effects of their transaction
| locally ad infinitum, and chose to transact once they're
| convinced of its behavior. Of course, this can't account for
| the response of other actors, but the point stands that
| Medjedovic (should have) been taking far less risk than
| implied by that quote.
| xur17 wrote:
| Medjedovic stood to lose all of the ETH he was paying in
| transaction fees (which could have easily been 3 ETH) if
| someone decided to frontrun his transaction. If that was
| most of his ETH, that does sound "significant" to me.
| vmception wrote:
| He used some kind of MEV shielding thing. But I'm not
| sure if it went directly to miners or did something else.
| xur17 wrote:
| Yeah, typically MEV shielding == sending directly to a
| mining pool that promises that not frontrun it. It's not
| a guarantee though, the miner could decide to still
| frontrun, or a small reorg could occur, and another actor
| could replace the transaction.
| vmception wrote:
| Another thing to note is that all the quotes from
| Medjedovic are directly to a journalist (at Bloomberg, the
| article was there a few days ago), which leads me to think
| there are intentional omissions towards the journalist. It
| is new that this level of detail is reported about
| happenings in the crypto space, from traditionally and
| previously non-crypto publications. It had usually been
| confined to "broad market selloff, here's a bunch of hot
| takes from our gloomy college friends on how it goes to
| zero!" instead of "specific incident within a crypto
| community, here's what happened". Medjedovic on the other
| hand is only seen as taking advantage of situations, such
| as a journalist that is perhaps merely enthused by the
| crypto asset economy at a publication that needs someone
| looking at it, but maybe not well versed in it or having
| editors that would notice either.
| qeternity wrote:
| * MEV has entered the chat *
|
| This is of course entirely untrue, and anyone who has done even
| the smallest amount of onchain trading would know this.
| vmception wrote:
| He used MEV shielding and the rest of this thread has already
| had that conversation to its completion
|
| Its improbable that the transactions he formed would have
| been able to be frontrun
| MockObject wrote:
| > You can fork the current head of the mainnet blockchain to
| localhost and try infinite permutations for free to see what
| the next state of the blockchain will be. And then if you like
| that state, you can then pay to send the working transaction to
| the mainnet to make that same state occur, in a sure bet.
|
| You have described mining.
| vmception wrote:
| Yeah good observation. But instead of arbitrarily hashing a
| algorithm used in consensus to find a block, this would be
| hammering specifically constructed bytecode at a smart
| contract's ABI endpoints to see how many other things get
| effected.
| buggeryorkshire wrote:
| Jesus, and we wonder why grandma is entirely unsuited to
| putting her savings in this crap.
| vmception wrote:
| This is only slightly different than what goes on in the
| stock market
|
| But yield farmers and high value targets should open
| insurance policies
|
| And the insurance pool participants should also be wary ha
| Dylan16807 wrote:
| That's just a complicated way of saying "you can locally test
| a smart contract that you're coding".
|
| Nobody is suggesting grandmas code their own smart contracts.
|
| _This_ is not the reason to keep grandma 's savings away.
| uncomputation wrote:
| Not quite a sure bet. It depends on your magic TX getting
| picked up from the mempool by the winning node.
| SamBam wrote:
| If anyone could perfectly predict what was going to happen in
| the next state then those with this ability would only ever
| make money and never lose it. Yet this can't happen. In the
| real world there are sniper bots and all sorts of other things
| that another agent could do in parallel with your own script,
| which would lead the outcome to be uncertain.
| vmception wrote:
| The main issue is constructing a valid transaction.
|
| An exploiter conducting a big heist and disappearing never
| has to prove that they can't do it again, because they're
| rich immediately.
| tromp wrote:
| > would only ever make money and never lose it.
|
| They'd at least risk losing the transaction fees...
| [deleted]
| jallen_dot_dev wrote:
| I took "fail" to mean someone seeing his transaction in the
| mempool and frontrunning him, exploiting the flaw for
| themselves before he could. AKA Ethereum's "Dark Forest." Not
| that the transaction would fail as in a bug or something. I'm
| sure he knows how to simulate transactions locally if he could
| figure all this out.
| shockeychap wrote:
| "But passivity also created risk. If there was a problem with the
| code, someone could exploit it directly, without needing to
| bypass any human safeguards. And limiting blockchain interactions
| to cut costs entailed a trade-off: When a smart contract--a
| script that executes automatically when certain criteria are met
| --has fewer steps, it can leave more room for security
| vulnerabilities."
|
| So much of this reminds me of Chesterton's Fence, where
| "innovative" solutions are deployed by people who never put forth
| the time and effort to fully understand how the existing system
| came to be the way that it was - and the problems that it had to
| deal with and solve along the way.
|
| I'm not trying to sing the praises of finance and banking;
| there's much there that is broken. (I'm also not a fan of crypto
| or NFTs.) But I am saying that many of the "old" ways came about
| in response to a litany of problems that are neither obvious nor
| intuitive, and you need to understand why it works the way it
| does before putting out a new solution.
| blakesterz wrote:
| This was an interesting read. The case is now in limbo until
| authorities can locate Medjedovic or he decides to appear.
|
| "I did not steal anyone's private keys. I interacted with the
| smart contract according to its very own publicly available
| rules. The people who lost internet tokens in this trade were
| other people seeking to use the smart contract to their own
| advantage and taking on risky trading positions that they,
| apparently, did not fully understand."
| dehrmann wrote:
| Reminds me of the standard advice of "don't roll your own
| cryptography." There are a lot of subtle nuances that make it
| hard to get right. When you have well-funded teams of absolute
| novices writing rules for complex games with money on the line,
| this is what happens. Rather than _just_ having user accounts
| taken over and having to do a mea culpa, the reward isn 't lolz
| or dark web money, it's actual money, and a lot of it.
| Gordonjcp wrote:
| I read a thing where someone called cryptocoins "Dunning-
| Krugerrand" and that has stuck with me for years.
| hartator wrote:
| > I did not steal anyone's private keys. I interacted with the
| smart contract according to its very own publicly available
| rules.
|
| Yes, it's a little disingenuous to claim "code is law" until it
| doesn't suit you anymore.
| liminal wrote:
| The fact that Ethereum code is public seems to weigh in favor of
| allowing him to get away with his "hack". For any other financial
| instrument, we rely on verbal descriptions of how it will be
| conducted and behave. With Ethereum, the code speaks for itself
| -- for better or worse. This leads to a rather absolutist dog-
| eat-dog rationality that I don't much like, but also don't see
| how to avoid.
| cbm-vic-20 wrote:
| > For any other financial instrument, we rely on verbal
| descriptions of how it will be conducted and behave.
|
| My brokerage sends me plenty of prospectuses and other
| documentation that I don't read that describes exactly that. I
| depend on the regulators and the lawyers of other clients that
| have a lot more to lose than I do to make sure they stick to
| the rules.
| vfclists wrote:
| Why did this link land me on the Indian site ntdv.com?
| qgin wrote:
| Hey, code is law right? He is the rightful owner now.
| postalrat wrote:
| Until someone finds a way to calculate another key to move his
| eth.
| snickerbockers wrote:
| "code is law" until you suddenly realize you suck at coding and
| come crying to the actual law.
| antishatter wrote:
| What'd he do that was illegal? Seems like he didn't cheat and
| insider trading laws don't seem to apply. Oops crypto is a
| unregulated market.
| postalrat wrote:
| Isn't making people angry illegal yet?
| onepointsixC wrote:
| It's an exploit no matter how you look at it.
| postalrat wrote:
| Would it be an exploit if I discover the math to move all
| bitcoin in existence to whatever address I want then do so?
| grumple wrote:
| Uh... yes? Are you seriously trying to imply that would be
| legal?
|
| If someone ever cracks modern encryption, that doesn't mean
| they can do whatever they want with everyone's accounts
| everywhere. If you find an exploit and exploit it, that's
| illegal.
| postalrat wrote:
| What doesn't owning bitcoin really mean? If I had the
| math to generate keys why wouldn't I also be considered
| an owner?
| grumple wrote:
| If you copy my signature does that mean you can sign my
| checks?
| billpg wrote:
| If you discovered a significant shortcut to hashing and
| then went back to block 1 and re-mined every block until
| your branch was the one with the most proof-of-work, I'd
| have a hard time trying to claim that your branch wasn't
| the legitimate one, according to Bitcoin's own rules.
|
| I suspect in this hypothetical scenario, however, the
| bitcoin developers would write a new rule.
| postalrat wrote:
| Perhaps a way to generate working private keys for any
| address. So I could move coins as I wish.
| [deleted]
| iak8god wrote:
| FTA:
|
| > In their complaint, lawyers for Kellar and Day argued that
| two particular steps of the attack violated statutes against
| market manipulation and computer hacking. One was swapping
| almost all the UNI tokens out of the DEFI5 pool, the otherwise
| irrational trade that distorted the pricing such that
| Medjedovic could buy tokens out from under Indexed users, who
| were forced by the algorithm to sell. "The only purpose of that
| trade was to mislead token holders to part with tokens on terms
| they never would have agreed to," says Stephen Aylward, a
| lawyer representing Kellar and Day. "We say that's a form of
| market manipulation." The same argument applied to Medjedovic's
| interaction with the CC10 pool.
|
| > The second illegal transaction, they argued, was when
| Medjedovic overwhelmed the pool with free Sushi, thereby
| tricking the algorithm into letting him bypass the size limit
| on certain trades. Aylward calls this "an intentional act by
| Andean to disable a security measure, like disabling the
| security system at a bank." He argues that this falls under
| Canada's "extremely broad" legal definition of a hack, which
| can be interpreted as "subverting the intended purpose of a
| computer system."
| motohagiography wrote:
| Their complaint hinges on an interpretation of what the
| correct level of abstraction for describing the transactions
| is. Their argument, "to mislead token holders to part with
| tokens on terms they never would have agreed to," is
| literally a counterfactual that presumes both fictional
| market conditions as well as intentions of anonymous owners.
|
| The second argument is an analogy, "disable a security
| measure, like disabling the security system at a bank," and
| the limit expressed in the code was definitely an expressed
| preference by the contract author, but if they wanted it to
| be a legal contract subject to human interpretation, they
| would have specified this in English. Instead, they created a
| software tool, and they did not take into account how that
| tool might be used by the public.
|
| The argument about this is whether code written for the
| express purpose of partipating in risky transactions can be
| imbued with any other coherent intention. The closest analogy
| would be that Medjedovic was at their gambling table and was
| counting cards, except there was no policy keeping him out of
| there, or against card counting.
| colinmhayes wrote:
| > to part with tokens on terms they never would have agreed
| to
|
| Didn't they agree when they bought the token though?
| paulmd wrote:
| So for the first claim, they are arguing that forcing a
| leveraged short squeeze is market manipulation? There seems
| to be lots of straightforward counterexamples that it's not -
| that's an extremely common tactic the big guys use to squash
| little guys in the regulated markets. The little guys "would
| never have agreed to part with those securities on those
| terms" and the squeeze is often deliberate, transient, and
| leveraged.
| faeriechangling wrote:
| If the law is held to have supremacy over "smart contracts"
| and implicit intent is held to be more important than
| explicit terms, than this undermines not just a major
| argument for smart contracts but a major argument as to why
| crypto as a whole is valuable.
|
| Enforcing a contract through a written contract & traditional
| finance vs a smart contract becomes a mere implementation
| detail since in either case somebody can come crying to the
| courts when they lose money. Smart contracts are only
| interesting if they're a form of binding arbitration. If
| smart contracts are not binding, they just become poorly
| written contracts.
|
| Smart contracts being binding honestly might need to be
| legislated.
| antiterra wrote:
| Even then, a binding contract is still subject to what is
| contractually enforceable, which could break the
| functionality and purported benefit of a smart contract.
| TameAntelope wrote:
| Yes, that's exactly the problem with smart contracts and
| why people are interested in resolving the case.
| xur17 wrote:
| > If the law is held to have supremacy over "smart
| contracts" and implicit intent is held to be more important
| than explicit terms, than this undermines not just a major
| argument for smart contracts but a major argument as to why
| crypto as a whole is valuable.
|
| No, it really doesn't. There are 2 questions that you are
| conflating here:
|
| 1. Can the courts force a user to return funds made via a
| valid smart contract transaction?
|
| 2. Can the courts force a blockchain to reverse a
| transaction that was made.
|
| > Enforcing a contract through a written contract &
| traditional finance vs a smart contract becomes a mere
| implementation detail since in either case somebody can
| come crying to the courts when they lose money. Smart
| contracts are only interesting if they're a form of binding
| arbitration. If smart contracts are not binding, they just
| become poorly written contracts.
|
| Can you elaborate on why this would be the case? To me
| there is a large difference between a system (like credit
| card settlement) that can have transactions revoked easily
| after settlement, and one that can only be revoked by
| another separate transaction that the sender makes. To me
| it comes down to a mix of probability of reversal, and who
| can actually do the reversal (only the sender in the case
| of a blockchain system).
| faeriechangling wrote:
| >2. Can the courts force a blockchain to reverse a
| transaction that was made.
|
| The courts already can't necessarily force a transaction
| to be reversed as it is. The money can be gone long
| before they get involved.
|
| >To me there is a large difference between a system (like
| credit card settlement) that can have transactions
| revoked easily after settlement, and one that can only be
| revoked by another separate transaction that the sender
| makes.
|
| There's a good deal of irreversible transactions, such as
| inter-bank transfers in traditional finance. It's also my
| understanding that most "Reversals" are just new
| transactions or cancellations of pending transactions. I
| don't see a HUGE difference in how an inter-bank wire
| transfer works and how sending somebody crypto works
| except that in the case of crypto it's the wallet/account
| holder in full control.
|
| I'll acknowledge there are differences, which impacts the
| probability of reversal and who can do the reversal, but
| I still feel it borders on the edge of "implementation
| detail". It only feels like a truly profound difference
| if you want to make a transaction a bank would normally
| interfere with, like a ransom payment, payment for
| fraudulent goods/services, drug deal, money laundering,
| funds being sent to political dissidents, or similar.
| Whereas the idea of smart contracts bypassing the expense
| of the courts entirely seemed like a much more broadly
| useful notion.
| hedora wrote:
| Isn't the intended purpose of this particular computer to
| part fools and their money in a non-regulated "code is law"
| ecosystem?
|
| It seems like it's working as designed, even if it's not the
| outcome its operators wanted.
| betwixthewires wrote:
| The funny thing is, based on the architecture of these
| types of systems, they aren't the operators. Arguably the
| miners are the operators, otherwise only the users are the
| operators.
| davidweatherall wrote:
| Stop regulating crypto! (Unless I've been hacked, then we need
| to regulate it)
| rnk wrote:
| Or unless you've lost money! Lots of people saying "the fed
| could make crypto losers whole without putting up a sweat"
| the last few days.
| antifa wrote:
| And they already do for all crypto that's FDIC insured.
| lupire wrote:
| He was in communication with the IF team, and contributed
| something to their system, so it's _possible_ that he defrauded
| them and inserted malicious code into the protocol, not just
| interacted with the protocol.
| rnk wrote:
| I'd tend to agree with you. People with money and power will
| push for laws that protect them though. But this situation is
| why I'm skeptical of these kinds of contracts - too much
| potential for problems.
| WhitneyLand wrote:
| Some insight as to what this guy is made of:
|
| _The Ethereum address Medjedovic used for the attack included
| the number "1488"--shorthand for a neo-Nazi slogan--and he 'd
| written the N-word into the code itself, 16 times. A Twitter user
| called him the "Dylan [sic] Roof of Balancer Pools," a reference
| to the mass shooter who killed nine Black people at a church in
| Charleston, S.C., in 2015. Medjedovic liked the tweet._
|
| Completely counter to every experience I've had working with
| Waterloo people. My sample group always seemed smart,
| interesting, kind.
| zecken wrote:
| I feel like the fact this person, per the article, is a white
| supremacist who used the n-word in his code repeatedly is under-
| discussed here. Folks here jumping through hoops to rationalize
| why what he did is actually demonstrative of either flaws in
| crypto or the purity of arbitrage come off seeming very tone
| deaf.
| antiterra wrote:
| What exactly are you proposing here? That we have a different
| set of financial and legal rules for despicable people? Or that
| the financial and legal rules everyone is subject to should be
| based on how they impact a specific despicable person?
|
| If a despicable bigot is facing the death penalty for stealing
| a bag of chips, would it be 'tone deaf' to say that's an unfair
| punishment?
| caymanjim wrote:
| Forget about the exploit itself. Why are people trusting two
| young nobodies (Day and Kellar of Indexed Finance) with so much
| money in the first place? Ok, so Day has some decent academic
| credentials, but he's just one person. Who was doing risk
| analysis? Which independent experts analyzed their algorithms?
| Which accounting firm audited them? Where's the oversight? These
| two guys whipped something up, threw it out in the wild, and the
| masses fed tens or hundreds of millions of dollars into it
| without a care in the world.
|
| This is how crypto operates. Buyer beware.
| pohl wrote:
| Haven't people who are attracted to crypto, for the most part,
| already decided that oversight is bad because something
| something decentralization?
| Red_Leaves_Flyy wrote:
| It's the Libertarian fantasy. Crypto bros, many VCs, angels,
| and other mini napoleons think they can solve the world's
| problems without addressing any of their personal problems,
| studying history, taking responsibility for their actions,
| engaging in community building, or hiring people with spines.
| Which is why crypto and ilk keep reinventing every scam and
| repeating the mistakes of the past that directly led to
| regulation.
| fron wrote:
| "Libertarians are like house cats: absolutely convinced of
| their fierce independence while utterly dependent on a
| system they don't appreciate or understand."
|
| No idea who said this originally but it continues to be
| true. Abandon the system, and they find it was there for a
| reason.
| xur17 wrote:
| Because people want to and decided the risk was worth it to
| them? If a consenting adult wants to deposit their money into a
| system that they have full visibility into, why should we stop
| them?
|
| > This is how crypto operates. Buyer beware.
|
| This statement rings very true for me, and perhaps is the bit
| we agree on. With crypto there is no "oversight" that blocks
| you from depositing your funds into unsafe contracts, etc. It's
| up to you as the user to do your own research before depositing
| funds.
|
| There are many projects within crypto that ARE well built, and
| have been carefully tested, analyzed, slowly released to the
| public, etc. I like having the ability to make this choice
| myself instead of relying on some gatekeeper to decide what I
| can do with my money ( _cough_ "accredited investor rules").
| rootusrootus wrote:
| > If a consenting adult wants to deposit their money into a
| system that they have full visibility into, why should we
| stop them?
|
| We already do exactly that, e.g. Accredited Investor.
| why_only_15 wrote:
| Yes but _should_ we do it? Those rules prevent most people
| from e.g. investing into startups.
___________________________________________________________________
(page generated 2022-05-23 23:01 UTC)