$ 150 million stolen in ‘make money’ crypto / DeFi hacks

[ad_1]

This week saw a pair of high profile cryptocurrency thefts totaling over $ 150 million. One from MonoX and one from BadgerDAO.

And the details illustrate the astounding naivety and ineptitude of these cryptocurrency fanbois. Yes, of course, let’s sweep away the centuries of governance, guarantees and legal practice in the banking industry. Because… uhhhh… something-something fiat?

Schadenfreude for those of us who know this fantasy money craze is hilariously silly. In today’s SB Blogwatch, we’re bringing out the popcorn.

Your humble blogger has curated these pieces of blogging for your entertainment. Without forgetting: Big box, small box, cardboard fish.

DeFi DAO D’oh!

What is the craic? Dan Goodin reports: “Really stupid ‘smart contract’ bug allowed hackers to steal $ 31 million”:

“Multi-Million Dollar Hack” Hacker Stole $ 31 Million By Exploiting Software Bug [that] Blockchain startup MonoX Finance… uses it to write smart contracts. [It] allows users to trade digital currency tokens without some of the requirements of traditional exchanges.… An accounting error [in] the company’s software allows an attacker to inflate the price of the MONO token and then use it to cash all other deposited tokens. … More precisely, the hack used the same token as the tokenIn and the tokenOut [which] dramatically inflated the price… because the tokenOut update overrode the tokenIn price update.… MonoX isn’t the only decentralized financial protocol to fall victim to a multi-million dollar hack.

You can repeat it. Thomas Claburn says once again: “BadgerDAO DeFi reimbursed”:

“Claim of overconfidence” BadgerDAO, creator of a decentralized finance (DeFi) protocol, said … he is investigating reports that … $ 120.3 million … in user funds have been stolen . … The DAO in BadgerDAO stands for Decentralized Autonomous Organization [which] Perhaps explains his headlight deer crisis communication.… BadgerDAO does not list a head office, or phone number, or… e-mail. Instead, it directs customers to its Discord channel. Not really. Discord.… Yes, people still use the term “smart contract” with a straight face, even if they laughed in the room if they used an equivalent overconfidence statement like “my bug-free code”,… or “” my impenetrable self-rolling crypto library “.

Who in their right mind trusts these platforms? Whoever they are, Bruce Schneier wants them off his lawn – “Smart Contract Bug”:

“Reason enough to never use it” The basic problem is that the code is the ultimate authority – there is no arbitration protocol – so if there is a vulnerability in the code, it there is no recourse. And, of course, there are plenty of vulnerabilities.… This is reason enough to never use smart contracts for anything important. Human-based arbitration systems are not unnecessary human baggage before the Internet, they are vital.

Well said. Julien Bouteloup is afraid to update his firmware – “rekt roadkill”:

“DeFi users can’t afford to be too comfortable” One user reported the suspicious approval to increase the allowance () … almost two weeks ago. … How did Badger not notice?… $ 120 million from various forms of wBTC and ERC20. … The vast majority of assets stolen were vault deposit tokens… with the underlying BTC tied to the Bitcoin network, and all ERC20 tokens remaining on Ethereum.… Should regular users be required to spot a contract illegitimate? … If long-standing projects with a reputation as solid as Badger can be recreated like this… DeFi users can’t afford to get too comfortable.

As Schneier said, humans are not pre-Internet baggage. Bongle agrees:

“It’s really, really difficult” I love how, with smart contracts, they managed to create something so obtuse that for an operation a human would instantly say “sorry, we don’t do that”, the contract intelligent allowed them to run away with [$150 million].… It’s really, really hard to prove that even the simplest code does what the specification says. And then the specs are hard to write too.

Indeed, as olliej asserts, “This is not theft”:

“That’s the right result.” The whole point of the “smart contract” absurdity is that the code is the exact legal contract. What is “served” is irrelevant and the ability to discuss such things in court is seen as a flaw that these contracts are meant to correct. … Someone obeyed the terms of the contract and won coins in return. By all the definitions the crypto folks threw up, this is the correct outcome, and if people didn’t like the terms of the contract, they weren’t obligated to agree to it.

Interesting point. garyisabusyguy is a busy guy, so puts it more succinctly:

Is it a bug if it was designed for this? I’m just asking for a friend.

If we can say it’s not theft, what is it? Incredibly Stupid categorizes it like this:

“The code is vulnerable” People need to think about this sort of thing. This should have been reported more correctly as security researchers collecting a [$150M] bug bounty.… We need to stop calling things “smart” when they’re stupid. … Maybe the best term for these things is “hackable contracts”. The code is vulnerable… and any developer who doesn’t understand this is a dumb hire.

But people don’t know what they don’t know. Here’s Richocet, bouncing off that idea:

“Dunning-Kruger” I worked in the financial industry for 10 years and in IT for 20 years. I wouldn’t touch crypto with a pole.

And I sort of understand it. Why are so many people who don’t understand how crypto works, speculate or trust it? Dunning-Kruger?

Meanwhile, LuDux makes an allegation:

Work as planned. Who wants to bet that this “hacker” was just the owner of the business that was looking to get out of the scam?

And finally:

Wait what?

Previously on And finally

You have read SB Blogwatch by Richi Jennings. Richi curates the best blogs, the best forums, and the weirdest websites… so you don’t have to. Hateful messages can be addressed to @RiCHi or [email protected]. Ask your doctor before reading. Your mileage may vary. E&OE. 30.

Image Sauce: Steve Berry (cc: by-nc-sa)

Sources

1/ https://Google.com/

2/ https://securityboulevard.com/2021/12/150m-stolen-in-imaginary-money-crypto-defi-hacks/

The mention sources can contact us to remove/changing this article

[ad_2]

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts