[ad_1]
Jump Crypto (JC) published a research paper on December 21 analyzing Proof of Solvency (PoS) vulnerabilities and how PoS works in theory but fails in practice.
In the article, the research-driven quantitative trading firm states:
“For proof of solvency mechanisms to prevent an exchange from misappropriating consumer deposits, consumers must verify that their deposits are included in the list of deposits reported by the exchange.”
As a mechanism used by exchanges to show customer deposits, the report states that the PoS mechanism is not always effective in practice.
“If exchanges can predict future attestations or cast doubt on failed attestations, they can successfully divert consumer funds.”
JC said the “high-probability guarantees” that back PoS in theory “are remarkably fragile in practice.”
Flaws in practice
JC’s findings lay out three perspectives that reveal flaws in the reliability of PoS mechanisms. They are:
From a verifiability perspective: JC said that “exchanges may not verify the on-chain addresses they claim.” From a financial point of view: JC said that PoS “does not guarantee the actual solvency of the company, because exchanges hold other assets and liabilities on their balance from a technical point of view: JC said that the point of sale “is not necessarily plug-and-play and requires careful consideration in choosing the appropriate approach”.
JC acknowledged that the crypto community was already partly aware of these flaws, but suggested further thinking about removing exchanges if PoS checks fail.
Failed PoS checks
JC suggested that it is critical for exchanges and users to look at the mechanism for users to initiate checks and raise potential issues to restore PoS efficiency.
“An exchange can probably predict which consumers will check, and an exchange can also remove a handful of failed checks, which means it can weaken or undermine the probabilistic security that proof of credit provides.”
JC also suggested that users learn the decision mechanisms when PoS checks fail.
“If a verification fails, there’s often no official mechanism to escalate or verify, leaving users to post it on Twitter or other social networks.”
While advertising on social media, JC said that “a single voice, or a handful of voices arguing on Twitter, can easily be confused with FUD”.
JC also warned that malicious exchanges could “easily build on this narrative”, turning criticism from public users against them, calling them “engagement farmers and convincing their userbases to ignore them”.
Potential Solutions
JC outlined five separate changes that exchanges could implement to help mitigate the discussed vulnerabilities, but flaws remain:
Exchanges can help users verify financial stability, but this can lead to the collection of more user information and potentially confuse users. Exchanges may offer rewards for finding incorrect attestations, but this may lead to false positives and no consequences for false accusations. Exchanges can automatically send tree or user-specific proofs to users, which can increase false positives and discourage new users. Exchanges can generate evidence faster and more frequently, which can allow exchanges to modify evidence after investigation. In the process.
JC concluded the research paper by stating:
“This article is not a critique of exchanges, which are rapidly building their proof of solvency infrastructure. These are commendable and timely efforts, and we anticipate that these mechanisms will become more common and mature over time.
Read our latest market report
|
Sources 2/ https://news.google.com/__i/rss/rd/articles/CBMiW2h0dHBzOi8vY3J5cHRvc2xhdGUuY29tL2p1bXAtY3J5cHRvLXJlbGVhc2VzLXJlc2VhcmNoLW9uLXByb29mLW9mLXNvbHZlbmN5LXZ1bG5lcmFiaWxpdGllcy_SAWFodHRwczovL2NyeXB0b3NsYXRlLmNvbS9qdW1wLWNyeXB0by1yZWxlYXNlcy1yZXNlYXJjaC1vbi1wcm9vZi1vZi1zb2x2ZW5jeS12dWxuZXJhYmlsaXRpZXMvP2FtcD0x?oc=5 The mention sources can contact us to remove/changing this article |
[ad_2]