14 ms·
Ethereum Is a Dark Forest
- deleted 6y ago[deleted]
- pjc50 6y agoAs an elaborate real-money PVP system, Etherum is amazing. As a means of doing relatively normal business, being sniped, frontrun, or exploited is hugely off-putting.
- redahs 6y agoIn order for money to be both real and useful it should be secured by unencumbered interest in durable real property. The simplest way to circulate commercial paper for daily transactions is the Benjamin Franklin paper money system which involves appointing public loan officers throughout a nation to issue equity loans to anyone in possession of unencumbered interest in durable real property which they are willing to pledge as collateral which the public can auction in the event of non-payment. This way money is placed in circulation so that the interest paid for the first use of legal tender is publicly collected and immediately spent back into the economy and so that the total quantity of money expands dynamically in proportion to the aggregate quantity of physical durable capital.
- deleted 6y ago[deleted]
- Qworg 6y agoWhy? This is unnecessarily encumbering the utility of money. Real and Useful: people can use the money as a store of value, medium of exchange, and a unit of account - and enough people believe in it.
- redahs 6y agoBecause allowing new public legal tender to be created on security of fictitious capital such as speculative land values and deposits of credit created by other banks is accounting fraud, transfers wealth from the poor to the rich, creates speculative bubbles in financial asset markets, promotes disinvestment in the real economy, decreases demand for labor, inflates the price of land relative to wages for unsupervised labor, and worsens inequality.
- pjc50 6y agoThere is no way of distinguishing between a "real" and "speculative" land value.
- CryptoPunk 6y agoThe only reason inflated valuations based on speculative hype, i.e. your 'fictitious capital', are able to redistribute wealth from the productive economy to rent-seeking interests is that parties taking irresponsible risks are bailed out by government programs that socialize losses. These programs are sold to the public as making the market safer for consumers: https://www.nber.org/papers/w22223 https://www.nber.org/papers/w22223
- maest 6y agoCompeting theories say that the main value of monetary tokens comes from the government's monopoly on violence. What I mean is that governments ask taxes to be paid in tokens that they issue (pounds, dollars etc) and they threaten you with jail / physical violence if you don't pay. Governments then issue these tokens and pay people in order to employ them. Under this model, money is devoid from the value of the asset backing it (in the case of fiat money, no such asset actually exists).
- DennisP 6y agoTrue, but the article was about a situation in which they were retrieving money that was inadvertently available to anyone. That's not normal. Any well-written smart contract has protections against front-running. For about a year I audited them for a living, and front-running opportunities are definitely something we looked for.
- Groxx 6y agoThis is primarily an issue for contract writers[1], of which there are relatively few. You get similar kinds of automatic exploitation on exchanges of all kinds too (stock, currency, futures, etc), though I think it's fair to say Ethereum makes it (quite a bit) more complex and more automate-able on average. [1]: transitively it affects users too, but it's a bit different either way.
- jkepler 6y agoI thought Ethereum's primary aim was to be an unstoppable world computer that runs any code where the fas fee was paid, not money. Bitcoin aims to be peer-to-peer censorship-resistant electronic cash---and at this point its protocol has far higher levels of tested security.
- AtHeartEngineer 6y agoTransactions on ethereum get processed from the mempool in order of who wants to pay the most gas to have their stuff processed. And yes, ethereum has more potential for problems, it's a much more complicated system than bitcoin. Their current goals are proof of stake (getting away from energy wasting mining) and scalability. Bitcoin is great for what it's great for, being digital gold, but it's pretty far from replacing Visa, ethereum actually has a shot at that.
- dmihal 6y agoMany of these transactions are not using ETH the currency, just Ethereum the network. Ethereum has many tokens such as stablecoins (USD pegged tokens), governance tokens (capital assets), synthetic assets, even wrapped versions of Bitcoin. Ethereum is still a "world computer", but it's a world computer for high-value transactions, which are generally financial.
- sukilot 6y agoHow so? Ethereum requires a computer, and it's far cheaper to compute on your computer than compute has on your computer. Ethereum is an unstoppable world chat room (ledger), maybe.
- ur-whale 6y agoYou do realize that replacing "ethereum" with "the stock market" or "the USD" in your sentence pretty much yields another truism, right?
- pstrateman 6y agoThat's a lot of words to say "this system is insanely complicated for what it does (ie doesn't do)".
- lisper 6y agoOh, but the details in this case are absolutely fascinating! Well worth all the words IMHO.
- recursive 6y agoFor me, there weren't enough words to actually make any sense of it. What I got is approximately "if you try to do ethereum stuff, bots will somehow do the same thing but earlier, and you'll lose your money".
- lazzlazzlazz 6y agoYou don't lose your money — you may lose the arbitrage opportunity or free lunch you think you spotted.
- marcus_holmes 6y agoThis is the bit I didn't get about the article. How could the original owner of the $12K get their money out without getting pwned by the same bots?
- pstrateman 6y agoThey can't.
- marcus_holmes 6y agoSo, assuming the original person in TFA had some kind of authentic claim on the money, why are they not losing it according to GP?
- AaronFriel 6y agoFantastic story and analogy to Liu Cixin's novel. Writing bug-free code is hard enough, but this adversarial environment is fascinating and takes it to another level.
- kfarr 6y agoNot sure if it's covered in the novel but reading this really makes me think these adversarial environments could be very cool hosts for emerging (or seeded and self replicating) intelligent agents some day.
- cwkoss 6y agoEthereum or some other cryptocurrency will likely be the 'glucose' of future AI organisms. I'm excited (and slightly terrified) to consider a future where autonomous agents rent compute time to host themselves, provide 'services' autonomously within the cloud to earn funds, and then periodically reproduce by splitting their wallet and moving it to a new host. Add in the ability to mutate (or even hire humans to implement directed mutations), and I think this hits all the requirements for my definition of 'what is a living organism'.
- DJBunnies 6y agoIt's internet food!
- jessaustin 6y agoI thought the biggest flaw in 3BP was that none of the characters and none of the unknown assailants seemed to do any temporal discounting. A species that might be a threat in a billion years is not worth worrying about now. Resources should be used for immediate survival, not for eventually-it-might-be-nice extermination. It made the story seem more like a fantasy of contending royals than speculative fiction of scientists and soldiers. Of course, it probably seems natural to those who have different priors than I have. It's funny to see it cited in this context; I'm sure everyone on Ethereum knows about temporal discounting.
- andybak 6y agoThis was as much fun to read as some of the classic Eve Online war stories. Thank God it's just a game.
- Igelau 6y agoI see I'm not the only one. Most blockchain stuff seems like an incredibly dull game of Fantasy Stock Exchange, but this was more like Eve Online.
- hombre_fatal 6y agoThey have nothing on the current financial system, like banks being able to block you because you sell adult sex toys or someone being able to pull money from your account whenever they want because you once gave them your card details to buy a $5 sandwich or having to find a merchant relationship just for people to send you money. These are nonstarters that would get laughed out of the room if pitched today. You're just used to the stupidity, so it's easier to scrutinize the new things. But there are people out there who take those downsides seriously. And sure, you're always trading old problems for new, different problems, but it's nice to have the choice between those trade-offs for once.
- weego 6y agoYou can as easily blame the previous generations of sex toy sellers for their shady practices as you can banks for responding to it by separating those industries for special treatment. Higher processing fees or outright blocking is just a response to risk. It's not some moral pillar that crypto is taking a stand against at all, it's just removing all the processes that protect both sides of transactions and distributing those trust mechanisms to those parties instead.
- AnthonyMouse 6y agoExcept that it's not "shady practices" that caused it. It's, man buys porn on credit card, wife questions the man about it, man denies it was him, wife has the charge reversed. Then the bank stops wanting to deal with anything related to the adult industry. What you need is a payment system that can handle transactions where the seller is honest and the buyer is flaky when the existing one is built around the opposite assumption. And if the banks can't provide that (or the existing regulatory environment doesn't allow them to) then it's good when something else fills the gap.
- atarian 6y agoDoes anyone else think that Solidity is far too low-level for the purpose it serves? I really don't think connecting to ports (as an example) should be something in a financial contract.
- keymone 6y agoIt’s far too everything. Too low level, too high level, bad abstractions, bad syntactic constructs, bad evaluation model. The more I see people burning themselves on “smart contracts” the more I realize how deeply thought through bitcoin’s design is. Creators have thought of so many things in advance, it’s outright creepy.
- kinakomochidayo 6y agoWell, Bitcoin design WAS well thought out, until Blockstream nerfed it, and pushed its own product, Lightning Network.
- keymone 6y agoThat’s a myth. Blocksize limit increase was rejected by all parties relevant to bitcoin: miners, developers, users, and merchants. Blockstream has no control over bitcoin protocol. They built a product on top of it and there isn’t anything in bitcoin that prevents you from building a competing product.
- Animats 6y agoYes. They should have gone with something simple and declarative, like decision tables.[1] Those have a finite number of cases and can be exhaustively tested. Which is what you want for a smart contract for something real. But no, they had to make it Turing-complete. That failed quickly. Remember the DAO debacle. That should have been a teaching moment. But no. Because the people burned were insiders, the whole Etherium blockchain was split to rescue them. [1] https://en.wikipedia.org/wiki/Decision_table https://en.wikipedia.org/wiki/Decision_table
- 6y ago
- hooande 6y ago"Better yet, if you happen to know a miner (we didn’t), you could have them include the transaction directly in a block, skipping the mempool—and the monsters—entirely." ugh. It's not what you know, it's who you know That said, this looks like a very interesting and rewarding system to hack. But it seems to serve little purpose. The other comments comparing it to Eve Online are spot on
- solotronics 6y agoThe "purpose" is to be able to trade one coin for another without having a trusted intermediary such as an exchange or escrow.
- cynusx 6y agosounds like a legitimate service a miner could offer for (real) money
- acjohnson55 6y agoI don't see how that would work. Wouldn't that miner have to win the race to find a block in order to help? Seems like this would greatly lengthen the amount of time for a transaction to commit. You'd have to tell your transaction to a bigger set of miners to increase your chances, but that would also increase the chance of your transaction leaking to a front-runner.
- rsync 6y agoI came here to ask about that specific quotation: "Better yet, if you happen to know a miner (we didn’t), you could have them include the transaction directly in a block, skipping the mempool—and the monsters—entirely." In the bitcoin ecosystem, as far as I know, basically everyone can be a miner, right ? If you are running the bitcoin client you are mining and there is no particular barrier to entry to mining ... just run the client and mine. How is the ethereum ecosystem different ? If they could avoid all of these complications by mining, why didn't they just fire up their miner ?
- 6y ago
- josh2600 6y agoI really think that all of this DeFi stuff is playing with fire. If these tools scale large enough, it's easy to imagine breaking the right link in the system at the right time to cause catastrophic failures. Remember that all complex systems operate in a degraded state. If there's ever a way that only part of a complicated swap executes correctly the trade can get really far out of position. People in Ethereum land will say things like "the smart contracts can't possibly execute if all of these conditions aren't met!", but I can assure you that lots of extremely fault-tolerant systems built by very smart people (like electronic stock exchanges) have failed in very surprising ways. Weakly collateralized flash loans are just faster leveraged tools with all of the tradeoffs that entails. YMMV, there's definitely a lot of money to be made. https://www.youtube.com/watch?v=SjbPi00k_ME https://www.youtube.com/watch?v=SjbPi00k_ME << Relevant.
- solotronics 6y agopossibly when you are depending on transactions being verified on two different chains but one can do child pays for parent or can be overwritten on a smaller blockchain you could end up with a "blockchain race condition"
- ethbro 6y agoIsn't that the whole security / obscurity point? That true security only comes by being exposed to active, intelligent, informed adversaries for a sufficient amount of time? Or, another way: each exploit and oops only improves the system, rather than being a signal of its failure. And let's be honest, the competition is still "Oops, I accidentally sent $900M to the wrong party." [1] [1] https://news.ycombinator.com/item?id=24222045 https://news.ycombinator.com/item?id=24222045
- Analemma_ 6y ago> And let's be honest, the competition is still "Oops, I accidentally sent $900M to the wrong party." [1] The counterargument there is that Citibank is currently pursuing a resolution in the courts to that issue, and if they win they will get their $900M back. If you flub a DeFi transaction, you're shit outta luck.
- sickygnar 6y agoThe whole thing is a complicated, wacky game. The DeFi stuff is especially fun right now. Opportunities (and danger) abound. There is so much money locked up in DeFi. It's not necessarily always good for the bots either. They can be exploited and tricked as well.
- r00fus 6y agoI would love to hear of how the bots feed off each other.
- sickygnar 6y agoI heard of one being baited into making transactions that would fail, but still being charged gas
- cesarb 6y ago> There is so much money locked up in DeFi. Is the money really "locked up"? No money actually enters these systems; whenever someone buys a token with money, there was someone else selling that token for money, and the money went from the buyer to the seller, who is free to do anything with that money.
- sickygnar 6y agohmm, maybe you are referring to money as currency, where i am referring to it as assets (tokens) anyway, yes there is money locked in the lending platforms. most of it is used as collateral, which is locked when borrowed against. the reserve ratios are high (60-80%), so unlike a regular bank, no money is "printed" when lent. "real money" does enter these systems. people spend resources to acquire real money which is subsequently traded then locked into these platforms. also, while a lot of ethereum tokens are simply minted with no real backing, some are mined (even erc20), which again people dedicate finite resources to
- Sargos 6y agoYou are confusing money with value. Value is what something is worth and is what people prize. Money is just a convenient way to transfer value. I think you got stuck on that one piece of money (USD) that went from buyer to seller but forgot that the value transferred between them as well.
- throwaway4good 6y ago"Because I’m a professional DeFi thought leader, I had never actually deployed a contract to Ethereum before."
- josh2600 6y agoHaving deployed a contract to Ethereum, I can tell you that it is not for the faint of heart for a variety of reasons too numerous to list here. If the VM can change, but the code can't, it's gonna be hard to maintain.
- throwaway4good 6y agoI have the feeling that there might actually be more "professional DeFi thought leaders" out there than people who have deployed something to Ethereum.
- StavrosK 6y agoIs DeFi an actual thing, or just a term for cryptocurrencies in general?
- warkdarrior 6y agoDeFi is basically financial applications built on top of cryptocurrencies. Sometimes these financial applications (like exchanges, money markets, loan offerings, etc.) are decentralized.
- StavrosK 6y agoHmm, only sometimes? Doesn't the name imply otherwise?
- jamesonhodge 6y agoThere are varying levels of decentralization an application can take on, e.g. the back end (often Ethereum for financial applications), the front end (hosting on a peer-to-peer database like IPFS or Sia), and governance (by a DAO (decentralized autonomous organization) or some voting mechanism). Many DApps are founded with certain parts being decentralized and other parts centralized, and transition to a more/fully decentralized model.
- est31 6y agoI wonder how these bots perform the shorting. Do they take the modified instruction and increase miner reward to make it more prioritized than the original transaction? Such a bot would be hard to counter as if you set some reward value, even if it's extremely high, it would take it and increase it by 1. Even if you saw that value yourself and increased it yourself, they could counter your counter by inceasing again, the process continuing until everything is eaten up by miner rewards. If you have multiple such bots, would they fight over the loot, increasing the reward until it's all given to the miners? Are there any logs of rejected transactions that existed in the mempool? Is there evidence of such fighting?
- sickygnar 6y agoWell, gas prices are insane right now so no doubt bots are bidding them up. Gas prices hit 250 gwei or so 2 weeks ago. $150 fees for some of these contracts and arbitrage aren't abnormal. Here is a $188 transaction fee - looks like they were trying to "mine" compound from a $5 million flash loan? https://etherscan.io/tx/0x0d5def630cd20a1a24389982e99801e011bc3859293ba664a6823799221f533d https://etherscan.io/tx/0x0d5def630cd20a1a24389982e99801e011...
- iSnow 6y agoThey farmed $4140 before tx fees and interest, so they made about $4k. Not too shabby...
- marcell 6y agoCurious, you seem pretty well informed about Ethereum, blockchain, etc. Do you work in the space?
- iSnow 6y agoWish I were, but I am too old to work in a start-up, and I have family to feed so I won't work for $30k/y. I am just spending all my free time reading up on the stuff - to me, it's the most interesting tech revolution since the early web of the 1990's
- zdkl 6y agoI have dabbled extensively in the "traditional" *coin scene, but always shied from eth and the associated ecosystem. Stories like this are the reason why. While I could articulate -and genuinely believe in- a raison d'être for the alt-finance tools created by blockchain systems, the premise and concrete value of the exceedingly sophisticated mechanisms in ethereum continue to elude me. Given the primitives of account & transactions through distributed ledgers, one can construct a wide variety of services and use cases that interface with the real world on the user side and on the 3rd party service side. Are there any services and use cases in ethereum-land that are actually oriented towards users? Because it seems to me that the only group getting measurable value beyond education are actors seeking to extract profit from "legitimate" value store or flow. And I thought getting away from them was the entire point of Bitcoin et al. for the ordinary man.
- woah 6y agoA lot of this DeFi stuff is about people getting returns by providing liquidity to financial instruments that would have been done by centralized exchanges otherwise. So, still speculation driven ultimately, but not totally useless.
- AcerbicZero 6y agoCan you really call them smart contracts, if they're this dumb?
- Zarkonnen 6y agoOr use normal banking which has actual regulations for a reason.
- Sargos 6y agoIt's still an option but it's more work and harder to use and is pretty limiting in what you can do.
- ladberg 6y agoAs soon as I saw the title I thought of the Three Body Problem and I'm glad it wasn't a coincidence!
- nix23 6y ago>The Dark Forest is my favorite science fiction book Mine too and Hyperion andandand :)
- DevX101 6y agoDid the author get permission for this attempted Good Samaritan deed? Or did he go out on his own and screw up the implementation without the contract owner's knowledge? If it's the latter, that's kind of a shit move.
- gus_massa 6y agoHe didn't need permission: "Code Is Law"
- DevX101 6y agoI don't think what the author did was illegal. This is more of an ethical consideration where consent should have been requested from contract owner before doing a known risky operation.
- andrewflnr 6y agoThe Copenhagen Interpretation of Ethics strikes again. OP tried to help and didn't actually make things worse, but they touched the situation so now it's their fault.
- jessaustin 6y agoThe poor sap who motivated the whole snipe hunt got a mention in the third sentence and was never considered again...
- literallycancer 6y agoHe says it in the article. The first person to call that function gets the extra money. Why would you ask permission in that case? You can't make it worse.
- DodgyEggplant 6y agoSimilar things happen with real money all the time. Many players can hack, over charge, short, manipulate etc. It may be less obvious, or somehow perceived legit, but we are not really shielded from other players taking our invested money with all kinds of "financial tools" that are hard to understand. Ethereum is just more direct, more feasible
- modeless 6y agoThis is fascinating. I never thought of writing a bot to watch the mempool for exploitable transactions. Perhaps in the future it will be more common to send your transactions privately to a miner instead of putting them in the mempool.
- vugffuivuf 6y agoYou can measure the ignorance of hacker news by the number of people that take Ethereum seriously. Looks like it's at 100% today
- shard 6y agoMakes me think of the book Accelerando, where sentient viral corporations and Economics 2.0 posthuman intelligences running amok in virtual space, trading uploaded human constructs as currency.
- mrfredward 6y agoIn the article: "Better yet, if you happen to know a miner (we didn’t), you could have them include the transaction directly in a block" But how could you guarantee the miner was trustworthy, and wouldn't just take the money after you told them. Hmm...what if we could come up with some sort of smart contract... (recursion ensues)
- aazaa 6y ago> On Wednesday afternoon, someone asked whether it was possible to recover Uniswap liquidity tokens that had been accidentally sent to the pair contract itself. Uniswap itself is a pretty interesting protocol: > Uniswap is an exchange protocol that allows users to trustlessly swap ERC20 tokens. Rather using the traditional order book model, Uniswap pools tokens into smart contracts and users trade against these liquidity pools. Anyone can swap tokens, add tokens to a pool to earn fees, or list a token on Uniswap. https://docs.ethhub.io/guides/graphical-guide-for-understanding-uniswap/ https://docs.ethhub.io/guides/graphical-guide-for-understand...
- emerged 6y agoWriting this sort of bot seems like a legitimately fun and interesting thing to work on, but somehow I have less than zero interest in actually doing it. There's just something intrinsically repulsive about the entire blockchain world to me where I just don't want to touch it. I don't mean to offend people who do love blockchain tech, in many ways I don't blame you. But is this feeling I have somewhat common? I'm not even sure how to justify it.
- bsenftner 6y agoIt's a logic trap: an intellectually complex toy with the promise of access to untold riches to those "smart enough". It's a trap.
- api 6y agoIt always makes me think of that STTNG episode where they destroy the Borg collective by injecting a fascinating but impossible geometry problem. Cryptocurrency basically did that to the hacker and startup spheres, wasting unfathomable amounts of money, resources, and brain power.
- Sargos 6y agoDo you honestly believe, and this is a real question, that all of these brilliant people who come from well known companies spend nearly a decade of their life working tirelessly on building an ecosystem that many thousands of other developers interact with daily, just haven't realized yet that it's completely useless?
- bsenftner 6y agoThere are complex developed pseudo-sciences filled with serious people too deep and stubborn and too invested and too old to start over - so they continue, creating a masterpiece of fiction that carries too many fools to ever end. Religions, pseudo-sciences, short sighted and impossible political ideologies are rampant today and have been throughout human history. Of course I believe it is a sham.
- cecida 6y agoSounds like an enormously complex Rube Goldberg machine.
- mangecoeur 6y agoI have rarely seen so much effort and intellect expended for something so wildly pointless... conspicuously missing from these whole shenanigans: anyone doing anything that a normal person could recognise as being of practical use.
- beervirus 6y agoSee also Facebook, as well as large swaths of Google. A generation of our best and brightest are using their talents to spy on users and get ads into their eyeballs.
- cryptica 6y agoAnd the value of those ads is totally speculative. We live in a 0-utility economy. No wonder Warren Buffet's 'intrinsic value' investment strategy doesn't work anymore. Since the 1970s, the true driver of the economy was the Fed and its reckless borrowers; not workers, not consumers. It took 50 years for rich investors and their descendants to lose touch with reality to the point that they can't tell the difference between something important and something which is completely useless.
- deleted 6y ago[deleted]
- cryptica 6y agoBut if you think that this is just a problem with crypto, you should look under the hood of today's top S&P500 corporations and academic institutions. The Fed did such a great job printing money to meet its 100% employment mandate that many people can literally feel their jobs getting more useless by the day (but at least they get to keep them). Intelligence has become completely detached from utility. Also, I have never seen a project simultaneously so intelligent and so devoid of wisdom (or vision) as Ethereum. Its complexity is going to turn people insane. It's a case of the blind leading the blind; making things up as they go.
- maest 6y ago
- dakial1 6y agoWell, all this exploits should make the system more resilient in the long run (as they are fixed) no?
- emrehan 6y agoI’d prefer to live with a system where frontrunning is available for anyone rather than exchanges and brokers only. So that we could upgrade the system to be frontrunning resistant for good. There’re front running resistant decentralized exchange PoCs on Ethereum. It’s only a matter of time (and governance) before we could have this technology on Ethereum.
- vvpan 6y agoPerhaps due to a certain naivete I enjoy almost all discussions on HN. There are few exceptions and discussions under blockchain-related posts are the a prime example. I will disclose right away that I wholeheartedly think that blockchains are here to stay and to solve many problems. The general sentiment on HN, and this thread so far is an example, seems to be animosity toward the idea in general lightly veiled by pretext of pointing out technical challenges (which are numerous, I do not think the most ardent blockchain proponent will deny). Every time I try to point some great ability of "smart contracts" in return I hear blanket unthoughtful responses like "well how is it better than a database" or "how is it better than a REST call" (for example this exchange about the Baseline protocol https://news.ycombinator.com/item?id=23824584 https://news.ycombinator.com/item?id=23824584). Perhaps starting with a general accusation of the community is not the best method. But I'll move on... There are things that are very important to understand about blockchain. The most important one is that the technology and the systems built on it are _extremely_ young. Blockchain is like the 80s of computing. I would compare it to editing Unix system settings with "nano" to adjust a basic setting of your operating system - lots of horror stories for sure. The big difference is that people are out there to make money off of your mistakes. Yes, it can be a hostile environment. As the article alludes to - full anonymity of transactions is still in the pipeline! I do no know a single blockchain project out there that allows to interact with contracts anonymously yet. If blockchain is still alive a few years from now (and I have little doubt about that) then things like Optimism (mentioned in the article) will have made a whole array of shortcomings obsolete. Awesomeness does not happen overnight, it took _decades_ for the internet to become the ubiquitous integral thing that it is now. Actually, I'm glad the author used Uniswap as an example, because it is a simple and powerful system that would not have been possible without blockchain. (Aside: Uniswap is actually one of the first products to create a POC of running on top of Optimism's Optimistic rollups, so they are no unaware of issues). It was conceived initially by Vitalik himself and implemented as an Ethereum grant. The basic idea is that a contract controls two pools of tokenized assets. The assets are provided by people who get a cut when a trade happens. The price of assets being exchanged is equal to the ratio of their quantities in every pool. That is it!! Now, why do I think that a system as Uniswap is awesome. Right now most tokens are either tokens for other projects or USD. As the variety of tokenized assets grows (for example some Japanese banks are looking to create a digital Yen, and there are clues that suggest it might be on Ethereum) what you get is an extremely simple no-middlemen system for exchanging things of value. Now, in theory, any programmer can write a program, say, for currency exchange in one evening - no middlemen, no 3rd parties to trust, no banks, no clearing houses and a basic API anybody can integrate. The system is not perfect, and that's what the article is about. But the concept can be revolutionary. The blockchain money-grab is disgusting to look at. But do not throw the baby out with the bathwater.
- d33lio 6y agoIMO this is why anyone dumb enough to spend time building trading algos for crypto should really just use that time looking for vulnerable smart-contracts / projects if they actually want to see returns LMAO. I used to work in the space in the blockchain tracing space - I helped build one of the first intelligent tracing systems that could handle tokenized assets on ETH. I have zero regrets leaving the space...
- NazisAreStupid 6y agoGosh, I can't imagine why cryptocurrency hasn't replaced real money yet.
- Twisell 6y agoNothing in this article seem to make any sense, does the gibberish pseudo-code actually mean something for anyone? I feel like the dumbest of all (and maybe it's normal it's far away from my area of expertise). But seriously this sound more like a sci-fi plot that actual engineering.
- rkayg 6y agoI'm glad someone else feels like this. One of my friends is in the space, and I don't understand anything he says. I wonder if this community has created a whole language / framework to give a feeling of value to what they are doing. It's kind of like gamers talking about KDA, meta, etc.
- iSnow 6y agoMy god, have you tried to explain React code so someone outside of coding? Every field with any kind of intellectual depth invariable has to create an own set of terms to describe what they are doing. Stop talking down on people just because you don't understand their jargon. Either keep quiet and learn or don't judge at all.
- Twisell 6y agoAnd maybe also stop talking down on people just because they don't understand your jargon. Either keep quiet and learn what's not obvious for outsiders or just explain your jargon so that more people understand it.
- Sniffnoy 6y agoThere's no pseudocode in the article. There's Solidity (what the contracts are written in) and there's Javascript (what the rescue script is written in).
- ballenf 6y agoHave a friend who lost more than $12k in the process of buying a house. Scammers sent the wiring instructions a few hours before the legit closing attorney sent the real instructions. The email looked exactly right except for a minor change to the domain name from address. After one hour, wire transfers sent in error are no more recoverable than crypto. How the thieves knew so much about the process and timing is supposedly being investigated, but no one is holding out much hope. And the attorneys have a strong incentive to cover up any evidence of intrusion on their side, assuming it was their infrastructure infiltrated.
- api 6y agoIs it just me or is there fantastically more fraud these days than a decade or two ago? Any transaction feels like walking around in northern Canada during black fly season. I receive several cold scam calls per day and I’ve known people who have done things like purchase a home and been inundated by fake calls from “the underwriter” and other scams. Is there no mail and telemarketing fraud enforcement any more?
- ikiris 6y agoI wonder what changed in global cyber security and law enforcement during this time window.
- pmarreck 6y agoImagine a world with way less wealth inequality
- hnick 6y agoWe're definitely getting more of the Chinese robocalls and other SMS spam here in Australia too. I think there are two sides to it: scammers like everyone else are feeling the pinch from reduced economic activity, and desperate people are easier to scam. A lot of scams do feel like low hanging fruit that would be easy to track down. I think there is a lack of will and capability for resolving "small" scams of up to a few thousand dollars which can be crippling for individuals.
- 6y ago
- lmeyerov 6y agoI can't imagine running (or investing) in a software-based company here without also having an automatic model checking layer for verifying all runs + 24/7 monitoring for disabling any live contract. If you're going to put $10M+, years of your life, and who knows how much customer money into this, why not spend $500K of it so you're running with the blockchain equiv of CI testing? You'd be able to deploy faster, with more confidence and less stress, and fewer of these weird midnight Europe phone calls. Viable model checkers for basic software contracts existed since the 80's, and the modern incarnations are insanely powerful (Z3, ...) + quite approachable (Rosette, ...). They're used to tackle software verification problems magnitudes harder than "money can only go from here to there in this tiny software contract": race detection in distributed file systems, bugs in hardware circuits, security holes in big javascript libraries, etc. I think of these same not-very-secret tools every time I see one of these articles, and yet the engineering fails keep happening. A few teams deploy tech here, including built on the above, but it seems like most do not. I'd say mind-blowing, but at this point... mind-numbing? I do appreciate the author being frank about how bad the status quo is. EDIT: To give a sense of this -- the same people will talk about meticulous cold storage key exchanges with someone always being there to watch, driving into the desert for bootstrapping secrets, and then for their actual operations, deploy unverified contracts.
- Taek 6y agoI hate to be that guy but you are vastly underestimating the challenge of formally verifying these software systems. Blockchains are highly adversarial, open source, and doing a lot of innovation. Innovation which means that nobody has ever tried to verify that type of system before. Model checkers can tell you thinks like 'there are no underflows' and 'these two pieces of code are identical', but if you want to know whether there is no arbitrage or front-running, you're well past the capabilities of the state of the art. It's not merely a matter of spending $500k on CI and auditing. And then you've got a separate issue, which is that the space is super competitive and moves extremely fast. If you spend 6 weeks getting your new contract audited, you may well miss the window where people will care about the project you launched. I don't think this is a healthy culture, but it is one that many teams are trying to compete in. And therefore they ARE willing to bet millions of dollars without taking any time to audit, because the expected value of deploying faster is higher than the expected value of deploying more safely. For projects that are comfortable moving more slowly, formal verification IS a big focus, and the cryptocurrency industry has been a material driving force in many security related technologies such as reproducible builds (Gitian), reproducible bootstrapping (Guix), and software verification methodologies.
- dimmke 6y agoThe environment described in this article is horrifying and definitely sounds worse than our current financial system. That person just lost $12k to fraud and has no recourse at all. I agree with the other comments on here. Blockchain/crypto has always made me uncomfortable. I think it's a mix of the slimy get rich quick aspect of it that draws a lot of people and the cyberpunk/dystopian rhetoric around it. I also think it's telling that even though Blockchain has been this hyped thing for 6+ years at this point, we haven't really seen it actually be used for anything outside of cryptocurrency, which in and of itself isn't used for much outside of speculation. On the other hand, machine learning is used in everything now and makes a lot of stuff better. It definitely sounds like there's an additional major innovation that needs to happen with this stuff before it's really usable.
- xur17 6y ago> The environment described in this article is horrifying and definitely sounds worse than our current financial system. It's a different system with a different set of tradeoffs. I don't think it's accurate to just call it "worse".
- Taek 6y ago> I also think it's telling that even though Blockchain has been this hyped thing for 6+ years at this point, we haven't really seen it actually be used for anything outside of cryptocurrency, which in and of itself isn't used for much outside of speculation. On the other hand, machine learning is used in everything now and makes a lot of stuff better. Did you know that the Neural Network has been around since 1958 [1]? Machine learning is not a technology that is just 6 years old. The latest AI trend is also not the first or second time that AI has been through a massive hype cycle. The problem with the cryptocurrency space is that it's financial innovation. And just like financial innovation on Wall Street, this tends to draw out the slimiest people in society, because if you get someone to believe in your product they may well leverage their mortgage and throw their life savings at you. It's crushing to see people do this, especially because pretty much only the malicious projects get hyped up that much. But that doesn't mean that there isn't any truly groundbreaking innovation out there. Cryptocurrency changes the fundamental scalability of society. A key bottleneck for human society is trust - at some point a system gets large and corrupt, and it becomes difficult to keep bad actors from imparting a large amount of negative influence. But cryptocurrency allows us to design systems that don't require any trust at all. They _cant'_ be corrupted, because a combination of incentives and cryptography keep everyone safe. As this blog post shows, there are still a lot of rough edges out there, but the technology is innovating rapidly. I do think the hype is probably 5-10 years ahead of the technology, but in the grand scheme of technology (think of how long it too Arpanet to mature, or Neural Networks to mature) that is not much time at all! [1]: https://www.computerworld.com/article/2591759/artificial-neural-networks.html https://www.computerworld.com/article/2591759/artificial-neu...
- segfaultbuserr 6y agoIn additional to the "Dark Forest" analogy here, there's another hilarious analogy of Ethereum I've heard of - it's a game of Core War, but with money in it.
- theether2020 6y agowww.theether.io
- finder83 6y agoAre these bots legal that are doing the sniping/etc? I know next to nothing about Ethereum, but the whole environment sounds questionable
- Sargos 6y agoIt depends on your definition of illegal. It's not illegal in lots of places and is a gray area in most places. It's hard to know who would even handle the case since you're not sure who has jurisdiction, if anyone.
- kleer001 6y agoThe weakest link is always the human followed by entropy.
- lallysingh 6y agoSo who actually uses these contacts? Who's transacting on this?
- deleted 6y ago[deleted]
- xg15 6y agoOk, I got the part with the arbitrage bots and frontrunners - but could someone ELI5 to me what the uniswap contract was supposed to do in the first place?
- dnprock 6y agoI'm not sure when Ethereum supporters would wake up. Ethereum's design creates this kind of Dark Forest problem. When it is programmable, you are at risk of being overpowered by bots. Computers are far more efficient than humans. Smart contracts are not smart. If they're too complicated (smart), humans can't comprehend them. So they're mostly dumb. Bots will overrun humans. With Ethereum, you know you're entering a digital Dark Forest. But you still want to explore it. You venture into the Dark Forest and got attacked. It does make an interesting story. But it's a fairly useless system. With cryptocurrencies, you want to "slow" the system down. You want more redundancy. You want less efficiency. It's the only way to fight the automation monsters. Bitcoin is money. Ethereum is a fun and experimental Dark Forest.
- literallycancer 6y agoMost trading is automated. This is not something that's unique to smart contract platforms. How come the world didn't end already?
- pkilgore 6y agoI'm personally quite excited to vote by blockchain aren't you?
- desdiv 6y agoWhy did they try rescuing the $12,000 pot on their very first attempt instead of planting a bunch of $10 dummies and rescuing those instead? Once they perfected how to rescue the dummies, then move onto the real target.
- Sargos 6y agoIt says in the article that they ran out of time. Doing test runs would have required even more time.
- gottagetmac 6y agoTime pressure was the main reason. We also couldn’t have been sure that a method that could recover $10 would be able to recover $12,000. Bots won’t bother to snipe opportunities that are too small (they have to put a little money at risk to even try). Finally, there was a nagging worry that demonstrating this kind of transaction for the bots could “teach” them to look for this opportunity, which could lead them to this money even before we tried to pick it up (since they could scan the blockchain for it). I had heard that these bots sometimes used recent transactions as “hints” to look for new profit opportunities. It sounded like a wild idea, but all of this was pretty wild.
- vmception 6y ago> Because I’m a professional DeFi thought leader, I had never actually deployed a contract to Ethereum before. As a developer that uses the EVM quite often, this had me laughing out loud! That matches my experience with pretty much everyone! And yet there are still the people doing things I could never think of doing and doing it very quickly. I want to get to that place.
- marcell 6y agoCurious what do you use the EVM for?
- vmception 6y agoSell shovels during a gold rush, just like I did for mobile apps a decade ago. That turns into open source contributions in packages that affect far more than EVM. And some truly lucrative knowledge and utility. Except people want to debate utility whereas nobody batted an eye at mobile even though people only use like 5 of the hundreds of apps they have. (People made fun of apps getting big checks but it was all in fun, or congratulated individuals developers making 5-6 figures from app stores, but mention a dapp on a blockchain and everyone looses their minds)
- longnguyen 6y agoNot related to the content but why on earth an anchor link is styled as a strike through text?
- aero-glide 6y agoThis reads like a cyberpunk novel. Except its all real
- ur-whale 6y agoThis paper is really worth a read, if only because it shows how much smart contracts is a brand new territory, mostly unexplored, full of opportunities (and therefore dangers). If you're a blockchain naysayer [1], I'd invite you to go read this paper to measure how deep, rich and complex the world of smart contracts is, and at the very least get a feeling that you may simply not know how uninformed your negative opinion is. [1] https://en.wikiquote.org/wiki/Incorrect_predictions https://en.wikiquote.org/wiki/Incorrect_predictions
- Aeolun 6y agoI have literally no idea what all of the stuff in the article means, but it sounds like the whole thing was broken from the start. If someone can take the transaction you just sent and somehow jump in front of you to execute the same one, your system seems fundamentally broken.
- jklepatch 6y agoI turned that blog post into a video A visual explanation of how someone made 12,000 USD in a single Ethereum transaction with front-running. https://youtu.be/vP5hVkH_1gs https://youtu.be/vP5hVkH_1gs
- mgraczyk 6y agoI didn't study the specific contract in detail, so I could be way off base here, but... It seems like the money could have been safely claimed using a tiny amount of crypto. Something like creating this contract: contract Example { function Example() public { if (keccak256(msg.sender) == HARD_CODED) { do_transfer(); } else { do_something_terrible(); } } Would be bots be able to automatically determine that they need to swap out HARD_CODED with the hash of their own address?