8 ms·
Escaping the Dark Forest
- ladberg 6y agoI love that they're continuing the Dark Forest analogy! Makes me also realize I never want to dip my toe in crypto like that. It's like an amateur going up to an entirely unregulated wall street and expecting to earn some quick cash.
- nullc 6y agoThe word you want here is "ethereum" not "crypto". Crypto is cryptography, and even if you want to redefine it as 'cryptocurrency' the sheer reckless yolo incompetence and scammyness of ethereum is not especially representative.
- ladberg 6y agoI think "crypto" can mean cryptography or cryptocurrency depending on context. Every cryptocurrency I've seen has a Dark Forest, even if it's not as bad as Ethereum. For example, if you create a private key using something guessable [1], point a camera at a QR code [2], or make a wallet using software you didn't write yourself [3], you can expect your money to irreversibly disappear faster than you can react. [1] https://www.wired.com/story/blockchain-bandit-ethereum-weak-private-keys/ https://www.wired.com/story/blockchain-bandit-ethereum-weak-... [2] https://www.theverge.com/2013/12/23/5238764/news-anchor-receives-bitcoin-as-a-christmas-gift-on-air-stolen-promptly https://www.theverge.com/2013/12/23/5238764/news-anchor-rece... [3] https://cryptonews.com/news/popular-private-key-generator-compromised-fake-crypto-wallet-3941.htm https://cryptonews.com/news/popular-private-key-generator-co...
- ClumsyPilot 6y agoThere are worse coins out there than etherium
- swensel 6y agoIn terms of ethereum, do you mean ethereum smart contracts? The ethereum platform, as defined by it's creators, is actually quite technical. Anyone who spends the time to learn the Solidity language and what it takes to deploy a smart contract is free to, so yes there can be legitimate, illegitimate, poorly designed or well designed smart contracts, just like other software programs.
- microtherion 6y agoWhat IS a "representative" cryptocurrency, then, if the #2 by market cap is not representative? Would it be Bitcoin, used for such time-honored business as drug purchases and hiring contract killers? Would it be Tether, the fiat currency for people who think that central banks are excessively transparent? The one extra element that Ethereum brings to the table is computationally much more powerful contracts, which makes it technically intriguing, but also adds another level of scammyness and incompetence to the enterprise.
- d3nj4l 6y ago> Would it be Bitcoin, used for such time-honored business as drug purchases and hiring contract killers? Well, at least it's used for business! Do people use eth for meatspace transactions, at all?
- BTCOG 6y agoPerpetuating myth and propaganda that even the US government doesn't say about Bitcoin, I see. Did you pay attention to the recent Bloomberg article about cryptocurrencies being the best gaining asset class of 2020, or the article about the $2 trillion dollars worth of laundered money being done using traditional USD and banks? And how much money was laundered through Bitcoin again? A money that is very hard to hide. Bitcoin has smart contracting so it would appear you're just regurgitating things you've read rather than reaching into an in-dept knowledge on this subject.
- microtherion 6y ago> cryptocurrencies being the best gaining asset class of 2020 And tulips were the best gaining asset class of 1636. The existence of speculation is not proof of the soundness of the underlying asset. > trillion dollars worth of laundered money being done using traditional USD The difference being that I have firsthand knowledge of honest economic activity being conducted with USD. I see practically zero evidence of cryptocurrencies being used in any honest economic activity, other than speculation. > Bitcoin has smart contracting Yes, but my understanding is that Ethereum can handle much more complex contracts.
- pron 6y agoAmateur has nothing to do with that. Ethereum, and "smart contracts" in general, are built on such shaky foundations that unless shakiness is what you're looking for, you have nothing of interest to find there.
- vvpan 6y agoCan you elaborate? Why do you find that "smart contracts" are built on a shaky foundation?
- drchopchop 6y agoBecause there is no real formal verification process for smart contracts, it's extremely easy to slip bugs into the contract code, the contract itself is generally immutable (can't fix bugs), and the effects of a breach are generally catastrophic and irreversible. Need more reasons?
- BTCOG 6y agoThis as well. Immutable bugs.
- vvpan 6y agoYou are incorrect. Contracts are immutable but you can upgrade your application. There are different patterns, one where you make a shell contract that has pointers to contracts with actual business logic. Also, there are patterns where the user needs to confirm that yes they want to use the new version. There are also systems of insurance on contracts.
- ShorsHammer 6y ago> there is no real formal verification process for smart contracts Not following here, instead of process you mean no requirement to do so? The process is pretty clear and simple, there's a few different frameworks being built for smart contract formal verification along with the traditional methods working fine. What was the last bit of code you wrote or used that was formally verified? https://sci-hub.se/https://ieeexplore.ieee.org/document/8905010 https://sci-hub.se/https://ieeexplore.ieee.org/document/8905...
- gabereiser 6y agoWhen's the movie script due? This was an amazing read mainly for the multiple perspectives and story. Great job!
- formerly_proven 6y agoThis read like a piece by William Gibson in the Neuromancer universe. I finally understand now why people are attracted by cryptocurrencies.
- ordinaryradical 6y agoYes, if you're an enthusiast, it seems like good, technical fun. But I have no idea how an "investor" could read this and think they can price the risk correctly. This isn't even the wild west of finance--this is intergalactic space.
- jquery 6y ago> But I have no idea how an "investor" could read this and think they can price the risk correctly. This isn't even the wild west of finance--this is intergalactic space. To be a successful investor, you don’t necessarily have the price the risk correctly, you just have to price it better than others. I imagine someone successfully investing in crypto can read stuff like this fluently.
- pfisch 6y agoAnyone "successfully" investing in crypto got in at least 4 years ago or when we the last big run up was and just held in a reputable exchange or in their own wallet that they secured well. They don't need to understand anything really except how to deposit 5000+ in a reputable exchange. I think this makes up most successful crypto investors.
- bojo 6y agoI am not an advovate for crypto by any means, but this is false. There are some Wall Street level investors out there. https://www.forbes.com/sites/michaeldelcastillo/2020/08/06/valuable-sec-data-on-20-institutional-bitcoin-investors-could-soon-disappear/#4227304a1de2 https://www.forbes.com/sites/michaeldelcastillo/2020/08/06/v...
- Analemma_ 6y agoThis is all very interesting to read about, but in the same way epic battles in Eve Online are interesting to read about but not participate in. I hope the author doesn't think this article is functioning as an enticement to use ETH myself, because it's only confirming for me that I never, ever want any of my money near that shambling wreck.
- itronitron 6y agoseems like a very interesting story however after the third voice change I lost interest and the specialized tech jargon just makes it sound goofy
- AgentME 6y agoI was wondering why the article kept repeating details in re-worded ways as if they happened to other people. I didn't even realize that different parts were by different authors.
- bambataa 6y agoOh! That explains how they managed to get beachy cocktails in the middle of the night. I was very confused too. Overall, though, I do think DeFi has potential. Every attempt to anchor blockchain stuff to the real world (supply chain validation etc) seems to founder on the fact that non-blockchain solutions already exist. Providing new functionality on the blockchain seems to be more successful.
- squeezingswirls 6y agoAddendum https://zengo.com/generalized-front-running-ethereum-arbitrage-bot-attack/ https://zengo.com/generalized-front-running-ethereum-arbitra...
- kevinpet 6y agoMakes me think of salvage operations, and then raises the question of how do people get paid? They're providing a valuable service. I think in shipping there are both conventions and an ability to quickly negotiate that allows contracting for a salvage ship to rush to the aid of a grounded or sinking container vessel.
- MacsHeadroom 6y agoThe people helping here did it for compensation in the form of good will with key players and/or potential future customers of their respective crypto products. If you're going to use two similar looking services for something using ETH, do you go with the one by some no-name or the one created and championed by community heros?
- huac 6y agoyou will pay a higher fee to a trusted miner to process your transaction without sending to mempool.
- Animats 6y agoYes, there are. It's the Lloyds Open Form.[1] "No Cure - No Pay". This is the standard deal for salvage operations, and is well over a century old. It's very simple, since it's intended to be executed by someone on a sinking ship. It's sufficient for the captain of a ship in trouble to contact a "salvor" and say they accept the standard Lloyds Open Form. A message "ACCEPT SALVAGE SERVICES ON BASIS LLOYDS STANDARD FORM LOF 90 NO CURE NO PAY ACKNOWLEDGE" is enough. Contractors’ basic obligation: The Contractors identified in Box 1 hereby agree to use their best endeavours to salve the property specified in Box 2 and to take the property to the places stated in Box 3 or to such other place as may hereafter be agreed. If no place is inserted in Box 3 and in the absence of any subsequent agreement as to the place where the property is to be taken the Contractors shall take the property to a place of safety. The Contractors’ remuneration and/or special compensation shall be determined by arbitration in London in the manner prescribed by Lloyd’s Salvage Arbitration Clauses in force at the date of this agreement. That's the deal. You need some agreed way to resolve how much the job is worth for this to work. The Lloyds Open Form is an agreement to do the job and discuss later how much it's worth. That's generally settled by insurance adjusters. It's much like the aftermath of auto accidents. How much does the salvor get? 15% - 35% of the recovered value, reports Lloyds.[2] Of course, salvors work under tough conditions. They have to have equipment and people ready 24/7 to go somewhere and do something. That's expensive. Some classic worldwide names exited in the past decade. Mammoet and Titan both dropped out. All this is against accidental losses, not against an adversary. Where there's an opponent, it's a much tougher problem. Marine salvage is vs. the ocean. Whether this model can be made to fit programmed contract problems or ransomware is a big question. One worth pursuing. [1] https://www.lloyds.com/market-resources/lloyds-agency/salvage-arbitration-branch/lloyds-open-form-lof https://www.lloyds.com/market-resources/lloyds-agency/salvag... [2] https://www.tugadvise.com/wp-content/uploads/2015/10/lloyds-open-form-report-2014.pdf https://www.tugadvise.com/wp-content/uploads/2015/10/lloyds-...
- currymj 6y agoi tried writing some toy Ethereum smart contracts circa 2016. at that time it was immensely difficult to write them in a secure way -- even a simple "hello world" level Solidity contract could easily have exploitable bugs if you don't code in an extremely defensive style. i'm told things have improved since then -- can anyone who's used Solidity more recently comment on this? is it true? this, plus the fact that putting information from the real world onto the blockchain unavoidably requires some trust, seemed like the two big problems then, and it seems like they haven't really been fixed.
- vvpan 6y agoWell, what are the fixes? Writing "smart contracts" is not meant to be for anybody but very seasoned developers. Also if you write a contract and do not get it audited by 3rd parties than nobody will (or should) take for anything other than a toy application. That's just the nature of writing immutable code that potentially transfers a value. About Solidity in particular - I think most people would say it's not the best. There are endeavors to develop better languages but Solidity has become quiet deeply entrenched in the Ethereum world. Everybody is busy with much more pressing issues - like scalability.
- finnh 6y agoI've posted this before [0], but it's still apropos regarding the foolishness that is Ethereum. [Ethereum] only makes sense if all of the following obtain: (a) the code is 100% bug-free (b/c accidents cannot be rewound) (b) all code-writers are 100% honest (their code does what they say) (c) all contract participants are 100% perfect code readers (so as to not enter into fraudulent contracts) (Strictly speaking, only one of (b) and (c) needs to be true). None of these conditions will ever obtain. [0] https://news.ycombinator.com/item?id=14471465 https://news.ycombinator.com/item?id=14471465
- vvpan 6y agoAnd yet the marketcap of the funds locked in a subset of contracts on Ethereum is almost 10 billion today (https://defipulse.com/ https://defipulse.com/) and I have been using a popular contract wallet for a while to hold my funds and transact with friends. So clearly it cannot be nearly as catastrophic as you mention, no?
- snake_plissken 6y agoI still don't understand what's happening at the core of this and the other dark forest post from a few weeks ago. How exactly are these bots front-running/stealing the ethereums? My understanding: -these bots scan the smart contracts that are waiting to be executed by the miners -the bots find vulnerabilities (another grey area in my mind) in the contract -the bots adjust the destination address of where the contract is supposed to send the the ethereums -then the bots continually execute the vulnerable smart contract code
- schoen 6y agoMy understanding of the front-running issue in these two cases is that a human being found vulnerabilities in particular smart contracts, which would allow anyone to claim the value protected by a particular contract. The human beings wanted to use these vulnerabilities to transfer the value somewhere, such as to an escrow account or to the original owners of that value. However, since the vulnerabilities allow anyone to do this, the front-runners could take this value for themselves by noticing the humans' attempt to execute the transactions, and then more quickly executing the exact same transaction with a different destination. You can't take advantage of a "normal" cryptocurrency transaction this way because the "normal" transaction is like a super-minimal smart contract that's designed to pay only one hard-coded recipient. Therefore, that transaction either happens or doesn't happen, but its recipient can't be altered. Nor can you take advantage of a non-vulnerable smart contract this way, because the non-vulnerable smart contract can't be triggered to perform an action that its creators would consider inappropriate. But for a vulnerable smart contract, there's a series of events that would cause it to send value to an arbitrary address (and not in exchange for some other adequate compensatory value). It's this case where the front-runners want to find a way to swap in their own addresses for these transactions, and that's also why obfuscation could deter that -- making it hard for the front-runners to notice that that was possible.
- AgentME 6y agoI think it's an important detail to point out that legitimate transactions mostly aren't vulnerable to the "Dark Forest" issue. A lot of comments I'd seen on the original "Ethereum is a Dark Forest" blog post seemed to be under the impression that this was a general Ethereum issue affecting normal users.
- iameli 6y agoLove whitehat crypto postmortems like this. They always read like heist movies. Curious about the use of SparkPool to bypass the mempool and get the transactions minted directly into a block. It looks like anyone can sign up and contribute their hashrate to SparkPool. Is there a risk of malicious miners running workers in their competitors' pools and then frontrunning?
- bodski 6y agoAFAIK only the pool operator can see the full set of transactions for the block being mined. Pool workers only get to see the block header for the new block. This header only contains the hashed root of the transaction tree, and so they are unable to front-run private transactions in this way.
- iameli 6y agoThat makes sense, ty
- sneak 6y agoI offer that anyone who did the work that these researchers did would have also been “rightful owners” of that money. This is the consequence of programmable money; there’s no getting around it, and, in my opinion, people shouldn’t want to. Rescuing people and brands who don’t put the effort into security from the consequences of their own mistakes isn’t a net benefit. I'm all for anonymous teams, but look at the hoops this person had to jump through just to get in touch with them to report the bug. When you're anonymous, all you have is your brand, and theirs should have burned to the ground for this entirely preventable error.
- lukev 6y agoI agree with this. The whole "value" proposition of cryptocurrency is that there is no governing authority, no undo, no takebacks, the code is the only law. If that's _not_ what you want, you should 100% be using a bank instead. All that "rescuing" people who have fucked up does is make the system seem more artificially reliable than it is. Providing a failsafe to people who have very deliberately and explicitly eschewed failsafes (at extreme effort and by subverting the system itself, no less) seems rather pointless and paternalistic.
- huac 6y agointeresting read - seems like the solution to the dark forest is equivalent to a dark pool in traditional finance? the logical conclusion is that within a few months we'll have dark pools run by miners who will process your transactions without broadcasting to mempool, in exchange for an increased gas fee. and, within a year, we'll find out that some dark pools sold order flow to those HFT's anyways, a la UBS https://sites.law.berkeley.edu/thenetwork/2015/01/29/ubs-dark-pool-leads-to-14-5-million-in-settlement-paid-to-sec/ https://sites.law.berkeley.edu/thenetwork/2015/01/29/ubs-dar...
- centimeter 6y agoIt seems to me that basically no cryptocurrency outside of Bitcoin has its shit together.
- pavlov 6y agoNice work, but honestly I'm not sure why they bother. The article states that the purpose of these smart contracts is: "Stake your tokens with us and you could be the next cryptocurrency millionaire" That's an obvious scam. Anyone who gave real money to such a cause has already lost it. So why is the author giving away his time to help the scammers?
- SiempreViernes 6y agoFor the glory? Because even chumps deserve justice? Because someone needs to defend the reputation of digicoins?
- asdfasgasdgasdg 6y agoTwo things: if digicoins have a deservedly bad reputation, maybe it shouldn't be defended. And: if this is defending their reputation I'd hate to see what attacking it looks like. I have never wanted less to be involved in cryptocurrency or been more skeptical of it's future than now having finished reading this article.
- mlang23 6y agoSame here. Having read this article, I know why I never wanted to have anything to do with cryptocurrency. Its a scam all over the place.
- rsync 6y ago"Stake your tokens with us and you could be the next cryptocurrency millionaire" Forgive me - I thought that was tongue in cheek ? I thought the op was humorously paraphrasing some current, popular trend in ethereum contracts ? No ? That's the actual function of these contracts ? Can someone point me to one of these in the wild where I can see the actual pitch / advertisement ?
- falava 6y ago> Can someone point me to one of these in the wild where I can see the actual pitch / advertisement ? https://uniswap.org/blog/uni/ https://uniswap.org/blog/uni/
- superkuh 6y agoI guess the take away here is that if you have the right connections then you can bypass the system.
- larzang 6y agoRight? Forget bugs in the contract system, if you have pools writing whatever history they want in private that seems to defeat the entire point.
- zxcmx 6y agoThe transactions still have to be valid (accepted by majority) to get consensus. It's just that some subset of valid transactions are exploiting vulnerabilities in poorly written contracts. In this case, you want to make dead sure that your "good" exploit runs first. This is not usual.
- superkuh 6y ago>This is not usual. I agree. Due to specialized compute taking over mining and economies of scale most cryptocurrencies don't do what they say and are manipulated by their big pools (like this) consistently.
- ve55 6y agoVery interesting story, it really does sound like a scifi thriller to me. It also makes me wonder what type of legal battle would ensue if a blackhat were to have taken all of these funds instead, I'm not sure I've seen any public high-profile cases like that yet.
- wins32767 6y agoOne of my good friends has a saying, "Humans are really good at optimizing the hell out of the wrong thing." I can't help but think that when reading about any sort of heroics involving blockchain.
- NKosmatos 6y agoNice read! That’s why I respect whitehat hackers, to be tempted by ~10million and then proceed doing the right thing. I wonder if they got a reward/bounty for managing to save all this ETH.
- vvpan 6y agoIf anybody would like more intense blockchain story-telling check out this longish write-up about Justin Sun's takeover of Steem.it from a few weeks back. https://decrypt.co/38050/steem-steemit-tron-justin-sun-cryptocurrency-war https://decrypt.co/38050/steem-steemit-tron-justin-sun-crypt...
- johannes1813 6y agoI clicked on this really hoping it was related to the Fermi Paradox.
- deleted 6y ago[deleted]
- stackzero 6y agocryptocurreny != investment scam. It's just another way to transfer and store value. Interacting with automated contracts is an interesting extension to that system which can make things alot more complex. The 'dark forest' comes from a kind of man-in-the-middle attack where anyone can see the order book and exploit it, by putting their own slightly better orders in. Hence the need for co-operation with a closed order book (miner) to get the transaction in safely.
- askmike 6y agoI quickly want to point out that we've recently seen a surge in uniswap/bancor based "liquidity pools" (all projects copying each other). The main idea here is that you can lock up your crypto in a smart contract - which is considered "secure" as to no one can steal it (audited code by reputable companies and such). If true the risk is very small with things like impermanent loss, which doesn't apply to all pools. The idea here is that your money is provided liquidity and you'll get paid a portion of the fees as well as some new token which can have a very high value (for a fleeting moment). This is important to realize when looking at the crazy marketing around these projects, if it's based on uniswap you can reasonably sure your principal won't get stolen - regardless of the scammy and weird marketing.
- clay-dreidels 6y agoAll this research into smart contracts and crytpocurrency may seem pointless and a waste of time. It is very risky to dabble in, and I don't think assigning value to these "bitcoins," or whatever they may be called, will be the lasting effect of all this research. Perhaps some new programming language, or something we haven't even thought of, could be the result of these people working on the outer edges of current knowledge.
- ecmascript 6y ago"Smart contracts" has always seem incredible dumb to me. Code that controls how money being transferred that cannot be updated or changed even if a bug is found. Awesome design. It is like the opposite of what I would want to control my money in any transaction.