@optimizoor Same. Curse of productivity. The only things I can enjoy lately are short animes due to the low amount of time they require. Otherwise, it's the thought of: 'I am wasting "x" amount of minutes'.
Pains me to see so many people agree with something that misses the point. It doesn't surprise me, though. This ecosystem, as a whole, has lost its essence.
With respect, I found @ErikVoorhees' keynote to be jejune, anti-democratic, and disingenuous. It may be effective as a rallying cry for libertarians, but as a strategic framework for the global adoption of crypto, it is so divorced from reality as to be worthy of ignoring.
The speech's strongest points centered around the notion that "code is better than law." There is merit to the claim that transparent, mathematically-based rule-making can yield superior results to an opaque, politically-based process. I also agree with his characterization of the right to transact as fundamental to human existence.
However, I disagree with the perspective that American democracy is so deserving of disdain as to be rejected. Voorhees' conflation of the "state" as a single entity ignores the variety of political systems across the world and their relative levels of freedom. Democracy is categorically better than totalitarianism, and to reduce both to the machinations of men with "dead eyes and weak hearts" is to deny millennia of political progress, as well as the suffering of those under more oppressive regimes than the one Voorhees himself is subject to.
Voorhees' political framework reveals a level of hypocrisy and immediately crumbles when applied to the real world. Does he not comply with the subpoenas issued to him by the regulators he calls out in the audience? Does he not pay the income taxes that he castigates at the beginning of the speech? Would he have the creation of roads, bridges, and highways mediated through smart contracts today? There is a place for decentralized finance; there is also a place for the actions of a centralized state on behalf of its people, and to deny that is childish.
Voorhees says: "The political class... that legion of bureaucrats suckling at the teat of plundered wealth, with all their ornaments of authority, with all their hubris masked as confidence, with the inauthenticity of their smiles matched only by the absurdity of their ideas, and I see no reason to submit to the permissions under which they seek to restrain me. To such people, we owe nothing."
The reality is that Voorhees - and all of us - do submit to these permissions because we recognize the rule of law under a democratic system, arrived at through voting and lawmaking. The process is never perfect; it can even be corrupt; yet, we comply because we have faith that the inclusive political institutions that propelled America to become the financial hegemon will eventually recognize the importance and utility of crypto. It is reasonable and just to seek the consent – i.e., the permission – of the governed; that is democracy.
I strongly question a strategy which alienates all those involved in government as weak-willed and immoral. What does painting with such a broad brush achieve beyond revealing your own biases? In government, like in crypto, there are good people and bad people. We should aim to excise the bad people and have the good people in both spheres work together towards an open, global financial system.
I have much respect for Voorhees as an OG of crypto, and I understand that his perspective is a large part of how crypto came to be as big as it is today. But it is an untenable perspective weighed down by its idealism, dogmatism, and hyperbole and will slow down the adoption of crypto as we approach its next phase of global adoption.
To wholly reject the democratic state is libertarian propaganda and is of no use for the growth of crypto as an open, global financial system. We should instead recognize the merits of democracy and use them to further expand the reach of crypto.
@samczsun this comes to mind:
a) a subtle on-chain message to the deployer and if no answer after a deadline, perform a whitehat rescue anonymously
b) reach out to the devs and coordinate with them what to do, if they don't care, perform the whitehat rescue
1) is to avoid legal risk
2) is to not brick funds
3) is to ease scripting
either way, good writeup, and good on @trust__90 for explaining the situation thoroughly. he's an invaluable agent of the ecosystem and i'm certain there was no ill-intent
small psa:
- don't whitehack without team's consent
- use a fb bundle to avoid the mempool and ensure a tx ends up with the funds. this is due to fb not submitting the bundle if it fails simulation
- if on a ledger, transfer funds to a hot wallet, should take two minutes
People are saying all kinds of terrible things while being uninformed so allow me to share more details.
I've initiated coordination privately with Immunefi officials 3 hours before the white-hack. 90 minutes later, I realized the asset is currently used by the frontend and although the contract is not in scope (which almost certainly means a zero-ish bounty), fully disclosed it to Sushi with a mainnet fork POC. About 30 minutes later Sushi replied saying they are actively working on it. Unfortunately, Immunefi system only sent a mail saying the issue is escalated (automated msg), and not that there's a new message, due to throttling.
The script locating wallets at risk finished and showed 0xsifu has the vast majority of funds at risk. It was ~5:30 AM local time and I saw an option to save most funds. There was incomplete information - I couldn't know if the team would reply before the start of next week. You can't know when an attacker would strike and steal all funds. MEV was a possibility, but didn't imagine it would be this fast and deadly (attack required a callback and had 2 setup transactions). I had a ledger setup so going private mempool would take a long time. I decided to white-hack 100 ETH (to verify I'm not bricking most funds) followed by the rest of 0xsifu and other significant wallets. 99.99% of people have never put themselves in such high-pressure situations and don't know what it's like. I've also factored in that the contract can't be paused and you can't coordinate everyone's revokes, so white-hack is the only real play even for the team.
In hindsight, it was a mistake. But we're all biased with the results in a specific universe where the MEV unknown was worst-case, the team was actually aware, and we don't get a chance to see an attacker taking it all without the white-hack.
Everyone who knows me is aware of the countless millions of $ I've saved in the ecosystem, my ethics, integrity, transparency, and never-ending support and education for new auditors. Seeing some allegations and people bashing me without context is heartbreaking. The only thing keeping me from sinking is support from dear community members and friends.
Let's take the opportunity to improve as a community and formulate clear policies for when white-hacking is the right thing to do (it's usually not) and the exact procedure.
Regarding the 10ETH bounty 0xsifu chose to award me, which seemed to annoy some folks, I'm donating it to the recovery fund. If my intention was to monetize from this hack there were a billion better ways. I'm here for the crypto users and will continue to ethically safeguard them for years to come.
@mitdtest @functi0nZer0 i don't think this was intentional--if it was, i would be shocked. assuming he had the scripts, it would've been way easier to just extract the 1800 ETH claim 10% and not risk anything. i believe this was a case of not thinking well under pressure.
mev is a multi-million dollar game. check eigenphi. bots are advanced. partial recoveries are a bad idea, more so if you expose your transactions in the mempool. better to bundle txs to save as much as possible.
im certain trust meant no harm, but the rescue was reckless
@functi0nZer0 that boggles my mind. it's an rpc call with an array of objects as payload. besides, many of the reported vulnerabities often involve MEV bots. mev-boost readme is only 10 min of reading and you get the overview, 10 more for fb docs.
it's crazy that knowledge is lacking
@optimizoor your own ego is what protects you from other's ego. to me, ego is good as long as it's controlled. too large an ego makes you a shit human, and the opposite makes you too lenient. ego and a bit of trauma can also be a great driver for improvement.
@refcells yes, it's insane. i've stopped bothering with trivial scripting since i discovered how good it can be at producing these.
it's both scary and fascinating how quick it's advancing.
@alphaK3Y Disagree. Natspec should be in both contracts and interfaces. Makes user understanding simpler. Makes auditors do less jumps. It's ensure compatibility with Etherscan. Seaport did it right.
listened to bankless episode with @ESYudkowsky. is there a good, detailed counterargument to his scenario?
had a hard time finding one and if the possibility of what eliezer claims is nonzero, it seems like this should be seriously discussed?
learning to think about what a certain piece of code should do is an overlooked skill. abstraction is not easy. studying formal verification and writing rules seems to be a great way to train this, and can probably give you an edge when it comes to bug hunting.
Did you read all of the post-mortems of 2022? Well, I did it for you and tried to boil it down into a single article.
Made for web3 auditors and bug hunters.
No SEO/marketing bs, just one giant blogpost for you to review at your own pace. Merry christmas! https://t.co/BPYo7QZUYF