They should not know what have I bought with my own money. I earned the money by working as a free person, not a slave. Money is for freedom and money should benefit the user, not some centralised banks 🏦.
They could combat all terrorist and nefarious activities if they wanted to do so. But they are not doing. They are trying to bring this narrative in that it is for the safety of the public, but it is all about control. More and more control every single day.
All the while they have the capabilities to use technologies like cryptography and blockchain which enables free trade, permissionless spending, composability, authenticity by DESIGN.
First and foremost all public institutions should have all their spendings public, that is why they are called public. A fun fact that most politicians and public officials will use cash, just because that gives them privacy.
We do not want central bank to have absolute control. Europe forcing this is a bigger story than tariffs. No for CBDCs.
Visualize this: At a shop, you hand a $20 bill for a $10 item. The merchant gives you the item but keeps the surplus, leaving you shortchanged.
❓ That would be totally unfair, right?
In Web3, sandwich attacks follow a similar pattern and hurt regular users at a rampant scale. The damage likely amounts to billions of dollars annually.
So, what can be done to minimise this industry-plaguing issue? But first, what really happens behind the curtain for a better view. Sandwich attackers:
1) Monitor public mempool data
2) Identify pending inefficient trades w/ fat slippage
3) Frontrun with priority fee
> this pushes the price up closer to the slippage limit of the victim, who ends up with fewer tokens received
4) Backrun in quick block succession
The attack’s effectiveness is tied to how probable a successful frontrun is.
Validators are incentivized to prioritize transactions with higher fees, which is a normal game theory behavior.
However, the unfair advantage comes when the prioritisation is also applied to the execution order within the block.
❗️At MultiversX, we see this as the root problem and the key to addressing it.
To make sandwich attacks and other harmful MEV types less feasible, we’ve implemented deterministic random transaction ordering since 2022.
With it, validators no longer have control over arranging and sequencing transactions. The randomness source is unbiased, verifiable and taken from the previous block header.
Try a sandwich attack on MultiversX and, by chance, you might end up being the one sandwiched 🤭
Quick review two years+ post-implementation:
i) Bad MEV is a flaw, not a feature, and is solvable to a high extent
ii) Sandwichers are not risk averse and avoid low-probability environments
iii) TX randomness introduced unpredictability → raised cost to attack → reduced profit margins → drastically discouraged & minimized bad MEV on MultiversX
iv) Users interact on-chain without the fear of invisible taxes
v) Trust in on-chain markets is higher
In certain industry circles, MEV is glorified and — checks notes — ripping off users is considered the only metric that matters.
So it inevitably cheers us up to see that we are not alone in fighting to make user safety a priority in Web3.
Well done on the progress @cz_binance & @BNBCHAIN!
This is exactly the reason why centralised entities in crypto won’t let us have nice things.
“I believe insiders like this person who took $200m worth of 50x leveraged longs probably knows what it is.”
This is maddening, it puts everything which is wrong today in blockchain development into one single place.
Web3 was started as this fully trustless, decentralised, permissionless, composable new internet.
L3s on top of already centralised L2s is driving the space back to web2, with the web of trust between people and projects. No more trust in code, but trust in people and permissioned access to everything. Cascading trust assumptions will kill everything.
Please stop with this.
L1 can be scaled. L1 is scaled. Build on L1, it is cheaper, faster, much more secure and you get all the network effects.
Get back to fundamentals, use L1s and scale L1.
Increase capacity, reduce latency, but stay with fundamentals, stay on L1, stay where security is.
A few comments on the attack:
1. EVM is not secure 🪓, like literally after all these years it is shown to us at every hack how many security vulnerabilities are there. And it is so sad that nobody wants to do a thing. Outsourcing security to higher layer is not good, not need better primitives.
2. DelegateCall, Upgrade Via Proxy, just brings in thousands of backdoors, thousands of problems. Like, literally if everyone needs an upgrade, why not make contracts upgradable with a clear function. Not the delegateCall stupidity, which has so many design falls.
3. Almost all of the so called “L2s” have similar design of multisigs and contracts upgradable via proxy and delegateCall. So everyone using L2s is actually at the mercy of the Lazarus Group, whether they attack those or not.
4. This is not the first MultiSig attack or similar one. We have seen bridges compromised by these, where hundreds of millions were lost. 😞
5. Even after all these years, all these hacks, EVM remains unchanged. Totally wrong. You cannot outsource security vulnerabilities to others. And all integrators are still requesting for “EVM compatibility”. So mad at the state of this
How MultiversX solves these issues?
1. Contracts can be set to upgradable/non upgradable. Fully programatic upgradability, with clear function which calls the update of code, no delegateCalls.
2. The Wallet can actually interpret and show what the user is going to execute. In a clear message. Even txData is easily readable by human eyes. The final signature is done directly from the wallet which clearly shows out what are you going to sign, like Update/Transfer/Execute or any combination.
3. No ugly txData which is hard to decipher.
4. No ERC-20 token standards, no smart contract based token standards, no approve and transferFrom mechanism, but everything is native assets, everything is clear around TransferAndExecute atomically.
5. On-chain guardians for every wallet, thus you have an extra layer of security, which can be linked to any cold wallet, which again shows out clearly what you are going to sign.
6. Against, the wallet interprets and explains what you are going to sign, as a manifest, in clear english.
All systems with multiSigs, especially on EVM are in danger. ⚠️ Most L2s have this sort of MultiSig and delegateCall and proxy update. So billions are at risk. And people still praise EVM, just don’t get how and why.
Exciting to see two talented Romanians, Octavian Lojnita (Blockchain Lead) and Bogdan Purnavel (Lead Developer), part of Donald Trump’s DeFi project ‘worldlibertyfi.’ @worldlibertyfi
I have the opportunity to connect MultiversX with one of them for discussions about the future of blockchain. Let’s build the next chapter of innovation together!
@beniaminmincu@xAdamBates@MultiversXUSA@MultiversX