Welcome! I, Degen is a podcast about crypto technology, security, and culture. With a healthy balance of enthusiasm and skepticism, we cut through the misinformation and hype in search of a signal in the noise. Our weekly round-up will keep you updated on the latest in crypto hacks and security. With our open-source audio audits, we interview founders and hackers to surface relevant info about how to stay safe in crypto land.
Show Notes--->https://wolfdefi.com/i-degen/e22-ethereum-merge-security-with-david-theodore/
Full show notes --> https://wolfdefi.com/i-degen/e21-gala-games-gets-owned-by-a-whitehat/
Full show notes --> https://wolfdefi.com/i-degen/e20-team-finance-hacked-profanity-hacks-continue/
Full Show notes can be found here.
Be on the lookout for a new I, Degen Sequence on Zeevo in the next few days 😉
Stay up, fren.
---> Full show notes on HackMD <---
I, Degen - E17: OPSEC at DEVCON 6 - 10/06/2022
Listen at: idegen.fm
Contact us: @idegenfm
Intro
Welcome to I, Degen - A podcast about crypto technology, security, and culture. With a healthy balance of enthusiasm and skepticism, we dig into a weekly look at crypto, cutting through the misinformation and hype in search of signal in the noise.
Episode Summary
This week we’ll do our usual weekly review of crypto security-related topics. We’re going to dig into the issue of conference OPSEC, or operational security, as we’re less than a week out from Ethereum’s flagship developer conference, and rumors swirl about security concerns in Bogota.
I,Degen - Weekly Review
Moving on… Usually, we focus on looking back at crypto security-related events of the previous week. I thought maybe we could also highlight any relevant upcoming events each week.
I, Degen - Looking Forward
I, Degen - Deep Dive
A wave of Tweets and some articles surfaced questioning the safety of conferencegoers leading up to Ethereum’s flagship developer conference in Bogota, Columbia, next week.
Veteran Devcon attendees will remember a similar panic from previous events, including Devcon III in Cancun, Mexico, where
Is this FUD or a legit concern? Let’s dig in.
Question: Is this a credible threat, in which there is a concentrated effort to target Devcon attendees, or is this FUD?
If we follow the Tweets, the picture is unclear.
This year Devcon security panic seems to have started with news outlets picking up a tweet from crypto_mackenna.
However, it’s worth note the article in question doesn’t mention Crypto_McKenna follow-up Tweet reply on that same day which balances the original Tweet.
Also, some sensational crypto influencer tweets that we’ll ignore. Mainly because they are purely opinion based, don’t provide any credible evidence of a threat, and are likely just ego-feeding clout farmers. I mention them because it is essential to understand and acknowledge that they play into the overall perception and conversation, even if they hold little substance and merit.
Staying safe at Devcon in Bogota Twitter threads:
-@camiinthisthang
Good OPSEC at conferences in general
While those are important and contain good information relevant to staying safe in Bogota, I thought it might be helpful to dig deeper and tap into the wealth of existing information on conference OPSEC.
OPSEC for Defcon #1 from Darkangle.net
Before we continue, you should understand that everyone’s security needs are not the same.ZW: What is the personal threat model? Most crypto people don’t need to defend against nation states.
ZW: Physical access to a device opens a lot of new threat vectors and can make things a lot easier for an attacker.
ZW: take inventory of what’s on your devices. Leave your noods at home…
ZW: Ensure your OS, browsers, and wallets are fully updated. It’s much easier to attack outdated software.
ZW: You should have your HDs encrypted or know they are trivial to access.
Some devices will retain a history of SSIDs that they have connected to. If your device is set to connect to an access point automatically, it may send multiple probe requests containing an SSID that you have previously connected to. This can be used to set up a rouge AP, and force your device to connect to it.Unless you are using a access point, it is recommended that you leave your wi-fi feature disabled. When connecting to new access points, ensure that you will not be connecting to them automatically.1. Use a VPN 2. Use E2E apps ZW: Use end-to-end encrypted apps for chatting, like Signal
For the uber-paranoid…
OPSEC for Defcon #2 specfically, this comment:
Leave all tech at home RFID shieldsWrapping it all up
I, Degen - Freestyle Convo
ScamLikely…
On any given day now, I receive more Spam Likely calls than I do real/legit calls. While this anecdotal observation is likely specific to my number, how common is this? Nocoiners often point to the epic number of scams in crypto, which is no doubt a severe problem, but other technologies are free from spam/scams, either. This is a modern problem across various mediums. Crypto is newer and has a more direct path to profits, so it’s awful.
FCC threatens to block calls from carriers for letting robocalls run rampant
The seven companies have two weeks to address the agency’s concerns. Otherwise, compliant carriers will have to block their incoming traffic.I, Degen - Personal Hack Attempt of the Week
Hunt: online weed in Bogota scam…
[[[Outro]]]
We do our best to report accurately on the topics we discuss but we’re not always going to get everything right. Please comment here or reach out to us @idegenfm with corrections or comments!
Select or create a markdown file
Listen at: idegen.fm
Contact us: @idegenfm
Intro
Welcome to I, Degen - A podcast about crypto technology, security, and culture. With a healthy balance of enthusiasm and skepticism, we dig into a weekly look at crypto, cutting through the misinformation and hype in search of signal in the noise.
Episode Summary
This week we discuss the draft of the US House’s Stablecoin bill. CFTC’s 250k fine for BzX & the Ooki DAO. We talk about the 0xBAD MEV bot getting owned, and we dig into the recent paper on reversible ERC20 and ERC721 transactions.
I, Degen - Weekly
NOTE: This is an early draft, not final so take it for what it is.
–>coindesk 3. Terra Luna Saga Continues --> Interpool issues arrest warrant for Do Kwon 4. Reddit user claims Gemini shut down their account because the interacted with Wasabi BTC Mixer 5. Lazarus Hacker Group targets MacOS users with fake crypto.com jobs postings 6. China busts ring of 93 people for allegedly laundering more than 5B * 9.15 Gang * 4 years of operation * The group, in operation since 2018, also facilitated the cashing of illicit funds from fraud, gambling, and other crypto-related activities into U.S. dollar to eliminate traces of illegality. 7. Binance launches Global Law Enforcement Training Program to help LE fight cyber crime 8. 0xBAD MEV Bot gets owned
I, Degen - Deep Dive
Tracking separate doc with notes for ERC20R stuff here
I, Degen - Freestyle Convo
Dear Redditors: If you torture the data long enough, they will confess anything
First Chess, now Poker…
I, Degen - Hack Attempt of the Week
Github Key Scraper - This is not new, but never a bad idea to have a reminder: Be careful what you commit to your repos.
[[[Outro]]]
We do our best to report accurately on the topics we discuss but we’re not always going to get everything right. Please comment here or reach out to us @idegenfm with corrections or comments!
Full show notes on hackmd @ https://hackmd.io/@idegen/E16-Reversible-ERC20-ERC721
Listen at: idegen.fm
Contact us: @idegenfm
Intro
Welcome to I, Degen - A podcast about crypto technology, security, and culture. With a healthy balance of enthusiasm and skepticism, we dig into a weekly look at crypto, cutting through the misinformation and hype in search of signal in the noise.
Episode Summary
In this episode, we hunt for Do Kwon and look at the White House’s comprehensive framework for the responsible development of digital assets. Then we look into Wintermute’s 119M key generation issue. We discuss emerging post-merge Ethereum narratives and the Omni bridge replay attack. We also get into an IRL customs scam for our hack attempt of the week.
I,Degen - Weekly
The wanted crypto developer Do Kwon, who is accused of fraud by investors following the $45 billion (€45 billion) collapse of his cryptocurrencies Luna and TerraUSD, is reportedly trying to evade South Korean authorities.Prosecutors have accused Kwon of financial fraud, arguing that his terraUSD stablecoin was a kind of investment security under South Korea’s capital markets act [2]Kwon moved from South Korea to Singapore, where the now defunct stablecoin issuer Terraform Labs, which he co-founded, has a base. However, Singapore Police Force said on Saturday he is currently not in the city-state.South Korean prosecutors told Bloomberg in a text message on Monday that there has been “circumstantial evidence of escape” since he left Singapore. The media outlet said prosecutors declined to comment on whether the office knows of Kwon’s whereabouts or if it will contact the international police agency Interpol.Last week, Kwon was charged with violating the Capital Markets Act, and an arrest warrant was issued for him and five allegedly connected to the case who were believed to be in Singapore.
–EuroNews1. White House Releases Comprehensive Framework for Responsible Development of Digital Assets
Over the past six months, agencies across the government have worked together to develop frameworks and policy recommendations that advance the six key priorities identified in the EO: consumer and investor protection; promoting financial stability; countering illicit finance; U.S. leadership in the global financial system and economic competitiveness; financial inclusion; and responsible innovation.The nine reports submitted to the President to date, consistent with the EO’s deadlines, reflect the input and expertise of diverse stakeholders across government, industry, academia, and civil society. Together, they articulate a clear framework for responsible digital asset development and pave the way for further action at home and abroad.Protecting Consumers
Still sellers commonly mislead consumers about digital assets’ features and expected returns, and non-compliance with applicable laws and regulations remains widespread. One study found that almost a quarter of digital coin offerings had disclosure or transparency problems—like plagiarized documents or false promises of guaranteed returns.The reports encourage regulators like the Securities and Exchange Commission (SEC) and Commodity Futures Trading Commission (CFTC), consistent with their mandates, to aggressively pursue investigations and enforcement actions against unlawful practices in the digital assets space.The reports encourage Consumer Financial Protection Bureau (CFPB) and Federal Trade Commission (FTC), as appropriate, to redouble their efforts to monitor consumer complaints and to enforce against unfair, deceptive, or abusive practices.The reports encourage agencies to issue guidance and rules to address current and emergent risks in the digital asset ecosystem. Regulatory and law enforcement agencies are also urged to collaborate to address acute digital assets risks facing consumers, investors, and businesses. In addition, agencies are encouraged to share data on consumer complaints regarding digital assets—ensuring each agency’s activities are maximally effective.The Financial Literacy Education Commission (FLEC) will lead public-awareness efforts to help consumers understand the risks involved with digital assets, identify common fraudulent practices, and learn how to report misconduct.Advancing Responsible Innovation
The Office of Science and Technology Policy (OSTP) and NSF will develop a Digital Assets Research and Development Agenda to kickstart fundamental research on topics such as next-generation cryptography, transaction programmability, cybersecurity and privacy protections, and ways to mitigate the environmental impacts of digital assets.Quite a bit more to the report.
And the Forbes Headline reads…
Joe Biden Just Sent A Stark Warning To Bitcoin And Crypto After $2 Trillion Price Crash
What is your narrative?
What do the machines think?
Let’s start with a story that broken on September 14th. 1Inch, a dex aggrator protocol’s community discovered an issue with Profanity, a Ethereum address generator tool
Even worse, the possibility of this issue was raised on the Profanity Github on January 17th, 2022.
Why didn’t Wintermute act when the Profanity issue was raised with proof six days ago? Well, the did:
Around the time that the disclosure happened, Wintermute removed all ether from an admin address which suggests that they realized it might have been vulnerable. However, they forgot to remove this address as an admin from their vault.The attacker is likely a seasoned hacker/solidity developer. They created a helper contract, deposited stables into curve to avoid blacklisting, and figured out this vulnerability in a closed sourced vault contract in the first place.
–Mudit’s BlogThe stolen funds were mostly various stablecoins, totalling $118.4M. The majority of these were deposited into Curve’s 3pool, presumably in an attempt to avoid any blacklisting.The exploiter is now the 3rd largest holder of 3CRV with over 13% of the supply.I, Degen - Deep Dive
Reflecting on the merge ETH?
Ethereum itself
Social Attacks - Narrative-based attacks in crypto. We tend to think about FUD as a person or small group spreading disinformation, but with crypto it seems we have more large-scale coordinate narrative-based attacks. For example,
“Only 2 addresses control 46% of all ETHs PoS” - Santiment Tweet
–Beaconcha.in
Flashbots does build the vast majority of relay blocks… but all relay blocks only make up less than 20% of the network … so, it’s missing the much more interesting point, which is that surprisingly few validators are using MEV Boost at all.
–r/EthstakerHowever:
Larger Ecosystem Impact
According to the security researchers, the attacker first transferred 200 WETH through the Omni Bridge and then replayed the same message on the PoW chain, getting an extra 200 ETHW.In short, the root cause of the exploitation is that the Omni bridge on the PoW chain uses the old chainId and doesn’t correctly verify the actual chainId of the cross-chain message. Besides, the similar issues may exist in other protocols.From Peck Shield - Seems like @EthereumPow
suffered a replay attack. $ETHW has dropped -12%. Be Alert
I, Degen - Freestyle Convo
Crypto(graphy) guru Bruce Schneier on the Crypto/Blockchain Disaster
I, Degen - Other Stuff
I, Degen - Personal Hack Attempt of the Week
Central American customs shakedown
[[[Outro]]]
We do our best to report accurately on the topics we discuss, but we’re not always going to get everything right. Please comment here or reach out to us @idegenfm with corrections or comments!
Show notes at: https://hackmd.io/@idegen/E15-wintermute-key-generation-lesson
I, Degen - E14: All Eyes On Ethereum - 9/11/2022
Listen at: idegen.fm
Contact us: @idegenfm
Full show notes with images on HackMD - https://hackmd.io/@idegen/E14-All-Eyes-On-Ethereum
Intro
Welcome to I, Degen - A podcast about crypto technology, security, and culture. With a healthy balance of enthusiasm and skepticism, we dig into a weekly look at crypto, cutting through the misinformation and hype in search of signal in the noise.
Episode Summary
All eyes are on Ethereum - we are now less than four days out from the merge. We’ll talk about some possible scenarios the merge might bring and what you can do to stay safe during the merge. We’ll also look into recent updates on the Tornado Cash sanctions, a new report on fraudulent crypto trading volume, and other crypto security-related news.
I,Degen - Weekly
Cryptosphere
The U.S. Commodity Futures Trading Commission defines wash trading as “entering into, or purporting to enter into, transactions to give the appearance that purchases and sales have been made, without incurring market risk or changing the trader’s market position.” The reason why some traders engage in wash trading is to inflate the trading volume of an asset to give the appearance of rising popularity. In some cases trading bots execute these wash trades in tokens, increasing volume, while at the same time insiders reinforce the activity with bullish remarks, driving up the price in what is effectively a pump and dump scheme. Wash trading also benefits exchanges because it allows them to appear to have more volume than they actually do, potentially encouraging more legitimate trading.“Fraudulent or non-economic”
The biggest problem areas regarding fake volume are firms that tout big volume but operate with little or no regulatory oversight that would make their figures more credible, notably Binance, MEXC Global and Bybit. Altogether, the lesser regulated exchanges in our study account for approximately $89 billion of the true volume (they claim $217 billion).On Forbes method:
We apply volume discounts based on a proprietary methodology that relies on 10 factors such as an exchange’s home regulator if any and volume metrics based on an exchange’s web traffic and estimated workforce size.So, private trading firms numbers are being grok’d by proprietary methodology.
Worth note, the Bitwise Study from early 2019 said 95% of BTC trading was fake… so it’s getting better.
In case you’re interested in this topic, here is another nice paper from 2019 that talks about fake BTC trading
Launched in August, the unit will help combat crypto criminals by targeting their assets and providing investigative tracing capability and insight to other AFP authoritiesThe new crypto unit will operate as part of its Criminal Assets Confiscation Taskforce (CACT), which has been seizing illicit crypto funds since 2018, but without a dedicated standalone teamThe Australian Federal Police have confiscated over AU$600 million (US$408 million) in illicit funds and property since 2020, and though the amount of crypto funds seized were small compared to “traditional” criminal assets, the additional focus helps provide intelligence insights1. Solana didn’t go down this week - high TPS spike that might have caused a network outage before, didn’t cause one this time. 2. September 5th withdrawals frozen at crypto mining firm Poolin because of a lack of liquidity - From theBlock.
Poolin, one of the world’s biggest crypto mining pools, is suspending bitcoin and ether withdrawals from its wallet service due to “liquidity problems.”And now, from September 9th Bitcoin hash rate cut in half as miners leave
This is significant because 1) Poolin is a China-based mining pool service, operating in China after the mining ban, and 2) the pool was estimated to have roughly 10% of the hash rate before withdrawals were suspended.1. Flash Loan used against single NXUSD market on Nerus
At approximately 10:30PM UTC on September 6th, the Nereus team notified the community of an incident through the community discord; this was later picked up by CertiK and other on-chain analysis groups and reported broadly as a flash-loan exploit resulting in a $371k gain.An exploiter was able to deploy a custom smart contract and that leveraged a $51M flash loan to manipulate the AVAX/USDC Trader Joe LP pool price for a single block resulting in the ability for the exploiter to mint 998,000NXUSD against ~$508k worth of collateral.In the hours that followed, Nereus quickly consulted security experts, developed a mitigation plan, and notified law enforcement to support efforts. In response, the Nereus team has mitigated the exploit by liquidating and pausing the exploited JLP market.The team has also paid off the bad debt using NXUSD from the Team’s treasury. No users funds are at risk, and NXUSD continues to be over collateralised.In addition, no part of the lending and borrowing protocol was ever at risk.1. Tornado Cash Sanctions Update * 1. Coinbase Bankrolls Suit Against Treasury Department over Tornado Cash Sanctions - Basis/premise is that OFAC is overstepping because a smart contract is not a person or org. * This CNBC article is quoting the ‘7B laundered using TC’ which as we’ve discussed is not an accurate number. * some members of the suit have coins locked in TC 1. Base Layer Neutrality Sept 8th, from Paradigm * On August 8, 2022, the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) added certain Ethereum addresses associated with Tornado Cash, an open-source privacy protocol on Ethereum, to the Specially Designated Nationals and Blocked Persons List (SDN List).2 Since the announcement, many participants in crypto’s base layer have expressed concern that they could be required to monitor or censor blocks involving SDN List addresses to comply with sanctions, jeopardizing the neutrality of the base layer and compromising its integrity and core functionality. However, we believe that under current OFAC guidance, base layer participants are not required to monitor or censor these addresses as part of a risk-based sanctions compliance program. * Specifically, while the application of sanctions law to decentralized blockchain systems and smart contracts presents novel legal issues, we believe the Tornado Cash sanctions and blockchain address sanctions imposed to date should not require blockchain technology infrastructure providers including builders, pool operators, relays, searchers, sequencers, and validators to monitor or censor transactions that involve blocked addresses. 1. Tether will not block Tornado Cash addresses (yet) [1] 2. [1. Tornado Cash dev Alexey Pertsev alleged links to Russian FSB] [2. - The Actual Report] [3. - US Treasury Press release from 2018] 3. Digital Security was designated pursuant to E.O. 13694, as amended, for providing material and technological support to the FSB. As of 2015, Digital Security worked on a project that would increase Russia’s offensive cyber capabilities for the Russian Intelligence Services, to include the FSB. * *Alexy worked at Digital Security in 2017 2. August 29th, Solana DeFi Exchange Optifi Bricks Itself By Running Solana Shutdown Program Command During Upgrade and Loses 661K
@OptifiLabs
Other Stories of Interest
I, Degen - Weekly Deep Dive - All Eyes on Ethereum - What need to stay secure during the merge
Respond, Don’t React - It could get crazy, don’t panic.
Should I move my coins to an exchange? No, why would you?
Some info from Decrypt on what to expect with NFTs around the merge
If you’re not an advanced user willing to take on the high risk, your best is to do nothing.
I, Degen - Other Random Stuff
Reminder, guys, never take yourself too seriously. This is pretty funny…
I, Degen - Personal Hack Attempt of the Week
Email enumeration for Zeevo:
What’s going on here? Either bot building a list for marketing spam or email address enumeration for phishing attack?
What’s not show in the screen shot is email addresses they were sending too. They were not random but instead lined up with accurate shortend verisions of my name. That would imply manual operation behind the probe or that the data was scraped and fed to a bot. I kind of suspect the latter and have a hunch it was from Angel list’s website but that’s just a guess.
[[[Outro]]]
We do our best to report accurately on the topics we discuss but we’re not always going to get everything right. Please comment here or reach out to us @idegenfm with corrections or comments!
Select a repo
I, Degen - Episode 13 - Open Source Audio Audit with Kevin Seagraves & Zach Herring from Niftyapes.money
If you have a moment, please check out episode 13 I, Degen sequence on Zeevo. Give your feedback on the show, and we'll mint you a custom token of appreciation 🙏
Listen at: idegen.fm
Contact us: @idegenfm
Intro
On this episode of I, Degen we chat with Kevin Seagraves and Zach Herring from Niftyapes. They recently came out of stealth mode to launch their NFT lending platform and bravely agreed to an open-source audio audit with us.
Welcome to I, Degen gentleman, and thanks for taking the time to chat with us. Before we jump into the audit, can you tell us a bit about yourselves and what NiftyApes is?
Intros Kevin Seagraves & Zach Herring:
Who are we talking to?
Tell us about your background and how you built an NFT lending platform.
For KS: Can you tell us more about your work with ETHSecurity?
Hunt questions:
Intro NiftyApes:
Open Source Audit:
Security audits are expensive and rarely a priority for founders. This is especially dangerous when it comes to Defi apps and protocols, given the natural ability of an attacker to take something of value.
The idea for our Open Source Audit is to help others learn about securing a crypto project by asking some questions about how you’ve approached the security of the Niftyapes.
KS: we only store tx receipts in DB after a tx has taken place and been confirmed, so the attack surface for us on Web2 is low.
3(b). Have you taken steps to ensure your DNS records are secure?
“The NFT lending platform BendDAO has collateralized almost 3% of the entire Bored Ape collection, and many NFTs have recently entered the “danger zone” of liquidation.”ZW: Would this kind of thing be a potential problem on Niftyapes too?
ZW: Are you tracking any risks related to game theoretic bugs? For example like, Flash Loan attacks?
Outro Questions:
Contact Info for NiftyApes
You can find more info about NiftyApes on their website niftyapes.money or their Twiiter @niftyapes.
You can find Kevin Seagraves on Twitter [@captnseagraves] (https://twitter.com/captnseagraves) and Zach Herring @zherring
Full show notes on hackmd can be found here.
I, Degen - E12: Ethereum Fights to Remain Censorship Resistant - 8/24/2022
Listen at: idegen.fm
Contact us: @idegenfm
Intro
Welcome to I, Degen - Each week, we track down and explore the most exciting crypto stories. Hacks, mysteries, exploits, and anything that feeds our crypto curiosity. We dig in, cutting through the misinformation and hype in search of a signal in the noise.
Episode Summary
This week we have a bunch of weekly news updates. Then we take a deep dive into the upcoming Ethereum merge and rippling effects on Ethereum protocol level censorship from the OFAC Tornado Cash sanctions.
I,Degen - Weekly Stories
1.The Chicago Mercantile Exchange (CME) Group will launch Ethereum option contracts on its platform on September 12. The company announced that it’s waiting for regulatory review, and if approved, these new investment products will join its ETH futures and mini futures contracts.
2.Alleged Russian Money Launderer Extradited from the Netherlands to U.S.
According to court documents, Dubnikov and his co-conspirators laundered the proceeds of ransomware attacks on individuals and organizations throughout the United States and abroad. Specifically, Dubnikov and his accomplices laundered ransom payments extracted from victims of Ryuk ransomware attacks.3.Reaper Farm Yield Aggregator Owned
4.TikTok monitoring all keyboard inputs and taps
When you open any link on the TikTok iOS app, it’s opened inside their in-app browser. While interacting with the website, TikTok subscribes to all keyboard inputs (including passwords, credit card information, etc.) and every tap on the screen, like which buttons and links you click.5.Wrench Attack - 3 men targeted an Indian realtor they knew held bitcoin and abducted him while posing as sellers of a plot of land. They tortured him for 3 hours until he gave them 8 BTC. - [r/CryptoCurrency post]
6.Hackers steal crypto from Bitcoin ATMs by exploiting zero-day bug - via Bleepingcomputer, August 20, 2022
Hackers have exploited a zero-day vulnerability in General Bytes Bitcoin ATM servers to steal cryptocurrency from customers.When customers would deposit or purchase cryptocurrency via the ATM, the funds would instead be siphoned off by the hackers.The attacker was able to create an admin user remotely via CAS administrative interface via a URL call on the page that is used for the default installation on the server and creating the first administration user. This vulnerability has been present in CAS software since version December 2020. General Bytes Official Advisory7.iOS VPNS have leaked traffic for years, Proton CEO says.
8.U.S. Lawmaker Questions Treasury Over Tornado Cash Sanctions August 23, 2022 via CryptoBriefing.com
Rep. Tom Emmer (R-MN) raised questions over the decision to sanction Tornado Cash in a letter sent to the Treasury Department today.Emmer called the ban of a “neutral, open-source, decentralized technology” a “divergence” from historical precedent.Among other things, Emmer asked what recourse law-abiding users of Tornado Cash may have to claim funds trapped in the protocol.I, Degen - Deep Dive - The Merge & Ethereum censorship in a post-sanctioned TC world.
What is the merge TLDR?
The Merge represents the joining of the existing execution layer of Ethereum (the Mainnet we use today) with its new proof-of-stake consensus layer, the Beacon Chain. It eliminates the need for energy-intensive mining and instead secures the network using staked ETH. A truly exciting step in realizing the Ethereum vision – more scalability, security, and sustainability.- https://ethereum.org/en/upgrades/merge/
What's the problem? OFAC Tornado Cash sanctions fallout continues.
Ethermine, the largest Ethereum pool, has refused to pack Tornado Cash-related transactions into blocks in the past week. Several pool technicians also confirmed the news and said it was the first time in history.— @WUBLOCKCHAIN AUGUST 20, 2022 - https://t.co/XLC3ZjddLR
Individual miners can refuse to include whatever they want, but it has little effect; the transaction just gets into the next block. Need a 51% attack (so, reverting blocks and not just excluding txs) to fully prevent txs from being included.— @VitalikButerin August 19, 2022
The Case for Social Slashing <-- Best dive in Ethereum Censorship via OFAC
So, what’s the issue here?Well, one of the absolute core purposes for blockchains such as Ethereum is to provide neutrality and censorship resistance. That’s why we tolerate that the system is slow and expensive to use at times—because of these unique qualities. A threat to censorship resistance is a threat to the system’s raison d’être.Other censorship & merge-related stuff Centralized censorship of privacy protocols outside of Tornado Cash
Recently, FTX froze a user account who sent coins to @aztecnetwork’s zkmoney. According to FTX, Aztec Connect - Aztec network / zk money has been identified as a mixing service, which is a high-risk activity prohibited by FTX. * Tax implications of the merge ETH POW fork * Most PoW miners intend to mine Ergo, not Ravencoin or Ethereum Classic post-Merge
I, Degen - Personal Hack Attempt of the Week
Zak: Just more Pig Butchering Telegram DM scams Hunt’s mom: email scams to get her coins
E12 References & other links
Reminder - US law enforcement can legally use stingrays and does not require a probable cause warrant
If you’re interested in this, check out Season 1, Episode 3 of Truth and Power on Netflix.
Daniel Rigmaiden- a brilliant, young scam artist turned whistleblower-evades the FBI for months after being accused of filing fraudulent tax claims and illegally collecting hundreds of thousands of dollars from the IRS. After being tracked down and arrested by the feds, Daniel becomes convinced his location was identified through illicit means.* IPFS use outside blockchain and NFTs? * 3AC Bought DickButt NFT?
Show image courtesy of 3AC on OpenSea
We do our best to report accurately on the topics we discuss, but we’re not always going to get everything right. Please comment here or reach out to us @idegenfm with corrections or comments!
show notes here -->https://hackmd.io/@idegen/E11-Acala-hack-and-anti-crypto-sentiment
I, Degen - E11 - Acala Bug Exploited & Exploration of Popular Anti-crypto Sentiment - 8/18/2022
Comment
Listen at: idegen.fm
Contact us: @idegenfm
Intro
Welcome to I, Degen - We track down and explore the most exciting crypto hacks, mysteries, exploits, and anything that feeds our crypto curiosity each week. We dig in, cutting through the misinformation and hype in search of a signal in the noise.
Episode Summary
This week we talk about the strange story of an Acala DeFi liquidity pool bug being exploited, leading to the minting of billions of illegitimate aUSD.
We also dive into an articulate Reddit comment that hits on a number of the more popular anti-crypto arguments floating around right now.
I,Degen - Weekly
According to the report, the law prevents unregistered crypto exchanges from operating without a license, but the 16 firms have been providing crypto services for Koreans and hosting events targeting Koreans.1. Canadian exchanges limit purchases to 30k a year in altcoins that are not BTC, ETH, LTC and BCH 2. Celer Protocol DNS poisoning
“The Celer protocol and smart contracts were not affected during the breach. Celer DNS root record was not compromised and was never modified.”“DNS poisoning can happen to any DeFi app frontend regardless of the protocol’s own security and we strongly suggest the entire blockchain community to turn on Secure DNS option in your web browser to reduce the such possibility to get affected.”I, Degen - Deep Dive Acala
Acala (the ‘DeFi hub’ of Polkadot)bug exploited to mint stable coins Rekt coindesk
Anti-crypto sentiment appears to be rising rapidly.
[image]
I, Degen - Most creative personal hack attempt of the week?
Zak: nothing too crazy, standard SMS ‘wrong number’ with a mild twist.
We do our best to report accurately on the topics we discuss, but we won’t always get everything correctly. Please comment here or reach out to us @idegenfm with corrections or comments!
https://hackmd.io/@idegen/E10-Tornado-Cash-Sanctioned-Saber-Protocol-Unmasked
I, Degen - E10: Tornado Cash Sanctioned, Saber Protocol Unmasked - 8/11/2022
Listen at: idegen.fm
Contact us: @idegenfm
Intro
Welcome to I, Degen - We track down and explore the most exciting crypto hacks, mysteries, exploits, and anything that feeds our crypto curiosity each week. We dig in, cutting through the misinformation and hype in search of a signal in the noise.
Episode Summary
This week we dive into the unprecedented Tornado Cash sanctions, including the arrest of a suspected developer. We also spent some time on the fascinating story of two brothers that operated 11 anon personas to fake a thriving DeFi ecosystem on Solana with the popular Saber protocol.
Weekly Thought
What’s your crypto narrative, and how is it defined/created?
I,Degen - Weekly
The Macalinao brothers used a web of bogus identities to create the illusion of a dev community, juicing value on the Saber protocol and Solana blockchain. Now they’re moving to Aptos. Ian Macalinao says that Saber and Sunny comprised $7.5 billion of the total Solana TVL of $10.5 billion at their peak. He believes this contributed to SOL’s meteoric rise when the token reached a record high of $188. * 11 devs all the same person * protocols built on Saber, used to artificially inflate TVL * Crypto data website DeFiLlama has changed the way it presents key decentralized finance (DeFi) metric metric in response to this news*
I, Degen - Deep Dive Tornado Cash Sanctioned
What: U.S. Treasury Sanctions Notorious Virtual Currency Mixer Tornado Cash
What is TC, and how does it work?
Tornado Cash is a decentralized application launched on the Ethereum blockchain in 2019 that allows someone to un-link the source and destination of coins. That is to say, provide privacy or ‘mix’ coins.
When you deposit your 1 ETH on the contract, you have to provide a “commitment”. This commitment is stored by the smart contract. When you withdraw 1 ETH on the other side, you have to provide a “nullifier” and a zero-knowledge proof. The nullifier is a unique ID that is in connection with the commitment and the ZKP proves the connection, but nobody knows which nullifier is assigned to which commitment (except the owner of the depositor/withdrawal account). - Understanding Zero-Knowledge Proofs Through the Source Code of Tornado CashWhy sanctions?
Tornado Cash, which has been used to launder more than $7 billion worth of virtual currency since its creation in 2019. - Treasury.govWe should point out that statement is not factually accurate, as not all coins moving through TC were being laundered.
“Despite public assurances otherwise, Tornado Cash has repeatedly failed to impose effective controls designed to stop it from laundering funds for malicious cyber actors on a regular basis and without basic measures to address its risks. Treasury will continue to aggressively pursue actions against mixers that launder virtual currency for criminals and those who assist them.”- Brian E. Nelson - Secretary of the Treasury for Terrorism and Financial Intelligence
Let’s look at a breakdown of funds received by TC from Chainanalysis:
Points of interest
“suspected of involvement in concealing criminal financial flows and facilitating money laundering,” and that “multiple arrests are not ruled out” as investigations into Tornado Cash continue. The Verge* first smart contract sanctioned * Famous accounts dusted by TC coin * TC Withdrawals increase (but how does increase in WDs == increate in usage?) - Maybe an attempt to get coins out before the platform updates blacklists? * as with most things crypto, there are lots of uninformed opinions on this one * TORN (DAO token for TC) down from ~$30 to ~$14
The Resistance
-https://twitter.com/jchervinsky/status/1557804087856570368
The tornado cash opportunity. How we can learn from this attack to prevent it from happening again
I, Degen - Most creative personal hack attempt of the week?
References/Links
TC Feature
Sabre Protocol House of Cards
We do our best to report accurately on the topics we discuss, but we won’t always get everything correctly. Please comment here or reach out to us @idegenfm with corrections or comments!
Full show notes:
https://hackmd.io/@idegen/E9-Nomad-owned-Solana-wallets-hacked-8-4-2022
I, Degen - E9: Chaos In Crypto - Nomad Owned, Solana Wallets Hacked, Nirvance Finanace Crushed, & more - 8/4/2022
Listen at: idegen.fm
Contact us: @idegenfm
Intro
Welcome to I, Degen - We track down and explore the most exciting crypto hacks, mysteries, exploits, and anything that feeds our crypto curiosity each week. We dig in, cutting through the misinformation and hype in search of signal from the noise.
Episode Summary
The word of the week is chaos. From the first-of-its-kind decentralized looting mob destroying Nomad to the mysterious draining of more than 8K Solana wallets, it’s been a crazy week. Sadly, there is more.
Quick word on signal
I,Degen - Weekly
What is Nirvana? Buddhist state of bliss? Iconic 90’s band? Nope in this context, Solana Based Yield Protocol (what even is a ‘yield protocol’?). Also, a stablecoin.
@Huntfrye Nirvana Finance, a Solana-based yield protocol. Nirvana allowed users to earn annual yields on their locked assets by creating and destroying tokens based on user demand as the ANA tokens were bought from and sold to the protocol.
Looks pretty similar to some other algorithmic coins that rebase or change supply daily due to demand
Is this Similar to the Beanstock flash loan attack we talked about on I Degen a few episodes back?
What’s a Flash Loan?
The loans enable merchants to obtain unsecured loans from lenders using smart contracts in place of intermediaries. No collateral is required because the contract only considers the transaction complete when the borrower pays the lender.If a borrower fails to repay a flash loan, the smart contract will halt the transaction and repay the lender’s money. – DeFi PlanetI, Degen - Deep Dives
1) Nomad looted for 190MM by a decentralized mob
What is Nomad?
Nomad is a bridge that allows you to move assets from chain to chain, such as avalanche, Ethereum, Moonbeam, EVMOS, and Milkomeda. “Wow I haven’t even heard of a couple of those”
What happened?
TLDR; ~190 MM, ~2.5 Hours, Initial TX exploiting the bridge, then a swarm of copycats loot the protocol.
Hunt: why not take it all at once? Good question.
Zak: let’s talk about how the hack worked.
How did it happen?
After a failed first attempt (costing $350k in gas), the original attacker’s exploit tx, which was copied by those that followed, was able to call the process() function directly, without having first ‘proved’ its validity. rekt.newsThis meant any process() calls could be executed as valid. In fact, a more sophisticated exploiter could have written a contract to drain the whole bridge for themselves.Initial reports claim the root of the issue was called out in the audit; however, that seems incorrect. Perhaps it was the audit the led the attacker to look at this section of the code. Still, the vulnerability that was exploited appears to have been introduced to the repository on May 23rd and then pushed to the blockchain with an update in June.
DeFi Dominos
The collateral damage from the unbacked assets is also severely affecting the chains that depended on Nomad. Moonbeam, EVMOS and Milkomeda have all taken a significant hit to their TVLs. rekt.newsHunt: The most interesting and crazy part about this hack to me was that other people noticed the hack going on in real-time, joined in the fun, and were able to withdraw funds. Whether these other users who were getting in on this honey pots were White Hats and trying to take some of the funds before the attacker could, or were they maliciously trying to steal for themselves? Nomad has placed an address on their home page asking for any white hats to return funds to a specific address.
Did you see that meme floating around Twitter? It was a bunch of people looting a stoor who were the copycat hackers after the main attacker busted into the store initially.
2) Solana Wallet Hack
What is Solana?
@Huntfrye Solana is an extremely well-funded alternate layer 1 that boasts as one of the main competitors to Ethereum. Most people agree that Solona has sacrificed some of the decentralization and security to provide extremely high throughput.
What happened?
Roughly 9K addresses on the Solana network were compromised, draining more than 6MM worth of various tokens. For perspective, there are more than 25MM addresses on Solana as of this writing.
11PM UTC on August 2nd, 2022, SOL and USDC started mysteriously being transferred from wallets.
A host of wild theories spread across crypto twitter including from a Solana Founder himself.
However, it now appears there is consesus the wallet compromises are likely rooted in an issue with the Slope Wallet.
An on-chain sleuth would later reveal that Sentry, a third-party event logging platform connected to Slope, was doing just that.* ‘whitehat’ tries to DDoS attacker * attempts to dox hacker with NFT image trick - psyops or legit? * Samczsun - Legendary whitehat, posts form to collect info and solve the puzzle * Various calls to point out, ‘it’s not an issue with Solana blockchain itself!’. Sure, but in a certain context that distinction doesn’t matter.
Hunt thoughts overall: Details are still coming to light on this hack, but it does not seem like it was an issue with the Solana blockchain itself but more a problem with hot wallets, including Phantom, Slope, and TrustWallet. While Slope wallet claims on its website that they are a “non Custodial Wallet and that slope wallet does not store your mnemonic seed phrase.”
White hats even tried DDOS attacking the Solana chain to slow down the attacker from draining wallets.
Human Perspective:
I, Degen - Freestyle Convo
Zak: Who lied and where is proof? Are you sure it’s not ignorance - IE devops enabled logging and forgot to turn it off, OR hacker enabled logging with intent to steal?
Either way, indeed Slope is responsible, it’s their app and network. Either way, this comment is especially toxic and based on assumptions that may or not be correct. Maybe wait for full before encouraging your 200K followers to be enraged?
Zak: No. This doesn’t have to happen, and it’s not good for crypto. Only in a perfect world can this can be ‘handled correctly.’ We still see SQL injection vulns in significant platforms in 2022. The idea that because an exploit happens, it will make any/all future code/systems better is hopium at best. This kind of misguided banter does nothing but harm the overall ecosystem by setting up a false narrative.
I, Degen - What’s the most creative way we almost got owned this week?
Hunt: Well, mine is interesting because I know they were trying to own me, but I am not sure how the scam worked. I got airdropped a random NFT; then all the sudden got a 1.1 ETH offer on that NFT that I was airdropped. When I looked at the collection, there were ZERO sales, and floor price was at zero ETH. I am not sure how the sale would be malicious, but I am pretty sure that one is too good to be true. How do you think they were trying to get me?
Zak: private key scam on Twitter. They a private key claiming they don’t know how wallets work in hopes that you will load up the key in an attempt to steal the tokens. Then you notice there is no ETH for gas, so you send ETH. But, it’s a smart contract wallet with a function to transfer incoming ETH out immediately. So, you get rekt for trying to steal.
References/Links:
1) Nomad Hack
2) Solana Wallet Hack
https://twitter.com/iamDCinvestor/status/1555015483107282944
3) Nirvana Flash Loan
We do our best to report accurately on the topics we discuss but we won’t always get everything correctly. Please comment here or reach out to us @idegenfm with corrections or comments!
https://hackmd.io/@idegen/E8-Audius-Gets-Owned
:::info
Follow--> @idegenfm
:::
:::success
Listen---> https://idegen.fm
:::
Welcome to I, Degen - Each week, we track down and explore the most exciting crypto stories. Hacks, mysteries, exploits, and anything that feeds our crypto curiosity.
Welcome degens! Come one, come all.
This week we explore the Audius governance attack.
funds were transferred from Nguyen’s wallet so that AXS short sellers “would not be able to front-run the news,”
What happened?
On July 23rd, 2022, Audius, a Web3 music platform, suffered a governance attack for $6M worth of AUDIO, it's native token.
What is Audius?
Before we jump in lets talk about what proxy contracts are and how they work.
Proxy contracts give the ability to upgrade or change a dapps contract logic, or even deploy clones.
High level, in this case (but not all proxy patterns), they separate the storage and logic layers of the app, where the proxy contract sits in front and handles storage, and another contract sits behind the proxy and handles the application logic.

source: https://blog.openzeppelin.com/proxy-patterns/
Key Point:
Whenever a contract A delegates a call to another contract B, it executes the code of contract B in the context of contract A.
The first contract is a simple wrapper or "proxy" which users interact with directly and is in charge of forwarding transactions to and from the second contract, which contains the logic. - OpenZepplin Docs
Instead of mapping every function one to one, the fallback function is leveraged.
That is, the logic contract controls the proxy’s state and the logic contract’s state is meaningless. Thus, the proxy doesn’t only forward transactions to and from the logic contract, but also represents the pair’s state. The state is in the proxy and the logic is in the particular implementation that the proxy points to.
Solidity uses slots to store data.
Using this bug, the attacker was able to call the initializer method of deployed Audius contracts that implement Initializable and change storage state that is intended to be set only once in initialization.
In other words:
the attacker was able to reinitialise governance contracts, delegating a large number of governance tokens to themself and bypassing safeguards meant to limit malicious proposals.
So, storage collision leads to deployment of malicious governance contract, and massive fraudulent token delegation which was used to pass a malcious governance proposal to send AUDIO tokens from the Audius community pool to the attacker.
Quick massive slippage sale of 6.1MM worth of AUDIO on Uniswap for ~1MM USD/704 ETH, ETH into TornadoCash.
Take aways:
super fast response, vuln mitigated within a few hours of discovery.
These contracts were deployed in October 2020 and this vulnerability has been live in the wild since that time. - audius-governance-takeover-post-mortem
Password Manager Nightmare
Evolving SMS scams, likely from Ledger breach
OpenZepplin Audius Contracts Audit
https://kubertu.com/blog/solidity-storage-in-depth/
Please checkout the I, Degen episode #7 Zeevo sequence here - https://app.zeevo.co/dashboard/sequences/bfdded05-2c09-4b5d-96da-90f2531409f2 you're feedback would be most appreciated!
I, Degen - E6: Mint Bots Deliver 7hr KO to Solana & Otherside NFTs Push ETH Gas Fees to Highs - 5/6/22
Listen at: idegen.fm
Contact us: @idegenfm
Intro
Welcome to I, Degen - Each week, we track down and explore the most exciting crypto stories. Hacks, mysteries, exploits, and anything that feeds our crypto curiosity.
Welcome degens! Come one, come all.
I,Degen - Weekly
I,Degen - Deep Dive
Solana Blockchain’s 11th outage, 7th of 2022.- Solana Incident Report
What: May, 1st - 4M transactions per second, initiated by NFT minting bots, took down Solana blockchain by preventing nodes from reaching consensus. The bots were targeting the Metaplex Candy Machine.
What is Metaplex?
Allows users to mint and sell NFTs.
On securing the network, from their site:
Security
Prevent bots from interfering with NFT sales with decentralized architecture, Certified Collections, and CAPTCHAS.Metaplex poses a solution charge a tax/fee on failed TXs.
Based on a Twitter poll on the same thread with the solution, 5k votes total. With 75% no, and 25% yes.
The speculation was that:
“Eth & AVAX maxi’s voting no”
“Bots voting no”
However, the proposed solution looks like an anti-pattern!
There is a chance that a real user could hit one of these cases, especially in # 2 (Trying to mint when there are no items left in the candy machine). But we think these will not be frequent.
This is not a fool proof fix, and it will not completely stop congestion but we belive it has a substantial enough impact to attempt it.How does Solana Consensus Work?
leewayhertz.com explains
I, Degen - Freestyle Convo
BAYC Otheside Metaverse Land Sale Pushes ETH gas fee to new high.
175M on fees total, many of which failed
^^ From Eth World News
UPDATE: They did refund gas fees to failed TX holders
Mental Gymnastics Required to Justify ETH Fees
We do our best to report accurately on the topics we discuss, but we’re not always going to get everything right. Please comment here or reach out to us @idegenfm with corrections or comments!
Full Show Notes:
https://hackmd.io/@idegen/I-DEGEN-E6-Mint-Bots-Deliver-7HR-KO-to-Solana
I, Degen - E5: Akutars NFT Auction Misfire Locks 11K ETH - 4/30/2022
Listen at: idegen.fm
Contact us: @idegenfm
Intro
Welcome to I, Degen - Each week, we track down and explore the most exciting crypto stories. Hacks, scams, exploits, and anything that feeds our crypto curiosity.
Welcome degens! Come one, come all.
Episode Summary
In this week’s episode, we take a look at the brutal AkuTars auction bugs that permanently sacrificed 11,539 ETH to the burn 🔥_🔥
5/2 - UPDATE - We recorded this on 4/28 and since have come across some new info related to how the Aku team is working with the community to set things right. The community seems to be aligned and supports AkuDreams on the plan.
I,Degen - Weekly
I, Degen - Deep Dive
Moment of Slience - $34 million, or 11,539 eth, is permanently locked into the AkuDreams contract forever.
What is Aku?
Aku is a character created by former MLB player turned artist, Micah Johnson, after hearing a young boy ask, “Can astronauts be black?”Aku was released to the world on Feb 21, 2021 as an NFT in the form of an animated video– Aku.wolrd
Ten chapters in total, with each chapter in it’s own style.
Next, comes the Akutars…new drop, 4/22/22.
What are the Akutars:
Akutars are a collection of 15,000 unique, 3D Aku avatars with partnerships from; Puma, Planes, Vandal, Who Decides War, BBC and, Ice Cream. Each Akutar grants you entry into the ever-expanding Akuverse, where lines are blurred between the digital and physical worlds and owners gain exclusive access to culture-defining experiences, products, and collaborations.
– Akutars on OpenSeaSo this drop was dutch auction with a unique feature that allowed the lowest bid to set the price for all minters. – TweetThen, when the auction ends, any bid higher than the lowest bid will receive a refund of the lowest bid, minus gas fees.
This is an interesting and cool mechanism. However, there was some faulty logic in the contract.
First issue: If you bid on the auction from a contract, and that contract didn’t have a fallback function to handle incoming ETH, then the refund loop would fail. This was exploited, however, the attacker was kind enough to build a switch into their contract that would bypass the failure and allow the refund loop to continue.malicious bidder contract's message
There is some mention that this bug was pointed out to the AkuDreams team ahead of time and they ignored it. I wasn’t able to verify that.
Next Issue: Bigger issue. The contract was designed to keep track of the bids, and addresses that made those bids. A simple ++ was used to increment the counter. However, this counter didn’t account for cases where a single address bid on more than one Akutar. AKA, multi-mint in a single transaction. This left the total bid count short. There were 5495 total Auktars to be auctioned, but bid counter only made it to 3669.
During the refund loop, there is a check to confirm:
require(_refundProgress < _bidIndex)
and then, in the claimProjectFunds function:
require(refundProgress >= totalBids)
Sooo… 11k ETH is permanently stuck.
What’s strange:
links:
I, Degen - Freestyle Convo
Musk buys Twitter
[[[Outro]]]
We do our best to report accurately on the topics we discuss but we’re not always going to get everything right. Please comment here or reach out to us @idegenfm with corrections or comments!
https://hackmd.io/@idegen/I-Degen-E5-Akutars-NFT-Auction-Misfire
Show Image right click saved from: https://opensea.io/assets/0xaad35c2dadbe77f97301617d82e661776c891fa9/5
Episode Summary
In this week’s episode, we take a deep dive in the fascinating flash loan governance attack delivered on the Beanstalk Farms protocol Sunday. Then we dig into trending criticism on Axie Infinity’s play to earn model.
Intro
Welcome to I, Degen - Each week, we track down and explore the most exciting crypto stories. Hacks, scams, exploits, and anything that feeds our crypto curiosity.
Welcome degens! Come one, come all.
It’s been another epic week. We will go deep on the Beanstalk Farms attack and explore some growing criticism of Axie.
But first, let’s jump into our choice-picked weekly Degen headlines.
Degen Weekly
U.S. Rep. Jared Huffman (D-Calif.), who leads a subcommittee within the House of Representatives’ Natural Resources Committee, has recruited almost two dozen Democratic colleagues to urge federal environmental officials to devote further scrutiny to the consequences of cryptocurrency mining. - CoindeskDegen Deep Dive
Beanstalk Farms Flash Loan Governance Attack
TLDR: On April 17th, 2022 an attacker used a barrage of flash loans to purchase a majority of BEAN tokens, the native governance token for Beanstalk Farms. Using this temporarily loaned voting power allowed them successfully pass an emergency governance proposal that drained the protocol of 76M in assets, sent 250K of the stolen money to the Ukraine War Fund, and sent the price of the stable BEAN tumbling.
Who:
victim: bean.money aka Beanstalk
Beanstalk is a decentralized and transparent solution to DeFi’s endemic stablecoin supply shortage. It was designed from first principles to be a paradigm-shifting DeFi primitive that makes decentralized, cost-efficient stablecoins available to anyone with an internet connection.Beanstalk was initially launched in August 2021 with just 100 Beans and has never taken traditional funding. Over the last eight months, Beanstalk organically grew to $100M in market cap, attracting $144M in long term-incentivized liquidity.* Beanstalk: The Path Forward
From the whitepaper:
To date, flawed stablecoin implementations sacrifice the main benefits of decentralized computing by requiring trust in a centralized party and limit their potential market capitalization by imposing collateral requirements.A stablecoin that (1) does not compromise on decentralization, (2) does not require collateral, and (3) trends toward more liquidity and stability, will unlock the potential of
DeFi.We propose an Ethereum-native, credit based stablecoin protocol that issues an
ERC-20 Standard token that fulfills these requirements.An on-chain price oracle leverages an existing centralized bridge between the Ethereum blockchain and the rest of the world to create a decentralized, reliable and inexpensive source for the price of a nonEthereum-native value peg.A Decentralized Autonomous Organization (DAO) governed
by a yield generating, inflationary, ERC-20 Standard token simultaneously provides security, encourages consistent liquidity growth, and dampens price volatility.Attacker:
Anon/unknown
What:
attack details:
Presumably, to avoid suspicion of an inside job, Publius, the anon behind the protocol, took the decision to reveal their identity as a group of three in a statement published to Discord.From ^^ rekt
How:
From Beanstalk whitepaper:
6.5 Governance
A robust decentralized governance mechanism must balance the principles of decentralization with resistance to attempted protocol changes, both malicious and ignorant, and the ability to quickly adapt to changing information.In practice, Beanstalk must balance ensuring sufficient time for all
ecosystem participants to consider a Beanstalk Improvement Proposal (BIP), join the Silo and cast their votes, with the ability to be quickly upgraded in cases of emergency.6.5.2 Voting Period
A Voting Period opens when a BIP is submitted to the Ethereum blockchain and ends at the beginning of the 169th Season after it is submitted, or when it is committed with a supermajorityDoesn’t matter though, as it looks like a super majority of tokens was used to override the 169th season (~7 days).
5 Seasons
Thus, Beanstalk creates a cost-efficient protocol-native timekeeping mechanism
and ensures cost-efficient code execution on the Ethereum blockchain at regular intervals.Confusing… How about this:
Seasons are the Beanstalk-native timekeeping mechanism. Each Season is ∼1 hour long.What’s odd:
Why is this important:
Source list:
https://rekt.news/beanstalk-rekt/
https://twitter.com/kelvinfichter/status/1515735717305008138
https://www.theverge.com/2022/4/18/23030754/beanstalk-cryptocurrency-hack-182-million-dao-voting
https://bean.money/blog/path-forward
https://medium.com/beanstalkfarms/introducing-beanstalk-557c45cb8d80
Beanstalk FlashLoan Exploiter contract
https://twitter.com/peckshield/status/1515692144190648322
Freestyle Convo: Axie Play to Earn or Play to be Exploited?
Hit piece or legit criticism? Both? - Kotaku
Outro
We do our best to report accurately on the topics we discuss but we’re not always going to get everything right. Please comment here or reach out to us @idegenfm with corrections or comments!
https://hackmd.io/@idegen/E4-Beanstalk-FlashLoan-Governance-Attack-Axie-Infinity-Under-Fire
I, Degen - Episode 3
Suspicious Coinbase Trades, Rug-pull Finder, more DeFi hack
Listen at: idegen.fm
Contact us: @idegenfm
Intro:
Each week we track down and explore the most interesting crypto stories we can find. We examine scams, hacks, defi exploits, and anything that feeds our crypto curiosity. Welcome degens! Come one, come all.This weeks show - evolving format, testing something new. Start with a run down of this weeks most wild and interesting crypto degen stories.1) Week in review
Crypto, DeFi, & NFT hacking
Tornado Cash uses
@chainalysis
oracle contract to block OFAC sanctioned addresses from accessing the dapp.Maintaining financial privacy is essential to preserving our freedom, however, it should not come at the cost of non-compliance.1. Another Former Bored Ape Holder Suing OpenSean over inactive listing UI bug
General Crypto News
From CryptoSlate Russia to legalize crypto as means of payment- "Russia’s Ministry of Finance is working on draft regulations that will legalize crypto as a payment method."
Another from CryptoSalte Monero community set to blitz CEXs in coming ‘Monerun’- "Suspicions of CEXs overstating XMR reserves will be put to the test in a coordinated run on Monero."
2) Feature - Coinbase Insider Making Bank?
What
Coinbase drops an article on April, 11th titled:‘transparency for new asset listings on coinbase’: from the article:
Starting immediately and as part of an effort to increase transparency by providing as much information symmetry as possible, Coinbase will be using this blog post as a pilot to communicate assets under consideration for listing in Q2 2022 (April 1st, 2022 to June 30th, 2022).The article inspired fears of insider trading and caused degens to hit the blockchain to see what they could find. Before we dig in, it’s worth noting that this is not a new issue for Coinbase. The BCH Coinbase insider trading issue was a thing in 2019
Post from Reddit user dragondude4 on r/cryptocurrency
Earlier today Coinbase made a “transparency post” naming about 50 assets that they are planning to list on their exchange. Most of them are illiquid shitcoins that no one can figure out why they are even listing in the first place.The post goes on to show 4-5 screen shots of tweets [like]((https://twitter.com/AlanStacked/status/1514062386851946499):
Thread blows up…but then:
So, it turns out this wasn’t a Coinbase insider, but instead a clever chart scammer.
What is chart scammer? idk, I just made that up.
Nansen AI, blockchain analytics, and intelligence platform. They do a lot of cool stuff, but in this context, the smart money dashboard lets you track flows of coins going to and from smart trader's accounts.
So the tricked the Nansen.ai into making it look like this coin was pumping:
How?
So, it looks like people gaming Nansen to make it look like honeypot/scam tokens are pumping. clever. But what does this have to do with coinbase? Nothing, so lets look at another:
This one looks legit. Indeed we can see large Pawtocol - UPI tokens being snagged up on Feb 8th before the Feb 11th coinbase announcement
It’s hard to say what this means. It could be legit. It could be insider trading from someone at Coinbase or maybe even just at UPI?
Cobie Tweet:
Who
Social media has a suspect but idk… it’s pure speculation. This guy was let go from OpenSea for front running NFT collections based on his insider info, and now he works at Coinbase.
What is r/LeopardsAteMyFace?
‘I never thought leopards would eat MY face,’ sobs woman who voted for the Leopards Eating People’s Faces Party.Crypto people are aware of regulations…
Takeaway:
Weekly reminder, be wary of what you read.
Seems likely that private information from Coinbase is making it’s way out and someone is profiting off that info.
If that is the case, it’s going to be hard for them to cover their tracks. It might not happen right away, but my bet is that someone gets busted on this.
3) Freestyle convo - Elon VS Twitter
https://www.protocol.com/elon-musk-twitter-takeover-faq
Outro
Full show notes:
https://hackmd.io/@idegen/E3-Insider-Trading-more-DeFi-hacks
https://hackmd.io/@idegen/E2-Inverse-Hydra
1) Ronin Bridge Attack update
2) Seven Lapsus$ group hackers arrested
Why this?
Infamous crypto hackers, sim swappers, and all around general obnoxious blackhats.
When: 4/2
What happened: Former hacking partners turned on this main guy and doxxed him. Law enforcement circled in.
Who:
Under his online moniker “White” or “Breachbase” the teenager, who is autistic, is said to be behind the prolific Lapsus$ hacker crew, which is believed to be based in South America.3) Buble Gum Ape Heist - Bored ape holder “s27” traded their bubble gum ape and matching mutant derivatives with floor value of $567k for a basic ass photoshopped imposter apes
Why cover this?
As if we needed another reminder that NFT markets are sketchy and the absolute simplicity of the scam.
Raises important questions around NFT verification.
What: simple photoshop scam
The victim entered into a direct swap trade with the scammer via a third-party service called swap.kiwi. Unlike regular marketplaces like OpenSea, platforms like swapkiwi allow direct NFT swaps between collectors, reducing transaction (“gas”) fees.Unknown to s27, the other participant in the trade put up knock-off NFTs in exchange for s27’s legitimate Bored Ape and Mutant Apes. The scammer used images of actual Bored Apes to create fake replicas and uploaded the same ones to OpenSea.
-https://www.theblockcrypto.com/post/140702/bored-ape-holder-loses-nfts-worth-567000-to-a-scammer
where: kiwi.swap
Who: anon & s27
When: 4/1-3/2022
It’s unclear if the scammer actually used Photoshop or some other editor.
4) Hydra Darknet Market bust
when: 4/5/2022
what is Hydra:
the world’s largest darknet market by revenue.Hydra specialized in same-day ‘dead drop’ services, where drug dealers (vendors) hide packages in public places before informing customers of the pick-up locationThe market primarily caters to criminals in Russia and surrounding nations. “Treasuremen,” or dealers connected with the site, push drugs throughout the region by hiding them in geo-tagged pickup locations.The website launched in 2015 selling drugs, hacked materials, forged documents and illegal digital services such as Bitcoin-mixing - which cyber-criminals use to launder stolen or extorted digital coins.The site was written in Russian, with sellers located in Russia, Ukraine, Belarus, Kazakhstan and surrounding countries.Police say 17 million customers and more than 19,000 seller accounts were registered on the marketplace, which now carries a police seizure notice.after a tip-off, German police seized the Hydras servers and confiscated €23m (£16.7m) in Bitcoin. 25.2 million USDHydra was seemingly impervious to police attempts to stop it.-BBC
Germany’s federal police shut down the Russia-based Hydra Market, the world’s largest darknet market by revenue. Later in the day, the Justice Department followed up by indicting one of Hydra’s key operators, and the U.S. Treasury’s Office of Foreign Assets Control (OFAC) sanctioned Hydra, adding more than 100 of its cryptocurrency addresses to the SDN list as identifiers.In 2021, Hydra received more than $1.7 billion worth of cryptocurrency, which accounts for over 75% of all darknet market revenue globally.- Chain Analysis
Who?:
Dmitry Olegovich Pavlov is said to be the mastermind behind Hydra.
5) Inverse Finance Hack
15M taken in exceptionally clever defi attack.
What is Inverse Finance?
Inverse Finance is a community of cryptocurrency enthusiasts organized as a Decentralized Autonomous Organization (DAO), started on the 26th of December 2020. Inverse DAO governs and develops a suite of permissionless and decentralized finance tools using blockchain smart contract technology. The code base is open-source, and maintained by the community.Inverse Marketing Pitch
Master the Game Of Positive Sum DeFiHere at Inverse Finance, we’re decentralized by design, moving past reckless, outdated systems towards a better solution: Positive Sum Defi. We help you maximize your earnings via revenue sharing, accumulate high yields with sustainable APYs, and benefit from low-cost stable coin borrowing. Join our community to grow and thrive.Why this?
When: 4/2/2022
Who: anon
What happened:
From Inverse Twitter:
This morning Inverse Finance’s money market, Anchor, was subject to a capital-intensive manipulation of the INV/ETH price oracle on Sushiswap, resulting in a sharp rise in the price of INV which subsequently enabled the attacker to borrow $15.6 million in DOLA, ETH, WBTC, & YFIFrom Rekt.news
A professionally executed hack allowed an anonymous actor to manipulate the price of INV and help themself to an exclusive deal from the ETH based lending protocol.Lets walk though the attack with Rekt:
^^ Start with mixed coins
^^ Used as prep to spam tx’s on step 4?
^^ Manipulate the oracle
^^ Beat other flashbots to the opp, not sure what exploit was in the TXs though?
The Inverse Finance oracle, through Keeper Network, ended up using SushiSwap TWAP as an oracle, returning the price that made the INV token on the platform incredibly expensive.^^ INV price is high because of attackers manipulation
The attacker then deposited his 1.7k INV (fair price - $644k) as collateral and (permanently) borrowed $15.6M.^^ Success
Final Thoughts:
Outro:
Big week, whats next?
You can find our shows at https://idegen.fm