Why White Hat Hackers Are Vital to the Crypto Ecosystem

CoinDesk发布于2022-02-22更新于2022-02-24

文章摘要

This past weekend at ETHDenver, Jay Freeman took the stage to highlight his nearly billion-dollar bug discovery within the core code of Optimism, Boba and Metis, which he dubbed "Unbridled Optimism."

This past weekend at ETHDenver, Jay Freeman took the stage to highlight his nearly billion-dollar bug discovery within the core code of Optimism, Boba and Metis, which he dubbed "Unbridled Optimism."
Freeman has a history of software development and hacking, notably playing a critical role in the development of software for jailbreaking iOS. His experience has proven to be priceless within the Wild West, open-source crypto industry. Just two weeks ago a smart contract vulnerability left the Wormhole bridge with a $350 million hole to repair – and that wasn't even the largest exploit in recent history. However, Freeman mentioned that bridge exploits are often found quickly as they are used often and watched over constantly by the teams responsible for maintaining them.
Read More: Jump Trading Backstops Wormhole’s $320 Million Exploit Loss
During the first week of February, Freeman discovered a critical bug within Optimism’s virtual machine – one that developers might not have been ready to patch quite as quickly. The bug was rooted in Optimism’s selfdestruct function that allows contracts to be destroyed and sends any remaining ether balance to a designated address.
It sounds dangerous, so why do blockchains contain the selfdestruct function? The function allows for obsolete or dangerous contracts to be removed from the chain while returning the ether balance to the rightful owner.
Unless there is a bug, of course.
Optimism’s selfdestruct function returned the ether balance to the designated address without ever burning the balance within a contract. According to Freeman, “This means that, when a contract self-destructs its balance is BOTH given to the beneficiary AND ALSO KEPT.” If attackers were able to successfully call the contract, they could create a loop that doubles their OETH balance until noticed and patched by Optimism developers.
Freeman noted that he was not the first person to find the bug after scanning previous selfdestruct calls on Optimism and tracking one wallet back to an employee of Etherscan. The employee had found and tested the bug, but apparently hadn’t understood the severity of the situation and let it be. The vulnerability had gotten worse over time as more funds were bridged to Optimism and other layer 2 systems copied the code Optimism had put in place. Layer 2s are companion networks connected but functionally separate from the base layer.
Consequently, Freeman noted, had he not found the bug, a minting vulnerability would have allowed an attacker to double their funds every time the selfdestruct function was called on Boba and Metis as well.
White Hats and DeFi
Even if the Optimism team had noticed and temporarily paused bridge transactions via the sequencer during a theoretical attack, an attacker could have still wreaked havoc on layer 2 decentralized finance (DeFi). Using the falsely minted OETH, any attacker would be able to drain decentralized exchanges and exploit lending platforms with useless collateral. The exploit would have likely caused irreparable damage within the Ethereum ecosystem and layer 2 users could have had all of their funds rendered useless, with no assets left on the other end of the bridge. Combined, Optimism, Boba and Metis had around $750 million locked in DeFi the day the vulnerability was reported, almost all of which was at risk.
The need for friendly adversarialism
Decentralized finance continues to be a vulnerable industry with anonymous founders, open-source code and billions of dollars looking to take on risk. This enormous amount of capital has created an incentive system aligned with teams that build fast and release tokens.
Read More: Wonderland (and DeFi’s) Anonymity Problem
Conversely, caution and professionalism are a lot less exciting to traders and investors. The world economy has seen over and over again the effect of incessant risk taking, even though the market eventually punishes shortcuts. There is no reason to think this same outcome won’t continue to play out in crypto and decentralized finance, with only the most meticulous protocols coming out alive in the end.
Freeman has also contemplated where the middle ground between “Code is Law” and third-party trust falls. He raised the point that bug bounties are essential in incentivizing good actors to seek out and find vulnerabilities. By setting the reward for being a good actor on a similar scale as the payout for being a bad actor, that scale suddenly tilts the incentives toward white hatting.
As Freedman put it, this sort of “friendly adversarialism” can encourage ecosystem participants to be more open, honest and even pessimistic about new ideas.
That pessimism is key. Today, the environment is perhaps overly optimistic, getting investors and DeFi users excited about protocols that could never work or might even be dangerous. This lack of oversight, combined with the nature of open-source code, creates the perfect environment for hackers and scammers, an issue much of the crypto industry does not seem ready to admit.
DISCLOSURE
The leader in news and information on cryptocurrency, digital assets and the future of money, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups. As part of their compensation, certain CoinDesk employees, including editorial employees, may receive exposure to DCG equity in the form of stock appreciation rights, which vest over a multi-year period. CoinDesk journalists are not allowed to purchase stock outright in DCG.


Edward Oosterbaan
Edward is an analyst on the CoinDesk Research team focusing on Ethereum and DeFi. He holds ETH, AVAX, OHM and a small amount of other cryptocurrencies.
Follow @TedDeFi on Twitter

热门币种推荐

你可能也喜欢

XRP价格预测:杠杆降低能否支撑其反弹至1.13美元以上?

XRP价格预测:杠杆率下降能否支撑其回升至1.13美元以上? XRP在经历数周抛售后持续窄幅震荡,显示市场信心依然不足。买家守住了1.0757美元的关键支撑位,防止了价格进一步下跌,但未能将价格推高至足以改变整体下跌趋势的水平。 目前XRP交易价格约为1.11美元,但仍低于其20日、50日、100日和200日指数移动平均线,表明卖方在更高时间框架上仍占优势。价格在1.07美元至1.12美元之间波动,形成狭窄的盘整区间。买家需要将价格推高至50日EMA(约1.1375美元)以上,才有可能测试1.18美元和1.23美元的阻力位。若跌破1.0757美元支撑,则可能重新下探近期低点1.0088美元。 衍生品市场数据显示,未平仓合约已从早期高点100多亿美元大幅降至约24.4亿美元,表明大量杠杆头寸已离场。这降低了清算风险,可能营造更健康的市场环境,但持续上涨需要更多资金重新入场。 现货市场则呈现更积极的迹象:从交易所流出的XRP持续多于流入,表明投资者更倾向于持有而非抛售,这为价格提供了长期支撑。近期每日净流出约520万美元,抛压较年初有所缓解。 技术分析指出,XRP正处于长期下跌后的盘整阶段,而非确立新的上升趋势。上行关键阻力位于1.1375美元至1.1841美元区域。XRP的短期前景取决于买家能否守住1.0757美元支撑,并积蓄足够动能突破1.1375美元。若成功突破,可能加速涨向1.18美元及1.23-1.29美元阻力区。反之,若失守支撑,则可能再次下探1.0088美元。尽管资金流出提供了建设性背景,但价格必须突破关键阻力位,才能获得更广泛看涨逆转的可信度。

cryptonews.ru52分钟前

XRP价格预测:杠杆降低能否支撑其反弹至1.13美元以上?

cryptonews.ru52分钟前

Bitmine 增持公司以太坊储备

比特矿池技术公司(Bitmine Immersion Technologies)持续增持以太坊,尽管其投资组合目前处于浮亏状态。上周,该公司再次购入9946枚ETH,而此前一周的购买量略低。然而,对比一个月前,单次购买规模已显著下降。 今年六月,Bitmine曾斥资买入超过52,000枚ETH。此后虽然增持强度减弱,但定期购买仍在继续。公司坚持一项战略,即让以太坊成为其企业储备资产的核心。 该积累计划始于2025年6月30日。在此之前,Bitmine主要以比特币矿工闻名。此次业务转向使其从开采比特币转变为构建以以太坊为基础的大型储备资产。自计划启动以来,公司持续增加其持仓,并不关注市场的短期波动。 最近一次购买后,Bitmine的以太坊储备已达到580万枚。然而,其投资组合的当前市值仍低于累计投入成本,平均购买成本几乎是市场价的两倍,因此持仓仍处于亏损状态。 尽管如此,未实现的亏损并未阻止Bitmine。公司仍计划在其资产负债表上集中持有以太坊总供应量的5%。这一目标要求未来继续大规模增持,而目前已积累的数量已使Bitmine成为以太坊最大的持有者之一。 这种集中持有的策略使Bitmine能显著影响企业对以太坊的需求结构。持续购买也表明,管理层将当前价格视为一个过渡阶段,而非退出持仓的理由。

cryptonews.ru54分钟前

Bitmine 增持公司以太坊储备

cryptonews.ru54分钟前

交易

现货

热门文章

加密市场宏观研报:美国“加密货币周”来袭,ETH开启机构军备赛高潮

本周,加密市场迎来两股重磅催化——华盛顿“加密货币周”的立法攻势与以太坊机构布局的密集爆发,共同构成加密行业2025年下半年的“政策拐点”与“资金拐点”。这一轮加密周期的深层逻辑,正从比特币转向以太坊、稳定币及链上金融基础设施。我们认为:美国的政策明朗化+以太坊的机构化扩展,标志着加密行业正进入结构性转正阶段,市场配置的重心亦应逐步从“价格博弈”过渡至“规则+基础设施的制度红利捕捉”。

1.9k人学过发布于 2025.07.17更新于 2025.07.17

加密市场宏观研报:美国“加密货币周”来袭,ETH开启机构军备赛高潮

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对ETH(ETH)币价的意见。

活动图片