this post was submitted on 16 May 2024
277 points (96.6% liked)

Technology

59207 readers
2939 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 115 points 5 months ago (3 children)

Here is a more detailed explanation of the exploit.

The Pepaire-Bueno brothers exploited a bug in MEV-boost's code that allowed them to preview the content of blocks before they were officially delivered to validators, according to the indictment.

The brothers created 16 Ethereum validators and targeted three specific traders who operated MEV bots, the indictment said. They used bait transactions to figure out how those bots traded, lured the bots to one of their validators which was validating a new block and basically tricked these bots into proposing certain transactions. [...]

So hardly an attack on any core system of cryptocurrencies.

[–] [email protected] 35 points 5 months ago (5 children)

So they discovered faulty code and made some money?

Can anyone explain to me how this is illegal?

The code is a contract. If someone writes bad code and loses money, then write better code - just like if someone writes a bad legal contract and loses money.

The justice system is awful.

[–] [email protected] 39 points 5 months ago* (last edited 5 months ago) (1 children)

IANAL and all, but bad/unfavorable contracts and literal deception/fraud are two different things, at least in the legal system. Not everything that's technically possible is also allowed, obviously.

Compare it to using a security flaw to hack into a system. Technically you're only using the official API, maybe in unusual ways, but still. But you're doing it in bad faith and causing harm, maybe pretending to be someone you're not or injecting fake data into the system, and that can make a difference.

[–] [email protected] 33 points 5 months ago (2 children)

This is like saying they discovered how to pick a lock so deserve everything in whats locked by it.

[–] [email protected] -2 points 5 months ago

The didn't pick the lock, they created bunch of fake exchanges.

[–] [email protected] 30 points 5 months ago (2 children)

You withdraw cash at an ATM but the software has faulty code which causes your balance to remain the same after withdrawing any amount.

You notice this and then empty the entire ATM this way, making $200,000. I'm sure once you explain to the jury that the ATM just gave you a bad contract, they will acquit you.

[–] [email protected] 4 points 5 months ago
[–] [email protected] 3 points 5 months ago (2 children)

No one ever said ATM-code is law. Ethereum code is supposed to be. Code is law is one of their slogans.

Everything that a blockchain does could be handled by a single office computer. The whole reason for the huge, expensive over-head is to put crypto beyond the law. Stuff like this exposes the whole, huge waste of human effort.

[–] [email protected] 2 points 5 months ago

Code is the law of the blockchain, his transaction wasn't reverted, he got caught irl. It's like saying constitution isn't law because laws of physics don't prevent murder.

[–] [email protected] 2 points 5 months ago

It isn't above law.

[–] [email protected] 5 points 5 months ago

They created a bunch of fake shell companies in foreign companies and were preparing to flee the US

[–] [email protected] 2 points 5 months ago (1 children)

Doesn't sound a huge deal different to High Frequency Trading, and Wall Street nobheads fall over themselves to exploit that.

[–] [email protected] 1 points 5 months ago

Sounds to me that the difference is they exploited a bug to get private information in order to game the bots.

[–] [email protected] 22 points 5 months ago (2 children)

Frustratingly vague for a Slashdot write-up.

“These brothers allegedly committed a first-of-its-kind manipulation of the Ethereum blockchain by fraudulently gaining access to pending transactions, altering the movement of the electronic currency, and ultimately stealing $25 million in cryptocurrency from their victims,” said Special Agent in Charge Thomas Fattorusso of the IRS Criminal Investigation (IRS-CI) New York Field Office.

Good to know the prosecutors have an understanding of what they're prosecuting... Not even a single mention of MEV in the DoJ press release.

[–] [email protected] 2 points 5 months ago (1 children)

by fraudulently gaining access to pending transactions

That makes no sense to me. The mempool is public, everyone can see pending transactions.

[–] [email protected] 1 points 5 months ago (1 children)

Because it's not the public mempool. It's a private MEV mempool that people pay to add their transactions to for special priority or conditional inclusion. For instance, asshole profiteers can use it to sandwich attack traders to siphon off "market inefficiencies" or some people just want immediate front of the line inclusion in the next block.

Presumably they exploited something in this MEV system (completely unrelated to the Ethereum protocol) that allowed them to see the pool and they shouldn't have. Wish I knew more but everything I read was incredibly vague and misleading.

[–] [email protected] 1 points 5 months ago (1 children)

It’s a private MEV mempool

Are you sure there is such a thing? My understanding was that they just submit their sandwich transactions to the mempool with higher and lower gas respectively to achieve their desired priority ranking. Could be wrong though.

[–] [email protected] 2 points 5 months ago (1 children)

I'm sure, yes. If you submit to a public mempool, you have no guarantees that your two transactions will land on either side of the target transaction in the same block (They likely won't). You need to leverage conditional transactions with MEV so you guarantee the miner will select and position your transactions where you need them. In this case, before and after the target transaction.

Check out the Ethereum Foundation's page on MEV for more info.

[–] [email protected] 1 points 5 months ago

Wow, thanks for the link. It seems things have gotten a lot more complicated with PoS. I didn't even know about PBS. I haven't been following along properly.

[–] [email protected] 2 points 5 months ago

What's funny is that that's a description of MEV.

gaining access to pending transactions, altering the movement of the electronic currency, and ultimately stealing $25 million in cryptocurrency from their victim

I skipped "fraudulent" because neither MEV bots nor this attack can be called fraudulent imo, although MEV is definitely taking value one didn't help create.

[–] [email protected] 2 points 5 months ago

Let them eat MEV bot operators.