Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO
No Result
View All Result
Invest In Crypto News
No Result
View All Result

Should crypto projects ever negotiate with hackers? – Cointelegraph Magazine

CryptoExpert by CryptoExpert
December 15, 2022
in Altcoin News
0
Should crypto projects ever negotiate with hackers? – Cointelegraph Magazine
  • Facebook
  • Twitter
  • Pinterest


You might also like

Is a Breakout to $2.24 Next?

Altcoins Have Recovered $90B Since February – Analyst Explains Market Dynamics

Bitcoin Holds $75K As Altcoins Search For Bullish Momentum

“A highly profitable trading strategy” was how hacker Avraham Eisenberg described his involvement in the Mango Markets exploit that occurred on Oct. 11.

By manipulating the price of the decentralized finance protocol’s underlying collateral, MNGO, Eisenberg and his team took out infinite loans that drained $117 million from the Mango Markets Treasury. 

Desperate for the return of funds, developers and users alike voted for a proposal that would allow Eisenberg and co. to keep $47 million of the $117 million exploited in the attack. Astonishingly, Eisenberg was able to vote for his own proposal with all his exploited tokens.

This is something of a legal gray area, as code is law, and if you can work within the smart contract’s rules, there’s an argument saying it’s perfectly legal. Although “hack” and “exploit” are often used interchangeably, no actual hacking occurred. Eisenberg tweeted he was operating within the law:

okex

“I believe all of our actions were legal open market actions, using the protocol as designed, even if the development team did not fully anticipate all the consequences of setting parameters the way they are.”

However, to cover their bases, the DAO settlement proposal also asked that no criminal proceedings be opened against them if the petition was approved. (Which, ironically, may be illegal.)

Eisenberg and his merry men would reportedly go on to lose a substantial portion of the funds extracted from Mango a month later in a failed attempt to exploit DeFi lending platform Aave.

The Mango Markets $47-million settlement received 96.6% of the votes. Source: Mango Markets

How much has been stolen in DeFi hacks?

Eisenberg is not the first to have engaged in such behavior. For much of this year, the practice of exploiting vulnerable DeFi protocols, draining them of coins and tokens, and using the funds as leverage to bring developers to their knees has been a lucrative endeavor. There are many well-known examples of exploiters negotiating to keep a portion of the proceeds as a “bounty” as well as waiving liability. In fact, a report from Token Terminal finds that over $5 billion worth of funds has been breached from DeFi protocols since September 2020. 

High-profile incidents include the $190-million Nomad Bridge exploit, the $600-million Axie Infinity Ronin Bridge hack, the $321-million Wormhole Bridge hack, the $100-million BNB Cross-Chain Bridge exploit and many others.

Given the apparently endless stream of bad actors in the ecosystem, should developers and protocol team members try and negotiate with hackers to attempt to recover most of the users’ assets?

1/ After four hacks yesterday, October is now the biggest month in the biggest year ever for hacking activity, with more than half the month still to go. So far this month, $718 million has been stolen from #DeFi protocols across 11 different hacks. pic.twitter.com/emz36f6gpK

— Chainalysis (@chainalysis) October 12, 2022

Should you negotiate with hackers? Yes. 

One of the greatest supporters of such a strategy is no other than ImmuneFi CEO Mitchell Amador. According to the blockchain security executive, “developers have a duty to attempt communication and negotiation with malevolent hackers, even after they have robbed you,” no matter how distasteful it may be.

ImmuneFi’s CEO Mitchell Amador
ImmuneFi’s CEO, Mitchell Amador. Source: LinkedIn

“It’s like when someone has chased you into an alley, and they say, ‘Give me your wallet,’ and beat you up. And you’re like, ‘Wow, that’s wrong; that’s not nice!’ But the reality is, you have a responsibility to your users, to investors and, ultimately, to yourself, to protect your financial interest,” he says.

“And if there’s even a low percentage chance, say, 1%, that you can get that money back by negotiating, that’s always better than just letting them run away and never getting the money back.”

Amador cites the example of the Poly Network hack last year. “After post-facto negotiations, hackers returned back $610 million in exchange for between $500,000 to $1 million in bug bounty. When such an event occurs, the best and ideal, the most effective solution overwhelmingly, is going to be negotiation,” he says.

For CertiK director of security operations Hugh Brooks, being proactive is better than reactive, and making a deal is only sometimes an ideal option. But he adds it can also be a dangerous road to go down.

“Some of these hacks are obviously perpetrated by advanced persistent threat groups like the North Korean Lazarus Group and whatnot. And if you are negotiating with North Korean entities, you can get in a lot of trouble.”

However, he points out that the firm has tracked 16 incidents involving $1 billion in stolen assets, around $800 million of which was eventually returned.

“So, it’s certainly worth it. And some of those were voluntary returns of funds initiated by the hacker themselves, but for the most part, it was due to negotiations.”

Perhaps the Poly Network hacker really just wanted a small bounty for his efforts
Perhaps the Poly Network hacker really just wanted a small bounty for his efforts. Source: Tom Robinson via Twitter

Should you negotiate with hackers? No.

Not every security expert is on board with the idea of rewarding bad actors. Chainalysis vice president of investigations Erin Plante is fundamentally opposed to “paying scammers.” She says giving in to extortion is unnecessary when alternatives exist to recover funds.

Plante elaborates that most DeFi hackers are not after $100,000 or $500,000 payouts from legitimate bug bounties but frequently ask upward of 50% or more of the gross amount of stolen funds as commission. “It’s basically extortion; it’s a very large amount of money that is being asked for,” she states. 

She instead encourages Web3 teams to contact qualified blockchain intelligence companies and law enforcement if they find themselves in an incident.

“We’ve seen more and more successful recoveries that are not publicly disclosed,” she says. “But it’s happening, and it’s not impossible to get funds back. So, in the end, jumping into paying off scammers may not be necessary.”

Many funds have been lost in DeFi exploits this year
Many funds have been lost in DeFi exploits this year. Source: Token Terminal

Should you call the police about DeFi exploits?

There is a perception among many in the crypto community that law enforcement is pretty hopeless when it comes to successfully recovering stolen crypto. 

In some cases, such as this year’s $600-million Ronin Bridge exploit, developers did not negotiate with North Korean hackers. Instead, they contacted law enforcement, who were able to quickly recover a portion of users’ funds with the help of Chainalysis.

But in other cases, such as in the Mt. Gox exchange hack, users’ funds — amounting to approximately 650,000 BTC — are still missing despite eight years of extensive police investigations.

Amador is not a fan of calling in law enforcement, saying that it’s “not a viable option.”

Not all hackers are interested in striking bounty deals with developers
Not all hackers are interested in striking bounty deals with developers. Source: Nomad Bridge

“The option of law enforcement is not a real option; it is a failure,” Amador states. “Under those conditions, typically, the state will keep what it has taken from the relevant criminals. Like we saw with enforcement actions in Portugal, the government still owns the Bitcoin they’ve seized from various criminals.”

He adds that while some protocols may wish to use the involvement of law enforcement as a form of leverage against the hackers, it’s actually not effective “because once you’ve unleashed that force, you cannot take it back. Now it’s a crime against the state. And they’re not just going to stop because you negotiated a deal and got the money back. But you’ve now destroyed your ability to come to an effective solution.”

Read also

Features

Inside South Korea’s wild plan to dominate the metaverse

Features

Retire early with crypto? Playing with FIRE

Brooks, however, believes you are obligated to get law enforcement involved at some point but warns the results are mixed, and the process takes a long time.

“Law enforcement has a variety of unique tools available to them, like subpoena powers to get the hacker’s IP addresses,” he explains.

Chainalysis’ VP of Investigations Erin Plante
Chainalysis’ VP of investigations, Erin Plante. Source: LinkedIn

“If you can negotiate upfront and get your funds back, you should do that. But remember, it’s still illegal to obtain funds through hacking. So, unless there was a full return, or it was within the realm of responsible disclosure bounty, follow up with law enforcement. In fact, hackers often become white-hats and return at least some money after law enforcement is alerted.”

Plante takes a different view and believes the effectiveness of police in combating cybercrime is often poorly understood within the crypto community. 

“Victims themselves are often working confidentially or under some confidential agreement,” she explains. “For example, in the case of Axie Infinity’s announcement of funds recovery, they had to seek approval from law enforcement agencies to announce that recovery. So, just because recoveries aren’t announced doesn’t mean that recoveries aren’t happening. There’s been a number of successful recoveries that are still confidential.”

How to fix DeFi vulnerabilities

Asked about the root cause of DeFi exploits, Amador believes that hackers and exploiters have the edge due to an imbalance of time constraints. “Developers have the ability to create resilient contracts, but resiliency is not enough,” he explains, pointing out that “hackers can afford to spend 100 times as many hours as the developer did just to figure out how to exploit a certain batch of code.”

Subscribe

The most engaging reads in blockchain. Delivered once a
week.

Subscribe to Magazine by Cointelegraph Newsletter.

Amador believes that audits of smart contracts, or one point-in-time security tests, are no longer sufficient to prevent protocol breaches, given the vast majority of hacks have targeted audited projects.

Instead, he advocates for the use of bug bounties to, in part, delegate the responsibility of defending protocols to benevolent hackers with time on their hands to level out the edge: “When we started on ImmuneFi, we had a few hundred white-hat hackers. Now we have tens of thousands. And that is like an incredible new tool because you can get all that enormous manpower protecting your code,” he says. 

For DeFi developers wanting to build the most secure outcome, Amador recommends a combination of defensive measures:

“First, get the best people to audit your code. Then, place a bug bounty, where you will get the best hackers in the world, to the tune of hundreds of thousands, to check your code in advance. And if all else fails, build a set of internal checks and balances to see if any funny business goes on. Like, that’s a pretty amazing set of defenses.”

Brooks agrees and says part of the issue is there are a lot of developers with big Web3 ideas but who lack the required knowledge to keep their protocols safe. For example, a smart contract audit alone is not enough — “you need to see how that contract operates with oracles, smart contracts, with other projects and protocols, etc.”

“That’s going to be far cheaper than getting hacked and trying your luck at having funds returned.”

Stand your ground against thieves 

Best to avoid getting hacked in the first place. Source: Pexels

Plante says crypto’s open-source nature makes it more vulnerable to hacks than Web2 systems.

“If you’re working in a non-DeFi software company, no one can see the code that you write, so you don’t have to worry about other programmers looking for vulnerabilities.” Plante adds, “The nature of it being public creates those vulnerabilities in a way because you have bad actors out there who are looking at code, looking for ways they can exploit it.”

The problem is compounded by the small size of certain Web3 companies, which, due to fundraising constraints or the need to deliver on roadmaps, may only hire one or two security experts to safeguard the project. This contrasts with the thousands of cybersecurity personnel at Web2 firms, such as Google and Amazon. “It’s often a much smaller team that’s dealing with a big threat,” she notes

But startups can also take advantage of some of that security know-how, she says. 

“It’s really important for the community to look to Big Tech firms and big cybersecurity firms to help with the DeFi community and the Web3 community as a whole,” says Plante. “If you’ve been following Google, they’ve launched validators on Google Cloud and became one the Ronin Bridge, so having Big Tech involved also helps against hackers when you’re a small DeFi project.” 

It was an honor to speak at #AxieCon and share the successful recovery of $30M in crypto that was stolen from the Ronin Bridge. In these hack investigations it is a long road to recovery. But the Axie Infinity community is strong and we will continue to partner in this fight. https://t.co/V0lwrOtThr

— Erin Plante (@eeplante) September 8, 2022

In the end, the best offense is defense, she says — and there’s an entire population of white-hat hackers ready and willing to help. 

“There’s a community of Certified Ethical Hackers, which I am a part of,” says Erin. “And the ethos of that group is to look for vulnerabilities, identity, and close them for the larger community. Considering many of these DeFi exploits aren’t very sophisticated, they can be resolved before extreme measures, such as waiting for a break-in, theft of funds and requesting a ransom.”

Read also

Features

DeFi abandons Ponzi farms for ‘real yield’

Features

Forced Creativity: Why Bitcoin Thrives in Former Socialist States

Zhiyuan Sun

Zhiyuan Sun is a technology writer at Cointelegraph. Initially starting out with mechanical engineering in college, he quickly developed a passion for cryptocurrencies and finance. He has several years of experience writing for major financial media outlets such as The Motley Fool, Nasdaq.com and Seeking Alpha. When away from his pen, one can find him in his scuba gear in deep waters.

Follow the author @Bio_Chameleon





Source link

  • Facebook
  • Twitter
  • Pinterest
Tags: Bitcoin
CryptoExpert

CryptoExpert

Recommended For You

Is a Breakout to $2.24 Next?

by CryptoExpert
April 21, 2026
0
Is a Breakout to $2.24 Next?

Most XRP investors are back in profit, increasing the chance for a rally to $2.24, but bulls must first hold the price above $1.40.XRP’s (XRP) 28% rebound from...

Read more

Altcoins Have Recovered $90B Since February – Analyst Explains Market Dynamics

by CryptoExpert
April 21, 2026
0
Altcoins Have Recovered $90B Since February – Analyst Explains Market Dynamics

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Altcoins have been one of crypto’s most painful stories of the past few years. The...

Read more

Bitcoin Holds $75K As Altcoins Search For Bullish Momentum

by CryptoExpert
April 20, 2026
0
Bitcoin Holds $75K As Altcoins Search For Bullish Momentum

Key points:Buyers aggressively bought into the dip in Bitcoin, indicating positive sentiment. That increases the possibility of a rally to $84,000.Several major altcoins have pulled back to their...

Read more

ZachXBT Flags Holder Concentration Concerns Tied to MemeCore

by CryptoExpert
April 20, 2026
0
ZachXBT Flags Holder Concentration Concerns Tied to MemeCore

Onchain investigator ZachXBT publicly challenged MemeCore on Monday to justify the valuation and supply distribution of its M token, asking the project to explain its market cap and...

Read more

RaveDAO token crashes below $1 after ZachXBT exposes price manipulation

by CryptoExpert
April 20, 2026
0
A trader analyzes a financial price chart on a smartphone while multiple market charts display on monitors in the background.

RaveDAO token plunged 95% from $26 to under $1. RAVE launched in December 2025 on Binance Alpha. ZachXBT’s on-chain analysis also highlights MemeCore, River and MYX among questionable...

Read more
Next Post
BTC price levels to watch as Bitcoin dives below $17.5K post-FOMC

BTC price levels to watch as Bitcoin dives below $17.5K post-FOMC

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

Sitemap

  • Market Cap
  • Donations
  • Trading
  • Mining
  • Contact

Legal Information

  • Privacy Policy
  • Anti-Spam Policy
  • Copyright Notice
  • DMCA Compliance
  • Social Media Disclaimer
  • Terms Of Service

Categories

  • Altcoin News
  • Bitcoin News
  • Blockchain News
  • Business
  • Doge News
  • Ethereum News
  • Finance
  • Market Analysis
  • Mining
  • NFT News
  • Politics
  • Regulation
  • Technology
  • Trending Cryptos
  • Video

© Copyright 2024 InvestInCryptoNews.com

No Result
View All Result
  • Home
  • Latest News
    • Bitcoin News
    • Altcoin News
    • Ethereum News
    • Blockchain News
    • Doge News
    • NFT News
    • Video
    • Market Analysis
    • Business
    • Finance
    • Politics
    • Mining
    • Regulation
    • Technology
  • Top 10 Cryptos
  • Market Cap List
  • IC DAO
  • Donations
  • Contact
  • Buy Crypto
  • IC DAO

© Copyright 2024 InvestInCryptoNews.com

This website is using cookies to improve the user-friendliness. You agree by using the website further.

Privacy policy
bitcoin
Bitcoin (BTC) $ 75,226.00
ethereum
Ethereum (ETH) $ 2,294.81
tether
Tether (USDT) $ 1.00
xrp
XRP (XRP) $ 1.42
bnb
BNB (BNB) $ 628.79
usd-coin
USDC (USDC) $ 0.999692
solana
Solana (SOL) $ 85.27
tron
TRON (TRX) $ 0.331847
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.03
staked-ether
Lido Staked Ether (STETH) $ 2,265.05

Pin It on Pinterest

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?