{"id":1360,"date":"2022-04-02T13:58:57","date_gmt":"2022-04-02T13:58:57","guid":{"rendered":"https:\/\/prendergast.net\/?p=1360"},"modified":"2022-04-02T13:58:57","modified_gmt":"2022-04-02T13:58:57","slug":"web3-is-supposed-to-be-secure-what-about-all-these-hacks","status":"publish","type":"post","link":"https:\/\/prendergast.net\/?p=1360","title":{"rendered":"Web3 Is Supposed to Be Secure What About All These Hacks?"},"content":{"rendered":"<h1>Web3 Is Supposed to Be Secure. What About All These Hacks?<\/h1>\n<h2>Web3 promised us a new era of privacy and security, but a series of recent major hacks make all that look like a lie.<\/h2>\n<p><span style=\"font-size:11px\">By&nbsp;<a href=\"https:\/\/decrypt.co\/author\/jeff-john-roberts\">Jeff John Roberts<\/a><\/span><\/p>\n<p><img alt=\"\" src=\"https:\/\/markethive.com\/uploads\/andriesvantonder\/images\/posted-images\/hacks%2Cweb3.png\" style=\"height:387px; width:700px\" \/><\/p>\n<p>Hacks remain common in DeFi.&nbsp;<\/p>\n<p>The promise of Web3 is that we&#39;ll get all the stuff we like about the internet, but with more privacy and a blockchain-based architecture to keep our data more secure than before.<\/p>\n<p>Well, that&#39;s the theory. In reality, Web3 is becoming a security nightmare as a slew of recent hacks has left some wondering if they should just turn our money and data over to Mark Zuckerberg and call it day.<\/p>\n<p>The latest security disaster involves the play-to-earn game&nbsp;<a href=\"https:\/\/decrypt.co\/90480\/web-3-nft-game-axie-infinity-hard-to-use\" target=\"_blank\" rel=\"noopener\">Axie Infinity<\/a>, which is supposed to be the poster child for what Web3 can be. If you missed it, hackers&nbsp;<a href=\"https:\/\/decrypt.co\/96322\/hacker-622-million-axie-infinity-ronin-ethereum\" target=\"_blank\" rel=\"noopener\">broke into<\/a>&nbsp;the Ronin &quot;bridge&quot; between Axie and the Ethereum blockchain and robbed it to the tune of $552 million at the time (now worth $630 million, since ETH is up)&mdash;a staggering amount even in this crypto gilded age.<\/p>\n<p>Even more shocking is how the attack took place. As Web3 engineer Molly White&nbsp;<a href=\"https:\/\/blog.mollywhite.net\/axie-hack\/\" rel=\"nofollow external noopener\" target=\"_blank\">explains<\/a>, the crew behind Axie set up the bridge in such a way that it required only nine trusted validators&mdash;meaning that a hacker only needed to compromise five accounts to get the keys to the kingdom. And that&#39;s what happened. Even worse, it took&nbsp;<em>six days<\/em>&nbsp;for the Axie team to notice that $630 million worth of Ethereum had been looted and to tell users, whose money is now gone.<\/p>\n<p>If a security team at a bank or a Web2 company behaved this way, they would be fired and face charges of civil or even criminal negligence. But since it&#39;s Web3, Axie leadership has offered only vague mumbles to the effect of what a shame this is. (Axie founder Jeff Zirlin&nbsp;<a href=\"https:\/\/twitter.com\/Jihoz_Axie\/status\/1508851948178399237\" target=\"_blank\" rel=\"noopener\">tweeted<\/a>&nbsp;on Tuesday, &quot;It&#39;s a hard day,&quot; and&nbsp;<a href=\"https:\/\/twitter.com\/Jihoz_Axie\/status\/1508880402827513857\" target=\"_blank\" rel=\"noopener\">two hours later<\/a>, &quot;This is when we show what we&#39;re made of.&quot;) As Bloomberg&#39;s Matt Levine archly&nbsp;<a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2022-03-30\/crypto-bridge-hacks-reach-over-1-billion-in-little-over-a-year\" target=\"_blank\" rel=\"noopener\">observed<\/a>, &quot;Nobody cares less about information security than the builders of cryptocurrency projects.&quot;<\/p>\n<p><a href=\"https:\/\/markethive.com\/andriesvantonder\/page\/eco-system\"><img alt=\"\" src=\"https:\/\/markethive.com\/uploads\/andriesvantonder\/images\/posted-images\/CRYPTO-COMMUNITY-BANNER-copy%20(1).png\" style=\"height:105px; width:700px\" \/><\/a><\/p>\n<p>The Axie debacle is hardly a one-off. Two months ago, hackers robbed&nbsp;<a href=\"https:\/\/decrypt.co\/91899\/hacker-steals-320-million-solana-ethereum-bridge-wormhole\" target=\"_blank\" rel=\"noopener\">Wormhole<\/a>, a popular bridge to the Solana blockchain, to the tune of $320 million. Fortunately for users, the venture capitalists beyond Wormhole, recognizing the terrible optics,&nbsp;<a href=\"https:\/\/decrypt.co\/92709\/jump-crypto-wormhole-defi\" target=\"_blank\" rel=\"noopener\">decided to backstop the losses<\/a>&nbsp;even as the engineers responsible all but shrugged their shoulders. Last week, $28 million was drained from Solana stablecoin protocol&nbsp;<a href=\"https:\/\/decrypt.co\/95772\/solana-stablecoin-project-cashio-plummets-zero-multi-million-dollar-hack\" target=\"_blank\" rel=\"noopener\">Cashio<\/a>. Last August,&nbsp;<a href=\"https:\/\/decrypt.co\/78275\/what-the-poly-network-hack-reveals-about-defi\" target=\"_blank\" rel=\"noopener\">Poly Network<\/a>&nbsp;was hacked for over $600 million.<\/p>\n<p>There are numerous other examples of Web3 users being robbed because the platforms they use are full of gaping security holes.<\/p>\n<p>Meanwhile, more than two dozen Web3 companies, including Circle and BlockFi, revealed last month that they had been&nbsp;<a href=\"https:\/\/decrypt.co\/95586\/hacker-steals-customer-data-circle-blockfi-big-crypto-firms\" target=\"_blank\" rel=\"noopener\">hit by a Web2-style attack<\/a>. In that case, hackers&nbsp;<a href=\"https:\/\/decrypt.co\/95586\/hacker-steals-customer-data-circle-blockfi-big-crypto-firms\" target=\"_blank\" rel=\"noopener\">compromised<\/a>&nbsp;one of their marketing vendors and made off with a trove of customer data that is already being used to conduct phishing campaigns and other scams.<\/p>\n<p>At this rate, Web3 risks inheriting the worst security failures of the previous internet but none of the accountability. At least big banks have insurance to make customers whole when they&#39;re robbed, while Big Tech firms deploy sophisticated security teams to guard their data. Many leading names in Web3, by contrast, appear focused on getting filthy rich by dumping tokens while not giving a fig about users left to navigate a predatory landscape on their own.<\/p>\n<p>The token gold rush has led many to forget the values that gave rise to crypto in the first place. Those include building secure architecture and remembering Ethereum founder Vitalik Buterin&#39;s &quot;<a href=\"https:\/\/coinmarketcap.com\/alexandria\/glossary\/blockchain-trilemma\" target=\"_blank\" rel=\"noopener\">blockchain trilemma<\/a>,&quot; the notion that it&#39;s easy to achieve two of three goals when it comes to decentralization, scale, and security, but very difficult to achieve all three. By the way, Vitalik spoke up about about bridges in January,&nbsp;<a href=\"https:\/\/thedefiant.io\/vitalik-eth-cross-chain-bridges-security\/\" rel=\"nofollow external noopener\" target=\"_blank\">warning<\/a>&nbsp;they are simply not as secure as Layer 1 projects like Ethereum or Bitcoin.<\/p>\n<p><a href=\"https:\/\/markethive.com\/andriesvantonder\/page\/eco-system\"><img alt=\"\" src=\"https:\/\/markethive.com\/uploads\/andriesvantonder\/images\/posted-images\/banner%2C3.png\" style=\"height:87px; width:700px\" \/><\/a><\/p>\n<p>And speaking of Bitcoin, I think this is one occasion where the broader Web3 world should consider learning from&nbsp;<a href=\"https:\/\/decrypt.co\/94058\/bitcoin-maximalists-muneeb-ali-gm\" target=\"_blank\" rel=\"noopener\">Bitcoin maximalists<\/a>. Obnoxious though they may be, the maxis are right that there is nothing more battle-tested and secure than the Bitcoin blockchain&mdash;one of the big reasons Satoshi&#39;s creation remains the world&#39;s most valuable crypto. Web3 founders should take more time to build their projects in a similar fashion rather than hitting the gas in hopes of a quick token payoff. If they don&#39;t, Web3 risks losing the little credibility it&#39;s built.<\/p>\n<p><em>This is&nbsp;<\/em>Roberts on Crypto<em>, a weekend column from Decrypt Editor-in-Chief&nbsp;<a href=\"https:\/\/decrypt.co\/author\/daniel-roberts\" rel=\"noopener\" target=\"_blank\">Daniel Roberts<\/a>&nbsp;and Decrypt Executive Editor&nbsp;<a href=\"https:\/\/decrypt.co\/author\/jeff-john-roberts\" rel=\"noopener\" target=\"_blank\">Jeff John Roberts<\/a>. Sign up for the&nbsp;<a href=\"https:\/\/decrypt.co\/modal\/emails\" rel=\"noopener\" target=\"_blank\">Decrypt Debrief email newsletter<\/a>&nbsp;to get it in your inbox every Saturday. And read last weekend&#39;s column:&nbsp;<\/em><a href=\"https:\/\/decrypt.co\/96063\/vitalik-ethereum-is-the-crypto-hero-we-dont-deserve\" target=\"_blank\" rel=\"noopener\">Vitalik Is the Crypto Hero We Don&#39;t Deserve<\/a>.<\/p>\n<p><a href=\"https:\/\/markethive.com\/andriesvantonder\/page\/eco-system\"><img alt=\"\" src=\"https:\/\/markethive.com\/uploads\/andriesvantonder\/images\/posted-images\/aaNEURAL_SEO_PLATFORM(1).png\" style=\"height:99px; width:800px\" \/><\/a><\/p>\n<p><\/p>\n<p>Tim Moseley<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Web3 Is Supposed to Be Secure. What About All These Hacks? Web3 promised us a new era of privacy and security, but a series of recent major hacks make all that look like a lie. By&nbsp;Jeff John Roberts Hacks remain common in DeFi.&nbsp; The promise of Web3 is that we&#39;ll get all the stuff we &hellip; <a href=\"https:\/\/prendergast.net\/?p=1360\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Web3 Is Supposed to Be Secure What About All These Hacks?<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[2],"tags":[],"_links":{"self":[{"href":"https:\/\/prendergast.net\/index.php?rest_route=\/wp\/v2\/posts\/1360"}],"collection":[{"href":"https:\/\/prendergast.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prendergast.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prendergast.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prendergast.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1360"}],"version-history":[{"count":0,"href":"https:\/\/prendergast.net\/index.php?rest_route=\/wp\/v2\/posts\/1360\/revisions"}],"wp:attachment":[{"href":"https:\/\/prendergast.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1360"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prendergast.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1360"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prendergast.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1360"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}