Analysis-Decentralised finance: Latest front in crypto's hacking problem

Analysis-Decentralised finance: Latest front in crypto's hacking problem

By Tom Wilson

LONDON (Reuters) - For most of the 13-year life of cryptocurrencies, exchanges were the epicentre for cyberheists. Now, a bigger hacking risk in the growing sector has exploded into view: peer-to-peer crypto platforms.

Our top trading bots

One such site, Poly Network, was at the centre of a $610 million crypto theft last week, one of the biggest ever. Within days of the heist, the decentralised finance (DeFi) platform said the "white hat" hacker or hackers had returned nearly all the loot.

The unusual ending to the Poly Network saga belies fast-emerging risks in this growing corner of crypto, where an estimated $80 billion or more is held, interviews with industry executives, lawyers and analysts show.

DeFi sites allow users to lend, borrow and save - usually in cryptocurrencies - while bypassing the traditional gatekeepers of finance such as banks and exchanges. Backers say the technology offers cheaper and more efficient access to financial services.

But the heist at Poly Network - previously a little-known site - has underscored the vulnerability of DeFi sites to crime.

Would-be robbers are often able to exploit bugs in the open-source code used by sites. And with regulation still patchy, there is usually little or no recourse for victims.

Centralised exchanges, which act as middlemen between buyers and sellers of crypto, had previously been the main targets of crypto cyberheists.

Tokyo-based exchange Mt.Gox for instance collapsed in 2014 after it lost half a billion dollars in hacks. Coincheck, also based in Tokyo, was hit by a $530 million heist in 2018.

Many major exchanges, under the regulatory spotlight and striving to attract mainstream investors, have since bolstered security and heists on such scale are now relatively rare.

LESS SECURE

An onus on security at major platforms such as Coinbase Global Inc has pushed less-secure venues to the sidelines, said Ross Middleton, chief financial officer at DeFi platform DeversiFi.

"What's happened is the big exchanges have got really good (on security) and the smaller exchanges aren't around anymore," he said. "The frontier is definitely DeFi now."

Losses from crime at DeFi platforms are at an all-time high, crypto intelligence firm CipherTrace said last week, with thieves, hackers and fraudsters making off with $474 million from January through July.

The spike came as funds poured into DeFi, mirroring flows into crypto as a whole. According to DeFi Pulse the total value held at such sites is now more than $80 billion, compared with just $6 billion a year earlier.

DeFi specialists say security risks tend to lie at newer sites which may run on less secure code.

"There is a widening security and risk gap between old, battle-tested DeFi protocols, and new, untested DeFi protocols," said Rune Christensen, former head of the body behind high-profile DeFi application Maker.

Proponents says the use of open-source code means vulnerabilities can be quickly identified and solved by users, reducing the risk of crime. DeFi can police itself, they say.

Yet for financial watchdogs and governments across the world looking at regulating the crypto sector, DeFi is increasingly in focus.

ENFORCEMENT ACTION

U.S. Securities and Exchange Commission (SEC) chair Gary Gensler has signalled he would take a tough stance on DeFi.

Such platforms may be captured by U.S. securities laws, he said in a speech this month, calling on Congress to draft legislation to rein in DeFi and crypto trading.

The SEC this month brought its first enforcement action https://www.sec.gov/news/press-release/2021-145 involving DeFi tech, alleging the company issued unregistered securities and misled investors. The SEC did not respond to further questions on its stance.

Officials at the U.S. Commodity Futures Trading Commission have also signalled greater scrutiny.

Commissioner Dan Berkovitz in June called DeFi a "Hobbesian marketplace" https://www.cftc.gov/PressRoom/SpeechesTestimony/opaberkovitz7 - a reference to a 17th century philosopher who saw life without government as "nasty, brutish and short". Unlicensed DeFi platforms for derivatives were violating commodities trading laws, he suggested.

Elsewhere, moves are slower. DeFi is still far from the political agenda in Britain, for instance.

A spokesperson for Britain's financial watchdog said while some DeFi activities may fall under its scope, much of the sector is unregulated.

For some analysts, greater regulation in inevitable, with little sign that DeFi sites can do the job themselves.

"The unfortunate situation is that (Poly Network) was seen as just an average Tuesday in the DeFi world," said Tim Swanson of blockchain firm Clearmatics.

"The industry likes to congratulate itself by claiming it resides on transparent systems, but it has repeatedly shown it is incapable of policing itself."

Continue reading with Reuters
How do you assess the value of an NFT?
Understanding the valuation matrixThere is no rule book on how to assess an NFT valuation. The metrics you use for evaluating private companies or conventional...
Want to weed out ransomware? Regulate crypto exchanges
Just between July 2020 and June 2021, ransomware activity soared by a whopping 1,070%, according to a recent Fortinet report, with other researchers confirming...
Marshall Islands officially recognizes DAOs as legal entities
The Republic of the Marshall Islands has moved to formally recognize decentralized autonomous organizations, better known as DAOs, as legal entities — a...
Climate-focused Hyphen aims to hold companies accountable for eco-data reporting
As concerns for environmental impact rose, the market started to require a framework that allows projects to showcase their ecological implications accurately....
Fossils vs. Renewables, PoW vs. PoS: Key policy issues around crypto mining in the U.S.
On Jan. 27, a group of eight U.S. lawmakers, led by Senator Elizabeth Warren, sent letters to the world’s six largest Bitcoin mining companies, demanding...
Ex-Wall Street execs lead new Bitcoin mining firm as US hash rate soars
Prime Blockchain (PrimeBlock), a new cryptocurrency mining company in the United States, is hiring its inaugural management team after starting to mine...
Solana and Arbitrum knocked offline while Ethereum evades attack
Surging Ethereum rival, Solana (SOL), has shed 15% of its value over the past 24 hours after suffering a denial-of-service disruption.On Sept. 14 at 12:38...
BREAKING: BitMEX will pay $100M in penalties to FinCEN, CFTC
Crypto derivatives exchange BitMEX has agreed to pay up to $100 million to resolve a case from the United States Commodity Futures Trading Commission, or...
Bad call? Bitfinex bears closed a block of Bitcoin shorts before the drop below $32K
Bitcoin price is still in a rut, trading near $33,000 and trapped in a downtrend that just seems to get worse with the passing of each day. As the price...
MakerDAO slashes stability fees as stablecoin demand wanes
Decentralized finance lending and stablecoin protocol MakerDAO has adjusted stability fees across a wide range of crypto assets used as collateral on the...
Bitcoin price hits $41K, then rejects after sellers defend the 200-MA
The overall mood of the cryptocurrency ecosystem is muted on June 15 with most altcoins trading flat while Bitcoin (BTC) bulls look for a daily close above...
Defying COVID-19: Blockchain events make an in-person return
The year 2020, for most of the inhabitants of our planet, was passed in lockdowns or quarantine due to the COVID-19 pandemic; many were forced to stay at...
Mass adoption looms as South America's second-largest company accepts crypto payments
On April 28, MercadoLibre (MELI), the largest Latin American online marketplace, launched a real estate section dedicated to cryptocurrencies. Although...
Nifty News: NYT says NFTs in pandemic-fueled bubble, Polkamon eggs produce $1M gas ...
Having just flogged an NFT column for half a million dollars, the New York Times is now wondering if perhaps the whole scene is in a bit of a bubble?In...
Stock Market or Bitcoin – Survey Shows What Americans Trust in More
Against the background that Wall Street has attempted to reign in Bitcoin’s light as two exchanges have launched Bitcoin futures trading, a survey among...