{"id":10324,"date":"2017-11-07T08:45:07","date_gmt":"2017-11-07T16:45:07","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/11\/07\/news-4097\/"},"modified":"2017-11-07T08:45:07","modified_gmt":"2017-11-07T16:45:07","slug":"news-4097","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/11\/07\/news-4097\/","title":{"rendered":"Someone \u2018Accidentally\u2019 Locked Away $300M Worth of Other People&#8217;s Ethereum Funds"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/video-images.vice.com\/articles\/5a01dcf176aca577836fed90\/lede\/1510071792255-shutterstock_95494732.jpeg\"\/><\/p>\n<p><strong>Credit to Author: Jordan Pearson| Date: Tue, 07 Nov 2017 16:24:10 +0000<\/strong><\/p>\n<p> On Tuesday, a single user permanently locked down dozens of digital wallets containing nearly $300 million dollars worth of ether, the unit of exchange on the Ethereum platform, allegedly by accident. <\/p>\n<p> Now, some in the Ethereum community are considering the possibility of a risky network split, known as a &#8220;hard fork,&#8221; to fix it.<\/p>\n<p> The affected wallets\u2014known as &#8220;multisignature&#8221; wallets because they require multiple people to sign off before funds are moved, making them popular with companies\u2014were all created with Parity, a popular program for digital wallets. Parity multisignature wallets <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/zmvkke\/this-is-not-a-drill-a-hacker-allegedly-stole-dollar32-million-in-ethereum\" target=\"_blank\">experienced a bug in July<\/a> that allowed a hacker to steal $32 million in funds before the Ethereum community <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/qvp5b3\/how-ethereum-coders-hacked-back-to-rescue-dollar208-million-in-ethereum\" target=\"_blank\">scrambled to band together to hack back<\/a> and secure the rest of the vulnerable ether. <\/p>\n<p> According to <a href=\"https:\/\/paritytech.io\/blog\/security-alert.html\" target=\"_blank\">a blog post released by Parity<\/a> on Tuesday, the code that fixed the July bug contained another vulnerability. That vulnerability allowed a user known as &#8220;devops199&#8221; on GitHub, a site for developers to collaborate on open source code, to allegedly accidentally trigger a function that turned the contract governing Parity multisignature wallets into a regular wallet address and made him or her the owner. Devops199 then killed this wallet contract, or, as Parity put it, &#8220;suicided&#8221; it. This made all multisignature wallets tied to that contract instantly useless, their funds locked away with no way to access them.<\/p>\n<p> If the story is true, it seems like Devops199 was jiggling door handles and when one door opened, they tried to close it and the whole house exploded. <\/p>\n<p><b>Read More: <\/b><b><a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/qvp5b3\/how-ethereum-coders-hacked-back-to-rescue-dollar208-million-in-ethereum\" target=\"_blank\">How Coders Hacked Back to &#8216;Rescue&#8217; $208 Million in Ethereum<\/a><\/b><\/p>\n<p> &#8220;We are asking for everyone to be patient until the full extent of the issue has been identified and we will communicate any necessary instructions or advice,&#8221; a Parity spokesperson wrote me in an email. &#8220;We are advising users not to deploy any further multi-sig wallets until the issue has been resolved and to not send any Ether to wallets that have been deployed and are in use already.&#8221;<\/p>\n<p> Devops199 made an appearance in the Parity chat channel after the incident. &#8220;I&#8217;m [an Ethereum] newbie\u2026 just learning,&#8221; devops199 wrote. &#8220;You&#8217;re famous now lol,&#8221; replied another user. When I reached devops199 for comment on the incident, they replied, &#8220;Sorry\u2026 I&#8217;m really afraid now\u2026 can&#8217;t talk.&#8221;<\/p>\n<p> A <a href=\"https:\/\/pastebin.com\/auYnE9vL\" target=\"_blank\">Pastebin document<\/a> that was circulating in the Parity chat channel on Tuesday lists dozens of affected wallets, containing more than 900,000 ether, worth nearly $300 million. Some Initial Coin Offerings (ICOs)\u2014<a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/ywwbvw\/ethereums-biggest-hacking-problem-is-human-greed\" target=\"_blank\">controversial and lightning-fast fundraising rounds<\/a> for Ethereum apps\u2014were affected, although it&#8217;s not clear which ones or how many. <\/p>\n<p> Somewhat ironically, one of the affected wallets was for Polkadot, an Ethereum app launched by Parity&#8217;s own founder Gavin Wood. Polkadot <a href=\"http:\/\/www.trustnodes.com\/2017\/10\/15\/polkadot-ico-raises-130-million-just-begun\" target=\"_blank\">recently garnered over $100 million in investments<\/a> from an ICO. &#8220;Polkadot will continue as planned,&#8221; a Parity spokesperson told me in an email.<\/p>\n<p> Potential solutions at this point are murky. Already, <a href=\"https:\/\/twitter.com\/localethereum\/status\/927920667760017408\" target=\"_blank\">users are speculating (or morbidly joking)<\/a> about the possibility of a &#8220;hard fork&#8221; to reverse the change and bring back the locked funds. After an Ethereum app called the DAO was hacked last year and <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/pgkzqm\/the-biggest-hacker-whodunnit-of-the-summer\" target=\"_blank\">an attacker siphoned away more than $50 million<\/a>, the community decided to create an entirely new version of Ethereum where the hack never happened. This was an <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/78kw3d\/ethereum-56m-hacker-the-dao-vitalik-buterin-hard-fork\" target=\"_blank\">extremely controversial and arguably risky<\/a> maneuver, because if the majority of the community doesn&#8217;t move over to the new network, a fork can result in serious instability. <\/p>\n<p> After the Parity bug in July saw an attacker steal $30 million worth of ether, <a href=\"https:\/\/twitter.com\/VitalikButerin\/status\/887783867129745412\" target=\"_blank\">Ethereum&#8217;s inventor Vitalik Buterin took to Twitter<\/a> in an apparent disavowal of a hard fork fix. The DAO hard fork was justified because the Ethereum ecosystem was &#8220;less mature then,&#8221; Buterin wrote. Ethereum has become more valuable and popular since then, and so this logic may continue to hold. <\/p>\n<p> Buterin did not respond to Motherboard&#8217;s request for comment. <\/p>\n<p>Parity may see things differently. &#8220;At the moment we are looking into every scenario, a hard fork is one of the options,&#8221; a spokesperson wrote me. <\/p>\n<p><a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/ywbqmg\/parity-multi-signature-wallet-vulnerability-300-million-hard-fork\" target=\"bwo\" >https:\/\/motherboard.vice.com\/en_us\/rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/video-images.vice.com\/articles\/5a01dcf176aca577836fed90\/lede\/1510071792255-shutterstock_95494732.jpeg\"\/><\/p>\n<p><strong>Credit to Author: Jordan Pearson| Date: Tue, 07 Nov 2017 16:24:10 +0000<\/strong><\/p>\n<p>And a hard fork is on the table. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,13328,10378],"tags":[16426,11210,16428,13662,13664,16060,13916,16430,16427,32,16429,1705,10467],"class_list":["post-10324","post","type-post","status-publish","format-standard","hentry","category-independent","category-motherboard","category-security","tag-16426","tag-bug","tag-dao","tag-ether","tag-ethereum","tag-hard-fork","tag-ico","tag-locked","tag-million","tag-news","tag-parity","tag-tech","tag-vulnerability"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/10324","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=10324"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/10324\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=10324"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=10324"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=10324"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}