New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

The Tornado Cash Exploit | ETHDam 2023

CryptoCanalSat, Oct 7, 2023, 12:00 AM

Ameen Soleimani is the founder of SpankChain. https://twitter.com/ameensol?t=IihfhpFRvtHpMwqypgXW6g&s=09 Kieran Mesquita is a contributor to RAILGUN DAO. https://twitter.com/mesquka ETHDam is a Hackathon & Conference that gathered over 500 DeFi and Privacy builders on the 20th and 21st of May 2023 in Amsterdam. Privacy is normal. Following the arrest of Alex Pertsev, a Tornado Cash developer in the Netherlands, ETHDam 2023 is determined to counter the chilling effects of the lawsuit and bridge worlds to discuss the future of privacy and encourage to build on the shoulders of cypherpunk giants. ETHDam is powered by CryptoCanal, - a blockchain education and events platform growing in Amsterdam, spreading its roots to Rotterdam and Zurich. ETHDam 2024 is on the map already! Keep up with us to see updates: CryptoCanal https://www.cryptocanal.org/ CryptoCanal Twitter https://twitter.com/CryptoCanal Join CryptoCanal Community https://t.me/CryptoCanalCommunity We would like to thank our partners and sponsors that made this event possible. 🌷 Our BFF 1inch https://1inch.io/ Our Frens: Sismo https://www.sismo.io/ Aleph Zero https://alephzero.org/ Scroll https://scroll.io/ RAILGUN https://railgun.org/#/ And our Sisters: oasis.app https://oasis.app/#earn Maven11 https://www.maven11.com/ bitvavo https://bitvavo.com/en Lido https://lido.fi/ Spankchain https://spankchain.com/ API3 https://api3.org/ Gelato https://www.gelato.network/ VanEck https://www.vaneck.com/nl/en/crypto-etn Marlin Protocol https://www.marlin.org/ Silent Protocol https://www.silentprotocol.org/ Cyber Capital https://cyber.capital/ … and Proto https://twitter.com/protolambda 🍍

Transcript

foreign [Music] this is going to be a fun one um yesterday we were celebrating a lot of things for alternator cash and welcoming Alexi here and his lawyer and then last night something happened I would like to welcome Kieran and amine to the stage to explain to us what in the hell happened I could only follow crypto Twitter last night really lately Round of Applause for Kieran and amine thank you [Applause] okay let's hear about this tornado cash exploit good morning hello good morning everybody uh yeah so last night the tornado cash governance was attacked by a malicious proposal uh it's always fun when these things happen during conferences because then we all get to talk about it uh I remember when like Geth was ddosed and eth Shanghai and vitalik had to go in the war room and figure out how to debug Geth like reprice some gas things so that it would work uh this was kind of like that uh the attacker submitted a proposal to the tornado governance and uh the proposal contract code was like self-destructible so he self-destructed it and replaced it with some other code that then printed him like a bajillion governance tokens and allowed them to take over the contract uh the governance so now tornado governance is in the hands of a malicious attacker and everything that the uh Dao owned is basically under their control so we're going to go over what how this happened uh what you know they took over and what we can do about it uh you want to go sure um yeah so a rough timeline of events about a week ago or eight days ago now um the attacker submitted a proposal to the tornado cash governance that you know in First Look did exactly what the description said it would um but yes as I mean uh stated it had the ability for the proposal contract to be self-destructed and there's an unfortunate interaction um with the way that some of the deterministic deployments on ethereum a work which allows which allows you to uh it's not meant to be possible but you can deploy something with the same deployment script which means it'll deploy to the same uh the same address but with a completely different functionality and so um the attacker uh you know obviously the proposal was something that um got passed and the attacker waited until the proposal was passed and deleted the old proposal and replaced it with one that minted a bunch of new um governance voting power to their address um and then went ahead and executed The Proposal um because you know the address that the proposal lived at um was the same as this this new malicious proposal um they ended up uh getting a whole bunch of government's power um and uh what have they done so far with it so they've uh they've got access to uh from from the government's contract they've got access to uh the torn uh Treasury and a couple of um kind of periphery contracts so the core um uh tornado cash classic polls are immutable they can't be changed and so anything in that can't be influenced by the governance but there's a couple of things that kind of surround that which the the government's contracts do have access to so there's the router contract the fee registry um the two main ones and the the tone Treasury and so they uh pulled a whole bunch of tone tokens out of the treasury there and have dumped it on Market um like that's that's about the the timeline uh for what's happened so far um they also control Nova if you want to talk about yes uh so Nova is kind of the the next iteration um or a new kind of um uh thing on top of um one on top of a new system um that um kind of is built on xdi and through a bridge operates or interacts with ethereum jump in uh so the tornado Nova is like on gnosis chain and the idea was for it to have like arbitrary deposit amounts and be able to have like internal shielded transactions uh it's a pretty cool system altogether but it was still experimental and so it was upgradable and by virtue of being upgradable that means the tornado governance uh can uh you know update it and you can like update one of the contracts to be like this is a valid proof if uh the message is my wallet or the sender of this message is my wallet and therefore give me all the money right uh that's that's not what you want that's just a rug pull waiting to happen so please note if you have any money in tornado Nova you should probably remove it if you're not a US citizen because if you are a US citizen you are still sanctioned and you can't remove it uh but for everybody else you should remove it um this isn't like an immediate threat you're not going to lose your money tomorrow because the attacker has to submit a proposal to go rug pull tornado Nova and the proposal will take a week so please proceed to the exits in an orderly fashion uh yeah um the the other thing that is annoying so he what he mentioned so far was that they control the like relayer registry and the router so the relayer registry is just like on the UI the drop down of like the relayers that you can pick to get you know relay the money uh and then the router is another thing that's used by the UI to like select you know which contract you're using uh and so for you know people should be advised that even if you uh have this uh you know replace the UI like you have to also then make it point to uh not those contracts because those contracts are controlled by the governance and they can point them to something malicious uh and so you know I'm sure on you know inevitably somebody is going to redeploy you know some a non or something uh is going to redeploy the contract uh the relayer registry the router the you know fee registry like he was saying and then not have them controlled by governance and point them to the immutable uh base you know tent 110 eth 100th uh pools which will allow you know people to continue to use and withdraw those if they're not US citizens uh because they're sanctioned I have to keep saying this um how you know it's whatever uh the other thing that's really annoying for me personally is that they control the tornado.e you know the ens the name uh and as a result of that uh I had to rip this uh QR code off the back of my shirt I burned it uh because it points to tornado cash.eath.link uh which is you know controlled by the ens name which is owned by the Dow which is owned by the attacker and so now it could be pointed to a malicious you know uh UI or web page tomorrow uh not great but it's not like a devastating loss you know we'll make new t-shirts or something uh yeah the the biggest risk is once again tornado Nova if you have money in there and you're not a US citizen go ahead and withdraw it and uh if you are still so bold as to have torn LP tokens and have been getting dumped on for the last day you might also want to pull those out of the people once again if you are not a US citizen Because the actual torn tokens are also sanctioned yeah um did find it a bit interesting um the particular method that the attacker used because they gave themselves looks for voting power um while they had like the execution context of the governance um contract they could have given themselves immediate access to everything um but now they've kind of locked themselves in the seven day um time lock and every every action that they're going to do so that's that's a bit odd um I don't know why uh yeah I think today is an important day for us to all learn the value of immutability and ungovernance every new code update that you deploy for whatever Dao you have you know you voted in you think it's a good idea well every update you know that has to be approached with the same level of scrutiny as you would any other part of your code base you have to get it fully audited every time there's no excuse you know Euler hack happened a couple weeks you know a month ago or whatever same basic idea they made a lot of governance updates and one of them had a bug in it uh I went and I told my you know reflexor Dao for Rye I'm like hey guys I think it's time to put up a bounty for a bot that like tags everybody in Discord every time there's a proposal so that we all know and are aware and can be on guard I've been talking about ungovernance for a while for the specific reason it's because you know if you keep like on a long enough timeline governance attack becomes the most risky way for a protocol to go down you know the sort of smart contract risk is is higher at the beginning and then over time it sort of drops because it sort of gets Lindy you know you build some confidence around it but the government attack risk always remains and so you need this constant vigilance in order to defend against that kind of thing and so the fewer things that governance can do to rug pull the users the more that you know there's delays in the process uh and the more there's you know potentially safeguards these are all good ways to protect the users from yourself and from the governance if somebody tries to attack it I assume we don't need to talk about admin keys oh yeah so uh the reason that the 110 eth all the classic pools are fine is because the admin key was set to zero on purpose four years ago so that today I wouldn't have to you know freak out and I could go enjoy Amsterdam last night it's a great City I just got here for the first time uh yeah bullish on Amsterdam [Applause] laughs and up on stage thanks for being up on stage and talking about this pretty timely attack um I mean what Frameworks do you have in mind for structuring ungovernance uh yeah so ungovernance is like a meme first you know it's it's like a culture of like we don't we don't we want to have meetings to like have less meetings you know we want we want to remove the ability of governance to do things you start out with like governance you know everything controlled by a multi-cig or something you progress to everything controlled by Dao and then for in the example of Rye right we've actually removed functions uh from being controlled by governance at all and set them to zero right or they can't be updated and so for the example of Rye like you can't actually update the collateral type right we we can't update certain contracts anymore uh and if we wanted to do that we would have to redeploy the whole contract right and in the case of tornado cash the ungovernance part the part that is currently saving you know the 110th 100 uh pools is uh the fact that we set the admin key to zero so governance does not control those nobody control those nobody can change those those are going to be immutable as programmed until the end of the ethereum blockchain or the you know heat death of the universe whichever one comes first so that's the thing and then like there's also other mechanisms that you can build in uh by adding delays for example to like you know hard code certain proposals or added delay before something is executed like in the case of Rye again uh if you want to add a new Oracle uh where oracles are typically the most risky type of you know uh governance thing to add because the maximum downside if your Oracle messes up is like oh okay here's what we're gonna do uh first we're going to set you know the collateral value to zero and then we're just going to liquidate everybody uh take all the money and then we're going to set the collateral value to infinity and then we're going to Mint Infinity rye and then we're going to go to Every lending pool and every amm on the blockchain we're going to wipe out everything in a single block right not great uh so we hard coded that to 60 days right and we can't change that and if you want to add a new one and that gives us the opportunity for example to oh uh you know the governance is like less than that so it's I think a week right now I want to make it more but even within that like if somebody somehow votes to add a malicious Oracle it doesn't take uh effect for 60 days and then people can sort of reconvene and be like whoa uh let's you know gather all the tokens and vote to make this uh you know remove this a new Oracle from from coming into existence next question thank you um so related to to what was just asked for the parts of the protocol where you do need governance because variables need to be flexible if you had a magic wand what does the optimal or like yeah what is the best risk management framework in your mind look uh look like so if you had to go from something as proposed all the way to it's implemented what are those steps at each point um I guess there's a couple of things that you want to look at um within your like Dow governance system so one um voting on as like a temperature check um and then having someone else implement the changes later is um I mean even even if you kind of trust the person to carry out the proposal honestly um not everyone has like well no one has perfect opsec um keys are going to leak eventually um so the kind of multi-sig model is a bit a bit dangerous um uh so you you want to be voting on the actual actions that get carried out on chain two um having some sort of like time lock so even if if a malicious proposal gets through there is some time to either remediate or um or how people you know find the exit um and and three um you know you want to be making sure that uh you're you're watching um the voting contract pretty closely because uh you don't want to be in a situation where um you don't know that a vote is um you know on the table and it passes and your your court off guard um so there's a number of like uh you know services and Bots and scripts and all that'll you can give it an arbitrary uh contract um and tell it to watch for uh calls that's a bit of function um so if you're like using a a particular uh protocol um or you have like a large position on the Dow I would recommend um you know grabbing something like that and setting it up point it to the voting contract just so at least you yourself I mean even if um if the uh the the governance like Discord or whatever has its own bot right you're trusting that bot or the person's running that bot not like give you false information or withholder um a voting thing so you run that thing yourself for yourself hopefully these are two different parties you know you're not getting rugged by the person who set up your Discord bot then you might have bigger problems uh yeah um another one like a funny one somebody was like hey man do you want to participate in like uni uh governance I'm like I am I'm Perma abstaining on everything and they're like no but we want you to get involved I'm like okay here's my plan for getting involved set up a smart contract that votes no on everything and I will delegate to that uh and like anybody could poke it and that just like no no no no no and that's like it actually raises the bar on like how hard it is to like attack the thing like it's a it's a useful contribution like I'm just saying you better really want this you know uh uh and and then like to to fill you know add to uh what Kieran was saying there's like typically the voting on and governance happens through like a couple phases right like a proposal is submitted and then there's like a delay before it enters the voting period and like the votes that you have are like tallied at the beginning of the voting period so you have that window of time between when a proposal is submitted and when it enters the voting if you set it up you know this way uh to like go around and be like hey do we have enough tokens to vote on this like properly uh so that's one of the things you want to be able to watch uh and others then during the voting period you know you vote you do what you know you can uh let's say you fail then there's like a grace period or or a time lock uh as you know different people call it different things uh but it's like the delay before a passing proposal is then executed uh and so that's the window during which not very many systems are set up to like cancel a passing vote during that delay very few that I know of Malik V3 has has a thing uh for it but it's railgun huh railgun oh nice uh and then like I think compound Bravo had one but like you need to it's like the the person who proposed it can uh like cancel it which I don't know if that uh would help in this type of situation uh because like the proposer is the attacker um what one one other mechanism that I I would think is cool is having like I don't know hundreds let's call them Sentinels right and they each get like one nft and the they can only do one thing which is like you can burn the nft uh one time and that will simply extend the time lock for executing a passing proposal by like one day and maybe it's like a global thing for like all proposals right and so that way you can like brick you know the hundred of you in a decentralized fashion can like brick all of this and you know in this case that would actually be helpful because like if they go and try to execute any proposals while we're this is like a has hit the fan and you are exiting this protocol and you just need to like cover people while they get out right you've already you've already lost uh in this scenario uh but like in order to protect the people's funds while they exit you could for example burn you know a bunch of these Sentinels can burn their nft and then break the governance for like a while and that way the governance can't do anything else malicious while the people are exiting nobody to my knowledge has implemented something like that but that would be pretty cool too all right now next last question definitely first of all thank you so much for sharing the whole story with us I totally understand from personal experience it's not easy at all to talk about something some kind of incident that has happened to you so huge respect and thank you and my question would be that several of the things that you mentioned have happened in the past they are things that we have been through as a community right and they have been resolved one thing that I would ask is the deterministic deployment address is kind of issue has been addressed by agnosis in the past I believe then the second question would be from what I understand the proposal contract was upgradable or was able to be upgradable by the user who made The Proposal and the contract itself could contain code which can be executed where the user able to decode that piece of code and they were they educated by the tornado cash team to be knowledgeable enough to understand what that code does and if they understand that it's malicious to kind of decline The Proposal um the the like proposal contract it essentially gets like delegate called from the governance contract and so you get the execution contract and when you have execution context you can change mappings on um on the um or you can stay change whatever storage you want on the governance contract right and so if you've got your voting power mapping on your governance contract you can you can go in and change that right um the um I'm sorry we'll see second part of your question there was since there was malicious code in The Proposal where the people educated from the tornado cash team in order to understand how to decode that code and potentially vote against it yeah so the the um because it took advantage of like deleting the um all proposals on replacing it at the same address the code that was voted on actually did what it said on a on the tin right like the proposal description says it's going to do this and the the actual proposal does actually do that it's just the fact that they were able to go in after the fact and change what the proposal code was like yeah I mean the simple answer to this is like don't accept any proposals with a self-destruct education towards the users to understand this kind of contract proposal or this tornado cash team is trying to stay out of jail I don't know what you think they're up to like but yes now we've all learned not to accept the one with the self-destruct okay uh one last question thank you so it's one of the solutions you said audits more auditing every update um but could it be that the current state of audits is maybe part of the problem because you have to pay a lot of money for basically the batch and many of the exploits you've mentioned have actually been audited instead of spending the money on a lot of overhead audit firms would it not be better to spend that money directly on security researchers to avoid these problems in the first place um yeah I think the order process is um it's unfortunately it's um overly shaped by uh what kind of people expect the output to be in in a marketing sense um and so there's um like even even projects that have been audited a lot of bugs get introduced in as part of the remediation phase and so you know the order will order it will go and produce a report uh and you know good orders will actually follow up and make sure that the remediation is done properly um but often you know you'll just have this kind of report as the output you'll fix the issues and you'll take them off on the report saying fixed fixed fixed but what if your fix has a bug in it right and so yeah I think the I think the auditing process can be can be improved uh yeah I mean if if you can't afford to upgrade your contracts maybe don't that's another t-shirt okay thank you so much one last final comment anything for this event uh this exploits and then you're off thank you for the entertainment [Laughter] [Applause]

Automatic transcript — names and jargon may be misspelled.