Originally published by Patron#1 on Oct 29, 2021 at pint.network/t/
case-forensics-dao/
Following came about from @bantg drawing out a lesson from another Cream Finance exploit worth ~$130m; However the origin is from Patron#1's long-existing thoughts on compiling information related to rugs in a community-oriented manner. Recently, we've also publicly called for discourse on such provisions through open on-chain call (eth:13468000#162) to decentralized security community, however to not a single approach despite increase in traffic, which tells two things, one, PINT Network is early in its endeavor and as expected, will not attract quality minds for quite a while, second, community is comfortable in slavery and market euphoria, therefore, we have a lot of hard and thankless work to do to liberate them.
The lesson is money markets need to be extra careful when adding tokens which can be burned or minted. ~ @bantg at Twitter on CREAM Finance exploit
Decentralized space has been in a vicious loop of protocol exploits, with its legos nature, one protocol plugs into another, another into another, and we have a full circle of dependencies holding lots of monetary value. Unfortunately as we have discussed prior, most of these protocols are tied up into VCs and corrupted in their functions, not only technologically, but also in service level by selling trust in a trust-less economy, thereby such contradiction leaving that full circle rife for increasingly brazen exploitation.

Moreover, after an exploit causes loss, the script flips and the general course of corrupt systems follows i.e. if the founders have clout (enough VC backing), they go on to mask the exploit with their "marketing" budget and keep going, until they get exploited again, CREAM finance being a classic example; On the other hand, those without clout, get tainted for years to come, especially if they had made enemies; It's very easy to spin CT propaganda. Certain of these have not even bothered fixing the issues even after being exposed in advance and getting exploited. This is also made easy due to the greed in market, and the possibility that more new investors are pouring in all the time.
Let us switch to the tone of topic: Given the facts, we have searched and found no grail that takes facts of the exploits, public analyses by the security community, their extracts, and in an open manner, makes the lessons public in an easily accessible manner. Just like traditional systems, this leaves security aspects of building decentralized solutions, in the knowledge of few actors, thereby centralizing a core function of monetary protocols i.e. derisking without prejudice. These entities are mainly independent security researchers, enthusiasts and centralized audit companies. If such centralization was beneficial, we would not have the flux and velocity of exploitation loop increasing in magnitudes relative to total value locked.
Presently existing data is a scatter in a way that analyses have to be discovered on individual publications. The traces of transactions involving exploits have to be searched on centralized trust-based 3rd parties like etherscan. The lessons have to be learned through searching for obscure websites containing development hacks, or searching for twitter threads. People, stakeholders, institutional investors and audit companies involved have to be searched from archives of the official websites or reaching out and trusting the people involved.
By tagging the facts and actors, signing the analyses publications, past audits, and drawing out lessons, within a decentralized experience, we produce a corpus of verifiable intelligence, from which discourse and learning material can be extracted with relative ease, thereby publicly identifying repeating issues, and repeat offenders without prejudice, instead of just scapegoating engineers, destroying their careers thereby penalizing non-anonimity, then rinsing and repeating. The system can be further extended to enable other aspects of forensics.
Following are pointers to establish a rough solution space; They may be components of a Forensics DAO by contracts and by supported transparent, trust-less, open and highly available services:
Exploitative transactions and involved actors are tagged through verifiable integrations with open trust-less chain discovery systems. Builders of discovery solutions are incentivized to aid such specialized forensics integrations.
Tools that enable and incentivize interconnection of actors associated with the exploit, entities associated with the exploited technology, the associated protocol or project, the associated institutional investors, the associated auditors and other key associations.
Tools that present the above in an analysis friendly manner.
Systems that enable provision of certain level of above transparency, near instantaneously following a suspected exploitative activity on-chain.
Analysts are incentivized to primarily publish on permaweb, tools may be designed to attract them and make the transition easy and fun, along with provision of integrations with above designed tools.
Identified security actors are incentivized to conjecture on analyses and lessons learned.
All the data created is collectively made part of permaweb, and indexed across key factors.
This is a very early work, PINT Network will follow up on concrete steps towards Forensics DAO, we truly believe there is a vacuum to be filled with such provisions. We invite all interested parties to reach out, we aim to be open to hearing out and acting on every extent that doesn't compromise our spirit. Anyone may send absolutely any kind of relevant messages to our communication media, as well as reaching out to Patrons personally, there are no formalities yet, neither do we exist to build walls and fences.
https://web.archive.org/web/20220104113141/https://pint.network/t/case-forensics-dao/
