我从比特币学到的21课
本文取得了Gigi翻译的同意,非常感谢Gigi。 Gigi是Twitter上一个知名的Bitcoiner。 19年我在微博上翻译了Gigi的这个系列,但今年因为国内zc,我把这个内容下架了,最近想还是把这个系列发到Mirror。 比特币是一个兔子洞,真正掉进去的人就别想出来了,我们只有不断向下探寻,这个就是一个真正Bitcoiner的冒险之旅。 因为我懂得不多,英语水平有限,另外我也不是哲学、经济学科班,虽然计算机专业小硕毕业,但是密码学这块涉猎也不多,所以很多内容我都还不能很好的把握,后面准备每个月把自己学习到的和感悟更新到这个系列里面。 另外希望大家指正,不对的地方我下次一起修正。Philosophical Teachings of BitcoinWhat I’ve Learned From Bitcoin: Part ISome questions have easy answers. “What have you learned from Bitcoin?” isn’t one of them. After trying to answer this question ...
以下为@DeFiMiner 翻译整理的Multicoin创始人Kyle Samani近期推文,学习
1、下一轮熊市将跟以往不同,事实上,可能根本不会有熊市。或者只会有半个熊市,熊市周期缩短,这取决于每个人对熊市的定义。 不会那种出现矿难大面积萧条的熊市了,只会有你手中币不涨的熊市 2、广义上讲,加密货币有2类群体:货币加密&技术加密。2011到2017年,由货币加密群体主导;2017年以后,技术加密成为主流。 应该也可以称为加密货币&加密技术可能更准确 3、2017-2018年是货币加密阵营就权利和相关性的争夺,但今天很明显,技术加密主导了时代。 4、仍然有很多人只把 BTC 看作通胀对冲工具,但他们在媒体、社交渠道、会议演讲等中所占的比例越来越小。 ~~加密世界/时代Base 不一定挂在嘴边,就像我们每天用互联网不会提一嘴TCP/IP ~~ 5、货币加密群体主要考虑利率、央行政策等,而技术加密群体更关心建设。 6、作为通胀对冲,政客/央行不可避免地会做一些对 BTC 不利的事情。无论是禁止(或试图禁止),还是提高利率,或者其他行为。这些机构的动作有自然的潮起潮落,BTC-USD自然会做出反应。 7、技术加密群体不关心这些,他们只想打造很酷的新东西。哪怕BTC-USD 的价格因...
Curvance
Curvance: Wrapped Token Lending ProtocolA new way to earn yield and unlock the full power of your liquidity Curvance is a decentralized stablecoin lending protocol with an initial focus on wrapped tokens from the Curve, Convex, Yearn, and Badger ecosystems. Curvance seeks to allow users to continue earning yield while unlocking capital through peer-to-peer lending. Assets such as cvxCRV, bveCVX, and yvBOOST could earn similar or higher APR they would earn on their original platforms, but with...
我从比特币学到的21课
本文取得了Gigi翻译的同意,非常感谢Gigi。 Gigi是Twitter上一个知名的Bitcoiner。 19年我在微博上翻译了Gigi的这个系列,但今年因为国内zc,我把这个内容下架了,最近想还是把这个系列发到Mirror。 比特币是一个兔子洞,真正掉进去的人就别想出来了,我们只有不断向下探寻,这个就是一个真正Bitcoiner的冒险之旅。 因为我懂得不多,英语水平有限,另外我也不是哲学、经济学科班,虽然计算机专业小硕毕业,但是密码学这块涉猎也不多,所以很多内容我都还不能很好的把握,后面准备每个月把自己学习到的和感悟更新到这个系列里面。 另外希望大家指正,不对的地方我下次一起修正。Philosophical Teachings of BitcoinWhat I’ve Learned From Bitcoin: Part ISome questions have easy answers. “What have you learned from Bitcoin?” isn’t one of them. After trying to answer this question ...
以下为@DeFiMiner 翻译整理的Multicoin创始人Kyle Samani近期推文,学习
1、下一轮熊市将跟以往不同,事实上,可能根本不会有熊市。或者只会有半个熊市,熊市周期缩短,这取决于每个人对熊市的定义。 不会那种出现矿难大面积萧条的熊市了,只会有你手中币不涨的熊市 2、广义上讲,加密货币有2类群体:货币加密&技术加密。2011到2017年,由货币加密群体主导;2017年以后,技术加密成为主流。 应该也可以称为加密货币&加密技术可能更准确 3、2017-2018年是货币加密阵营就权利和相关性的争夺,但今天很明显,技术加密主导了时代。 4、仍然有很多人只把 BTC 看作通胀对冲工具,但他们在媒体、社交渠道、会议演讲等中所占的比例越来越小。 ~~加密世界/时代Base 不一定挂在嘴边,就像我们每天用互联网不会提一嘴TCP/IP ~~ 5、货币加密群体主要考虑利率、央行政策等,而技术加密群体更关心建设。 6、作为通胀对冲,政客/央行不可避免地会做一些对 BTC 不利的事情。无论是禁止(或试图禁止),还是提高利率,或者其他行为。这些机构的动作有自然的潮起潮落,BTC-USD自然会做出反应。 7、技术加密群体不关心这些,他们只想打造很酷的新东西。哪怕BTC-USD 的价格因...
Curvance
Curvance: Wrapped Token Lending ProtocolA new way to earn yield and unlock the full power of your liquidity Curvance is a decentralized stablecoin lending protocol with an initial focus on wrapped tokens from the Curve, Convex, Yearn, and Badger ecosystems. Curvance seeks to allow users to continue earning yield while unlocking capital through peer-to-peer lending. Assets such as cvxCRV, bveCVX, and yvBOOST could earn similar or higher APR they would earn on their original platforms, but with...
Share Dialog
Share Dialog

Subscribe to andywan

Subscribe to andywan
https://twitter.com/Justin_Bons/status/1492561186310733824
1/14) Polygon in its current state is insecure & centralized!
It would only take 5 people to compromise over $5B!
4 of those people are the founders of Poly!
This is one of the largest hacks or exit scams just waiting to happen
Reckless & irresponsible, a warning to the wise:
2/14) The Polygon smart contract admin key is controlled by a 5 out of 8 multi-signature contract.
This means that polygon can gain complete control over Polygon with only 1 of the 4 outside parties conspiring.
The other 4 parties in the multisig where also selected by Polygon.
3/14) This also means that these 4 other parties are not exactly impartial.
Control over the contract admin key equals the power to change the rules.
At which point anything becomes possible.
Including emptying out the entire Polygon contract which is currently worth over $5B!
4/14) What is even worse is that Polygon has been completely opaque,
In terms of their operational security & cryptographic ritual around the creation of this multisig.
Which is important to at least establish trust in the multisig, as bad as that might already be.
5/14) Without any of these guarantees,
It is within the realm of possibility that a single individual already controls the admin key!
The use of admin keys at the very least requires very high standards of security.
6/14) To make things even worse @ChrisBlec from @DeFiWatch formally requested this disclosure
The Polygon team actually refused to respond!
This lack of response on its own should be considered as a giant red flag!
Transparency is severely lacking.
Second letter to Polygon about multisig
7/14) I know that this practice is already far to common in cryptocurrency as a whole.
But that does not justify that it is wrong & reckless.
I am focusing on Polygon because they are one of the largest cryptocurrencies that has this issue.
It is a disaster waiting to happen!
8/14) This is not about the quality of the founders.
The founders of Polygon seem like good people besides from this one weakness.
They might have confidence in themselves.
But they are exposing themselves to a grave danger as they become targets as points of centralization.
9/14) The higher the value locked, the higher the incentive & sophistication of potential attacks becomes.
Organized crime could target these individuals, potentially even through kidnapping & blackmail!
The 4 founders meeting in person could even lead to a accidental loss!
10/14) The point I am trying to make is that a 5 out of 8 multi-sig is wholefully insufficient for $5B!
I could continue to provide examples where loss occurs but I think I have made my point.
Polygon criticized @ChrisBlec for not providing an alternative, which is unfair.
11/14) I will provide Polygon with a clear alternative so that there is no excuse:
First of all Polygon has to decentralize their own governance based on the Matic token holders.
Currently this is still far to centralized following a DPoS model with a low number of validators.
12/14) Once Polygon has decentralized their governance.
They will have to transfer the smart contract admin key to the Matic token holders.
Effectively turning control over to the "Matic DAO".
This would most likely require a migration over to a new Polygon Smart contract.
13/14) This would obviously be very difficult & costly to do.
However that is the price to pay for not doing things right to begin with.
It is the price we pay for decentralization & the security that comes along with that.
This is what cryptocurrency should be all about.
14/14) Pretending to be secure & decentralized is not good for anyone in the long run.
There is a clear path for redemption here.
A simple acknowledgement of the problem & a commitment to fix it would go a long way.
I hope this message can serve as a constructive criticism.
https://twitter.com/Justin_Bons/status/1492561186310733824
1/14) Polygon in its current state is insecure & centralized!
It would only take 5 people to compromise over $5B!
4 of those people are the founders of Poly!
This is one of the largest hacks or exit scams just waiting to happen
Reckless & irresponsible, a warning to the wise:
2/14) The Polygon smart contract admin key is controlled by a 5 out of 8 multi-signature contract.
This means that polygon can gain complete control over Polygon with only 1 of the 4 outside parties conspiring.
The other 4 parties in the multisig where also selected by Polygon.
3/14) This also means that these 4 other parties are not exactly impartial.
Control over the contract admin key equals the power to change the rules.
At which point anything becomes possible.
Including emptying out the entire Polygon contract which is currently worth over $5B!
4/14) What is even worse is that Polygon has been completely opaque,
In terms of their operational security & cryptographic ritual around the creation of this multisig.
Which is important to at least establish trust in the multisig, as bad as that might already be.
5/14) Without any of these guarantees,
It is within the realm of possibility that a single individual already controls the admin key!
The use of admin keys at the very least requires very high standards of security.
6/14) To make things even worse @ChrisBlec from @DeFiWatch formally requested this disclosure
The Polygon team actually refused to respond!
This lack of response on its own should be considered as a giant red flag!
Transparency is severely lacking.
Second letter to Polygon about multisig
7/14) I know that this practice is already far to common in cryptocurrency as a whole.
But that does not justify that it is wrong & reckless.
I am focusing on Polygon because they are one of the largest cryptocurrencies that has this issue.
It is a disaster waiting to happen!
8/14) This is not about the quality of the founders.
The founders of Polygon seem like good people besides from this one weakness.
They might have confidence in themselves.
But they are exposing themselves to a grave danger as they become targets as points of centralization.
9/14) The higher the value locked, the higher the incentive & sophistication of potential attacks becomes.
Organized crime could target these individuals, potentially even through kidnapping & blackmail!
The 4 founders meeting in person could even lead to a accidental loss!
10/14) The point I am trying to make is that a 5 out of 8 multi-sig is wholefully insufficient for $5B!
I could continue to provide examples where loss occurs but I think I have made my point.
Polygon criticized @ChrisBlec for not providing an alternative, which is unfair.
11/14) I will provide Polygon with a clear alternative so that there is no excuse:
First of all Polygon has to decentralize their own governance based on the Matic token holders.
Currently this is still far to centralized following a DPoS model with a low number of validators.
12/14) Once Polygon has decentralized their governance.
They will have to transfer the smart contract admin key to the Matic token holders.
Effectively turning control over to the "Matic DAO".
This would most likely require a migration over to a new Polygon Smart contract.
13/14) This would obviously be very difficult & costly to do.
However that is the price to pay for not doing things right to begin with.
It is the price we pay for decentralization & the security that comes along with that.
This is what cryptocurrency should be all about.
14/14) Pretending to be secure & decentralized is not good for anyone in the long run.
There is a clear path for redemption here.
A simple acknowledgement of the problem & a commitment to fix it would go a long way.
I hope this message can serve as a constructive criticism.
<100 subscribers
<100 subscribers
No activity yet