Cointime

Download App
iOS & Android

Beyond the Headlines: The Underlying Issues in Cryptocurrency in 2022 by Merkle Science

Validated Media

When we look back at the state of cryptocurrency in 2022, it’s easy to focus on the headlines. The news cycle was dominated, after all, by a handful of articles that captured the public’s attention with extraordinary stories, where digital currencies were stolen, hacked, laundered, and more. Like a soap, there was drama at every turn, including even tragedy - during the Luna crash, when the contagion effect between Luna and UST dropped the value of both in a never-ending death spiral, one man committed suicide after losing US$2 million.

While it’s important to pay attention to these twists and turns - narratives are indeed easier to remember - it’s equally important to examine the mechanisms that enabled them to occur in the first place. Doing so may help the cryptocurrency community avert similar disasters in 2023, and restore retail and institutional confidence in an industry reeling from a prolonged downturn.

Most of the exploits, failures, and issues in 2022 can be categorized into a few trends, all of which we should seek to curb.

Poor corporate governance - The news of poor corporate governance in tech is not a novelty. Within just the last five years, we saw the rise and fall of both Theranos and WeWork. The former was led by Elizabeth Holmes, who is now facing criminal charges for her role in fabricating data about her medical devices, while the latter was led by Adam Neumann, who engaged in many acts of self-dealing, including paying himself US$5.9 million for the trademark rights to the word “We.”

Cryptocurrency was pegged to be different in 2022. There should have been controls in place to prevent the corporate malfeasance that characterized the early Wild West days of the industry. But FTX proved the world wrong. On November 2, CoinDesk journalist Ian Allison made a stunning revelation: Alameda Research, the trading firm founded by Sam Bankman-Fried, held most of its funds in FTT, the token created by FTX, an exchange also founded by Sam Bankman-Fried.

Questions of impropriety aside, Alameda’s vast holdings in FTT, rather than a third-party asset like Bitcoin or Ethereum, cast doubts on the exchange’s solvency. Sure enough, the article triggered a chain of events that uncovered financial wrongdoing from Bankman-Fried, invited an acquisition attempt from Binance that was eventually aborted, and culminated in the firm’s bankruptcy just nine days after the initial story broke.

When John J. Ray III was appointed as FTX’s replacement CEO, he famously said, “Never in my career have I seen such a complete failure of corporate controls and such a complete absence of trustworthy financial information as occurred here,” implying FTX was even worse than Enron, a company he also presided over in the wake of its collapse.

The lack of corporate governance had been evident in many different ways. For one, FTX’s board of directors consisted of just Bankman-Fried, and a company representative rebuffed suggestions from a well-meaning venture capitalist to put one together with an unambiguous response. Without a board of directors, self-dealing abounded at FTX - from the company funneling US$8 billion of customer funds to sister company, Alameda, and even a loan of US$1 billion to Bankman-Fried. It even became evident that FTX has deliberately obfuscated the misuse of customer funds through software, which was just one of many knocks in an endless list showcasing the lack of financial controls.

While there is still debate on whether these behaviors represented intentional theft and fraud or just reckless business practices, analysts generally agree that it all could have been prevented with some semblance of corporate governance.

Proof of reserve - The poor corporate governance that plagued FTX could be addressed by proof-of-reserve, which will enable enterprises to show that they have control over the coins that they say they do. There are issues with how some businesses are handling PoR, however. Reportedly, some, such as Binance and HBTC, submitted their PoR without an auditor; others, such as Luno, Revix, Bitbuy, and Shakepay, did not follow the Merkle approach to user validation; and still, others took assets into account that did not have a cryptographic record, such as OKX, KuCoin, and Huobi.

For PoR to truly flourish as a safeguard on organizations (rather than just as marketing speak), it must be done by a third party. This auditor should provide transparency into the process of verifying the business has the correct value of customer funds, while protecting user privacy through hashing with a unique salt. But PoR needs to be taken a step further with proof of solvency. What good is it, after all, if a business has control of its funds if its liabilities exceed that value? The revelation of high liabilities could similarly trigger a bank run that would crater the business and its holdings.

The formula for PoS (Proof of solvency = proof of reserve + proof of liabilities) would go a long way toward ensuring a business can meet its obligations to all its stakeholders, from its customers to its creditors.

Social engineering - Cryptocurrency enthusiasts are viewed as technically savvy, leading the adoption of some of our world’s most cutting-edge solutions. But people in the ecosystem are just as susceptible to social engineering attempts as anyone else, as we witnessed in the Axie Infinity hack of US$620 million. This hack started from what seemed innocuous enough: an email.

Hackers affiliated with the North Korean government sent an email to a senior engineer at Axie Infinity, posing as company recruiters. The senior engineer was then led through a series of interviews for a position with a generous salary, which built enough plausibility for the worker to open an email containing the job description. The file infected the engineer’s computer, eventually giving hackers access to the Ronin blockchain. The hack could not have come at a worse time for Sky Mavis, the developer of Axie, as the players in emerging markets who quit their full-time jobs to earn from P2E were now spiraling into debt.

Affiliation with criminality - This is not so much a specific incident like the others on the list, but an ongoing issue. Ever since the advent of cryptocurrency, there were worries that bad actors would use it for criminal purposes, such as money laundering and sanctions evasion.

While crypto mixers were not developed to facilitate money laundering, bad actors use it to conceal illicit financial flows, including Lazarus Group, a North Korean cybercrime group.

Using notable crypto mixers as examples, the U.S. Department of Treasury brought this issue to the forefront. Built on Ethereum, Tornado Cash gives users a secret hash when depositing coins into the protocol’s liquidity pool. When the user intends to withdraw, he merely invokes his secret hash to prove ownership of the coins. In this way, Tornado Cash operates as a crypto mixer, while giving users the complete anonymity that would only be seemingly necessary for nefarious purposes, such as hacking. For example, the hacks used sanctioned mixer Tornado Cash to launder $2.34 million of funds in the TempleDAO hack.

Poor token design - In October 2022, decentralized finance platform Mango Markets lost more than US$100 million dollars. While some of the immediate reports classified the loss as a hack, the nature of the crime was more of an exploit, one that capitalized (quite literally) on loopholes in the smart contract protocol. Former FBI agent Chris Tarbell classified the scheme as market manipulation.

The scheme was quite clever. The perpetrator, Avraham Eisenberg, took different positions on MNGO tokens from two separate accounts, betting long on one and short on the other. He then used more funds to manipulate the MNGO price to go up and subsequently cashed out on the account banking on the token’s rise in value. Details of this scheme are public because Eisenberg has been very vocal about the incident, calling it a legitimate trading strategy. While he vowed to return some of the funds, he has since been charged with the Commodity Futures Trading Commission with violations against the Commodity Exchange Act.

Economic model exploits - Stablecoins are supposed to be, well, stable. Pegged to a relatively more stable currency like the US dollar, stablecoins are supposed to be less susceptible to the wild up-and-down price fluctuations that have characterized most cryptocurrencies. In 2018, Do Kwon of Terraform Labs, a graduate of the computer science program at Stanford University, created an algorithmic stablecoin. Built on the Terra network, the UST was backed by a sister token, Luna, the latter of which needed to be burned to create the former.

Some predicted that this mechanism would not work, and they were right. In May 2022, the Luna entered a death spiral, going from US$120 to US$.02 in the span of 48 hours. The loss was linked between the close relationship between the two tokens: People started to panic sell their UST for a slightly higher value of Luna, which drove more people to sell their UST, further lowering its price and encouraging more people to follow suit as its value continued to plummet.

With the wipeout of about US$60 billion in value from the Luna crash, the government may accelerate its plans to regulate stablecoins. In March 2022, the Biden administration proposed the regulation of stablecoins as part of an executive order on the responsible development of digital assets. 2023 could be the year that this idea evolves from proposal to policy, driven by the mounting pressure from consumers for more protective stablecoin regulation.

Looking ahead to 2023

As bad as some of these issues were in 2022 - especially if you experienced any of them first-hand - people should be bolstered by the fact that they are largely addressable.

As the industry matures, technologists will be more aware of possible exploits against smart contract protocols and economic models, DeFi aggregators that obfuscate the flow of funds, bridges that are used for chain-hopping and could also fall victim to exploits. Our soon-to-launch hackhub report contains more such insights for people who want to stay ahead of the curve.

New solutions related to security, privacy, and compliance shall emerge as part of what venture capital firm, A16Z, calls the “price-innovation cycle.” Cryptocurrency, of course, needs more than just technological innovation to succeed. Just as crucial is the regulatory environment. The recent sanctions against Tornado Cash, for example, have made it much more difficult to access the crypto mixer. More regulations and policies are needed to quash out tools like these that give the entire industry a bad name.

Finally, people in the industry should not just be cryptocurrency enthusiasts - they should be technologists, period. Central to this is advancing one’s knowledge of cybersecurity, especially as it relates to common hacks, such as spearfishing. More people embracing this orientation would bode well for our shared security since systems are only strong as their weakest link (the US$620 million Axie hack was again caused by a single bumbling engineer).

Innovations along these dimensions - technology, policy, and market education - suggest a more positive future for cryptocurrency in 2023. There may be light ahead of this crypto winter.

Read more: https://blog.merklescience.com/general/beyond-the-headlines-the-underlying-issues-in-cryptocurrency-in-2022-by-merkle-science?

Comments

All Comments

Recommended for you

  • Xinjiang launches special campaign to combat illegal fundraising, with key areas including virtual currency, blockchain, etc.

    According to Chang'an Xinjiang Public Account, Xinjiang Autonomous Region and Corps have launched a joint special action to crack down on illegal fund-raising, with key areas including third-party wealth management, fake private equity, fake gold exchange and other traditional fields, as well as emerging fields such as virtual currency, blockchain, cultural tourism, film and television investment, and debt resolution services. It is reported that key cases include cases involving more than 100 million yuan and cases that have been criminally filed for more than five years.

  • A British court has postponed the final sentencing of Wen Jian, a British-Chinese national involved in the country's largest Bitcoin money laundering case, until May 24.

    On May 11th, it was reported that Jian Wen, a 42-year-old British Chinese citizen, was found guilty of "participating in arranging money laundering" in the UK's largest Bitcoin money laundering case. He could be sentenced to up to 14 years in prison. Jian Wen's defense lawyer, Mark Harries, stated that due to the judge's busy schedule, the UK court has postponed Jian Wen's final sentencing, which was originally scheduled for May 10th, to May 24th.

  • Web3 startup Star Nest completes $6 million in Pre-A round of financing

    Hong Kong Web3 music startup Star Nest announced that it has completed a $6 million Pre-A round of financing, led by Chuangqi International Limited, a wholly-owned subsidiary of Hong Kong Stock Exchange-listed company Guofu Innovation. Star Nest will collaborate with Armonia Meta Chain to develop the Star Nest SpaceStar metaverse game, which includes music, role-playing, and social features.In addition, Star Nest plans to launch its NEST project in the third quarter of 2024. Nest will receive 2.1 billion NEST tokens tailored for the project, and Star Nest will use the NEST token to build a more complete music industry token economic system. The NEST token will be widely used for purchasing performance tickets, chain game cooperation, metaverse consumption, governance voting, and other activities.

  • Over $594 million worth of PYTH is staked

    According to Dune data,  there are currently 1,201,167,362 PYTH tokens in the staked state, with a total staked value exceeding $594 million. The number of PYTH stakers has reached 151,211.

  • US Department of Justice: Tornado Cash indictment has nothing to do with "free speech"

    On May 11th, the US Department of Justice explained why the motion to dismiss the criminal case against Tornado Cash founder Roman Storm was invalid. The Department of Justice reiterated that their indictment was not related to whether the Tornado Cash computer code had freedom of speech or was protected by the First Amendment of the Constitution. The defendant was not charged for publishing computer code, but for using it to facilitate profitable illegal activities.

  • USDC circulation decreased by $100 million in the past week, with a total circulation of $33 billion

    According to official data,as of May 9th, Circle has issued approximately $2 billion USDC and redeemed approximately $2 billion USDC in the past 7 days, with a decrease in circulation of approximately $100 million. The total circulation of USDC is $33 billion, with a reserve of $33.1 billion, including approximately $3.3 billion in cash and Circle Reserve Fund holding approximately $29.8 billion.

  • SEC rejects Coinbase's request for appeals court ruling on cryptocurrency rules

    The US SEC has rejected Coinbase's request to appeal to the court to review whether traditional securities rules are applicable to cryptocurrencies. In its application, Coinbase stated that it hoped the appeals court would consider whether the Howey test, which has long been used for securities evaluation, should be applied to digital assets. However, the SEC pointed out that Coinbase has not successfully demonstrated the need for such an evaluation. The SEC stated that Coinbase is attempting to create a "new legal test," but this attempt was rejected by the court. The court found that Coinbase's arguments lacked consistency and did not successfully demonstrate the existence of decisive issues. Currently, the judge responsible for hearing the SEC's case against Coinbase will make a ruling on Coinbase's intermediate appeal motion.

  • Colombian President Suspected of Accepting $500,000 in Illegal Crypto Donations

    Colombian President Gustavo Petro is suspected of accepting over $500,000 in digital token donations from a fraudulent cryptocurrency project during his 2022 election campaign. A former contractor revealed that the illegal donation occurred during a meeting in February 2022 that discussed the advantages of cryptocurrency and the possibility of working with the government. This allegation is one of the latest charges faced by President Petro during his election campaign, with the Colombian Prosecutor's Office investigating his campaign last year.

  • Fed's Kashkari: The bar for another rate hike is high, but it cannot be ruled out

    The Federal Reserve's Kashkari expressed a cautious attitude towards restrictive monetary policy; he is adopting a wait-and-see attitude towards future monetary policy; he is in a wait-and-see state to see if inflation is stagnating; the threshold for raising interest rates again is high, but this possibility cannot be ruled out; if inflation data supports it, the Fed will maintain interest rates.

  • The address that defrauded 1,155 wBTC has returned more than 96% of the funds to the victims

    Blockchain data shows that the address poisoning attacker lured users to send 1,155 Wrapped Bitcoins (wBTC) (valued at $68 million at the time) to them. The attacker has returned almost all of the stolen funds. These funds were exchanged for Ethereum (ETH) during the attacker's holding period, and the price of ETH has since fallen. However, the attacker returned about 22,960.07 ETH, worth about $65.7 million, which accounts for over 96% of the initial stolen funds in terms of US dollar value.