சரடம் & கருத்துரை
ஒரு கற்பனைத் தணிகை நிர்வாக நிகழ்வு
சாவிகளை வைத்திருந்தவர்கள் மாற்றத்தை அனுமதித்த பிறகு, $500,000 பக்-பவுண்டி காப்புத்தொகை எவ்வாறு ஒரு “மேம்பட்ட” ஹாக் ஆனது.
இந்தப் பக்கம் அசல் ஆங்கில கட்டுரையின் இயந்திர மொழிபெயர்ப்பு; இது மனித ஆசிரியரால் பரிசீலிக்கப்படவில்லை, ஆகவே உறுதிப்படுத்தப்பட்ட பதிப்புக்காக ஆங்கில மூலத்தைப் பார்க்கவும்.

முழுமையாக கற்பனையான பரிகாசம்: Osprey Finance, அதன் treasury, பங்கேற்பாளர்கள், பரிவர்த்தனைகள், மேற்கோள்கள், மற்றும் நிகழ்வுகள் அனைத்தும் உருவாக்கப்பட்டவை. இந்த parody எந்த உண்மையான protocol, company, person, proposal, அல்லது event தொடர்பாகவும் தவறான நடத்தை நடந்ததாக விவரிப்பதில்லை அல்லது குற்றஞ்சாட்டுவதில்லை. இது commentary மட்டுமே; reporting அல்ல, investment advice அல்ல.
ஆசிரியர் குழு
உள்ளடக்கப் பதிவு
கடுமையான பரிகாசம்
முழுமையாக கற்பனையானது
Osprey Finance, அதன் treasury, பங்கேற்பாளர்கள், பரிவர்த்தனைகள், மேற்கோள்கள், மற்றும் நிகழ்வுகள் அனைத்தும் கற்பனையில் உருவாக்கப்பட்டவை. இந்த parody எந்த உண்மையான protocol, company, person, proposal, அல்லது event தொடர்பாகவும் தவறான நடத்தை நடந்ததாக விவரிப்பதில்லை அல்லது குற்றஞ்சாட்டுவதில்லை.
I. A Treasury Reserve Is Discovered, Miraculously, In December
ஆண்டின் இறுதி வாரத்தில் முழுமையாக கற்பனையாக, Osprey Finance இன் core team $500,000 bug-bounty treasury இன்னும் இருப்பதை கண்டறிந்தது. அந்த reserve, ஆபத்தான குறைகளை பிறர் காணும் முன் கண்டுபிடிக்கும் சுயாதீன பாதுகாப்பு ஆராய்ச்சியாளர்களுக்காகத் திட்டமிடப்பட்டிருந்தது.
இது மூலதனத்தின் சிறந்த பயன்பாடாகக் கருதப்பட்டது, ஆனால் அவசரமானதாக அல்ல. ஆண்டு முடிந்துகொண்டிருந்தது. காலெண்டர்கள் நிரம்பிக் கொண்டிருந்தன. இன்னும் உடனடியான ஒரு வாய்ப்பு தோன்றியது: அந்த பணத்தை reserve இருப்பதை அறிந்திருந்த, signing access கொண்டிருந்த, மற்றும் ஒரு emergency-ஐ அங்கீகரிக்கத் தயாராக இருந்த அதே team members கட்டுப்படுத்தும் ஒரு multisig-க்கு மாற்ற முடிந்தது.
- December 27 · 8:12 a.m. — கண்டறிதல்: ஒரு team dashboard dormanth $500,000 bug-bounty treasury-ஐ கவனிக்கிறது.
- December 27 · 8:19 a.m. — மறுபெயரிடல்: reserve ஒரு internal memo-வில் “incident-containment liquidity” என மறுபெயரிடப்படுகிறது.
- December 27 · 8:31 a.m. — முன்மொழிவு: ஆண்டு almost over என்பதால் OFP-365 17-minute discussion period-உடன் திறக்கப்படுகிறது.
- December 27 · 8:44 a.m. — அங்கீகாரம்: ஏற்கனவே உள்ள signers தங்களின் own emergency-response multisig-க்கு transfer-ஐ அங்கீகரிக்கிறார்கள்.
- December 27 · 8:57 a.m. — இழப்பீடு: பெறுநர்கள் தங்களுக்கு “emergency incident-response compensation” வழங்கிக் கொள்கிறார்கள்.
II. The Governance Proposal Arrives With Its Shoes Still On
அவசரமாக தயாரிக்கப்பட்ட OFP-365 என்ற proposal, அந்த transfer-ஐ “incident-containment liquidity realignment” என விவரித்தது. treasury-க்கு ஒரு “unauthorized accounting event” ஏற்பட்டதாக அது கூறியது; ஆனால் அந்த accounting event signing keys வைத்திருந்தவர்களால் அங்கீகரிக்கப்பட்டது என்பதை வாசகர்கள் கவனித்ததும், அந்த சொற்றொடர் அச்சமூட்டுவது குறையத் தொடங்கியது.
Discussion window 17 minutes என நிர்ணயிக்கப்பட்டது. இது wallet history-ஐ சுயாதீனமாக மதிப்பாய்வு செய்யவும், security researchers-ஐ தொடர்புகொள்ளவும், destination multisig-ஐ யார் கட்டுப்படுத்துகிறார்கள் என்று கேட்கவும், அல்லது “incident-containment liquidity realignment” உள்ள வாக்கியத்தைப் படித்து முடிக்கவும் போதுமான நேரம் அல்ல. இருப்பினும், community-யின் மௌனம் ஆதரவாகப் புரிந்துகொள்ளப்பட்டதாக proposal authors பதிவிடுவதற்கு இது போதுமான நேரமாக இருந்தது.
Osprey Finance · OFP-365
Emergency Treasury Reclassification
Requested action: independent bug-bounty reserve-இலிருந்து $500,000-ஐ team-controlled emergency multisig-க்கு realign செய்து, பின்னர் authorized responders-க்கு incident-response compensation-ஐ பகிர்ந்தளிக்கவும்.
“The event is being treated as a hack because the funds moved unexpectedly from their original purpose.”
Discussion period: 17 minutes. Independent review: not scheduled. Destination signers: already authorized.
III. The Community Asks Several Extremely Advanced Questions
“PleaseCheckTheSigners” என்ற கற்பனையான username-ன் கீழ் செயல்பட்ட ஒரு community member, பரிவர்த்தனையை sign செய்தவர்களே ஏன் investigators, proposal authors, மற்றும் compensation பெறுபவர்களாகவும் இருந்தனர் என்று கேட்டார். இந்தக் கேள்வி 8:39 a.m. மணிக்கு பதிவிடப்பட்டது; அர்த்தமுள்ள பதிலுக்காக எட்டு நிமிடங்களும், team அதை resolved என விவரிக்க ஒன்பது நிமிடங்களும் மீதமிருந்தன.
“If the signers, investigators, proposal authors, and recipients are the same people, who exactly is investigating whom?”
— PleaseCheckTheSigners, fictional community member
Core team இந்த ஏற்பாடு அசாதாரண நுணுக்கத்தை காட்டுகிறது என்று பதிலளித்தது. “அது authorised ஆக இருந்ததால் தான் அது advanced,” என்று ஒரு கற்பனையான incident lead கூறினார். “ஒரு ordinary hack-க்கு attacker தேவைப்படும். இது permission கொண்டவர்களை உள்ளடக்கிய coordinated internal security event; இதை quarterly report-இல் விளக்குவது much more difficult.”
இரண்டாவது team member, transfer-ஐ self-dealing என அழைப்பது “self-dealing review, conducted by the recipients, முடியும் வரை premature” என்று சேர்த்தார். compensation ஏற்கனவே approved ஆகியிருந்ததால் அந்த review objectivity கொண்டதாக இருக்கும் என எதிர்பார்க்கப்பட்டது.
IV. The Incident Report Finds That Everything Went According To Plan
Osprey Finance இன் ஆண்டு-இறுதி incident report, bug-bounty treasury conventional sense-இல் திருடப்படவில்லை என்று முடிவு செய்தது. அதற்குப் பதிலாக, authorized signers தங்களுக்கு known இருந்த funds-ஐ தாங்கள் கட்டுப்படுத்தும் wallet-க்கு நகர்த்தி, அதன் விளைவாக ஏற்பட்ட emergency-ஐ compensation framework-ஆக மாற்றிய “controlled surprise” ஒன்று நிகழ்ந்தது.
“The absence of an external attacker should not diminish the complexity of the event,” என report கூறியது. “The team successfully identified the reserve, approved the response, transferred the reserve, and documented the response before anyone could confuse the sequence of events with a normal payment.”
Translation from governance dialect
பணத்திற்கான access கொண்டவர்கள் அதை நகர்த்த முடிவு செய்து, விரைவாக vote செய்து, அவர்கள் கட்டுப்படுத்திய multisig-க்கு அனுப்பி, அந்த நிலையை கையாளுவதற்காக தங்களுக்கே பணம் வழங்கினர்.
V. The Treasury Is Safe From Independent Researchers
கற்பனையான ஆண்டு முடிவடையும் நேரத்தில், $500,000 bug-bounty reserve அதன் intended purpose-இலிருந்து வெற்றிகரமாக பாதுகாக்கப்பட்டது. Osprey Finance இதை rapid governance, advanced incident response, மற்றும் signed transfer-ஐ weather event போல ஒலிக்கச் செய்யக்கூடிய vocabulary-யின் வெற்றி என அழைத்தது.
Team incident report-ஐ எழுதினது, response-ஐ அங்கீகரித்தது, பணத்தை நகர்த்தியது, மற்றும் compensation-ஐ பெற்றது. “hack” என்ற சொல் அந்த transaction-ஐ, accounting-ஐ, அல்லது ஒரு security reserve ஆண்டு-இறுதி bonus-ஆக மாறிய அதிவேகத்தைக் குறிக்கிறதா என்பதே தீராத ஒரே கேள்வி.
Governance-இல், “who approved this?” என்பதிலிருந்து “the incident is contained” என்பதற்கு செல்லும் குறுகிய பாதை மிகப் பரிச்சயமான signers கொண்ட ஒரு multisig ஆக இருக்கலாம்.