About a decade ago, some electricity traders at JPMorgan Chase & Co. read the rule book of the electricity market really closely and noticed that the rules would reward them for insanely uneconomic activity. They did this insanely uneconomic activity, and were richly rewarded. And then they were even more richly fined by regulators. I once wrote about this case:

JPMorgan read the rules carefully and greedily, and exploited the rules. It did this openly and honestly, in ways that were ridiculous but explicitly allowed by the rules. The Federal Energy Regulatory Commission fined it $410 million for doing this, and JPMorgan meekly paid up. What JPMorgan did was explicitly allowed by the rules, but that doesn’t mean that it was allowed. Just because rules are dumb and you are smart, that doesn’t always mean that you get to take advantage of them.

At some very high level of generality, there are the explicit rules — the words of the contract, the mechanisms of the stock exchange, etc. — and then there is a background set of fairness norms. And if you find a way to make a ton of money with a too-clever reading of the explicit rules, the background fairness norms will kick into gear and you will get in trouble. Following the rules is good, but following the rules to absurd places is bad, perhaps a crime.

In crypto … yeesh. In crypto, explicit rules are very popular, and are often coded into computer programs. The rules of a decentralized finance market will be embedded in open-source smart contracts, and you can read them, and if you find a clever way to exploit them — to “hack” the smart contract, or to “manipulate” the market, to use loaded, traditional terms — then you can do that, quickly and efficiently and at scale.

But crypto is also very young, as an industry, which means two things:

All these smart contracts were written 20 minutes ago, they do not have many years of testing, and some of them will have big flaws that someone can exploit.
There is not long-standing agreement on some set of background norms about what to do when that happens.
And so sometimes there will be a “hack” or “exploit” in crypto and people will say “hey that’s great, the contract worked as written, you’re not allowed to complain.” (Thus the scare quotes around “hack” and “exploit”: Some people will deny that those loaded terms apply.) Other times, people will say “this is unacceptable,” and everyone will get together to reverse the transactions and act like they never happened. Other times, people will say “hey let’s call the police,” and perhaps the police will come and arrest the “hacker” for hacking or market manipulation or whatever. There are other possible outcomes. I wrote yesterday, somewhat fancifully, about decentralized autonomous vigilantism as a possible solution to crypto hacks.

Still there does seem to be a developing norm that says “if you hack a decentralized finance protocol and run off with a bunch of money, you can keep some of it as a reward for your cleverness, but you have to return most of it because keeping it all would be mean and perhaps a crime.” The model is a “bug bounty,” though sort of after the fact: If you find a flaw in a protocol’s security, they should pay you a reward for pointing it out, but you should not get to take all their money.

And so we talked last week about a guy who did a market manipulation on a DeFi protocol called Mango, taking something like $116 million. The guy’s name is Avraham Eisenberg. Here is a post by Chris Brunet rounding up Eisenberg’s alleged Discord posts as he planned this exploit, which include:

Eisenberg asks: “I’m investigating a platform that could maybe lead to a 9 figure payday. Should I do it”
Someone in the Discord replies “probably … unles it is highly illegal,” and Eisenberg replies “Are there rules these days”
Someone asks “is this just one of those oracle manipulatooor things to drain LPs,” and he replies “Sorta. You take a long position. And then you make numba go up.”
And then Eisenberg himself went on Twitter to issue a “statement on recent events” that might be up there with Satoshi Nakamoto’s Bitcoin white paper as one of the great foundational documents of crypto:

I was involved with a team that operated a highly profitable trading strategy last week.

I believe all of our actions were legal open market actions, using the protocol as designed, even if the development team did not fully anticipate all the consequences of setting parameters the way they are.

Unfortunately, the exchange this took place on, Mango Markets, became insolvent as a result, with the insurance fund being insufficient to cover all liquidations. This led to other users being unable to access their funds.

To remedy the situation, I helped negotiate a settlement agreement with the insurance fund with the goal of making all users whole as soon as possible as well as recapitalizing the exchange.

Mango built a game, and Eisenberg played that game in a highly profitable way, and as a result he got $116 million and the game ended. But now he will give back some of the money so the game can continue for everyone else.

You can imagine a lot of different background norms working here. “Code is law, anything that happens is fine, and adversarial hardening will over time make hacks less likely” is definitely a popular take in crypto, and maybe it’s fine. But my sense is that if you want crypto to be a big industry, if you want it to be appealing to retail investors and large institutions and governments, you will want some other norm. Some norm like “if there’s a hack, someone will fix it.”

Sam Bankman-Fried runs the crypto exchange FTX, and his net worth is pretty directly tied to broad retail, institutional and governmental adoption of crypto. Bloomberg’s Joanna Ossinger reports:

Crypto billionaire Sam Bankman-Fried has outlined a framework for limiting the impact of the hacks and exploits plaguing the industry, including capping the maximum bounty for attackers at $5 million. …

Bankman-Fried, co-founder of digital-asset exchange FTX, proposed in a blog post what he called a “5-5 standard” where hackers keep either 5% of the amount they’ve taken from a protocol or $5 million, whichever is smaller.

Other key provisos are that customers must be made whole and that the hacker is acting in “good faith” and fully intended to cooperate and return most of the assets. In crypto, attackers are sometimes viewed as white-hat hackers who seek to expose vulnerabilities in return for a reward rather than to make malicious gains.

Here is the rest of that post, which consists of Bankman-Fried’s draft proposals for “a set of standards that we as an industry could enact to create clarity and protect customers while waiting for full federal regulatory regimes,” covering things like sanctions, disclosure, securities regulation, decentralized finance, etc. But I suppose the proposed standardization of hacking rewards is the most interesting part. The idea is to have rewards for cleverness that are generous, but not absurd, to reward cleverness without making clever hacking the entire point of the game.

Of course this doesn’t solve everything. For one thing, how do you make hackers follow the industry standards? If a hacker/exploiter/manipulator comes up with a really good trade and steals $500 million, and decides not to give back $495 million of it, what do you do? I suppose the answer is “call the police,” and then you are back to relying on the background norms of the traditional legal system.

Also: What if you find a “highly profitable trading strategy” and you “believe all of [your] actions were legal open market actions, using the protocol as designed,” but others disagree and think you did a hack? “The maximum reward for market manipulation is $5 million” is a fine standard, but you still have to have some way to decide what is “market manipulation” and what is just clever trading.

Its worth a read. Interesting.

The basic idea is along the lines that you can’t write a contract that enslaves someone, and then appeal to the contract language and expect the court to enforce your slavery. It seems like some crypto dudes are trying to do objectively unfair things because “the rules” they wrote allow for it, but the law doesn’t just permit any two parties to agree to any set of terms through contract. “Read the fine print” is good advice, but is not an legal cheat code.

When asked to choose one word that describes the space, the two most popular answers were almost evenly split between “Ponzi” and “future.”


This was a really worthwhile read.


I agree with the point he keeps circling back to is “What does this all ultimately build?”

I think his point is very well made which is that there are limitations to how well the Crypto space can impact the real, tangible world. The financial system grew because it addressed concerns of the real, physical world. The Crypto space may only continue to grow insomuch as our lives continue to happen more often and in more significant ways in an online space.

The thing I like about Levine - which the grumpy haters have never understood - is that even as a skeptic he appreciates how fun it all is even if it never amounts to much.