A single accidental selfdestruct freezes $280 million in Parity multisig wallets forever

NOV 06 2017 · 12:10

A single accidental selfdestruct freezes $280 million in Parity multisig wallets forever

Video: How One Mistake Froze $500 Million - The Parity Disaster Date: 2017-11-06 · Type: failure · Hub: berlin · Tags: smart-contract, immutability, parity, gavin-wood, eip-999, selfdestruct, composability-risk, 2017 EIP-999 was rejected; the code is still there, and so is the money On November 6 2017 a GitHub user calling himself "devops199" interacted with Parity's shared library contract, accidentally triggered ownership initialization, became its sole owner, and then called `selfdestruct`. The library was a dependency of hundreds of multisig wallets. Without it, those wallets — including Polkadot's pre-launch fundraise, holding roughly 306,000 ETH — could issue no further transactions. The funds are on-chain, visible, and permanently inert. The episode is the purest demonstration of the composability risk that the DAO hack had only suggested. In the DAO case, the vulnerability was in business logic; here, a shared infrastructure contract was simply deleted, and everything depending on it became permanently read-only. Gavin Wood's Parity Technologies took the loss. EIP-999, a proposal to recover the funds via hard fork, came to a rough community vote in early 2018 and was rejected — a deliberate contrast with the DAO precedent, and a signal that the community had concluded the July 2016 fork was a one-time exception, not a corrective mechanism. The parity freeze sits in the archive as the reductio ad absurdum of "code is law": the code ran exactly as written; nobody was hacked in any adversarial sense; and $280M in ETH (far more at subsequent cycle highs) became untouchable not through fraud but through the protocol's own rigorous commitment to immutability. The EIP-999 rejection was, in its way, the community keeping its word. Facts • Date: November 6 2017 • ~513,774 ETH locked across 587 multisig wallets (~$280M at the time) • Largest victim: Polkadot pre-launch fundraise (~306,000 ETH) • devops199 had also triggered a separate $30M Parity multisig exploit in July 2017 • EIP-999 (hard-fork recovery proposal) rejected April 2018 by community rough consensus • Funds remain frozen on-chain as of 2026 Primary Documents • Parity Technologies: A Postmortem on the Parity Multi-Sig Library Self-Destruct (Nov 15 2017) — https://www.parity.io/blog/a-postmortem-on-the-parity-multi-sig-library-self-destruct/ • EIP-999 discussion (rejected) — https://github.com/ethereum/EIPs/issues/999

Source: cyberpunkoracle.com

Part of Cypherpunk · Watch in the documentary

More from Cypherpunk