Can (and Should) DeFi Enable Crypto Thieves to Profit?

Another day, another centralized exchange hack. This time 342k ether, or about $49 million, got stolen from Upbit. The South Korea-based exchange said it will replace the funds with the company's assets, and suspended all crypto deposits, withdrawals, and transfers to cold wallets.

Upbit calls itself “the most trusted crypto-asset exchange,” but these hacks are exactly why it’s better not to trust exchanges and have the ability to control your funds. I wrote about how Dexes are an answer to this just yesterday, here.

Aside from the “not your keys, not your crypto” meme that comes up whenever centralized exchanges get hacked, this time, because ETH was stolen, another interesting question came up: What if the hacker is able to more easily profit from the stolen funds thanks to DeFi.

Whereas before, hackers had to somehow obscure the flow of funds and cash out before their accounts were blacklisted, they can now profit from the stolen funds using decentralized finance platforms, which largely don’t do KYC and aren’t supposed to interfere with users’ trades and funds by design.

The hacker may move the stolen ETH into a MakerDAO Vault to mint DAI, or use Kyber Network or Uniswap Exchange to swap, and then deposit that Dai into Compound Finance to generate interest, Bobby Ong of Coingecko and Su Zhu of Three Arrows Capital said. Or any other combination using the dozens of platforms designed to enable anyone, anywhere to engage in complicated financial transactions.

Do these organizations need to stop the stolen money flow?

If they do, that would potentially put them in a tough position with regulators who can use their interference as evidence to say that they actually do control these systems and should be held liable for any other forms of misconduct (like money laundering or unregistered securities trading) happening on them. If they don’t, they’d be enabling thieves to profit from other people’s money, and signaling to other hackers that the door is open for them to do the same.

Another question is, can they stop them?

The New SaaS is Staking-As-A-Service

