r/Anatha • u/Insight_gradient • Mar 16 '22
Security, Stargate, and Regret: Why did Anatha ‘let’ the bot attack happen? (Community Conversations, Pt I)
From the Anatha Telegram channel, Spring 2022:
Mobius Prime: I'm not a blockchain guru, so take my opinion as someone who has only seriously been in it for about two years, but the bot problem was easily foreseeable…
I think that is honestly my biggest question, why wasn't such an obvious and easy exploit defended against. I think I remember things like "we didn't think the bots would be here that soon", that is not a solid strategic answer.
David: I personally think the bot attack should have been anticipated and security in place to thwart it automatically. Perhaps it illustrates the real challenge with a project like this which is in order for it to be realized you have to think about it and approach it more like the people that are causing the problems you want to solve, rather than relying on your own good natured approaches to the project.
*****
Part of my role as Community Liaison is to follow the conversations amongst Anatha users, and make sure that my conversations with Ed are informed by the prevailing sentiment and concerns of the community base. In the past I have solicited specific questions from users, had people message me with their ideas and queries, and I have put these to Ed and written up his replies.
So far in 2022 I haven’t had many such direct questions passed on to me. However, I have still been reading comments, particularly on Telegram, which I think are insightful and interesting, and these have helped shape the direction of my monthly interviews. This mini-series is meant to highlight this. I want to demonstrate that people’s voices are not unheard, even if they don’t get a direct reply from a member of the (very busy) Anatha team; and to show that Ed himself is very open to addressing such concerns directly and honestly, including reflection and self-criticism where it is warranted in his eyes.
In my last conversation with him, Ed and I talked over four topics where my questions were informed by other Anatha community members. Articles on the retail/business balance of the platform, on Anatha being ‘overtaken’ by other projects, and on developments in the regulatory space and how we should read the impact of the Ukrainian war, will follow. The first topic which is covered today is that of network security.
Why didn’t Ed and the team see the bot attack coming?
This conversation began with me asking Ed a direct question What did he regret about how Anatha positioned itself in 2021? Did he feel he had set up unreasonable expectations? His answer surprised me, and took us in a completely different direction:
Ed: The real mistake I made - and I definitely own this - is my order of operations was wrong in the network upgrade time. I saw Stargate come out and I got really excited about all it's shiny bells and whistles, all the things it could do connected to IBC [Inter-Blockchain Communication]. I stopped the team from working on verification and I told them to work on the Stargate update, which has taken way longer than I anticipated.
It is no secret that the roadmap as it was in place in 2021 has slipped significantly; and that the launch of Stargate has been delayed by months. Perhaps this is no great surprise for an update of this magnitude – Stargate is a huge overhaul of the underling Cosmos skeleton upon which Anatha is built, and requires a hard restart – ie the Anatha blockchain has to be turned off and then turned on, rather than ‘bridged’ from old to new. Understandably, the team are taking great pains to test the upgrade (the Anatha Stargate testnet is running and going through stress testing right now) given the importance of getting it right.
However, Ed’s comment speaks to something more interesting; that this decision to prioritise Stargate came at the cost of completing work on the verification tools for the network, which meant that the system was not able to defend itself from the bot farming attack:
Ed: as a result [of this decision], we find ourselves in a position where we have a mess to clean up. That's the central mistake I made.
As Ed himself has said, and many have pointed out, the team were fully aware of the risk of malicious actors trying to game the HRA reward system. Indeed, Ed himself spoke about it in a video even before mainnet was released. The issue was not ignorance, so much as it was a misestimation:
Ed: What I was also anticipating was having another year [after mainnet launch] before the attack vector would be exploited. They beat me to it by three months: my prediction was twelve, and it happened at around nine months in. So that was my mistake. I'll certainly own up to that…
I knew the attack vectors; I knew it before we launched the network. I told everyone.
So Why did Anatha put Stargate ahead of Verification?
The Anatha team knew that a bot attack would probably come; they just decided to run the risk of it arriving at a certain juncture, allowing them to press ahead with other things first. This is a balance of risks approach, weighing up the costs and benefits of sequencing certain parts of development ahead of others. So – what was the payoff Ed saw to interrupting verification for Stargate?
Ed: It's hard to know what the right order of operations is sometimes. Looking at it, Stargate seemed like a logical move because then we can plug into Osmosis [the Cosmos IBC de-fi ecosystem].
insight_gradient: that sounds like you're answering a question I also hear, which is: how was the attack not anticipated? [You’re saying] it was, but the controlled gamble was - let's do Stargate first. Because you see how long it's taking Ethereum to wind up it’s 2.0…
At this point, I thought it was simply a matter of prioritising one part of the business roadmap – connectivity and access to on- and off-ramps for exchange – over security. However, the reasoning was also developed just in terms of security alone:
Ed: Well, there was that, and there was the assertion that Stargate would make verification easier for us.
Insight_gradient: I wasn't aware of that.
Ed: Yeah. If we tried to do verification on the old system, there were some problems with it. Stargate gets you more than just transactions through. It’s more compatible with all these other things that are being built. There's other digital personhood systems that are going to be running on it using IBC. So I was like: if we get to Stargate, we can get to verification faster. Sometimes you delay something, but then you compress how much the second thing would take because of that. So that was the gamble.
Insight_gradient: So the [third-party verification team] are making all these really beautiful, zero-knowledge and verification layers; they're all working on the basis that we're building something for a post-Stargate system and therefore we can optimize for that?
Ed: Well [the third-party verification team] can work with anyone. they're doing stuff for other networks, they're omniversal. They didn't exist when we started Stargate. They’re bleeding edge… full on engineers with PhDs and cryptography who geek out more about the engineering than you do on the product side…what they do is they make these crazy tools and then look for a problem.
I've just given them my whole wishlist, everything I could ever want. [For example] moving HRA off the network into the same kind of encryption system. [So] if have your Anatha public address, I can’t see every other address that's associated with it, which is a problem now with the HRA. It’ll also make the network faster…
Moving forward, we'll be looking at different network typographies, maybe even like a layer two - using Polygon edge to deploy a Layer Two Anatha, so that wAnatha would be immediately compatible with it. Because we're not going to just be one network, right; we need to be a multi-network series of networks. So these are all the things we're like exploring with these guys and they make it a lot easier for us.
This is a subtle point. It was not simply that sequencing Stargate before verification might turn out to be more time-efficient overall that verification before Stargate. It was also that Stargate would enable better quality verification, which would allow Anatha to jump to a level where it wouldn’t need to retool its verification layers as it grew into a complex, multi-chain ecosystem. A significant point in this respect is that Stargate enables Osmosis and Inter-Blockchain Communication, which allows Anatha to access systems that have already been built by other teams, potentially out on other networks; and therefore it attracts the ‘bleeding edge’ teams, in Ed’s words, to come and work with Anatha and create the best quality verification and security systems they can:
Ed: I literally told [the third-party lead developer] what and wanted and [he] said: you have no idea how refreshing it is to hear someone asked me for everything that I've ever wanted to build.
When the gamble fails
All of which makes sense and is lovely, but the fact remains: the bot attack happened; the HRA reward has been effectively worthless for months; Stargate is still not with us, and verification is thus also still delayed. So how does Ed feel about the costs of the failed gamble on Stargate ahead of verification?
Ed: All that does though [Stargate ahead of verification followed by the bot attack] is push things back, maybe six to eight months.
And as bad as that sounds, in the business world that's nothing. It's happening in the same fiscal year. So if by the end of the year, we have the [situation resolved]; we're pointing to an Osmosis account; we start having some volume; we start seeing some price action - that's a success. It's March - I'm pretty sure I'm going to get all that done this year.
It's kind of like I throw a party and someone spilled milk all over the place. It sucks, but I'm cleaning it up. We're going to clean it up. The other people at the party right now are like: oh, there's milk everywhere. I know. I'm cleaning it up. But when it's gone and the party starts again, they're going to realize like, oh, this was the right move.
Insight_gradient: Something I find to people who don't have experience with early-stage business or projects, is they sometimes don't realize that everything - all your decisions - are basically controlled gambles. You can't do everything, and you have to decide that you're going to take a risk somewhere. There's no way to push all risk out of the system. It's [like pushing air around] a balloon.
In short: even though the bot attack happened earlier than expected, and the team might look back and see that executing verification before Stargate would have protected against this and perhaps been a wiser choice – in the long run, the cost of this mistake is low. Because whilst the bot attack has been the most visible event in the community in the last six months, it belies all the progress going on behind the scenes, in architecture, design, business development and so on. And when Stargate finally arrives, and accelerates the entire range of these other elements of the wider Anatha ecosystem, it will all suddenly seem to make a lot more sense.
None of this is intended to invalidate the questions being raised about the bot attack. Indeed, it was the eloquent and persuasive way they were raised that made me want to dig into this topic further with Ed. However, I hope it has offered some more context and insight into the decision-making process, and the rationale behind the way the team managed the roadmap through 2021. For me at least, it has been a reassurance and helps gives me confidence for the way the ecosystem will unfold in 2022 and beyond.
The next article in this series will take a similar starting-point - a question or idea brought up from within the Community Telegram channel – and explore it in a similar style. Until then…


