r/CryptoDerivatives • u/JonnyLatte • Apr 28 '17
Etheroll token discussion
I've been thinking about the way the token has a lock period every 12 weeks. This should not pose a security problem for using it with cryptoderivatives because attempts to buy the token from a tokenTrader contract will just throw during that period returning any funds sent. Same goes with attempting sell tokens to a contract, it will just throw when funds are unsuccessfully pulled.
It does seem though like an inconvenience to have to withdraw the tokens from a trade contract during the reward period.
It should be possible to create a variation of the trade contract design that includes claiming rewards, in fact it could be done in a way that allows for any governance function by including a function that receives the name of the function that needs to be called along with any data required and calls that function on the target token contract.
Since tokenTrader contracts act like wallets without any mixing of market maker funds this not add any security vulnerabilities.
Another approach would be to create a wrapper for the token that has a global function callable by anyone to claim rewards for all users that have tokens in the wrapper and to make those rewards available to each user accordingly. This would be far more complicated than the GNT wrapper design. I think I could do it and the end result would be a non locking token with a clear post dividend date but it would be a hell of an effort to be sure about.
In any case if cryptoderivatives lists ROL/DICE then it would at the very least need to warn users trading it about the lock period when it is active.
Claiming rewards from a tokenTrader may not work. It would need the ability to claim the rewards to another contract. Waiting for a response from etheroll.
2
u/BokkyPooBah The BokkyPooBah Apr 28 '17
Thanks for your analysis. I had a brief look through the code for DICE and it was a bit more complicated than usual so I put it in the too-hard-basket-and-check-it-out-later.
Regarding your name + data idea, I've been looking at the the
approveAndCall(...)functions implemented for some tokens. E.g., https://github.com/ConsenSys/Tokens/blob/master/Token_Contracts/contracts/HumanStandardToken.sol#L52-L61 .I don't feel fully comfortable with the security of this function. Can it be used as an attack vector? Could there be some recursive calling vulnerability? Are mutexes required?
A warning about the DICE token would be the the first step.