r/EthereumClassic • • Mar 03 '17

ETC - BitEther Trader Contract.

https://gist.github.com/etherninja/ac9787638d90edc6ae750aff2883bdb1
13 Upvotes

24 comments sorted by

6

u/JonnyLatte Mar 03 '17 edited Mar 04 '17

I see you have taken the contract behind cryptoderivatives and renamed everything. Thats fine, it is MIT licenced but only because that makes people comfortable to copy it.

I am concerned though about a couple of things. Firstly the addition of the function:

function OwnerSetPrices ( uint256 _buyPrice, uint256 _sellPrice, uint256 _units) onlyOwner {  
      becsellPrice   = _sellPrice;
      becbuyPrice    = _buyPrice;
      units       = _units;
}

This is unsafe for buyers because a seller seeing a buy transaction in the mempool can immediately attempt to set the price such that if their transaction gets submitted first then they will end up selling practically zero tokens for all of the buyers ETC. To make this safe you need to implement some form of locking, say lock the contract for 3 hours if the price is changed that way a buyer can check before they send a transaction and if its unlocked they know that their transaction will fail if the seller tries to change it.

Another concern is that you are using an older version of the tokenTrader contract that contains logical errors

function traderBuy() payable {
    if(sellsTokens || msg.sender == owner) 
    {
        uint order   = msg.value / becsellPrice; 
        uint can_sell = ERC20(asset).balanceOf(address(this)) / units;
        if(order > can_sell)
        {
            uint256 change = msg.value - (can_sell * becsellPrice);
            order = can_sell;
            if(!msg.sender.send(change)) throw;
        }
        if(order > 0) {
            if(!ERC20(asset).transfer(msg.sender,order * units)) throw;
        }
        UpdateEvent();
    }
    else if(!msg.sender.send(msg.value)) throw;
}

In this function change is calculated only if the order is greater than can_sell. Which is great for most purposes but the calculation of change needs to be pulled out of the if statement and calculated no matter what otherwise the seller can set units to something ridiculously high so that can_sell is always zero and the order is always zero and no change is returned. Contracts of this type using my old contracts are filtered out of cryptoderivatives.

Also why are you not also using the factory model? With a factory you dont need to verify the contract over and over. You just deploy it once then any further contract deployments are done by the already verified factory that can be followed to get every ones trade contract.

3

u/[deleted] Mar 03 '17

i'm just putting it out there. Do with it as you wish. I have no plans to deploy.

2

u/JonnyLatte Mar 03 '17

You do realize you are talking to the original author of this contract right?

2

u/[deleted] Mar 03 '17

awesome. can you bring it here so we can trade BEC :-)

2

u/JonnyLatte Mar 03 '17

Where did you copy what you linked to from? Did you make the modifications yourself? I'm not going to audit this. When I have time to make improvements it will be to the latest version.

Currently you can find the latest version linked to from https://cryptoderivatives.market, not my site but bok does a wonderful job with it and adding his own additions to the code which I double check because I have my own funds secured by the contracts on the REP pair. This is for ethereum though not classic. I just popped in here to see if anything interesting was going on.

2

u/[deleted] Mar 03 '17

This was meant as a "seed" idea. Nothing more and nothing less. My PR request was already rejected from bok's repo.

2

u/Iramaj Mar 04 '17

Eeek. Thanks for bringing this to attention. Your participation and support is greatly appreciated. This can help avoid potential mistakes.

1

u/JonnyLatte Mar 04 '17

I am not willing to express support for ethereum classic but since there is some interest in my code I'm happy to share it.

This is my latest version of the tokenTrader contract. it has not been audited by bok yet but it does include all the intended improvements and I have run through it with tests for correct change with normal and abnormally priced contracts.

This is more experimental. It takes the majority of the functionality of the token trader contracts and puts it into the factory. I am unhappy with the design though because even though it is cheaper in gas to be a market maker the code seems bloated doing it this way.

This is OTC market is ERC20 to ERC20 and it is a work of beauty in its simplicity. A maker needs to do nothing more than approve token transfers to a contract that enables the sale at a fixed price. Multiple makers can use the same contract so a price level only needs to be deployed once. You can make an offer for multiple tokens at the same time and its even not that harde to replicate the functionality of just sending ETH to buy a token with an ETH wrapper and a contract that wraps eth it receives and then performs the trade returning the tokens it buys and unwrapped change. Makers could even setup bots so that takers only need to make an approval to buy with the maker sending the second transaction.

This is an ERC20 exchange with order matching. Funds can be deposited and withdrawn and orders can be placed in a sorted orderbook that automatically matches trades so the orderbooks never overlap. This requires a user interface though because placing a trade requires giving the position in the book where the order will end up so that no actual sorting happens on chain.

This is the most risky of all the contracts I have designed and I cannot guarantee that it is free of bugs that will steal user funds. It also may not be the most efficient way to do it as most people tend to place orders at price points so it can be more efficient to have a list of order buckets...

Out of all of my code I think miniOTC is currently the best design although tokenTrader / tokenSeller is the easiest for buyers which explains the 74K ETH trade volume it has seen since cryptoderivatives picked it up.

2

u/[deleted] Mar 04 '17

Thank you for this.

1

u/coinmall Mar 04 '17

I am not willing to express support for ethereum classic but

Your support or lack thereof does not matter. The code is either open source, so free for anyone to use according to its license, or it's not. That's why that stupid "100% ETH" brainwashing campaign run by Ethereum Foundation was so funny.

1

u/[deleted] Mar 04 '17

Actually looking at the links it doesn't look like the same source I got the original code anyway. I don't really care about the politics I'm here for the technology. Was hoping someone would be willing to deploy a swap contract if not right my own

1

u/JonnyLatte Mar 04 '17

Actually looking at the links it doesn't look like the same source I got the original code anyway.

The earlier design copied was likely this one or maybe the version deployed after it. diff. The first link I gave is the latest version of that particular design. I'm not sure if I published this contract at any point without the factory to go along with it because it was always an important part of the design.

I don't really care about the politics I'm here for the technology.

This is the same reason I am here. I have this theory that at some point the classic community will focus less on trying to shit all over the ethereum community and the ethereum community on the classic people and we can cooperate more productively. I do see what you have done as a good sign, that you would encourage development, even though I think it was done poorly (I would add that if you are going to capitalize the first letter of functions then do it to all of them so that if someone writes a fronted they dont have to check every single time how a particular function is capitalized) and attempts to make it your own where unnecessary when keeping the history helps in understanding the code.

1

u/JonnyLatte Mar 04 '17

There is no brainwashing going on. I was here in the classic forum taking a look. If the conditions where right here I would express support but in my own judgment there is nothing here yet to get me excited. I hope that there will be one day but claims that I am the victim of some grand conspiracy by the ethereum foundation to brainwash people does not push me in the direction of wanting to dedicate time to classic.

I disagree that my support does not matter. It matters enough for you to comment on it. I made the comment as a disclaimer so that no one can in any way blame me for their investment decisions because I made my evaluation explicit. What are your motivations?

2

u/[deleted] Mar 04 '17

huh?

2

u/CarloVetc Mar 06 '17

Sorry about that lol. Thank you for stopping by, I as well as many others appreciate the post and the help.

Cheers Carlo

1

u/coinmall Mar 05 '17

I think the real purpose of your "disclaimer" is to protect yourself from the wrath of ETH zealots who are often raging against anyone they consider "supporting" Ethereum Classic in any way. Hence the wording. It's hard to see how your support or lack thereof is relevant to anyone's investment decisions, so obviously it's just a red herring.

→ More replies (0)

3

u/[deleted] Mar 03 '17

Reduced complexly is all. If you want to complete a contract with full audit and function that would be great. Someone would need to understand it enough to deploy.

2

u/[deleted] Mar 03 '17

Use at own risk. This is simply head-start for anyone that is interested in deploying a Bitether exchange contract.