A while ago, I wrote a post about Fomo3D and how it was the crazy DApp on Ethereum. Now, slightly more than 2 months later, it's time to look back and see what happened.
What is this again?
If you don't know Fomo3D and are too lazy to read my other post, here is the short version:
Fomo3D is an Ethereum based pyramid scheme. The earlier you invest, the more you benefit from other people investing after you. Everyone who invests bumps up a timer (which runs down) by 30sec per share ("key"), and when timer eventually runs out the person who bought the last key wins the entire pot (consisting of a large share of any ETH invested before), or rather roughly half of it.
Once the pot has been paid out, the whole game restarts at 24:00:00.
Strategies
There were two basic strategies of how to benefit from this game:
- Buy in early to have many more people invest after you
- Grab the pot
Buying in early would result in dividends for you for every other key bought after yours, depending on the number of keys that you have. That's why very early in the game, the timer would keep being bumped up to 24:00:00 (which is the max), and even though buying keys didn't increase the timer further and chances were virtually 0 that you'd win the pot, people kept buying. This made Fomo3D the #1 DApp on DappRadar and was the reason for many congestions on the Ethereum network (just like in the good old early Cryptokitties days).
Who won?
At the peak of the Fomo3D craze the pot size was at more than 20000 (!) ETH. Winning this ergo was obviously lucrative. Therefore, some people put in tremendous efforts into grabbing the pot once the timer went down to close to 0:00:00. Obviously, once the timer gets really low, it's kind of a gamble on how fast the transactions of average users would get confirmed, so it was fairly unlikely any lucky person would win this. Instead, some professionals made it their goal to "hack" it, which can be read in this great article.
In essence, they had a very clever strategy to buy the last key and spam the Ethereum mainnet with super-high gas prices so that nobody could get in after them once the timer was really low. They also spent huge amounts of gas in order to fill the respective blocks, but still cashed out with a nice ROI when getting awarded the >10k ETH package.
What happened next
After the round was over, the second round started immediately. I wasn't able to buy into the second round early myself as the network again was congested and gas was expensive, so I missed out on getting into a good spot for round 2. Currently, round 3 is running, but pot sizes have decreased dramatically. We're now at a "meager" 780 ETH in the pot for round 3, and not much is happening there anymore.
In terms of volume, Fomo3D is not the top Ethereum DApp anymore, but has already been surpassed e.g. by Möbius2D which is pretty much the same and has been deployed about 2 weeks ago.
What can we learn from that?
As with the Cryptokitties hype end of last year, there's again a lot to learn here. It's not just how the makers of Fomo3D (Team JUST) were able to make a lot of ETH themselves via a rather simple DApp, but also how public blockchains and their users behave once there is a substantial amount of money at stake.
The fact that the attackers of Fomo3D were able not only to basically DoS the Fomo3D DApp, but the entire Ethereum mainnet, made me worry about the future of not only Ethereum, but public chains in general. And it's not merely a scaling issue: even if Ethereum could handle more transactions (e.g. via a higher block gas limit), the attackers would have (or might have) been able to DoS the mainnet. Gas fees per transaction would naturally be lower, so they could afford to pay gas for more such blocking transactions. As long as the attackers can expect a positive ROI, it would be worth pursuing such attacks. Even worse, if you had your business depend on the Ethereum mainnet during the attack, e.g. by running a blockchain-based eCommerce store (or, more likely, a DEX), the attack wouldn't just take out one business, but actually all of them running on Ethereum at once.
Obviously, sharding will make this less likely to happen (at least if the attack targets a specific shard and not the main chain), but I still wonder what an actual solution to this might look like. Imagine there weren't 20k ETH at stake, but maybe 200k ETH, how much gas someone could spend to effectively block the network while maintaining a positive ROI.