9 ms·
Over half a billion in assets and.. > We discovered the attack this morning after a report from a user Fuck me.
by outsb 5y ago
Over half a billion in assets and..
> We discovered the attack this morning after a report from a user
Fuck me.
- zaroth 5y agoSeriously. That was really really hard to read. So basically $600mm in a hot wallet and no one even watching it. Just wow. They didn’t even hack the smart contract, they just compromised 4 systems holding the private keys, and there was an RPC signing function giving free access to the 5th. Good god.
- mattbrewsbytes 5y agoSounds like if they had a checking account with their bank credentials stored in ENV variables and someone got access to that server it would be the same outcome. The details of it being on a crypto-currency are interesting but when password/passphrase/private key security is poor it doesn't really matter the medium holding the money.
- openasocket 5y agoAren't there methods of rolling back transactions in the traditional banking system though? And additional validations on larger volume transactions?
- mplewis 5y agoThat's right. None of these protections exist in their sidechain.
- mrits 5y agoIt would be much different outcome that would probably lead to recovering the money.
- oefrha 5y agoNo, $625M transfer out of a single bank account would raise tons of eyebrows. No way it’s authorized by some env vars.
- no-dr-onboard 5y agoMaybe, but 30d ago it would have been "No way someone would store $625M USD in a game dev bank account".
- mattbrewsbytes 5y agoIf the hackers are sophisticated, I would think they would start wiring in much smaller amounts and thru accounts so tracing is harder. Much like what they are going to have to do with the funds in that wallet. If they setup some plausible 3rd party company the game studio could use and started transfers of $10k a pop it might be some time before anyone catches it.
- manquer 5y agoThat is slow anything over 10,000 in bank transfers will reviewed, and there will be a dedicated account manager for a 600m account. They are going to review and flag it. You might loose few hundred thousands but not all 625m.
- gamblor956 5y agoTransferring $650 million out of a corporate bank account would usually require in-person approval by a C-level officer, or at the very least, prior notice to the bank of the transaction.
- mtoner23 5y agoYeah, banks dont let you move this money without multiple levels of identity verification by both parties.
- arthurcolle 5y agoNot always true: https://www.vice.com/en/article/ne8p9b/offshore-bank-targeted-phineas-fisher-confirms-hack-cayman-national-bank https://www.vice.com/en/article/ne8p9b/offshore-bank-targete...
- henriquecm8 5y ago> they just compromised 4 systems holding the private keys, and there was an RPC signing function giving free access to the 5th. This seems like the plot of a 90's hacker movie.
- deleted 5y ago[deleted]
- SilasX 5y agoYes, it is truly mystifying how they operate in some of these big projects. Recently, we had Optimistic Ethereum (by my count, ~$250 million locked up in that network) adamantly insisting that they did everything they could to warn users that transaction history would get deleted off of Etherscan.io -- trivially avoidably, no less! -- even though none of their communication channels mention it.[1] And that they had to make a "tradeoff" in how much effort to spend on warning users, even though their volunteers are choked every day, on Discord, with users wondering where their transaction history is. Which, of course, pales in comparison to how a hacker found a flaw that let him print infinite ETH within their network (see the main story for that thread), and the project only lives on because he was a white hat who accepted a bounty instead. [1] https://news.ycombinator.com/item?id=30293526 https://news.ycombinator.com/item?id=30293526
- bayesianbot 5y agoWhich was 6 days after the original transfers. Unbelievable.
- jandrese 5y agoWait, no, it's totally believable because this is the same story that happens over and over again with blockchains. It turns out that all of those pain in the ass compliance laws on traditional finance are there for a reason, and when you ignore the past you end up repeating it.
- tornato7 5y agoMost hacks are discovered within minutes or hours, not having the systems in place to know within seconds if your wallet is being drained is unbelievably bad for someone custodying half a billion.
- acdha 5y ago> Most hacks are discovered within minutes or hours Really? The figures I’ve seen have typically put it in days to weeks unless you’re talking only about the most obvious things like DoS attacks or defacing someone’s homepage.
- tornato7 5y agoSorry, I mean crypto hacks specifically. Most crypto traders/companies/firms have apps and monitoring tools set up to report any suspicious activity on their wallets or contracts. Unfortunately it's sometimes too late at that point, but sometimes not[1]. 1. https://ihodl.com/topnews/2021-07-19/white-hacker-helps-metamask-user-save-117000/ https://ihodl.com/topnews/2021-07-19/white-hacker-helps-meta...
- acdha 5y agoAh, that makes more sense. I'd be curious how what the timing is like between the compromises which give people access to keys or supporting systems and when the attacker does the noisy part of moving funds around.
- RL_Quine 5y agoNo monitoring whatsoever over $600M of funds stored in your system is crazy negligent.
- UncleMeat 5y agoIt isn't like monitoring would have done anything. Once the transaction goes out it is gone. The core problem here is the massive private-key bounty being created by a ton of organizations that don't have world-class security teams.
- parkingrift 5y agoTrue, but you would think they’d notice $650,000,000 missing before a user reported an issue withdrawing $5,000 (edit - 5k ETH). It’s honestly so impossible to believe that I’d wager the real story is they knew and were actively trying to recover the funds.
- zkldi 5y agojust a poke: it was 5K Eth ($16,924,050), not 5K USD, but i agree with your wager.
- parkingrift 5y agoAh right you are. Misread the article.
- mrep 5y agoGod damn, 17 million stolen forever from 1 person and there is nothing they can do about it.
- cowvin 5y agoEven more shocking, is why someone would hand 17 million dollars worth of assets to a random company that has no security apparently.
- Barrin92 5y agois there no point at which these companies become subject to securities or financial laws? How on earth can a random game studio just casually hold half a billion dollars worth of assets apparently without any idea what to do with it?
- tornato7 5y agoMany crypto companies are subject to RIA compliance laws or are considered "qualified custodians"
- deleted 5y ago[deleted]