7 ms·
The Resolv hack: How one compromised key printed $23M
- dmitrygr 6mo agoSelf-Funding Bug Bounties strike again.
- KK7NIL 6mo agoSounds like it's working as designed!
- le-mark 6mo agoTl;dr another bug in a smart contract exploited, hacker got away clean.
- MrDrone 6mo agoNot that it matters much, but this summary isn't right. The contract wasn't "exploited." The company's AWS account was compromised, giving the attacker access to a (off-chain) private key. The contract relied on the key to mint new tokens. The hacker gained access to the key (through AWS) and with it minted as much as they'd like. It is certainly a valid take that a contract that only required the private key to mint an unlimited amount of the token isn't a good one, but you don't exploit someone's front door lock by grabbing the key from under the welcome mat.
- dafelst 6mo agoBut guys, what you don't understand is that the code IS the contract!!! That means you don't even NEED regulation!!
- 0x3f 6mo agoYeah, people who genuinely believe that don't have any problem with smart contracts getting exploited. Of course there are people who _say_ that because it's financially expedient at the time, then change their tune. But both groups exist and this is not really a gotcha.
- protocolture 6mo agoI dont mind smart contracts getting battle tested. I also dont mind the whole chain coming together to vote to reverse the transaction. I also dont mind a bunch of people being unhappy with that and forking.
- 0x3f 6mo agoThat's fine. I just see it as heuristics at different levels. In the wider context, generally, markets work well, so people should be 'allowed' to do all of this. After all, you can choose not to use ETH if you think the foundation sucks. Whether ETH or the foundation sucks is a technical question given your goals, I suppose, rather than a moral one. In a western legal framework you might argue promissory estoppel if the foundation made certain statements about it, but if you take the libertarian code-is-law stance and you want to be consistent then you probably should have researched exactly what was possible at that level before investing. So all-in-all, seems fine to me.
- MrDrone 6mo agoThe contract code said, "if you have a valid (off-chain) private key, you can mint tokens." The hacker gained access to their AWS account and ultimately their keys. While I am happy to celebrate dumb crypto stuff, this isn't a situation where someone's code was "exploited." Their code was stupid, relying only on an off-chain private key to allow the minting of tokens. Their security was just also bad.
- m0llusk 6mo agostable as in house always wins?
- microtherion 6mo agostable as in "close the stable doors after the horse has bolted"
- outside2344 6mo agoHow is this industry still an industry?
- danny_codes 6mo agoPeople love gambling. Get rich quick pitches have always been popular. Now, as to why the SEC hasn’t regulated crypto out of existence.. I refer you to dementia Don
- bigfishrunning 6mo agoJoe had 4 years, Barack had 8. The office of the president doesn't seem motivated to regulate crypto
- deleted 6mo ago[deleted]
- consumer451 6mo agoOh wow, there's another interesting story on that site: > Trump Administration Likely to Un-ban Bitcoin Mixers, Dept. of Treasury Says They are “Not Unlawful” https://bfmtimes.com/trump-likely-to-un-ban-bitcoin-mixers/ https://bfmtimes.com/trump-likely-to-un-ban-bitcoin-mixers/
- 0x3f 6mo agoI thought Tornado Cash was already taken off the OFAC list a year ago.
- primitivesuave 6mo agoMissing from the article - the hacker first compromised Resolv Lab's AWS account, took a private key from KMS that was used to control minting, then managed to extract $25 million into ETH before all protocol functions were suspended.
- thebiblelover7 6mo agoDo you have a source for that information? I'd like to read more on it.
- layer8 6mo agohttps://www.chainalysis.com/blog/lessons-from-the-resolv-hack/ https://www.chainalysis.com/blog/lessons-from-the-resolv-hac... https://xcancel.com/zacodil/status/2035658779706974556 https://xcancel.com/zacodil/status/2035658779706974556
- abrookewood 6mo agoIt's explicitly mentioned in the article: A step by step breakdown of the attack Step 1. Gaining Access to Resolv’s AWS KMS Environment
- WatchDog 6mo ago> took a private key from KMS They used KMS to sign the minting operation, but they didn't "take" the key, AWS KMS doesn't let you extract keys.
- andai 6mo agoIf the admins can "lock all transactions", what's the point of it being a crypto?
- colordrops 6mo agoExactly. Stablecoins make zero sense.
- koakuma-chan 6mo agoyou can send them around easily without having to deal with bullshit payment systems
- bigfishrunning 6mo agoUntil it becomes another bullshit payment system
- snypher 6mo agoNo-one in the real world wants to be paid with a $USR. Most everyone wants a cashapp/zelle/PayPal/wire transfer. The bullshit payment systems gained ground on crypto while crypto became more difficult/less usable
- mothballed 6mo agoIf you track the FATFs crushing of bearer bonds, bearer notes, non-KYC/non-AML offshore banking, and Hawala it almost perfectly tracks with the rise of crypto.
- koakuma-chan 6mo agoI don't know what USR is, but I would prefer to be paid in USDT or USC if Wealthsimple supported it as deposit method. When I withdraw, I do Deel -> Wise -> Interac e-Transfer -> Bank -> Interac e-Transfer -> Wealthsimple. This is incredibly stupid and I am forced to buy Canadian dollars. For groceries or electronics, you can buy gift cards using crypto.
- AIorNot 6mo agodang.. stealing money from fools and speculators.
- tekla 6mo agoHacker? The coins were minted with perfectly valid code.
- s_u_d_o 6mo agoAnd what happened next? He mixed those coins? Transformed them into monero?
- mememememememo 6mo agoHas to. As ETH they are probably still tracable.
- Jommi 6mo agofirst step is to turn them into real crypo like ETH (so its unfreezable) then probably mix them via different methods then sell them via OTC-style swap platforms like fixedfloat / changelly etc
- s_u_d_o 6mo agoYeah but aren’t those KYC-based platforms? I mean eventually he can get tracked down… no?
- deleted 6mo ago[deleted]
- amarant 6mo agoWhat is the point of stable coins? Like why does anyone buy them? It seems to me that their initial value is 1usd per token (or some other fiat I guess) and that's also the roof of their value: they kinda guarantee that they won't become more valuable than that. They are less usable than fiat: more businesses accept fiat than crypto, especially weird and small coins like all stable coins are. There isn't really a floor to their value, as demonstrated here. I see plenty of downsides of owning one of these coins, but not a single upside? Yet people apparently do buy them, so what is the upside? There must surely be something that's good about them?
- ezfe 6mo agoTo take advantage of the ability to send money that way without the volatility
- JumpCrisscross 6mo agoLet’s be honest, it’s principally for illicit use, a tiny fraction of privacy folks and then a lot of people caught in between who don’t understand yield but want to bet on a volatile asset and have to use a stablecoin to go between. (Because the backers of the volatile thing are doing something illicit.)
- Saline9515 6mo agoYou are a decade late, nowadays stablecoins are commonly used in international trade. Most Alibaba sellers accept USDT nowadays, same for Indian ones.
- JumpCrisscross 6mo ago> stablecoins are commonly used in international trade For a rounding error value of "commonly," sure. (Catering to a financially-constrained market is good business. But it, by definition, will never be an important one in the grand scheme of things.)
- Aurornis 6mo agoAccording to a writeup at https://www.chainalysis.com/blog/lessons-from-the-resolv-hack/ https://www.chainalysis.com/blog/lessons-from-the-resolv-hac... this started with a plain old hack that compromised their signing key. They also had a smart contract which didn't do some proper checks, but the hack was only possible with the stolen private key. Whoever held the private key was able to mint a lot of money, unchecked. So there was a traditional hack at the core of this heist, not just a smart contract exploit.
- amarant 6mo agoIs there any proof, or even indication, that this wasn't an inside job?
- bravoetch 6mo agoUsually I would expect proof for a positive - like that it was an inside job, or there being an indication of it. I'm not saying whether it was or not, just that it seems unusual for you to ask about proof of it NOT being an inside job.
- kibwen 6mo agoWhen it comes to crypticurrencies, no, the "hack" that turns out to be an inside-job rugpull is so common that the correct burden of proof is on the people who think this wasn't an inside job.
- amarant 6mo agoIn a court of justice you'd be right, of course. But for online armchair speculation, you have to admit it seems a likely explanation.
- victorbjorklund 6mo agoIs there any proof that it was an outside job? If we don’t have any proof of either we should probably look at what is most common when it comes to crypto heists
- 6mo ago
- onemoresoop 6mo agoCould this be an inside job?
- FpUser 6mo ago>"However, the hacker was only able to siphon off $25 million; the rest was locked into the protocol after system admins got alerted." "Only" ?!!! Poor thing.
- curiousObject 6mo agoIf they take too much then confidence in the coin is absolutely lost and the coin fails and it’s price rapidly goes towards zero, so they’re possibly being smart by only taking a small percentage — if that was the hackers decision Yeah $25m is only little but could still be useful
- RS-232 6mo agoHas to be an inside job. One doesn’t just simultaneously hack into an AWS account, know exactly which key is needed for coin minting, and know internal details necessary to exploit a smart contract. The nature of the hack practically reveals their identity.
- gverrilla 6mo agonot even news.
- Panzer04 6mo agoWhy does everything have to be written by an AI?
- aswegs8 6mo agoWriting like AI isn't a bug, it's a feature - to read it is quite annoying. And that's the problem.
- cameldrv 6mo agoYou shouldn't have a key that controls millions/billions of dollars on a cloud service. It should be on an airgapped laptop that was purchased anonymously, has never been connected to the Internet, and only runs software that has been vetted and loaded onto it via a CD-ROM or some other comparable method.
- vlovich123 6mo agoHave you actually tried to run a business this way?
- mememememememo 6mo ago$24m was lost. Setting this up is say $10k in time and materials. Although I would use a rack server. .
- allreduce 6mo agoNo need to get fancy. A yubikey glued to a tungsten cube would have prevented this attack. Thats 50€ for the yubikey and 300€ for the tungsten cube.
- jiggawatts 6mo agoI have, I've set up "truly offline" root certificate authorities and the like in the past. Yes, it's a pain to operate, but if the alternative is "the bad guys get all of our money", then it can be worth it.
- vlovich123 6mo agoSure, I never said anything against offline root cert authorities. But did you do it literally exactly how this guy was saying to do it with a laptop that you load via CD-ROM for a signing key that’s being used for active transactions? It’s as if one of the things your root certificate authority signed got compromised. It doesn’t help that your root key is safe if attackers still managed to impersonate you before you revoked that cert. > privileged private key to sign off on how much USR could be created. Unfortunately, the smart contract itself did not enforce any maximum limit on minting – it only checked that a valid signature existed. The offline idea simply doesn’t work because this particular key has to be online
- momoddo 6mo ago[dead]
- bob1029 6mo ago> The attacker compromised Resolv’s cloud infrastructure to gain access to Resolv’s AWS Key Management Service (KMS) environment where the protocol’s privileged signing key was stored. Ok, but how was the AWS infrastructure compromised? This appears to be the crux of the entire article. AWS is very hard to break if you are using the IAM roles properly and avoiding manual secret management. If the only thing that can even sign a JWT is a very specific blessed EC2 instance that has exclusive access to KMS, your attack surface is nearly zero by comparison to a similar setup where administrators use email or Discord to communicate API credentials. https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-roles-for-amazon-ec2.html https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/iam-role... The protocol around using an HSM is just as important as the machine itself. It seems like some of us are going to be speed running PCI-DSS the hard way.
- nailer 6mo agoJust guessing: invite an engineer to a lucrative job interview and get them to install a “secure video conferencing” app (maybe call it Zoom Enterprise”) then use the screen viewing or filesystem permission to get access.
- Franklinwhite 6mo ago[dead]
- deleted 6mo ago[deleted]
- heartlinmachado 6mo ago[dead]