Live data from Hacker News

Hackers nab $500k as Enigma is compromised weeks before its ICO

techcrunch.com

11–20 of 249 posts

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#11
post #7

Can we get the title fixed? The editorialized title is misleading/inaccurate. (edit: Thanks, it's fixed now.)

In what way? The company's website, email lists and other property was compromised and investors lost 500k, seems pretty clear to me.

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#12
As with most things security, people tend to be the weakest link in the chain.

This type of issue could be solved in a lot of ways. I think a solution wherein:

1. ICOs use a standard 'escrow' contract wherein ether and coin get held by the contract for 7 days or so before either party can withdraw the opposite pair (where either can back out).

2. Building some standard 'ether address' widget that verifies the type of contract an address is. A user-wallet would usually be a warning sign.

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#13
This looks like another in a series of ICOs which are not being handled with appropriate security controls.

When people are planning on taking in millions of dollars of investment in an easily traded, easily stolen, digital currency, they've got to expect attention from relatively well funded/motivated attackers.

Unfortunately many of the founders of these ICOs don't seem to be that well setup in this regard as some of the disclosed hacks, including this one, aren't exactly advanced.

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#14
I wish that passwords like this stopped being the main form of authentication. I guess I'm not sure what's a better way (I like the physical object + pin of my credit card but that's probably not practical for all Web authentication) but it seems pretty obvious that passwords are broken in their current form unless you use a password manager, which can be a hassle

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#15

So what, just a couple of years worth of work at Google as a SWE.

The problem is that most people tricked into "investing" in such platforms probably don't make anything like a software engineer at Google. This loss hurts them a lot.

Even knowledgeable people can fall victim to attacks like this.

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#16
post #7

Can we get the title fixed? The editorialized title is misleading/inaccurate. (edit: Thanks, it's fixed now.)

In what way? The company's website, email lists and other property was compromised and investors lost 500k, seems pretty clear to me.

Well, it seems unfair to say "investors lost 500k" if they weren't really investing in the ICO so much as taking the bait on a phishing email, which is what it sounds like happened. If a hacker took control of their domain and Slack, and socially engineered people into sending funds into the hackers' personal accounts (which is what it sounds like has happened), Enigma never really had the funds to lose in the first place themselves.

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#17
Another ICO, another scam. I am not sure I feel bad for people who are gullible enough to send their hard earned money to these "companies". They have one PDF whitepaper and a generic Wordpress template website with some buzzwords, based in Cayman islands or some other tax haven for money laundering. And expecting to get rich from that.

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#18

Earlier quoted context omitted.

In what way? The company's website, email lists and other property was compromised and investors lost 500k, seems pretty clear to me.

Well, it seems unfair to say "investors lost 500k" if they weren't really investing in the ICO so much as taking the bait on a phishing email, which is what it sounds like happened. If a hacker took control of their domain and Slack, and socially engineered people into sending funds into the hackers' personal accounts (which is what it sounds like has happened), Enigma never really had the funds to lose in the first…

The title merely states that hackers stole $500,000. It does not say they stole it from Enigma. They stole it from people trying to invest in it - hence "investors lost 500k" seems perfectly apt.

Re: Hackers nab $500k as Enigma is compromised weeks before its ICO

#19
post #14

I wish that passwords like this stopped being the main form of authentication. I guess I'm not sure what's a better way (I like the physical object + pin of my credit card but that's probably not practical for all Web authentication) but it seems pretty obvious that passwords are broken in their current form unless you use a password manager, which can be a hassle

This is where two factor authentication comes into play. Then you can have something you know (eg password) and something you own (eg phone).

I quite like using Google Authenticator for my 2FA.

Post reply on HN