Live data from Hacker News

Poly Network hacker returns $258M after stealing $600M

forbes.com

51–60 of 303 posts

Re: Poly Network hacker returns $258M after stealing $600M

#51
post #27
post #14

Earlier quoted context omitted.

It matters because if the dollar amount is real this is probably the largest heist in history.

Well the Bangladesh Bank heist managed to transfer close to US$1B over SWIFT. Of course since this is the traditional banking system we’re talking about, most of the transactions were either quickly blocked or since recovered. According to Wikipedia about $63M remained unrecovered as of 2018. https://en.wikipedia.org/wiki/Bangladesh_Bank_robbery

In that hack, they attempted to transfer out $1B, but only managed about $100m, because the other transfers were blocked. And a portion of that 100m was eventually recovered.

Re: Poly Network hacker returns $258M after stealing $600M

#52

Since the beginning I've always looked at cryptocurrencies as a free for all. If you're dumb enough to leak your key, then the value is gone. If you send your currency away to something without looking into it first, then it's your own stupidity. Lost your key? Great job, dumbass. Crypto currency is and has always been a "do what you want, but if you mess up, it's on you" in my eyes. It seems most people using crypto…

Most people will not hold their own wallet. They just buy cryptocurrency through an exchange and let it sit as an "investment". They don't manage the wallet themselves and don't use the cryptocurrency for transactions. They simply think this is a quick way to make money and see it more as a more volatile alternative to the stock market.

Re: Poly Network hacker returns $258M after stealing $600M

#53
post #27
post #14

Earlier quoted context omitted.

It matters because if the dollar amount is real this is probably the largest heist in history.

Well the Bangladesh Bank heist managed to transfer close to US$1B over SWIFT. Of course since this is the traditional banking system we’re talking about, most of the transactions were either quickly blocked or since recovered. According to Wikipedia about $63M remained unrecovered as of 2018. https://en.wikipedia.org/wiki/Bangladesh_Bank_robbery

They tried to steal $1B. They succeeded with $101M. They got away with $63M.

Re: Poly Network hacker returns $258M after stealing $600M

#54
post #41
post #38

Earlier quoted context omitted.

Just because there are similar mechanisms doesn’t mean they haven’t been improved on in some way. Lawyers and courts are notoriously inefficient if this implementation achieves efficiencies, even if the mechanisms are analogous, seems like progress.

> doesn’t mean they haven’t been improved on in some way. In what way specifically ?

In that the specifications are formally specified, and thus can be objectively and automatically verified.

Re: Poly Network hacker returns $258M after stealing $600M

#55
post #38

Earlier quoted context omitted.

Just because there are similar mechanisms doesn’t mean they haven’t been improved on in some way. Lawyers and courts are notoriously inefficient if this implementation achieves efficiencies, even if the mechanisms are analogous, seems like progress.

> It’s important to remember that when you start from scratch there is absolutely no reason to believe that you are going to do a better job than you did the first time. First of all, you probably don’t even have the same programming team that worked on version one, so you don’t actually have “more experience”. You’re just going to make most of the old mistakes again, and introduce some new problems that weren’t in t…

I think this a lot about our politics now, we seem to want to tear down all the institutions and values that got us here.

Re: Poly Network hacker returns $258M after stealing $600M

#56

Earlier quoted context omitted.

I have to agree. I was going to counterargue that technically all hacking is executing permissible actions in the sense that the system you're hacking into ends up allowing you to do what you want. That leads to why we have laws around unauthorized access etc., and that leads to digital contracts that need to be interpreted by a human with some ability to enforce their interpretation. So yes. As the main point of dig…

I've wondered about things like this with video games. I played RuneScape a while back and one of the things my brother and I would do is lure unsuspecting players into the wilderness to kill them and take their stuff. That stuff, RuneScape gold, weapons, and armor, has some real world value. We took it from other people, often by lying to them (e.g. "follow me into the wilderness, I'll show you something cool"). Cou…

Such interesting food for thought. You are deceiving people for your own gains but then you're not breaking any rules (i guess since i don't know much about runescape), and it would really matter if it was an NPC who did that to them.

Re: Poly Network hacker returns $258M after stealing $600M

#57
post #9

The article tries to imply that the hacker had a change of heart after a public plea to return the funds. In reality, parts of the crypto community moved quickly to block transactions involving the funds and some security researchers claimed they had solid leads on tracking down the hacker’s identity. I think the hacker realized that if their identity was compromised then the legal system wouldn’t look kindly on some…

I love how the crypto community encourages circumventing laws, UNTIL someone steals from them using their own “smart” contract then calls on authorities for help.

That is not an accurate generalization. Many in the crypto community do not advocate breaking laws. Instead they look for ways to interact that do not legally require complying with onerous regulatory burdens, like peer-to-peer monetary transfers, that do not as of yet have the same amount of totalitarian restriction placed upon them as monetary transfers that are intermediated by a trusted third party middle-man.

As for the legitimacy of the law itself, and the opinion of the 'crypto community' on it: the distinction you're missing is that some laws prohibit victimless crimes, by infringing upon the freedom of contract, and always in the name of some supposed greater good, whether that's 'limiting systemic risk', 'protecting retail investors' or 'preventing money laundering', while others prohibit genuinely victimful crimes, where one party violates the rights of another. It can be entirely morally consistent to oppose the former while supporting the latter.

Re: Poly Network hacker returns $258M after stealing $600M

#58

Earlier quoted context omitted.

I have to agree. I was going to counterargue that technically all hacking is executing permissible actions in the sense that the system you're hacking into ends up allowing you to do what you want. That leads to why we have laws around unauthorized access etc., and that leads to digital contracts that need to be interpreted by a human with some ability to enforce their interpretation. So yes. As the main point of dig…

I've wondered about things like this with video games. I played RuneScape a while back and one of the things my brother and I would do is lure unsuspecting players into the wilderness to kill them and take their stuff. That stuff, RuneScape gold, weapons, and armor, has some real world value. We took it from other people, often by lying to them (e.g. "follow me into the wilderness, I'll show you something cool"). Cou…

In games we usually separate between exploits and hacks. Exploits are vague but typically things allowed by the game, but not intended (or have for more impact than expected).

I believe if you lied in the game that would constitute a written/verbal contract and what you did is fraud. Some games enforce written agreements, others say it's the wild west so too bad, this is role playing by a character, not the person. I'm not sure if either has ever been tested in court.

For the hacking thing I don't really agree that all hacking is 'allowed', phishing is of course a type of fraud, your access is unauthorised even with the correct credentials - authority to enter a building does not derive from stealing a key from someone. Likewise a buffer overflow is 'allowed' much the same way a window allows itself to be broken by a brick.

Post reply on HN