Live data from Hacker News

Poly Network hacker returns $258M after stealing $600M

forbes.com

91–100 of 303 posts

Re: Poly Network hacker returns $258M after stealing $600M

#91

I haven't seen any evidence there was in fact a hack at all. A digital contract was used in a way that complied with the contract that the bonehead writers of that contract did not intend. That's it. If bad contract writers get to cry "hack" and beg for their money back there is no point to digital contracts at all. If someone had physically or electronically broken into systems and illicitly copied private keys that…

It looks like you are debating whenever the hack was moral or not.

From a moral standpoint, it's like, if you accidentally leave behind your wallet with cash on a park bench with a lot of passer-by, then it's your fault for leaving it there and whoever finds it deserves to keep it. I'm sure you're familiar with the "finders keepers, losers weepers" saying... After all, it's in public, similar to how public blockchains work, right?

However, different people may come to different conclusions about this. In some countries in the world, the overwhelming consensus would be to return the wallet to the owner, even if it's found in public. I guess it's because it doesn't matter if you had to break through the window, or simply reach out and grab it from the bench; the property does not belong to you.

Re: Poly Network hacker returns $258M after stealing $600M

#92

I haven't seen any evidence there was in fact a hack at all. A digital contract was used in a way that complied with the contract that the bonehead writers of that contract did not intend. That's it. If bad contract writers get to cry "hack" and beg for their money back there is no point to digital contracts at all. If someone had physically or electronically broken into systems and illicitly copied private keys that…

To me, it boils down to incompetent auditing of the contract code.

Arguably things like this should make the future a bit more secure, from what gets learnt. In the same way other code industries learn from found bugs or exploits.

Re: Poly Network hacker returns $258M after stealing $600M

#93

Earlier quoted context omitted.

Of course every generalization is wrong but a not so little part of the crypto community seems very interested in avoiding taxation, money laundering and buying illegal stuff without detection.

You know whats used way more then crypto to buy illegal things and launder money? Cash

If you start moving more than $10,000, you will have IRS attention. (I think they like to pick on little guys because it's easier than the guys whom have lawyers, and CPAs?)

Actually, I was flagged over $6000 deposit over the sale of a car.

The IRS gives rewards to bank employees if they report (successful conviction) any suspicious behavior.

I still don't know why I was flaggged. Probally because I had long hair at the time?

I had a bunch of sleepless nights over that incident, and a bunch of emails back and forth.

Re: Poly Network hacker returns $258M after stealing $600M

#94

I haven't seen any evidence there was in fact a hack at all. A digital contract was used in a way that complied with the contract that the bonehead writers of that contract did not intend. That's it. If bad contract writers get to cry "hack" and beg for their money back there is no point to digital contracts at all. If someone had physically or electronically broken into systems and illicitly copied private keys that…

It's a hack because public statements about how the contract was supposed to behave describe the expected behaviour.

Anything outside the that was exploiting bad implementations and therefore a hack.

Some here might think the the code is a contract because that's the name. But that had never really been the case: public human statements supercede code.

Re: Poly Network hacker returns $258M after stealing $600M

#95
post #82

Earlier quoted context omitted.

> It’s important to remember that when you start from scratch there is absolutely no reason to believe that you are going to do a better job than you did the first time. First of all, you probably don’t even have the same programming team that worked on version one, so you don’t actually have “more experience”. You’re just going to make most of the old mistakes again, and introduce some new problems that weren’t in t…

The joy at a standup when you hear someone talk about fixing bugs they had to fix the first time they wrote the thing in a different language. We learnt nothing

Except in rust. There is no way to write buggy code in rust.

Re: Poly Network hacker returns $258M after stealing $600M

#96
post #9

The article tries to imply that the hacker had a change of heart after a public plea to return the funds. In reality, parts of the crypto community moved quickly to block transactions involving the funds and some security researchers claimed they had solid leads on tracking down the hacker’s identity. I think the hacker realized that if their identity was compromised then the legal system wouldn’t look kindly on some…

I love how the crypto community encourages circumventing laws, UNTIL someone steals from them using their own “smart” contract then calls on authorities for help.

Can someone explain to me why HN is so anti-crypto?

Re: Poly Network hacker returns $258M after stealing $600M

#97
post #66
post #18

Let S = smart contract writer's code intent - smart contract compiled code meaning. If S is legally meaningful it's all over for smart contracts. There's no way to prove the contract writer's intent, the compiler itself can have problems causing divergence, and it's not even possible to prove if the idea in the writer's mind can be captured by code. You could even come up with a sort of halting problem smart contract…

It's not that hard to infer writers intent from: - function and variable naming - social conventions around ownership - stated intent by code writers - common sense By any reasonable standard, this was theft. Is a door with a pickable lock always unlocked? No, that would be silly. What makes using a key on a lock different from using a lockpick. Social convention, intent of the creator, common sense, the fact that on…

But if when there's a dispute you have to rely on a trusted third party to determine intent and arbitrate the contract, what's the benefit of having a smart contract over a regular dumb one and relying on a trusted third party to determine intent and arbitrate the contract if there's a dispute?

Re: Poly Network hacker returns $258M after stealing $600M

#98
post #80
post #35

Earlier quoted context omitted.

It’s so funny to me when everyone touts crypto + smart contracts as revolutionary™ then when you follow a system implemented with them to its logical conclusions you have analogs to everything that already exists. Lawyers to audit the contracts for bugs (and yes there can be bugs in a formally verified spec as well), courts to arbitrate disagreements, and an authority to enforce rules when someone finds a security ho…

Just because a fart can propel a person, doesn't mean it will take you to the moon... i.e. just because analogs exist, don't expect their performance characteristics to be invariant

Cue the lost in space movie with beans, instead of potatoes...

Re: Poly Network hacker returns $258M after stealing $600M

#99

Earlier quoted context omitted.

> It’s important to remember that when you start from scratch there is absolutely no reason to believe that you are going to do a better job than you did the first time. First of all, you probably don’t even have the same programming team that worked on version one, so you don’t actually have “more experience”. You’re just going to make most of the old mistakes again, and introduce some new problems that weren’t in t…

I think this a lot about our politics now, we seem to want to tear down all the institutions and values that got us here.

This was at least an observed property of some modern reformers in 1929:

> In the matter of reforming things, as distinct from deforming them, there is one plain and simple principle; a principle which will probably be called a paradox. There exists in such a case a certain institution or law; let us say, for the sake of simplicity, a fence or gate erected across a road. The more modern type of reformer goes gaily up to it and says, “I don’t see the use of this; let us clear it away.” To which the more intelligent type of reformer will do well to answer: “If you don’t see the use of it, I certainly won’t let you clear it away. Go away and think. Then, when you can come back and tell me that you do see the use of it, I may allow you to destroy it. [0]

[0] https://en.wikipedia.org/wiki/Wikipedia:Chesterton's_fence

Re: Poly Network hacker returns $258M after stealing $600M

#100
post #58

Earlier quoted context omitted.

I've wondered about things like this with video games. I played RuneScape a while back and one of the things my brother and I would do is lure unsuspecting players into the wilderness to kill them and take their stuff. That stuff, RuneScape gold, weapons, and armor, has some real world value. We took it from other people, often by lying to them (e.g. "follow me into the wilderness, I'll show you something cool"). Cou…

In games we usually separate between exploits and hacks. Exploits are vague but typically things allowed by the game, but not intended (or have for more impact than expected). I believe if you lied in the game that would constitute a written/verbal contract and what you did is fraud. Some games enforce written agreements, others say it's the wild west so too bad, this is role playing by a character, not the person. I…

>... this is role playing by a character, not the person. I'm not sure if either has ever been tested in court.

Actually...

https://www.gwern.net/docs/rotten.com/library/bio/crime/crim...

>Patrick had an interesting mating ritual: Apparently the task of convincing a girl to meet you involves sending her a digital photograph of your wang, as Naughton did on several occasions. He described his flights of fantasy as role-playing as himself, pretending to be a successful, rich executive with everything going his way. When he bragged about running a company and owning a boat in chat sessions, he was telling the truth, unlike so many chatters before him. [...]

>If Mickey cried a little that night then certainly Michael Eisner had a bad day after learning that his young Vice-President in charge of E-mail and Chat Rooms had been arrested for, well, very un-Disneylike behavior. [...]

>Despite all of the evidence and the decades of prison time hanging over him, Naughton would eventually walk free. The jury in his trial deadlocked over the more serious charge and to avoid a retrial, he plead out to lesser charges.

https://www.latimes.com/archives/la-xpm-1999-dec-10-fi-42422...

Former Internet Exec Says Online Pursuit of Girl Was Role-Playing

DEC. 10, 1999 12 AM PT

>Taking the stand in his own defense, former Internet executive Patrick Naughton testified Thursday that he never intended to have sex with a minor and that his steamy online encounters with an undercover FBI agent posing as a teenage girl were part of a fantasy life he pursued to escape emotional problems and mounting pressures at work. [...]

>Naughton’s unexpected appearance represented a bold move by a defense team that is pursuing what many consider a risky and unprecedented legal strategy. Their central argument is that Naughton’s statements online and subsequent actions aren’t incriminating because they were grounded in an online fantasy world. [...]

>While claiming that role-playing is rampant online, Naughton admitted that he always provided accurate information about himself during online chats, even pointing his supposed 13-year-old correspondent--actually an agent--to one Web site that had a news article about him and another that had a picture of his exposed genitals.

>Asked why he furnished such information if fantasy was his real objective, Naughton replied: “The role I was playing was a character of me. If you ask my psychiatrist, I have a lot of self-image and ego problems. I was looking for approval.”

https://en.wikipedia.org/wiki/Patrick_Naughton#Novel_defense

>His line of defense was that he claimed he was persuaded to participate online in a ritualized sexual role-playing exercise, dealing with a mature woman acting as a girl.[14] His then-novel defense, became known as the fantasy defense for pedophiles.[2]

https://en.wikipedia.org/wiki/Fantasy_defense

>The fantasy defense is where a defendant accused of attempting a crime (enticing minors into sexual activity, for example) claims that they never intended to complete the crime. Instead, they claim they were engaged in a fantasy and, in the case of luring a minor, believed they were dealing with an adult.[1]

>The fantasy defense was developed by Donald B. Marks, the attorney for Patrick Naughton,[2] the Disney executive who eventually pleaded guilty to traveling in interstate commerce with the intent to have sex with a minor, in violation of 18 U.S.C. § 2423(b).[3][4][5] The "fantasy defense" used in the Naughton case was novel; however, since the closely watched Naughton fantasy defense was successful, defense lawyers were expected to use it to help other clients.[4]

https://digitalcommons.law.scu.edu/lawreview/vol41/iss2/6/

>Donald S. Yamagami, Comment, Prosecuting Cyber-Pedophiles: How Can Intent Be Shown in a Virtual World in Light of the Fantasy Defense?, 41 Santa Clara L. Rev. 547 (2000).

Post reply on HN