Live data from Hacker News

Poly Network hacker returns $258M after stealing $600M

forbes.com

111–120 of 303 posts

Re: Poly Network hacker returns $258M after stealing $600M

#111
post #9

Earlier quoted context omitted.

I love how the crypto community encourages circumventing laws, UNTIL someone steals from them using their own “smart” contract then calls on authorities for help.

That is not an accurate generalization. Many in the crypto community do not advocate breaking laws. Instead they look for ways to interact that do not legally require complying with onerous regulatory burdens, like peer-to-peer monetary transfers, that do not as of yet have the same amount of totalitarian restriction placed upon them as monetary transfers that are intermediated by a trusted third party middle-man. As…

I don't agree that placing regulations on the finance industry can be in any way equated to totalitarianism.

In fact, we have already seen what happens when the financial industry is entirely deregulated multiple times worldwide.

Re: Poly Network hacker returns $258M after stealing $600M

#112
post #75

I haven't seen any evidence there was in fact a hack at all. A digital contract was used in a way that complied with the contract that the bonehead writers of that contract did not intend. That's it. If bad contract writers get to cry "hack" and beg for their money back there is no point to digital contracts at all. If someone had physically or electronically broken into systems and illicitly copied private keys that…

> You have to be an absolute tool to use the poly network for anything serious ever again agreed > A digital contract was used in a way that complied with the contract that the bonehead writers of that contract did not intend. That's it I kind of disagree in philosophy here. If there's a bug in a bank API that lets me transfer funds to my account, I'm still "hacking", even if I'm doing exactly what the API lets me do…

Isn’t that the point though, when you access a bank api you have signed a contract in order to access it that states what is allowed and what’s not, the api code is not the contract but a way to access what you are allowed. With smart contracts the code is that contract so if the code allows it then it should be allowed.

Re: Poly Network hacker returns $258M after stealing $600M

#113

Earlier quoted context omitted.

Of course every generalization is wrong but a not so little part of the crypto community seems very interested in avoiding taxation, money laundering and buying illegal stuff without detection.

Internet file sharing was/is illegal when it first started. Now its the main form of distribution for music and movie industry. Are you only seeing criminal part of crypto and ignoring the rest to confirm your bias?

> Internet file sharing was/is illegal when it first started.

Internet file sharing is older than you think. Together with remote terminal access (TELNET), file transfer (FTP) is one of the oldest Internet protocols. When file transfer over the Internet first started, that is, when the Internet itself started, it was not "illegal".

Re: Poly Network hacker returns $258M after stealing $600M

#114
post #95
post #82

Earlier quoted context omitted.

The joy at a standup when you hear someone talk about fixing bugs they had to fix the first time they wrote the thing in a different language. We learnt nothing

Except in rust. There is no way to write buggy code in rust.

There is. You may accomplish preventing any memory leaks or buffer overflows but there always exist a bug in your code.

Re: Poly Network hacker returns $258M after stealing $600M

#115

The article tries to imply that the hacker had a change of heart after a public plea to return the funds. In reality, parts of the crypto community moved quickly to block transactions involving the funds and some security researchers claimed they had solid leads on tracking down the hacker’s identity. I think the hacker realized that if their identity was compromised then the legal system wouldn’t look kindly on some…

They blocked very little and can only do very little. He seems to know enough that I don’t believe he’s scared of them finding his identity His own explanation is the one I find the most truth in. https://sites.google.com/view/hackersconfession/home/hacker-...

> He seems to know enough that I don’t believe he’s scared of them finding his identity

I don't know about this but I agree that he doesn't seem to set out wanting to steal $600mio. Sounds like the typical "hacker" mentality where he's prodding around for security holes and just happened to find one.

Re: Poly Network hacker returns $258M after stealing $600M

#116

Earlier quoted context omitted.

Can someone explain to me why HN is so anti-crypto?

It’s not that HN is anti crypto, it’s that most (if not all) smart people are. The only smart people that are pro crypto are ones trying to sell shovels in the gold rush (like Elon or Dorsey). It’s ironic you’re asking this question in a thread about news proving how stupid crypto is to begin with.

https://www.reddit.com/r/iamverysmart/

Re: Poly Network hacker returns $258M after stealing $600M

#117
post #92

I haven't seen any evidence there was in fact a hack at all. A digital contract was used in a way that complied with the contract that the bonehead writers of that contract did not intend. That's it. If bad contract writers get to cry "hack" and beg for their money back there is no point to digital contracts at all. If someone had physically or electronically broken into systems and illicitly copied private keys that…

To me, it boils down to incompetent auditing of the contract code. Arguably things like this should make the future a bit more secure, from what gets learnt. In the same way other code industries learn from found bugs or exploits.

The code has now been competently audited and it costed them less than 600 mil. I'd say it was a bargain when the thing audited is multi-chain crypto financial smart contract.

Re: Poly Network hacker returns $258M after stealing $600M

#118
post #95
post #82

Earlier quoted context omitted.

The joy at a standup when you hear someone talk about fixing bugs they had to fix the first time they wrote the thing in a different language. We learnt nothing

Except in rust. There is no way to write buggy code in rust.

The program is the implementation of an intention, if the conception of how to achieve that intention was itself faulty the program does not actually implement the intention.

A program that does not implement its intention is buggy.

Re: Poly Network hacker returns $258M after stealing $600M

#119

I haven't seen any evidence there was in fact a hack at all. A digital contract was used in a way that complied with the contract that the bonehead writers of that contract did not intend. That's it. If bad contract writers get to cry "hack" and beg for their money back there is no point to digital contracts at all. If someone had physically or electronically broken into systems and illicitly copied private keys that…

If developer didn't put size check in his software then it's not bug with RCE exploit, it's just doing what author has intended.

Where do we put a border?

Re: Poly Network hacker returns $258M after stealing $600M

#120
post #19
post #4

> "Just dumped all assets on [blockchains] BSC & Polygon. Hacking for Good, I did save the project." It's a hot take, and a lot of people will write this off as pretentious and egocentric, but I believe him. Big crypto as a whole has to stop. The original intention of cryptocurrency was to be an experiment (!!!) with providing alternative peer-to-peer transactions that didn't rely on the value of a centralized econom…

1) FCC regulates mostly broadcast technologies, not the stock market (SEC?). 2) The amount of morale hazard we have allowed to build up since the great financial crisis is astronomical. No one has been held to account for that mess and the Too Big To Fail mindset has become deeply entrenched. The fact that no one backstops crypto is one of it's biggest features, we cannot continue to play the world's biggest janitor…

> No one has been held to account for that mess and the Too Big To Fail mindset has become deeply entrenched

People don’t actually want this. The problem in 2008 wasn’t bankers or any other boogieman. The problem is that people want housing to be affordable/accessible, but they also want it to be an investment/retirement plan.

If you subsidise housing to make it affordable (a market distortion in itself), and you encourage appreciation in said market (another distortion) you get bubbles. We stopped this bubble from popping so that boomers didn’t have to take a retirement hit. But Wall St’s role in all of this is insanely small. They played the role of the dealer at a card table. The players are the average Joes and the casino is the Fed.

Post reply on HN