I haven't seen any evidence there was in fact a hack at all. A digital contract was used in a way that complied with the contract that the bonehead writers of that contract did not intend. That's it. If bad contract writers get to cry "hack" and beg for their money back there is no point to digital contracts at all. If someone had physically or electronically broken into systems and illicitly copied private keys that…
Poly Network hacker returns $258M after stealing $600M
271–280 of 303 posts
Re: Poly Network hacker returns $258M after stealing $600M
#272Earlier quoted context omitted.
> a large number of HN community members are - somewhat ironically - very closed minded The other side of that coin – excessive open-mindedness – however, leads to being susceptible to cults, snake oil salesmen, and hyped up technologies. Crypto currencies, in particular, frequently tick all three boxes. Skepticism is generally a good thing, and so far crypto currency proponents have failed to refute the arguments of…
The Internet also failed to refute the arguments of skeptics until one day it didn't fail and now several of the largest companies in the world are entirely Internet based and providing indisputable value. Cryptocurrency offers new primitives that are unavailable in any other system known to man. It takes time to build up a backbone of technology that can take these new primitives and get them to the point where they…
Re: Poly Network hacker returns $258M after stealing $600M
#273Earlier quoted context omitted.
It’s so funny to me when everyone touts crypto + smart contracts as revolutionary™ then when you follow a system implemented with them to its logical conclusions you have analogs to everything that already exists. Lawyers to audit the contracts for bugs (and yes there can be bugs in a formally verified spec as well), courts to arbitrate disagreements, and an authority to enforce rules when someone finds a security ho…
> It’s so funny to me when everyone touts crypto + smart contracts as revolutionary™ then when you follow a system implemented with them to its logical conclusions you have analogs to everything that already exists. Lawyers to audit the contracts for bugs (and yes there can be bugs in a formally verified spec as well), courts to arbitrate disagreements, and an authority to enforce rules when someone finds a security…
Crypto is like that new car that can have a seat belt but you don't need to. The fact that it still doesn't have that seat belt doesn't means much, just that you need to be aware of it.
For sure any new paradigms will takes time to solve every indirect issues that comes with it, Rome wasn't build in one day.
> Of course, when that happens someone in that community will call it a seat-strap and claim its a revolutionary new invention.
Oh seems like you acknowledge that... but twist it like a bad thing? For sure it will be a great thing to add to cryptos, you just said it yourself that it's something lacking in cryptos...
What's amazing about crypto is the flexibility, the openness, the accessibility. Anyone can join theses networks, thus it can be done anywhere too, and because of the financial incentive, it's gonna happen anywhere. You'll probably say, but there's Western Union, Paypal, Visa, banks, etc... for all that... but check the Chikaordery story from Pleasant Green (as a Canadian I often laugh when the list include Venmo, or any US exclusive service, that just show how so many forget that the US isn't the world).
So yeah, some people will makes mistakes from time to time in their smart contract, it will happens, but we will get better each time to avoid that, when it's needed, just like we did with the previous ways of doing things. We will accept the risk when it can't be done, and that will be it (never heard of fraud using credit card, or bouncing checks? We are just used to them and accept the risks.)
Re: Poly Network hacker returns $258M after stealing $600M
#274Earlier quoted context omitted.
It's also possible that some people understand all of this and still don't think that crypto is a good idea, or that it has worked out well in practice, or that it does anything meaningful.
Ok. In my opinion an algorithmic censor-resistant, deflationary value network is a useful potential technology that can give us potentially the best store-of-value known to mankind so far. Why isn't it meaningful to further research this technology in your opinion? (While mathematicians are researching all kinds of esoteric topics?) In my opinion proof-of-stake research is one of the most-important research topics to…
First, I am very crypto skeptical, but I don't have any problem with "research continuing". However, that's not what I am experiencing. If crypto enthusiasts were off in a lab trying to figure out how to make it solve a real problem then great! Instead, I am the "tech expert" for many of my friends and family, and frequently have them reach out to me as they are on the verge of putting a non trivial amount of money into crypto that they can't afford to lose. Most of these people can barely keep their passwords safe, so I have to spend a lot of time talking them out of it because I care about them. A similar thing happens at work. Some random business exec has a great idea to "use blockchain" for some thing that frankly would be better solved with a regular database. I've had to spend a lot of time convincing business people to not use crypto or NFTs yet.
Second, what you're doing, and many crypto people do this, is identify real problems that would be great if we could solve them. And then you go, "and isn't crypto great because it hasn't solved these problems, but maybe it could". Yeah, maybe, but it hasn't yet. Crypto reminds me of the semantic web people in a lot of ways. They said, "wouldn't it be great if semantic information were embeded in data and APIs could be machine understandable". Sounds a lot like smart contracts doesn't it? Yes, it would be great if we solved that problem, but we never did. The most we got from the semantic web was the semi-useful json-ld you seen in HTML headers for SEO optimization. Here's the thing, the vast vast majority of new ideas don't pan out. It's a lot easier to identify legit problems than it is to solve them. Crypto people get super excited because it would be amazing to solve those problems, BUT there's no good reason to believe it's likely that it will. I say this as someone who spent years trying to get teh semantic web to work. It never did.
Re: Poly Network hacker returns $258M after stealing $600M
#275Re: Poly Network hacker returns $258M after stealing $600M
#276Earlier quoted context omitted.
> It’s so funny to me when everyone touts crypto + smart contracts as revolutionary™ then when you follow a system implemented with them to its logical conclusions you have analogs to everything that already exists. Lawyers to audit the contracts for bugs (and yes there can be bugs in a formally verified spec as well), courts to arbitrate disagreements, and an authority to enforce rules when someone finds a security…
> IMHO, crypto is like a new car with the revolutionary new feature of not having seat belt technology. Crypto is like that new car that can have a seat belt but you don't need to. The fact that it still doesn't have that seat belt doesn't means much, just that you need to be aware of it. For sure any new paradigms will takes time to solve every indirect issues that comes with it, Rome wasn't build in one day. > Of c…
> Crypto is like that new car that can have a seat belt but you don't need to. The fact that it still doesn't have that seat belt doesn't means much, just that you need to be aware of it.
You're missing the point. To put it slightly differently: crypto is like the overconfident kid who thinks seat belts are stupid because he doesn't truly realize he can get into an accident, let alone die. He actually does need a seat belt, he's just not wise enough to realize it. When he gets in an accident and files out his windshield, then he'll discover he wants to use one.
>> Of course, when that happens someone in that community will call it a seat-strap and claim its a revolutionary new invention.
> Oh seems like you acknowledge that... but twist it like a bad thing?
Reinventing the wheel when everyone else around you is riding in cars and on bicycles is not actually inventing anything, let alone anything revolutionary. Then, if you'd previously spent the previous few years mocking wheels as stupid and useless, there's the angle of refusing to acknowledge that you were wrong.
Re: Poly Network hacker returns $258M after stealing $600M
#277Earlier quoted context omitted.
I love how the crypto community encourages circumventing laws, UNTIL someone steals from them using their own “smart” contract then calls on authorities for help.
Can someone explain to me why HN is so anti-crypto?
Lack of methods to handle fraud and abuse is the one hilighted in this thread.
Re: Poly Network hacker returns $258M after stealing $600M
#278From what I recall, the hacker basically doxxed himself by accident by signing a message from his real wallet, linked to exchange wallets which presumably has his KYC info. From there, it was all over. Even if he could launder all that money, international authorities would find him. In fact, the writing style of his messages provide a pretty big clue where he is - Ukraine or Russia.
> In fact, the writing style of his messages provide a pretty big clue where he is - Ukraine or Russia. I think we're past trying to assume peoples identities based on writing styles, it's too easy to fake for the hackers, simply drop 1% of the words you're using and now suddenly people think you're no longer a native English speaker. And not only is it easy to guess wrong or easy for the hacker to fake, it also adds…
Re: Poly Network hacker returns $258M after stealing $600M
#279Earlier quoted context omitted.
Can someone explain to me why HN is so anti-crypto?
Most HN users are wealthy devs or they want to be wealthy devs or startup founders. They have no need for crypto and it threatens where their money is stored- equities and the traditional banking system. The “hackers” traded their soul for money. It’s really no different than a wealthy old man hating crypto. He has no need for it, he doesn’t want others to use it to get past him. He sees no problem with the current w…
The 100 richest ETH wallets own 25% of mined ETH. Many of those wallets are probably owned by the same person/organization. Switching to PoS will make inequality even worse.
Some critics are definitely jelly about not hitting the crypto-lottery...but crypto is not a solution for wealth inequality.
Re: Poly Network hacker returns $258M after stealing $600M
#280Earlier quoted context omitted.
More like a big sign says "A man named Jack may take this wallet", and you're named Jack, so you take the wallet, even though it wasn't meant for you. The smart contract is explicitly defined and on a public ledger. A lost wallet is accidentally left there. The context of it being available to be taken by anyone is not intended. There is no declaration of rules by which you may take it by the owner.
More like a big sign says “Jack may take this wallet, because it belongs to Jack”, and you happen to also be called Jack, even though you're not the Jack the sign was written about, but the sign enforcer only checks that your ID is valid and that you are named Jack.
You can't just expect people not to take free money laying out on a park bench with their name on it...