Live data from Hacker News

Social engineering scam that nearly cost me all of my ETH

twitter.com

301–310 of 423 posts

Re: Social engineering scam that nearly cost me all of my ETH

#301

Earlier quoted context omitted.

Look: if you want to clutch those hashes to the grave, more power to you. I think the Federalist Papers' authors wouldn't know whether to laugh or cry, but that's the wonderful thing about this little American Experiment of ours. But don't delude yourself into thinking that any meaningful number of people, even cryptocurrency believers, share your position. It's all fun and games until the Men with Sticks show up, an…

I think you mean keys , not hashes. > But don't delude yourself into thinking that any meaningful number of people, even cryptocurrency believers, share your position. You'd be surprised.

> I think you mean keys, not hashes.

Next you're going to tell me that the blockchain isn't made of Lego blocks!

> You'd be surprised.

Given the aggressive spread of custodial services, I don't think I would be. The average cryptocurrency user (even enthusiasts, true believers, &c.) is not a dyed-in-the-wool Burkean. Less prosaically: easy money comes with loose beliefs.

Re: Social engineering scam that nearly cost me all of my ETH

#303
post #280

So I don't know anything about crypto, but stories like this make me think that crypto can never become mainstream. I have been programming since 1970; I worked for major computer companies; I was a computer science professor; I have apps on the App Store. In spite of all of this, I have not the foggiest idea, even after reading the thread, how someone who offers to give me something can use the gift to steal from me…

> but stories like this make me think that crypto can never become mainstream. We had illegal p2p sharing where you could download a virus from bad people and then Jobs came along and made iTunes which set the standard for streaming. I am sure someone will come along in the crypto space and make crypto easy for the rest of us.

itunes isnt p2p

Re: Social engineering scam that nearly cost me all of my ETH

#304
post #289

I can get behind cryptocurrency and stuff, but the idea that anyone can write a contract that says "I get to do what I want with your money" and then build their own custom, one of a kind UI with no way to limit what the user thinks the button does for you to sign such a transaction, it's got to be the biggest, most massive security hole I've ever seen brushed off. You want me to put the title to my house on it? You…

Think of all the scams happening over TCP/IP every day! They built this thing where anyone can pretend to be a bank website? No checks or security? It's laughable. I'm in disbelief. And this is the web?

There are checks in place to make difficult to buy an SSL certificate for the official domain of a bank.

At least Chrome tracks malicious websites.

By comparison, there seem to be no checks in place to prevent writing an ethereym contract that drains a victim’s wallet.

Re: Social engineering scam that nearly cost me all of my ETH

#305
post #238

This was a multi-week long social engineering scam targeted at Thomas. Thomas has a Discord for a drone transportation startup, and the scammers proceeded to embed themselves in the community and provide valuable labor such as web design and graphics design in order to earn his trust. Thomas's wallet is public and advertised on Twitter via his ENS domain. He had $100M+ in aETH, a derivative token provided by Aave whe…

I'm surprised anyone reading this story wouldn't conclude that the real takeaway is to just not engage with cryptocurrency at all. This ecosystem is so convoluted it just turns me off at every level.

Taking a high-velocity ride in a cage of aluminum? I don't want to engage with that at all. I am so surprised that safety measures such as airbags and seat belts are discussed. Obviously cars are too dangerous to exist.

Re: Social engineering scam that nearly cost me all of my ETH

#306

This was a multi-week long social engineering scam targeted at Thomas. Thomas has a Discord for a drone transportation startup, and the scammers proceeded to embed themselves in the community and provide valuable labor such as web design and graphics design in order to earn his trust. Thomas's wallet is public and advertised on Twitter via his ENS domain. He had $100M+ in aETH, a derivative token provided by Aave whe…

I don’t see a bio on his website. Is he anonymous?

Re: Social engineering scam that nearly cost me all of my ETH

#307

I can get behind cryptocurrency and stuff, but the idea that anyone can write a contract that says "I get to do what I want with your money" and then build their own custom, one of a kind UI with no way to limit what the user thinks the button does for you to sign such a transaction, it's got to be the biggest, most massive security hole I've ever seen brushed off. You want me to put the title to my house on it? You…

> it's got to be the biggest, most massive security hole I've ever seen brushed off.

Well said. This goes hand-in-hand with the victim blaming that goes on in cryptocurrency circles. Any time a story like this appears, defenders come out of the woodwork to insist that it's the victim's fault for doing something or not doing something else. Even the linked Twitter thread is full of replies from people suggesting that the author was "asking for it".

Crypto seems to appeal to people who like to think that they are smarter than the average person and therefore will succeed by self-managing their finances right down to the private keys. Adding smart contracts to the mix basically opens up a can of worms that makes it unrealistic to actually control every detail of your money unless you strictly limit each contract to a separate wallet and only transfer funds into that wallet before activating the contract. That's honestly a good strategy if you're sitting on $100mm+ in cryptocurrency and the transaction fees are negligible (as was the case with the Twitter user). However, when transaction fees are $10/each or more, the average crypto user isn't actually doing anything of the sort. They're clicking the buttons and hoping for the best.

Re: Social engineering scam that nearly cost me all of my ETH

#308
post #86

Earlier quoted context omitted.

What exactly is censored when you use paper currency?

The amount. A real example is CNY, which is limit to 100 yuan notes, deliberately to make it hard to move large sums. 1000 USD bills exist but are very rare. 1000 euro note exists but I think that’s on the way out. Your point that cash is censorship resistant is good, yes and we need to make sure it remains, however the physical limitations are defacto censorship.

Sounds like something that only impacts rich people (aka almost no one).

Also I’m not sure that “censor” means what you think it means.

Re: Social engineering scam that nearly cost me all of my ETH

#309
post #238

This was a multi-week long social engineering scam targeted at Thomas. Thomas has a Discord for a drone transportation startup, and the scammers proceeded to embed themselves in the community and provide valuable labor such as web design and graphics design in order to earn his trust. Thomas's wallet is public and advertised on Twitter via his ENS domain. He had $100M+ in aETH, a derivative token provided by Aave whe…

I'm surprised anyone reading this story wouldn't conclude that the real takeaway is to just not engage with cryptocurrency at all. This ecosystem is so convoluted it just turns me off at every level.

agreed; it's all scams at every level, it's just that the pro-crypto people are the scammers or they are enthusiasts who haven't been scammed, yet.

stay away from all of it.

Re: Social engineering scam that nearly cost me all of my ETH

#310
post #289

Earlier quoted context omitted.

Think of all the scams happening over TCP/IP every day! They built this thing where anyone can pretend to be a bank website? No checks or security? It's laughable. I'm in disbelief. And this is the web?

There are checks in place to make difficult to buy an SSL certificate for the official domain of a bank. At least Chrome tracks malicious websites. By comparison, there seem to be no checks in place to prevent writing an ethereym contract that drains a victim’s wallet.

Actually most web3 wallets have their own version of "safe browsing" and track malicious/phishing web3 websites.
Post reply on HN