Live data from Hacker News

$625M worth of ETH drained on Axie Infinity's Ronin Network

roninblockchain.substack.com

231–240 of 761 posts

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#231
post #121

"We are working with law enforcement officials..." If the promise of ETH contracts is that code is law and to eliminate needing trust, then how and why would law enforcement get involved? Did the attackers break down the door and steal the money? Or did the provide a widget that met the contract and which just happened to have the unfortunate side-effect of siphoning off tokens, a bug which will be fixed in the next…

It's in the article. Keys were stolen.

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#232
post #197
post #47

In a system run by people, the transaction could be reversed, traced, and the culprits eventually brought to justice. In a system run by algorithms, designed to avoid oversight by people (governments), there is no such powers. There's no reversal. There's no checking the name on the account the transfer was to. It's just gone. I do not understand why people who have legal intentions would want to be part of the crypt…

> In a system run by people, the transaction could be reversed, traced, and the culprits eventually brought to justice. The answer to your question is encoded in the very first block of the very first blockchain. > The Times 03/Jan/2009 Chancellor on brink of second bailout for banks https://en.bitcoin.it/wiki/Genesis_block Some people feel like they weren't being represented by the "justice" you're talking about, so…

I don't think any of that is changed. If anything this allows that injustice to be amplified by those in power.

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#233
post #164

Earlier quoted context omitted.

Where in the world is it common to lose all money deposited in a bank? And, why not just create better banks?

Entire world in late 1920s, Iceland in 2008,Russia currently. Of course my examples are a bit tongue in cheek, much more nuanced and not as "Bank bad" as I paint them to be. But It's entirely possible for a bank run/economic downturn to wipe out a currency overnight. Does that mean crypto is the solution? It sure doesn't seem to be given cases like this (NFT/ETH being rugpulled from/by videogame devs). But I think th…

Currency takes on the value in which people believe it holds. Bitcoin is no different, and would instantly crash in the scenario of a worldwide financial system collapse.

It’s juvenile to believe otherwise, and reaffirms the believe that Crypto is just a 21st century pyramid scheme.

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#234
post #88

Earlier quoted context omitted.

Giving $650mm in USD to a random company is still infinitely safer than doing so with crypto. If a regulated bank claims they got hacked and lost that amount, there are a slew of federal and state laws and agencies in place to investigate it. With crypto, it could very well be in the wallet of the CEO or IT guy and no one would know.

Cryptocurrency theft is illegal and the US government does investigate and prosecute it. [0] https://www.theguardian.com/law/2022/feb/14/us-bitcoin-case-...

Not to anywhere near the extent as they'd investigate and prosecute for $625M stolen from a normal bank.....

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#235
post #47

In a system run by people, the transaction could be reversed, traced, and the culprits eventually brought to justice. In a system run by algorithms, designed to avoid oversight by people (governments), there is no such powers. There's no reversal. There's no checking the name on the account the transfer was to. It's just gone. I do not understand why people who have legal intentions would want to be part of the crypt…

> I do not understand why people who have legal intentions would want to be part of the crypto economy. There's nothing but more risks with zero benefits.

I agree 100% on the risk, and my main problem with it is the avg person getting caught up in it. But at the same time, you see all the "PayPal froze my funds" posts, etc, so obviously the current system is flawed in its own way.

You could imagine a future in which PayPal is a layer on top of Ethereum (or any other L1 chain) and provides reversibility, etc, for a fee, but at the same time the user also has the freedom to eject out of it and take all the funds with them. The maxi "everything must be 100% decentralized" take is a bit naive, so hopefully these accidents help us move in the right direction.

I think long term we might have a lot of the same guard rails we have today, but they'll just be re-built from scratch in a digital-first way, rather than what we currently have.

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#236
post #150

Can someone attempt to explain or speculate at what the attacker is doing with their wallet right now? https://etherscan.io/txs?a=0x098b716b8aaf21512996dc57eb0615e... As I write this at about 17:00 UTC, they seem to be doing lots of small transactions (about $1 USD), and they are coming "From" many different places, but only showing "To" the "Ronin Bridge Exploiter". I don't understand this stuff well enough to see w…

As some other commenters pointed out, those small transactions are all spam.

So I decided to go back in the transaction history and look at what the attacker has done with the funds. So far, it has all been funneled (through about 2 hops), to something called "Huobi 35", e.g. this transaction[0]. Some of these have taken place in just the last few minutes (17:15 UTC or so).

I'm assuming "Huobi 35" is the Huobi exchange?[1] And maybe "Huobi 35" refers to this 35% APY thing they offer?[2]

If that's accurate, why would the attacker take this approach? Won't authorities be storming Huobi's offices and taking the ETH? Is it possible that through Huobi the attacker is able to exchange for other coins very quickly?

If you look at all the transactions leading to Huobi so far it is only a small percentage of the amount stolen, but it's still many millions of dollars...

Also, why'd they wait so long to move into Huobi?

[0] https://etherscan.io/tx/0x075df6c4b44733a0e76aa4947b56b4c0c0...

[1] https://www.huobi.com/

[2] https://www.huobi.com/support/en-us/detail/74899843012340

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#237
post #125

Earlier quoted context omitted.

They think that government is tyranny, therefore lack of government is freedom. Yes, they are dumb as hell.

They forget, freedom to be screwed is also freedom

I don't think anyone actually forgot that. It's kind of the point.

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#238
post #89

Earlier quoted context omitted.

I disagree. It's definitely a trade-off, and there are downsides to it (this security breach being a good example), but there are also advantages. With normal ACH and credit card transactions, the payment never really settles, and can be reverted due to fraud for months. That means I have to slurp up lots of data (privacy?) about my users in order to increase my confidence that they won't try to scam me. And even wit…

What savings? The savings associated with transactions fees (reasonable for very large spends - utterly ridiculous for small amounts, even today after the major drops, at more than 1.7 USD/tx)? The savings associated with double spend fraud that occurs if you don't delay the transaction for 3 to 6 blocks even though you say it's final (hint - that's not true, and waiting is a large downside for prompt processing at a…

> The savings associated with transactions fees (reasonable for very large spends - utterly ridiculous for small amounts, even today after the major drops, at more than 1.7 USD/tx)?

On mainnet ETH, sure, but that arguably shouldn't be used for small payments like you are discussing. There are second layer networks that can do this for pennies on the dollar and make a lot more sense.

And arguably $1.7 USD / tx would compete quite well with credit card transactions. 0.17% vs credit card's 2-3%.

> The savings associated with double spend fraud that occurs if you don't delay the transaction for 3 to 6 blocks even though you say it's final (hint - that's not true, and waiting is a large downside for prompt processing at a point of sale)

Again second layer networks, but even on ETH itself, you're talking 10 - 20 seconds for 1-2 blocks, which is PLENTY. It's not going to be worth carrying out a double spend attack for a few thousand dollar transaction.

I do get that you don't "get" it, but I'll just say - I happily send and receive both BTC and ETH, and it is a night and day difference from sending using traditional bank accounts. I actually feel like I own the money, I can send it to anyone I want at any time, and the transaction settles in seconds. Last time I sent money via ACH, it took a solid 4 days (since I initiated on a Friday). I can deposit money into my crypto backed debit card in under a minute in the middle of a weekend.

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#239

Earlier quoted context omitted.

Here's another preposterous offering: 20% APY "risk free" from owning crypto.

They must just be loaning it out and slaying people endlessly on margin calls.

Congrats, you understand defi better than most degens now.

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#240
post #183

Earlier quoted context omitted.

> I don't recall last time seeing news on someone's bank account being hacked and drained, if anything its mostly family fraud. Anecdote time. My wife and I have a shared checking account that got hacked and drained. First her debit card got skimmed. Then the perp called USAA a half dozen times claiming to be her and asking for account credentials. Finally they got a helpful account rep to reset the password, disable…

I just want to point out that this comment is exactly why social engineering is a problem. You have been a victim of what happens when a company doesn't put in enough effort to verify the identity of the person they have on the phone. Yet when that company starts putting in that effort, you object and call it a "punishment". Convenience and security are often in direct competition with each other. Almost all of us wo…

I call it a punishment because it's over the top. It was a lot of money for an individual, not a lot of money for the bank. So the security should be proportional. Instead of putting in a 10-ton vault door in front of every customer interaction, I'd prefer they only escalated to that level when someone calls in saying things like "I lost my wallet and I'm stuck away from home, give me access to 'my' money, and oh by the way I don't even know my own login name."
Post reply on HN