Live data from Hacker News

$625M worth of ETH drained on Axie Infinity's Ronin Network

roninblockchain.substack.com

321–330 of 761 posts

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#321
post #44

Earlier quoted context omitted.

The only way to apply the court’s judgement (in the case of ETH) is to hark fork, because there is no governance contract in place. A blockchain can in theory support such things, which would allow a majority vote to approve the court’s judgement, but not ETH as it currently stands. Alternatively if you could get enough miners to just collectively agree to replay the blocks without that transaction you could let the…

> The only way to apply the court’s judgement (in the case of ETH) is to hark fork, because there is no governance contract in place. Courts can and do issue orders against any kind of asset in order to enforce justice and unlike smart contracts, their orders are backed by men and women with dogs and guns. Put another way: a court will not say "gee, gosh, if only ETH had a mechanism I could give orders for! I guess I…

> you owe $X and I will seize all assets you have today

Who owes?

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#322
post #43
post #22

This probably sounds like an insanely dumb idea to crypto people, but is it absolutely infeasible to reverse transactions when there's consensus that it's a hack? The TX fees need not be reversed (consider it to be a small price to pay for being hacked). A little bit of centralisation could make the whole network safer. Who is that centralised authority to decide what's a hack, I hear you ask. I don't know, but the a…

Maybe someone could invent the "FDIC" of crypto in smart contract form where everyone pays a periodic premium but if a hack occurs and there is consensus they get a payout. Only problem is everyone would have to use their own wallets for it to work, and for most people it's safer to store large amounts of crypto on an exchange instead of a wallet for personal security reasons.

> and for most people it's safer to store large amounts of crypto on an exchange instead of a wallet for personal security reasons.

This is the opposite of what is usually recommended.

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#324
post #31

I'm out of the loop and trying to understand - people lent over half a billion dollars of their 'real' fake money (ETH) to a game studio so they could transact on the studio's sidechain because gas fees are prohibitively expensive on ETH, and then the game studio got hacked and lost it all? How was this ever going to end any other way? Imagine how preposterous the idea of storing $650mm in USD in a random game studio…

when it comes to banking, random checking accounts are hacked into very rarely. to the point that in USA the FDIC is protecting your account up to $250,000. I don't recall last time seeing news on someone's bank account being hacked and drained, if anything its mostly family fraud. also there are all sorts of checks when you try to wire or withdraw more than $10,000, not to mention wire hundreds of millions. Such tra…

Story time: I also once had my bank account hacked - in a manner of speaking.

I tell you this story in the hopes that it helps you recognize if you have similar flaws in your own security.

I used to run a VNC server on my home PC (flaw 1). Chinese hackers discovered it and spent three weeks brute-forcing the password (flaw 2). Once in, they installed TeamViewer to allow themselves future access. Then, they logged in at 3am and used my browser-saved PayPal credentials (flaw 3) to paypal themselves $5k from my linked chequing account (flaw 4).

I discovered this several days afterwards when I saw the withdrawals hit my bank account. I then found a few further pending Paypal transactions, and pieced the rest together from VNC and router logs.

Thankfully my credit union believed me that I didn't authorize the transactions and reversed them, making me whole again.

But damn, it's a scary feeling having someone break into your computer, not knowing what they might have looked at or accessed. Very similar to having your home broken into.

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#325
post #31

I'm out of the loop and trying to understand - people lent over half a billion dollars of their 'real' fake money (ETH) to a game studio so they could transact on the studio's sidechain because gas fees are prohibitively expensive on ETH, and then the game studio got hacked and lost it all? How was this ever going to end any other way? Imagine how preposterous the idea of storing $650mm in USD in a random game studio…

The chance of $650 million being drained from a game studio’s bank account is significantly less than it being drained from their ETH wallets, at least as of now.

Depends on if the studio's bank account has security questions like "mother's maiden name", "first concert", etc type stuff and an employee with those answers that like to take quizzes on facebook. Otherwise, it could be quite simple to drain the account

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#326
post #278

5 of 9 validator nodes? The Byzantine Generals Problem Leslie Lamport, Robert Shostak, and Marshall Pease (1982) ACM Transactions on Programming Languages and Systems, Vol. 4, No. 3, July 1982, Pages 382-401 https://lamport.azurewebsites.net/pubs/byz.pdf From the abstract: ... It is shown that, using only oral messages, this problem is solvable if and only if more than two-thirds of the generals are loyal; so a singl…

I was thinking how secure DApps built on Cosmos [0] would be. But I guess no matter the theoretical soundness, your DApp's security is as good as your L2 code. And messing around with L1s with no proper security foundation is a recipe for disaster. Re cosmos, if you guys aren't aware it's based on Tendermint [1] which is an advance in the field of consensus.

[0] https://cosmos.network/ [1] https://tendermint.com/

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#327

This is the kind of pain that comes from trusting scammers and nincompoops about unworkable blockchain "scalability" fixes. Here's the sequence. Those dumb enough to ignore it are doomed to repeat the pattern. I'm probably getting some details wrong in this Rube Goldberg scheme, so feel free to correct. 1. Citing "Ethereum network congestion," Axie Infinity announces an ethereum side chain, Ronin.[1] 2. Ronin was a c…

>None of this is new. The Bitcoin "block size war" was fought over this very point. Unworkable scaling schemes are going to end in disaster with no fallback, and no recourse for those who lose money. You end up with nothing, and will be sad.

I don't see the parallel to 'the Bitcoin "block size war"', though? The solution on either side (bigger blocks, lightning network) doesn't require trusting some party to handle transactions.

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#328
post #206

Earlier quoted context omitted.

That's all well and good when the thieves are in the US or a country that will extradite them. What happens when the thieves are operating out of a country without an extradition treaty? In the regular financial world you can at least reverse the transaction. With crypto, is there anything you can do?

You can't always reverse the transaction in regular financial world. It is typically possible if all parties involved act in good faith, and often possible in other cases too, if you act fast, or the bad faith actor is less than competent. However, this is not always the case. Imagine the following scenario: bank A sends $100M to bank B, which then sends it to bank C. By "reversing" the A->B transaction, all you're d…

Reversing erroneous transactions is a useful feature of regular financial system.

Yes. A friend of mine is a branch manager for a major bank. She's one of the people who has to deal with unhappy customers victimized by scams. Recently, she had a customer who wanted to send a significant amount of money to a country in Southeast Asia. That's not unusual for a California bank. Then the customer showed up at the branch in tears. It turned out the customer was being victimized by a "relative in trouble" scam. Fortunately, the receiving bank had flagged the account at their end as suspicious, and hadn't yet let the recipient withdraw the funds. This allowed the transaction to be clawed back. It took phone calls, messages, management signoffs, and work by people in multiple banks to unwind the transaction, but the money was back in the customer's account in the US in a week.

Reversing a fraud transaction in the banking system is a rare event, and not easy, but it is often possible for a few days after the event.

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#329

Earlier quoted context omitted.

There are lots of us that recognize the new capability crypto provides (improved self-custody over assets, currency scarcity not controlled by governments) while also not claiming a new world order. Like most things it's not all or nothing and there are pros and cons.

Hitting yourself in the head with a hammer might offer some benefits: - The cool metal might cool your head on a hot summer day - Might knock yourself unconscious to avoid boredom (could be real handy during long flights!) But these nice features are inseparable from the fact that you're hitting yourself in the head with a hammer, which has many serious downsides, too. The "improved self-custody" crypto offers is one…

This is a comparison dumb enough to basically be in bad faith.

Ignoring that and focusing on the substance:

> "The "improved self-custody" crypto offers is one side of the ledger. The other side is: you lose regulatory protection, and can be swindled with virtually zero repercussions."

Yeah I don't disagree with this - the risks are real. Some of this can improve with better tools, but some is just higher risk that exists with self-custody. You don't need to move 100% of your wealth into crypto (and I'd argue you shouldn't in nearly all cases).

Crypto provides a new capability to take control in a way that other options don't or don't support as well. There is value in this capability even though it has associated risks.

> "Crypto's entire reason for existing is to circumvent government control—it's pretty "new world order" all the way to the core."

Not all governments are good and even good governments can implement bad policy. Self-custody is a lever against the kind of top down CCP like control of entire economies and a totally controlled cashless future. It's also a hedge against stupid actions from your government (like what we're seeing in Russia currently).

New world order suggests replacing the entirety of the existing thing. I'm not suggesting that, I'm focusing on the fact that it offers a new/improved capability that gives individuals more power. I think this is a good thing, but good/bad subjectivity aside it's just a true feature of crypto.

https://www.lesswrong.com/posts/PeSzc9JTBxhaYRp9b/policy-deb...

Re: $625M worth of ETH drained on Axie Infinity's Ronin Network

#330
post #183

Earlier quoted context omitted.

I just want to point out that this comment is exactly why social engineering is a problem. You have been a victim of what happens when a company doesn't put in enough effort to verify the identity of the person they have on the phone. Yet when that company starts putting in that effort, you object and call it a "punishment". Convenience and security are often in direct competition with each other. Almost all of us wo…

I call it a punishment because it's over the top. It was a lot of money for an individual, not a lot of money for the bank. So the security should be proportional. Instead of putting in a 10-ton vault door in front of every customer interaction, I'd prefer they only escalated to that level when someone calls in saying things like "I lost my wallet and I'm stuck away from home, give me access to 'my' money, and oh by…

This type of escalating validation is also ripe for social engineering. You said this person called 10 times. They don't need to do everything in one call. Instead the goal for earlier calls can be to gather information. You gave the example of the person trying to take over the account without knowing the login name. What information would someone need to supply to get the account name? Does that require escalation? If not, what is the value of requiring that as part of the identity validation process?

If the company is going to provide some level of support to people they haven't verified, that support will be abused as a means of passing the verification.

Post reply on HN