Earlier quoted context omitted.
Including actually having the money in your wallet!
not your keys, not your crypto :) your crypto won't get stolen if you have good opsec
$625M worth of ETH drained on Axie Infinity's Ronin Network
411–420 of 761 posts
Re: $625M worth of ETH drained on Axie Infinity's Ronin Network
#412Re: $625M worth of ETH drained on Axie Infinity's Ronin Network
#413Earlier quoted context omitted.
> Imagine how preposterous the idea of storing $650mm in USD in a random game studio's checking account would be. But it's decentralized. (Do the same hand movement as if saying "It's got electrolytes")
Its got what the internet craves!
Re: $625M worth of ETH drained on Axie Infinity's Ronin Network
#414This is the kind of pain that comes from trusting scammers and nincompoops about unworkable blockchain "scalability" fixes. Here's the sequence. Those dumb enough to ignore it are doomed to repeat the pattern. I'm probably getting some details wrong in this Rube Goldberg scheme, so feel free to correct. 1. Citing "Ethereum network congestion," Axie Infinity announces an ethereum side chain, Ronin.[1] 2. Ronin was a c…
Is bitcoin's lighting network any different? Just curious
Re: $625M worth of ETH drained on Axie Infinity's Ronin Network
#415Re: $625M worth of ETH drained on Axie Infinity's Ronin Network
#416Earlier quoted context omitted.
Cryptocurrency theft is illegal and the US government does investigate and prosecute it. [0] https://www.theguardian.com/law/2022/feb/14/us-bitcoin-case-...
Sure but it doesn't mean I will get my "money" back like it would with a bank. There is no FDIC for crypto.
Re: $625M worth of ETH drained on Axie Infinity's Ronin Network
#417Re: $625M worth of ETH drained on Axie Infinity's Ronin Network
#418,, Originally, Sky Mavis chose the five out of nine threshold as some nodes didn’t catch up with the chain, or were stuck in syncing state’’ Sounds like a great plan for storing half billion dollars. I’m not blaming the developers, as they are incentivized to move fast and break things, I’m just sorry for all the people who trust new protocols so easily without any knowledge in safe software security practices. Perso…
I am blaming the developers. Perhaps this is not a popular view, but this "blameless" culture is fine and good when it's a random service going down for 15 minutes and you're trying to collaborate and prevent it from happening again. There must be limits though. If you're handling that amount of money in a bank and you fuck it up like this, your ass is on the line, together with the ones who incentivized you to move…
I've been asked on two separate occasions to work on some crypto startup idea. Aside from my skepticism that they were even worthwhile projects, I declined because hell no I'm not writing code that touches other people's money.
Re: $625M worth of ETH drained on Axie Infinity's Ronin Network
#419Earlier quoted context omitted.
> Who is determining our monetary policy then? Who is setting interest rates? Where does the money for a trillion dollar stimulus package come from? I don't know... does the answer to any of these questions suggest to you that the issuance of currency is a government monopoly? If that's the case, you should probably start here: https://en.wikipedia.org/wiki/Monopoly
Yes, controlling the world's reserve currency and forcing others to adopt it fits the definition of monopolizing money. You should probably start here: https://en.wikipedia.org/wiki/Bretton_Woods_system https://www.thebalance.com/what-is-a-petrodollar-3306358 https://www.investopedia.com/terms/r/reservecurrency.asp
Re: $625M worth of ETH drained on Axie Infinity's Ronin Network
#420Earlier quoted context omitted.
I call it a punishment because it's over the top. It was a lot of money for an individual, not a lot of money for the bank. So the security should be proportional. Instead of putting in a 10-ton vault door in front of every customer interaction, I'd prefer they only escalated to that level when someone calls in saying things like "I lost my wallet and I'm stuck away from home, give me access to 'my' money, and oh by…
This type of escalating validation is also ripe for social engineering. You said this person called 10 times. They don't need to do everything in one call. Instead the goal for earlier calls can be to gather information. You gave the example of the person trying to take over the account without knowing the login name. What information would someone need to supply to get the account name? Does that require escalation?…
Back when this happened, that was my first question to USAA and one for which the security guy didn't have a ready answer, though probably it boils down to some version of "we are heavily regulated and continue to rely on software built for mainframes."
There are so many possible ways to mitigate the risk which should be triggered well before a half dozen attempts finally gets to a teller credulous enough to believe their excuses for ignorance.